[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f8AhXlWYK9KqbnrBVbRRBVpN--VNT8lWq3xMKL4OE2fA":3},{"article":4,"iocs":39},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"88ff3ab2-fada-460e-8257-f956e693b4a5","Garante per la protezione dei dati personali (Italy) - 462\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-462-2026-8b2fdf","Mainly wording and repetitions ← Older revision Revision as of 14:42, 4 August 2026 Line 135: Line 135: Over the month of January, the data subject booked and annulled several appointments with the controller to empty his locker. In this phase, communications between the controller and the data subject were mediated by the staffing agency. Eventually, the controller opened and emptied the locker. The opening took place the day before the last planned appointment and roughly one month since the data subject had last worked for the controller. Over the month of January, the data subject booked and annulled several appointments with the controller to empty his locker. In this phase, communications between the controller and the data subject were mediated by the staffing agency. Eventually, the controller opened and emptied the locker. The opening took place the day before the last planned appointment and roughly one month since the data subject had last worked for the controller. A collaborator of the controller (specifically, a member of the external security staff) record the opening of the locker with her personal smartphone, in order to defend the controller from possible claims over missing items. Inside the locker, the controller found some of its own products which could no longer be sold, along with personal items of intimate use which could not be preserved due to hygiene concerns. All the contents were destroyed. A collaborator of the controller (specifically, a member of the external security staff) recorded the opening of the locker with her personal smartphone, in order to defend the controller from possible claims over missing items. Inside the locker, the controller found some of its own products which could no longer be sold, along with personal items of intimate use which could not be preserved due to hygiene concerns. All the contents were destroyed. The data subject later learned that the controller had opened his locked and filed a complaint. He claimed that the opening of its locker constituted an unlawful processing of his personal data. The data subject later learned that the controller had opened his locked and filed a complaint. He claimed that the opening of its locker constituted an unlawful processing of his personal data. In its defense, the controller protested that the content subject’s locker, did not constitute personal data as defined under [[Article 4 GDPR|Article 4(1) GDPR]]. The controller also put forward the alternative argument that the emptying of the locker, did not fall under [[Article 2 GDPR|Article 2(1) GDPR]] (i.e.: it was neither an automated processing of personal data, nor a non-automated processing of personal data “which form part of a filing system or are intended to form part of a filing system”). Finally, the controller claimed that in any case, the processing would have been justified under its legitimate interest to free up the data subject’s locker and make it available to other employees. In its defense, the controller protested that the content of the data subject’s locker, did not constitute personal data as defined under [[Article 4 GDPR|Article 4(1) GDPR]]. The controller also put forward the alternative argument that the emptying of the locker, did not fall under [[Article 2 GDPR|Article 2(1) GDPR]] (i.e.: it was neither an automated processing of personal data, nor a non-automated processing of personal data “which form part of a filing system or are intended to form part of a filing system”). Finally, the controller claimed that in any case, the processing would have been justified under its legitimate interest to free up the data subject’s locker and make it available to other employees. === Holding === === Holding === Line 146: Line 146: ===== On the material scope of the GDPR ===== ===== On the material scope of the GDPR ===== First, the DPA found that the personal items in the locker constituted personal data under [[Article 4 GDPR|Article 4(1) GDPR]] because they provided information about an identified natural person (i.e.: the data subject) The DPA referenced its own case law in this regard: in [[Garante per la protezione dei dati personali (Italy) - 9509515|Garante per la protezione dei dati personali (Italy) - 235\u002F2020]] the DPA held itself competent to decide a somewhat similar case. It is worth mentioning, however, that the decision does not explicitly deal with the applicability of the GDPR to the case. . First, the DPA found that the personal items in the locker constituted personal data under [[Article 4 GDPR|Article 4(1) GDPR]] because they provided information about an identified natural person (i.e.: the data subject). The DPA referenced its own case law in this regard: in [[Garante per la protezione dei dati personali (Italy) - 9509515|Garante per la protezione dei dati personali (Italy) - 235\u002F2020]] the DPA held itself competent to decide a somewhat similar case. It is worth mentioning, however, that the decision does not explicitly deal with the applicability of the GDPR to the case. Secondarily, the DPA held that the opening of the locker, the filming of the operation, and the subsequent destruction of the employee's belongings, constituted data processing operations for the purpose of [[Article 4 GDPR|Article 4(2) GDPR]]. In this regard, the DPA clarified that the notion of “data processing” is to be understood broadly The DPA referenced CJEU, Case [[CJEU - C-175\u002F20 - Valsts ieņēmumu dienests (Processing of personal data for tax purposes)|C-175\u002F20, ''Valsts ieņēmumu dienests'']], 24 February 2022 and [[CJEU - C-579\u002F21 - Pankki S|Case C-579\u002F21, ''Pankki S'']], 22 June 2023 and that the data processing operation, listed in the Article, are mere examples. Second, the DPA held that the opening of the locker, the filming of the operation, and the subsequent destruction of the employee's belongings, constituted data processing operations for the purpose of [[Article 4 GDPR|Article 4(2) GDPR]]. In this regard, the DPA clarified that the notion of “data processing” is to be understood broadly The DPA referenced CJEU, Case [[CJEU - C-175\u002F20 - Valsts ieņēmumu dienests (Processing of personal data for tax purposes)|C-175\u002F20, ''Valsts ieņēmumu dienests'']], 24 February 2022 and [[CJEU - C-579\u002F21 - Pankki S|Case C-579\u002F21, ''Pankki S'']], 22 June 2023. and that the data processing operations, listed in the Article, are mere examples. Finally, the DPA held that the notion of a “filing system” under [[Article 2 GDPR|Article 2(1) GDPR]], must also be construed broadly The DPA referenced CJEU, [[CJEU - C-25\u002F17 - Jehovan todistajat|Case C-25\u002F17, ''Jehovan todistajat'']], 10 July 2018. . Finally, the DPA held that the notion of a “filing system” under [[Article 2 GDPR|Article 2(1) GDPR]], must also be construed broadly. The DPA referenced CJEU, [[CJEU - C-25\u002F17 - Jehovan todistajat|Case C-25\u002F17, ''Jehovan todistajat'']], 10 July 2018. On these grounds, the DPA held that the case fell within the material scope of the GDPR. On these grounds, the DPA held that the case fell within the material scope of the GDPR. ===== On lawfulness ===== ===== On lawfulness ===== The DPA held that legitimate interest interest was not a viable legal basis in the case at hand. Furthermore, the DPA held that the controller did not balance its legitimate interest correctly anyway. In this regard, the DPA observed that the reasonable expectation of data subjects, are relevant to the balancing of legitimate interest [https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX:62022CJ0621 CJEU, Case C-621\u002F22, ''Koninklijke Nederlandse Lawn Tennisbond''], 4 October 2024. . In the case at hand, the data subject had agreed to an appointment in order to empty his locker and, therefore, could not reasonably expect that the locker would be opened beforehand. The DPA held that legitimate interest was not a viable legal basis in the case at hand. Furthermore, the DPA held that the controller did not balance its legitimate interest correctly anyway. In this regard, the DPA observed that the reasonable expectation of data subjects are relevant to the balancing of legitimate interests. [https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX:62022CJ0621 CJEU, Case C-621\u002F22, ''Koninklijke Nederlandse Lawn Tennisbond''], 4 October 2024. In the case at hand, the data subject had agreed to an appointment in order to empty his locker and, therefore, could not reasonably expect that the locker would be opened beforehand. On these grounds, the DPA held that the processing of personal data was unlawful. On these grounds, the DPA held that the processing of personal data was unlawful. Line 168: Line 168: On these grounds, the DPA found a violation of [[Article 13 GDPR]]. On these grounds, the DPA found a violation of [[Article 13 GDPR]]. The DPA also clarified that within the employment relationship, the obligation to provide information to data subjects is a consequence of the general principle of fairness. On these grounds, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(a) GDPR]]. The DPA also clarified that within the employment relationship the obligation to provide information to data subjects is a consequence of the general principle of fairness. On these grounds, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(a) GDPR]]. ===== Other findings ===== ===== Other findings ===== The DPA held that the controller processed personal data very invasively by viewing items of personal and intimate nature. On these grounds, the DPA found a violation of the principle of of data minimization. The DPA held that the controller processed personal data very invasively by viewing items of personal and intimate nature. On these grounds, the DPA found a violation of the principle of data minimization. ==== On the position of the staffing agency ==== ==== On the position of the staffing agency ==== As explained above, the staffing agency was not directly involved in the opening of the locker but served as a messenger between the data subject and the controller, in order to help solve the locker issue. During the procedure, the staffing agency claimed that it had no role in the processing of personal data at hand, as it was not part of the employement relationship between the data subject and the controller. In this regard, the agency pointed out to a professional code of conduct for the sector. As explained above, the staffing agency was not directly involved in the opening of the locker but served as a messenger between the data subject and the controller, in order to help solve the locker issue. During the procedure, the staffing agency claimed that it had no role in the processing of personal data at hand, as it was not part of the employment relationship between the data subject and the controller. In this regard, the agency pointed out to a professional code of conduct for the sector. The DPA did not counter the argument and did not issue any findings with regards to the position and responsibilities of the staffing agency. The DPA did not counter the argument and did not issue any findings with regards to the position and responsibilities of the staffing agency.","The Italian Data Protection Authority (Garante) ruled that personal items found in an employee's locker constitute personal data under GDPR. The controller's actions of opening the locker, filming the process, and destroying the contents were deemed unlawful data processing. The DPA rejected the controller's defense of legitimate interest, citing the employee's reasonable expectation of privacy and the lack of proper balancing of interests.","Italian DPA rules employee locker contents are personal data, processing unlawful.","Help Garante per la protezione dei dati personali (Italy) - 462\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 10:12, 30 July 2026 view sourceCarloc (talk | contribs)719 edits ← Older edit Latest revision as of 14:42, 4 August 2026 view source Fm (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators109 editsm Tag: Visual edit Line 135: Line 135: Over the month of January, the data subject booked and annulled several appointments with the controller to empty his locker. In this phase, communications between the controller and the data subject were mediated by the staffing agency. Eventually, the controller opened and emptied the locker. The opening took place the day before the last planned appointment and roughly one month since the data subject had last worked for the controller.Over the month of January, the data subject booked and annulled several appointments with the controller to empty his locker. In this phase, communications between the controller and the data subject were mediated by the staffing agency. Eventually, the controller opened and emptied the locker. The opening took place the day before the last planned appointment and roughly one month since the data subject had last worked for the controller. A collaborator of the controller (specifically, a member of the external security staff) record the opening of the locker with her personal smartphone, in order to defend the controller from possible claims over missing items. Inside the locker, the controller found some of its own products which could no longer be sold, along with personal items of intimate use which could not be preserved due to hygiene concerns. All the contents were destroyed.A collaborator of the controller (specifically, a member of the external security staff) recorded the opening of the locker with her personal smartphone, in order to defend the controller from possible claims over missing items. Inside the locker, the controller found some of its own products which could no longer be sold, along with personal items of intimate use which could not be preserved due to hygiene concerns. All the contents were destroyed. The data subject later learned that the controller had opened his locked and filed a complaint. He claimed that the opening of its locker constituted an unlawful processing of his personal data.The data subject later learned that the controller had opened his locked and filed a complaint. He claimed that the opening of its locker constituted an unlawful processing of his personal data. In its defense, the controller protested that the content subject’s locker, did not constitute personal data as defined under [[Article 4 GDPR|Article 4(1) GDPR]]. The controller also put forward the alternative argument that the emptying of the locker, did not fall under [[Article 2 GDPR|Article 2(1) GDPR]] (i.e.: it was neither an automated processing of personal data, nor a non-automated processing of personal data “which form part of a filing system or are intended to form part of a filing system”). Finally, the controller claimed that in any case, the processing would have been justified under its legitimate interest to free up the data subject’s locker and make it available to other employees.In its defense, the controller protested that the content of the data subject’s locker, did not constitute personal data as defined under [[Article 4 GDPR|Article 4(1) GDPR]]. The controller also put forward the alternative argument that the emptying of the locker, did not fall under [[Article 2 GDPR|Article 2(1) GDPR]] (i.e.: it was neither an automated processing of personal data, nor a non-automated processing of personal data “which form part of a filing system or are intended to form part of a filing system”). Finally, the controller claimed that in any case, the processing would have been justified under its legitimate interest to free up the data subject’s locker and make it available to other employees. === Holding ====== Holding === Line 146: Line 146: ===== On the material scope of the GDPR ========== On the material scope of the GDPR ===== First, the DPA found that the personal items in the locker constituted personal data under [[Article 4 GDPR|Article 4(1) GDPR]] because they provided information about an identified natural person (i.e.: the data subject)\u003Cref>The DPA referenced its own case law in this regard: in [[Garante per la protezione dei dati personali (Italy) - 9509515|Garante per la protezione dei dati personali (Italy) - 235\u002F2020]] the DPA held itself competent to decide a somewhat similar case. It is worth mentioning, however, that the decision does not explicitly deal with the applicability of the GDPR to the case.\u003C\u002Fref>.First, the DPA found that the personal items in the locker constituted personal data under [[Article 4 GDPR|Article 4(1) GDPR]] because they provided information about an identified natural person (i.e.: the data subject).\u003Cref>The DPA referenced its own case law in this regard: in [[Garante per la protezione dei dati personali (Italy) - 9509515|Garante per la protezione dei dati personali (Italy) - 235\u002F2020]] the DPA held itself competent to decide a somewhat similar case. It is worth mentioning, however, that the decision does not explicitly deal with the applicability of the GDPR to the case.\u003C\u002Fref> Secondarily, the DPA held that the opening of the locker, the filming of the operation, and the subsequent destruction of the employee's belongings, constituted data processing operations for the purpose of [[Article 4 GDPR|Article 4(2) GDPR]]. In this regard, the DPA clarified that the notion of “data processing” is to be understood broadly\u003Cref>The DPA referenced CJEU, Case [[CJEU - C-175\u002F20 - Valsts ieņēmumu dienests (Processing of personal data for tax purposes)|C-175\u002F20, ''Valsts ieņēmumu dienests'']], 24 February 2022 and [[CJEU - C-579\u002F21 - Pankki S|Case C-579\u002F21, ''Pankki S'']], 22 June 2023\u003C\u002Fref> and that the data processing operation, listed in the Article, are mere examples.Second, the DPA held that the opening of the locker, the filming of the operation, and the subsequent destruction of the employee's belongings, constituted data processing operations for the purpose of [[Article 4 GDPR|Article 4(2) GDPR]]. In this regard, the DPA clarified that the notion of “data processing” is to be understood broadly\u003Cref>The DPA referenced CJEU, Case [[CJEU - C-175\u002F20 - Valsts ieņēmumu dienests (Processing of personal data for tax purposes)|C-175\u002F20, ''Valsts ieņēmumu dienests'']], 24 February 2022 and [[CJEU - C-579\u002F21 - Pankki S|Case C-579\u002F21, ''Pankki S'']], 22 June 2023.\u003C\u002Fref> and that the data processing operations, listed in the Article, are mere examples. Finally, the DPA held that the notion of a “filing system” under [[Article 2 GDPR|Article 2(1) GDPR]], must also be construed broadly\u003Cref>The DPA referenced CJEU, [[CJEU - C-25\u002F17 - Jehovan todistajat|Case C-25\u002F17, ''Jehovan todistajat'']], 10 July 2018.\u003C\u002Fref>.Finally, the DPA held that the notion of a “filing system” under [[Article 2 GDPR|Article 2(1) GDPR]], must also be construed broadly.\u003Cref>The DPA referenced CJEU, [[CJEU - C-25\u002F17 - Jehovan todistajat|Case C-25\u002F17, ''Jehovan todistajat'']], 10 July 2018.\u003C\u002Fref> On these grounds, the DPA held that the case fell within the material scope of the GDPR.On these grounds, the DPA held that the case fell within the material scope of the GDPR. ===== On lawfulness ========== On lawfulness ===== The DPA held that legitimate interest interest was not a viable legal basis in the case at hand. Furthermore, the DPA held that the controller did not balance its legitimate interest correctly anyway. In this regard, the DPA observed that the reasonable expectation of data subjects, are relevant to the balancing of legitimate interest\u003Cref>[https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX:62022CJ0621 CJEU, Case C-621\u002F22, ''Konink","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_462\u002F2026&diff=52609&oldid=52559","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-08-04T14:42:39+00:00","2026-08-04T16:00:18.583628+00:00",7,[18],{"name":19,"type":20},"Garante per la protezione dei dati personali","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,32,37],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":38},{"id":21,"icon":23,"name":24,"slug":25},[]]