Back to Feed
PolicyJul 28, 2026

Garante per la protezione dei dati personali (Italy) - 462/2026

Italian DPA fines company €6,600 for unlawfully processing former employee's personal data.

Summary

The Italian DPA has fined Cosmint S.p.A. €6,600 for unlawfully processing a former employee's personal data. The company opened and emptied the employee's locker in his absence, destroying its contents, and recorded the process with a smartphone. The DPA ruled that the locker's contents constituted personal data and the actions taken were unlawful processing operations under GDPR.

Full text

Help Garante per la protezione dei dati personali (Italy) - 462/2026: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 23:19, 28 July 2026 view source Carloc (talk | contribs)714 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 23:19, 28 July 2026 Garante per la protezione dei dati personali - 462/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 2(1) GDPR Article 4(1) GDPR Article 4(2) GDPR Article 5(1)(a) GDPR Article 5(1)(c) GDPR Article 6(1)(b) GDPR Article 6(1)(c) GDPR Article 6(2) GDPR Article 13 GDPR Type: Complaint Outcome: Upheld Started: 18.04.2024 Decided: 18.06.2026 Published: Fine: 6600.0 EUR Parties: Cosmint S.p.A. A former employee An unnamed staffing agency National Case Number/Name: 462/2026 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Italian Original Source: GPDP (in IT) Initial Contributor: Carloc The DPA held that a company unlawfully processed a former employee's personal data by opening and emptying his locker in his absence. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The case involves a worker (the data subject), his former employer (the controller), and the staffing agency that had provided the company with the worker. In late 2023 the data subject learned that its working relationship with the controller would soon end. The data subject called in sick and did not show up to work again. When his contract ran out, some of his belongings were still in a locker in its workplace. Over the month of January, the data subject booked and annulled several appointments with the controller to empty his locker. In this phase, communications between the controller and the data subject were mediated by the staffing agency. Eventually, the controller opened and emptied the locker. The opening took place the day before the last planned appointment and roughly one month since the data subject had last worked for the controller. A collaborator of the controller (specifically, a member of the external security staff) record the opening of the locker with her personal smartphone, in order to defend the controller from possible claims over missing items. Inside the locker, the controller found some of its own products which could no longer be sold, along with personal items of intimate use which could not be preserved due to hygiene concerns. All the contents were destroyed. The data subject later learned that the controller had opened his locked and filed a complaint. He claimed that the opening of its locker constituted an unlawful processing of his personal data. In its defense, the controller protested that the content subject’s locker, did not constitute personal data as defined under Article 4(1) GDPR. The controller also put forward the alternative argument that the emptying of the locker, did not fall under Article 2(1) GDPR (i.e.: it was neither an automated processing of personal data, nor a non-automated processing of personal data “which form part of a filing system or are intended to form part of a filing system”). Finally, the controller claimed that in any case, the processing would have been justified under its legitimate interest to free up the data subject’s locker and make it available to other employees. Holding On the position of the former employer On the material scope of the GDPR First, the DPA found that the personal items in the locker constituted personal data under Article 4(1) GDPR because they provided information about an identified natural person (i.e.: the data subject). Secondarily, the DPA held that the opening of the locker, the examination of its content, the filming of the operation, and the subsequent destruction of the contents, constituted data processing operations for the purpose of Article 4(2) GDPR. In this regard, the DPA clarified that the notion of “data protection” is to be understood broadly and that the data processing operation, listed in the Article, are mere examples. Finally, the DPA held that the notion of a “filing system” under Article 2(1) GDPR, must also be construed broadly. On these grounds, the DPA held that the case fell within the material scope of the GDPR. On lawfulness The DPA first clarified that in the context of an employment relationship. an employer may only process employees’ data on the legal grounds of contractual necessity (6(1)(b) GDPR) and legal obligation (6(1)(c) GDPR). Therefore, the processing could not be based on legitimate interest. Furthermore, the DPA held that the controller did not balance its legitimate interest correctly. In this regard, the DPA observed that the reasonable expectation of data subjects, are relevant to the assessment of the balancing of legitimate interest. In the case at hand, the data subject had agreed to an appointment in order to empty his locker and, therefore, could not reasonably expect that the locker would be opened beforehand. On these grounds, the DPA held that the processing of personal data was unlawful. On transparency and fairness The DPA held that the controller failed to provide workers with written information on its locker room policy. Furthermore, the DPA found that the controller failed to inform the worker about the urgency of clearing out his locker. In the DPA’s view, the controller should have communicated this urgency more clearly and should have given the data subject an ultimatum to clear his locker within a specific deadline. The DPA also found that the controller failed to inform the data subject about the opening of his locker, even after it had taken place. On these grounds, the DPA found a violation of Article 13 GDPR. The DPA also clarified that within the employment relationship, the obligation to provide information to data subjects is a consequence of the general principle of fairness. On these grounds, the DPA found a violation of Article 5(1)(a) GDPR. Other findings The DPA held that the controller processed personal data very invasively by viewing items of personal and intimate nature. On these grounds, the DPA found a violation of the principle of of data minimization. On the position of the staffing agency As explained above, the staffing agency was not directly involved in the opening of the locker but served as a messenger between the data subject and the controller, in order to help solve the locker issue. During the procedure, the staffing agency claimed that it had no role in the processing of personal data at hand, as it was not part of the employement relationship between the data subject and the controller. The DPA did not counter the argument and did not issue any findings with regards to the position and responsibilities of the staffing agency. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10268633] Decision of June 18, 2026 Register of Decisions No. 462 of June 18, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, members; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter, the “Regulation”); HAVING REGARD TO the Code on Data Protection, containing provisions for the adaptation of national law to Regulation (EU) 2016/679 (Legislative Decree No. 196 of June 30, 2003, as amended by Legislative Decree No. 101 of August 10, 2018, hereinafter the “Code”); HAVING REGARD TO the complaint filed by Mr. XX against Cosmint S.p.A.; HAVING EXAMINED the documentation on file; HAVING REGARD

Entities

Cosmint S.p.A. (vendor)