The document is a report on the implementation of the GDPR in the Italian banking sector, highlighting the need for a specific IT Action Plan to guide banks in complying with data protection regulations. It includes a synoptic framework of the necessary technological actions and an integrated meta-model for data governance. It describes the main areas of intervention, including management of data subjects' rights, data retention, security, and supplier management, also presenting practical tools such as templates for the treatment register and data breach management.