[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6oC8iZnnUrbAp_ogmc4gPh7oaF_6TaR1iMppwxrydsU":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"94345992-9c72-4805-b531-a55a48bf1603","Garante per la protezione dei dati personali (Italy) - 462\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-462-2026-8e1575","forgot about the fine amount. Fixed ← Older revision Revision as of 23:48, 28 July 2026 (4 intermediate revisions by the same user not shown) Line 124: Line 124: }} }} The DPA held that a company unlawfully processed a former employee's personal data by opening and emptying his locker in his absence. The DPA held that a company unlawfully processed a former employee's personal data by opening and emptying his locker in his absence. The authority issued a €6,600 fine. == English Summary == == English Summary == Line 140: Line 140: In its defense, the controller protested that the content subject’s locker, did not constitute personal data as defined under [[Article 4 GDPR|Article 4(1) GDPR]]. The controller also put forward the alternative argument that the emptying of the locker, did not fall under [[Article 2 GDPR|Article 2(1) GDPR]] (i.e.: it was neither an automated processing of personal data, nor a non-automated processing of personal data “which form part of a filing system or are intended to form part of a filing system”). Finally, the controller claimed that in any case, the processing would have been justified under its legitimate interest to free up the data subject’s locker and make it available to other employees. In its defense, the controller protested that the content subject’s locker, did not constitute personal data as defined under [[Article 4 GDPR|Article 4(1) GDPR]]. The controller also put forward the alternative argument that the emptying of the locker, did not fall under [[Article 2 GDPR|Article 2(1) GDPR]] (i.e.: it was neither an automated processing of personal data, nor a non-automated processing of personal data “which form part of a filing system or are intended to form part of a filing system”). Finally, the controller claimed that in any case, the processing would have been justified under its legitimate interest to free up the data subject’s locker and make it available to other employees. === Holding === ==== On the position of the former employer ==== The DPA issued a €6,600 fine over the violation of Articles 5, 6, and 13 GDPR. === Holding === ===== On the material scope of the GDPR ===== On the position of the former employer First, the DPA found that the personal items in the locker constituted personal data under [[Article 4 GDPR|Article 4(1) GDPR]] because they provided information about an identified natural person (i.e.: the data subject) The DPA referenced its own case law in this regard: see [[Garante per la protezione dei dati personali (Italy) - 9509515|Garante per la protezione dei dati personali (Italy) - 235\u002F2020]]. . On the material scope of the GDPR First, the DPA found that the personal items in the locker constituted personal data under [[Article 4 GDPR|Article 4(1) GDPR]] because they provided information about an identified natural person (i.e.: the data subject). Secondarily, the DPA held that the opening of the locker, the examination of its content, the filming of the operation, and the subsequent destruction of the contents, constituted data processing operations for the purpose of [[Article 4 GDPR|Article 4(2) GDPR]]. In this regard, the DPA clarified that the notion of “data protection” is to be understood broadly and that the data processing operation, listed in the Article, are mere examples. Secondarily, the DPA held that the opening of the locker, the examination of its content, the filming of the operation, and the subsequent destruction of the contents, constituted data processing operations for the purpose of [[Article 4 GDPR|Article 4(2) GDPR]]. In this regard, the DPA clarified that the notion of “data protection” is to be understood broadly The DPA referenced CJEU, Case [[CJEU - C-175\u002F20 - Valsts ieņēmumu dienests (Processing of personal data for tax purposes)|C-175\u002F20, ''Valsts ieņēmumu dienests'']], 24 February 2022 and [[CJEU - C-579\u002F21 - Pankki S|Case C-579\u002F21, ''Pankki S'']], 22 June 2023 and that the data processing operation, listed in the Article, are mere examples. Finally, the DPA held that the notion of a “filing system” under [[Article 2 GDPR|Article 2(1) GDPR]], must also be construed broadly. Finally, the DPA held that the notion of a “filing system” under [[Article 2 GDPR|Article 2(1) GDPR]], must also be construed broadly The DPA referenced CJEU, [[CJEU - C-25\u002F17 - Jehovan todistajat|Case C-25\u002F17, ''Jehovan todistajat'']], 10 July 2018. . On these grounds, the DPA held that the case fell within the material scope of the GDPR. On these grounds, the DPA held that the case fell within the material scope of the GDPR. On lawfulness ===== On lawfulness ===== The DPA first clarified that in the context of an employment relationship. an employer may only process employees’ data on the legal grounds of contractual necessity (6(1)(b) GDPR) and legal obligation (6(1)(c) GDPR). Therefore, the processing could not be based on legitimate interest. The DPA first clarified that in the context of an employment relationship, an employer may only process employees’ data on the legal grounds of contractual necessity (6(1)(b) GDPR) and legal obligation (6(1)(c) GDPR). Therefore, the processing could not be based on legitimate interest. Furthermore, the DPA held that the controller did not balance its legitimate interest correctly. In this regard, the DPA observed that the reasonable expectation of data subjects, are relevant to the assessment of the balancing of legitimate interest. In the case at hand, the data subject had agreed to an appointment in order to empty his locker and, therefore, could not reasonably expect that the locker would be opened beforehand. Furthermore, the DPA held that the controller did not balance its legitimate interest correctly. In this regard, the DPA observed that the reasonable expectation of data subjects, are relevant to the balancing of legitimate interest [https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX:62022CJ0621 CJEU, Case C-621\u002F22, ''Koninklijke Nederlandse Lawn Tennisbond''], 4 October 2024. . In the case at hand, the data subject had agreed to an appointment in order to empty his locker and, therefore, could not reasonably expect that the locker would be opened beforehand. On these grounds, the DPA held that the processing of personal data was unlawful. On these grounds, the DPA held that the processing of personal data was unlawful. On transparency and fairness ===== On transparency and fairness ===== The DPA held that the controller failed to provide workers with written information on its locker room policy. The DPA held that the controller failed to provide workers with written information on its locker room policy. Line 167: Line 168: The DPA also found that the controller failed to inform the data subject about the opening of his locker, even after it had taken place. The DPA also found that the controller failed to inform the data subject about the opening of his locker, even after it had taken place. On these grounds, the DPA found a violation of [[Article 13 GDPR|Article 13 GDPR]]. On these grounds, the DPA found a violation of [[Article 13 GDPR]]. The DPA also clarified that within the employment relationship, the obligation to provide information to data subjects is a consequence of the general principle of fairness. On these grounds, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(a) GDPR]]. The DPA also clarified that within the employment relationship, the obligation to provide information to data subjects is a consequence of the general principle of fairness. On these grounds, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(a) GDPR]]. Other findings ===== Other findings ===== The DPA held that the controller processed personal data very invasively by viewing items of personal and intimate nature. On these grounds, the DPA found a violation of the principle of of data minimization. The DPA held that the controller processed personal data very invasively by viewing items of personal and intimate nature. On these grounds, the DPA found a violation of the principle of of data minimization. On the position of the staffing agency ==== On the position of the staffing agency ==== As explained above, the staffing agency was not directly involved in the opening of the locker but served as a messenger between the data subject and the controller, in order to help solve the locker issue. During the procedure, the staffing agency claimed that it had no role in the processing of personal data at hand, as it was not part of the employement relationship between the data subject and the controller. As explained above, the staffing agency was not directly involved in the opening of the locker but served as a messenger between the data subject and the controller, in order to help solve the locker issue. During the procedure, the staffing agency claimed that it had no role in the processing of personal data at hand, as it was not part of the employement relationship between the data subject and the controller. In this regard, the agency pointed out to a professional code of conduct for the sector. The DPA did not counter the argument and did not issue any findings with regards to the position and responsibilities of the staffing agency. The DPA did not counter the argument and did not issue any findings with regards to the position and responsibilities of the staffing agency.","The Italian Data Protection Authority (Garante) has fined a company €6,600 for unlawfully processing a former employee's personal data. The company opened and emptied the employee's locker in his absence, which the DPA ruled constituted data processing under GDPR. The DPA found the processing unlawful due to violations of transparency, fairness, and data minimization principles, and because the employer could not rely on legitimate interest for such actions in an employment context.","Italian DPA fines company €6,600 for unlawfully processing former employee's personal data.","Help Garante per la protezione dei dati personali (Italy) - 462\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 23:19, 28 July 2026 view sourceCarloc (talk | contribs)714 edits Tag: Decisions [1.0] Latest revision as of 23:48, 28 July 2026 view source Carloc (talk | contribs)714 edits Tag: Visual edit (4 intermediate revisions by the same user not shown)Line 124: Line 124: }}}} The DPA held that a company unlawfully processed a former employee's personal data by opening and emptying his locker in his absence.The DPA held that a company unlawfully processed a former employee's personal data by opening and emptying his locker in his absence. The authority issued a €6,600 fine. == English Summary ==== English Summary == Line 140: Line 140: In its defense, the controller protested that the content subject’s locker, did not constitute personal data as defined under [[Article 4 GDPR|Article 4(1) GDPR]]. The controller also put forward the alternative argument that the emptying of the locker, did not fall under [[Article 2 GDPR|Article 2(1) GDPR]] (i.e.: it was neither an automated processing of personal data, nor a non-automated processing of personal data “which form part of a filing system or are intended to form part of a filing system”). Finally, the controller claimed that in any case, the processing would have been justified under its legitimate interest to free up the data subject’s locker and make it available to other employees.In its defense, the controller protested that the content subject’s locker, did not constitute personal data as defined under [[Article 4 GDPR|Article 4(1) GDPR]]. The controller also put forward the alternative argument that the emptying of the locker, did not fall under [[Article 2 GDPR|Article 2(1) GDPR]] (i.e.: it was neither an automated processing of personal data, nor a non-automated processing of personal data “which form part of a filing system or are intended to form part of a filing system”). Finally, the controller claimed that in any case, the processing would have been justified under its legitimate interest to free up the data subject’s locker and make it available to other employees. === Holding === ==== On the position of the former employer ==== The DPA issued a €6,600 fine over the violation of Articles 5, 6, and 13 GDPR. === Holding ======== On the material scope of the GDPR ===== On the position of the former employerFirst, the DPA found that the personal items in the locker constituted personal data under [[Article 4 GDPR|Article 4(1) GDPR]] because they provided information about an identified natural person (i.e.: the data subject)\u003Cref>The DPA referenced its own case law in this regard: see [[Garante per la protezione dei dati personali (Italy) - 9509515|Garante per la protezione dei dati personali (Italy) - 235\u002F2020]].\u003C\u002Fref>. On the material scope of the GDPR First, the DPA found that the personal items in the locker constituted personal data under [[Article 4 GDPR|Article 4(1) GDPR]] because they provided information about an identified natural person (i.e.: the data subject). Secondarily, the DPA held that the opening of the locker, the examination of its content, the filming of the operation, and the subsequent destruction of the contents, constituted data processing operations for the purpose of [[Article 4 GDPR|Article 4(2) GDPR]]. In this regard, the DPA clarified that the notion of “data protection” is to be understood broadly and that the data processing operation, listed in the Article, are mere examples.Secondarily, the DPA held that the opening of the locker, the examination of its content, the filming of the operation, and the subsequent destruction of the contents, constituted data processing operations for the purpose of [[Article 4 GDPR|Article 4(2) GDPR]]. In this regard, the DPA clarified that the notion of “data protection” is to be understood broadly\u003Cref>The DPA referenced CJEU, Case [[CJEU - C-175\u002F20 - Valsts ieņēmumu dienests (Processing of personal data for tax purposes)|C-175\u002F20, ''Valsts ieņēmumu dienests'']], 24 February 2022 and [[CJEU - C-579\u002F21 - Pankki S|Case C-579\u002F21, ''Pankki S'']], 22 June 2023\u003C\u002Fref> and that the data processing operation, listed in the Article, are mere examples. Finally, the DPA held that the notion of a “filing system” under [[Article 2 GDPR|Article 2(1) GDPR]], must also be construed broadly.Finally, the DPA held that the notion of a “filing system” under [[Article 2 GDPR|Article 2(1) GDPR]], must also be construed broadly\u003Cref>The DPA referenced CJEU, [[CJEU - C-25\u002F17 - Jehovan todistajat|Case C-25\u002F17, ''Jehovan todistajat'']], 10 July 2018.\u003C\u002Fref>. On these grounds, the DPA held that the case fell within the material scope of the GDPR.On these grounds, the DPA held that the case fell within the material scope of the GDPR. On lawfulness===== On lawfulness ===== The DPA first clarified that in the context of an employment relationship. an employer may only process employees’ data on the legal grounds of contractual necessity (6(1)(b) GDPR) and legal obligation (6(1)(c) GDPR). Therefore, the processing could not be based on legitimate interest.The DPA first clarified that in the context of an employment relationship, an employer may only process employees’ data on the legal grounds of contractual necessity (6(1)(b) GDPR) and legal obligation (6(1)(c) GDPR). Therefore, the processing could not be based on legitimate interest. Furthermore, the DPA held that the controller did not balance its legitimate interest correctly. In this regard, the DPA observed that the reasonable expectation of data subjects, are relevant to the assessment of the balancing of legitimate interest. In the case at hand, the data subject had agreed to an appointment in order to empty his locker and, therefore, could not reasonably expect that the locker would be opened beforehand.Furthermore, the DPA held that the controller did not balance its legitimate interest correctly. In this regard, the DPA observed that the reasonable expectation of data subjects, are relevant to the balancing of legitimate interest\u003Cref>[https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX:62022CJ0621 CJEU, Case C-621\u002F22, ''Koninklijke Nederlandse Lawn Tennisbond''], 4 October 2024.\u003C\u002Fref>. In the case at hand, the data subject had agreed to an appointment in order to empty his locker and, therefore, could not reasonably expect that the locker would be opened beforehand. On these grounds, the DPA held that the processing of personal data was unlawful.On these grounds, the DPA held that the processing of personal data was unlawful. On transparency and fairness===== On transparency and fairness ===== The DPA held that the controller failed to provide workers with written information on its locker room policy.The DPA held that the controller failed to provide workers with written information on its locker room policy. Line 167: Line 168: The DPA also found that the controller failed to inform the data subject about the opening of his locker, even after it had taken place.The DPA also found that the controller failed to inform the data subject about the opening of his locker, even after it had taken place. On these grounds, the DPA found a violation of [[Article 13 GDPR|Article 13 GDPR]].On these grounds, the DPA found a violation of [[Article 13 GDPR]]. The DPA also clarified that within the employment relationship, the obligation to provide information to data subjects is a consequence of the general principle of fairness. On these grounds, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(a) GDPR]].The DPA also clarified that within the employment relationship, the obligation to provide information to data subjects is a consequence of the general principle of fairness. On these grounds, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(a) GDPR]]. Other findings===== Other findings ===== The DPA held that the controller proce","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_462\u002F2026&diff=52525&oldid=52520","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-07-28T23:48:10+00:00","2026-07-29T00:00:33.60819+00:00",7,[18],{"name":19,"type":20},"Garante per la protezione dei dati personali","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,32,37,39],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":38},{"id":21,"icon":23,"name":24,"slug":25},{"category":40},{"id":41,"icon":23,"name":42,"slug":43},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]