Back to Feed
PolicyAug 11, 2026

Garante per la protezione dei dati personali (Italy) - 476/2026

Italian DPA fines company €460K for unlawful employee email monitoring.

Summary

The Italian Data Protection Authority (Garante) has fined a company €460,000 for unlawfully accessing and using employee email correspondence in disciplinary proceedings. The DPA found that the company's investigation was retrospective, examining emails dating back two years before a suspicion arose, violating GDPR principles of purpose limitation, data minimisation, and storage limitation. The authority also ruled that employees retain a reasonable expectation of privacy in the workplace, and the company's monitoring practices lacked proper safeguards and transparency.

Full text

Help Garante per la protezione dei dati personali (Italy) - 476/2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 07:38, 10 August 2026 view sourceDs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators272 editsm Tag: Visual edit← Older edit Latest revision as of 13:11, 11 August 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators272 editsmTag: Visual edit (5 intermediate revisions by the same user not shown)Line 125: Line 125: The data subjects also filed subsequent complaints arguing that the controller had accessed their previous email correspondence and used the messages in the disciplinary proceedings against them. They alleged that the controller had collected at least 18 emails sent or received through one data subject’s account, dating from November 2020 to January 2022, and 94 emails sent or received through the other data subject’s account, some dating back to April 2020. The correspondence also included emails exchanged with personal email accounts and third parties.The data subjects also filed subsequent complaints arguing that the controller had accessed their previous email correspondence and used the messages in the disciplinary proceedings against them. They alleged that the controller had collected at least 18 emails sent or received through one data subject’s account, dating from November 2020 to January 2022, and 94 emails sent or received through the other data subject’s account, some dating back to April 2020. The correspondence also included emails exchanged with personal email accounts and third parties. The controller stated that, following internal reports received in November 2022 concerning possible serious misconduct by the two data subjects, it decided to conduct an internal investigation. According to the controller, the investigation was limited to their corporate email accounts, used predefined filters and keywords and was conducted following a balancing assessment and consultation with its DPO. It maintained that the investigation constituted a defensive control intended solely to investigate possible unlawful conduct and protect corporate assets, not to systematically monitor its employees. The controller further relied on its internal policy, which mentioned that employees should not expect confidentiality in relation to communications, messages or files created, received or stored through company systems.The controller stated that, following internal reports received in November 2022 concerning possible serious misconduct by the two data subjects, it decided to conduct an internal investigation. The controller characterised these checks as “defensive controls”, namely targeted checks intended to verify suspected serious unlawful conduct by the employees and to protect corporate assets. According to the controller, the investigation was limited to their corporate email accounts, used predefined filters and keywords and was conducted following a balancing assessment and consultation with its DPO. It maintained that the investigation constituted a defensive control intended solely to investigate possible unlawful conduct and protect corporate assets, not to systematically monitor its employees. The controller further relied on its internal policy, which mentioned that all messages sent or received on the email system that pertained to the performance of work duties were and remained its property and that the company email account might be subject to monitoring by the controller. Regarding the unanswered requests, the controller argued that the data subjects had neither expressly requested the deletion of specific personal data nor referred to any provision of the GDPR. It stated that the accounts had already been deactivated on 16 February 2023 and permanently deleted on 27 April 2023, and that no one had accessed them following their deactivation. The controller also maintained that, because litigation concerning their dismissals was pending, the relevant emails had to be retained in order to protect its right of defence. Regarding the unanswered requests, the controller argued that the data subjects had neither expressly requested the deletion of specific personal data nor referred to any provision of the GDPR. It stated that the accounts had already been deactivated on 16 February 2023 and permanently deleted on 27 April 2023, and that no one had accessed them following their deactivation. The controller also maintained that, because litigation concerning their dismissals was pending, the relevant emails had to be retained in order to protect its right of defence. Line 135: Line 135: === Holding ====== Holding === Regarding the data subjects’ requests, the DPA held that both an individualised corporate email address and the correspondence associated with it constituted personal data relating to the employee. According to the DPA, a request to deactivate such an account therefore amounted to a request to cease the related processing, even where the data subject did not expressly refer to the GDPR or identify a particular data subject right. It also noted that the data subjects had requested only confirmation that their accounts had been deactivated, not the deletion of the emails relied upon in the employment dispute. It stated that even where the protection of legal proceedings may justify delaying or restricting the exercise of a data subject right, the controller must provide a reasoned response within the applicable period and inform the data subject of the available administrative and judicial remedies. The DPA found that the controller therefore infringed [[Article 12 GDPR|Article 12(3) GDPR]] in conjunction with [[Article 17 GDPR]].Regarding the data subjects’ requests, the DPA held that both an individualised corporate email address and the correspondence associated with it constituted personal data relating to the employee. According to the DPA, a request to deactivate such an account therefore amounted to a request to cease the related processing, even where the data subject did not expressly refer to the GDPR or identify a particular data subject right. It stated that even where the protection of legal proceedings may justify delaying or restricting the exercise of a data subject right, the controller must provide a reasoned response within the applicable period and inform the data subject of the available administrative and judicial remedies. The DPA found that the controller therefore infringed [[Article 12 GDPR|Article 12(3) GDPR]] in conjunction with [[Article 17 GDPR]]. With regard to the internal investigation, the DPA noted that a defensive control may be permissible where there is a specific and well-founded suspicion of unlawful conduct. It emphasised that the check must concern data or conduct occurring after the emergence of that specific suspicion. It pointed out that in the present case, the suspicion arose in November 2022, but the controller examined correspondence dating back as far as approximately two years earlier. It held that the investigation was therefore retrospective and relied on data that had already been systematically collected and retained before any specific suspicion arose. It noted that the use of keywords, filters and a balancing assessment did not remedy this. With regard to the internal investigation, the DPA referred to Italian Supreme Court case law according to which defensive controls may be carried out where there is a well-founded suspicion of unlawful conduct, provided that an appropriate balance is struck between the employer’s interests and the employee’s dignity and privacy, and that the control concerns data acquired after the suspicion arose. It pointed out that in the present case, the suspicion arose in November 2022, but the controller examined correspondence dating back as far as approxi

Entities

Garante per la protezione dei dati personali (vendor)