[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbMeMic1ZHWZtRbPkBGmfJd80H90iOaOFfcKj4hYf48c":3},{"article":4,"iocs":42},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"3928bad1-b3b5-4310-853c-2693dd6cb47e","Garante per la protezione dei dati personali (Italy) - 476\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-476-2026-3149c2","← Older revision Revision as of 13:11, 11 August 2026 (5 intermediate revisions by the same user not shown) Line 125: Line 125: The data subjects also filed subsequent complaints arguing that the controller had accessed their previous email correspondence and used the messages in the disciplinary proceedings against them. They alleged that the controller had collected at least 18 emails sent or received through one data subject’s account, dating from November 2020 to January 2022, and 94 emails sent or received through the other data subject’s account, some dating back to April 2020. The correspondence also included emails exchanged with personal email accounts and third parties. The data subjects also filed subsequent complaints arguing that the controller had accessed their previous email correspondence and used the messages in the disciplinary proceedings against them. They alleged that the controller had collected at least 18 emails sent or received through one data subject’s account, dating from November 2020 to January 2022, and 94 emails sent or received through the other data subject’s account, some dating back to April 2020. The correspondence also included emails exchanged with personal email accounts and third parties. The controller stated that, following internal reports received in November 2022 concerning possible serious misconduct by the two data subjects, it decided to conduct an internal investigation. According to the controller, the investigation was limited to their corporate email accounts, used predefined filters and keywords and was conducted following a balancing assessment and consultation with its DPO. It maintained that the investigation constituted a defensive control intended solely to investigate possible unlawful conduct and protect corporate assets, not to systematically monitor its employees. The controller further relied on its internal policy, which mentioned that employees should not expect confidentiality in relation to communications, messages or files created, received or stored through company systems. The controller stated that, following internal reports received in November 2022 concerning possible serious misconduct by the two data subjects, it decided to conduct an internal investigation. The controller characterised these checks as “defensive controls”, namely targeted checks intended to verify suspected serious unlawful conduct by the employees and to protect corporate assets. According to the controller, the investigation was limited to their corporate email accounts, used predefined filters and keywords and was conducted following a balancing assessment and consultation with its DPO. It maintained that the investigation constituted a defensive control intended solely to investigate possible unlawful conduct and protect corporate assets, not to systematically monitor its employees. The controller further relied on its internal policy, which mentioned that all messages sent or received on the email system that pertained to the performance of work duties were and remained its property and that the company email account might be subject to monitoring by the controller. Regarding the unanswered requests, the controller argued that the data subjects had neither expressly requested the deletion of specific personal data nor referred to any provision of the GDPR. It stated that the accounts had already been deactivated on 16 February 2023 and permanently deleted on 27 April 2023, and that no one had accessed them following their deactivation. The controller also maintained that, because litigation concerning their dismissals was pending, the relevant emails had to be retained in order to protect its right of defence. Regarding the unanswered requests, the controller argued that the data subjects had neither expressly requested the deletion of specific personal data nor referred to any provision of the GDPR. It stated that the accounts had already been deactivated on 16 February 2023 and permanently deleted on 27 April 2023, and that no one had accessed them following their deactivation. The controller also maintained that, because litigation concerning their dismissals was pending, the relevant emails had to be retained in order to protect its right of defence. Line 135: Line 135: === Holding === === Holding === Regarding the data subjects’ requests, the DPA held that both an individualised corporate email address and the correspondence associated with it constituted personal data relating to the employee. According to the DPA, a request to deactivate such an account therefore amounted to a request to cease the related processing, even where the data subject did not expressly refer to the GDPR or identify a particular data subject right. It also noted that the data subjects had requested only confirmation that their accounts had been deactivated, not the deletion of the emails relied upon in the employment dispute. It stated that even where the protection of legal proceedings may justify delaying or restricting the exercise of a data subject right, the controller must provide a reasoned response within the applicable period and inform the data subject of the available administrative and judicial remedies. The DPA found that the controller therefore infringed [[Article 12 GDPR|Article 12(3) GDPR]] in conjunction with [[Article 17 GDPR]]. Regarding the data subjects’ requests, the DPA held that both an individualised corporate email address and the correspondence associated with it constituted personal data relating to the employee. According to the DPA, a request to deactivate such an account therefore amounted to a request to cease the related processing, even where the data subject did not expressly refer to the GDPR or identify a particular data subject right. It stated that even where the protection of legal proceedings may justify delaying or restricting the exercise of a data subject right, the controller must provide a reasoned response within the applicable period and inform the data subject of the available administrative and judicial remedies. The DPA found that the controller therefore infringed [[Article 12 GDPR|Article 12(3) GDPR]] in conjunction with [[Article 17 GDPR]]. With regard to the internal investigation, the DPA noted that a defensive control may be permissible where there is a specific and well-founded suspicion of unlawful conduct. It emphasised that the check must concern data or conduct occurring after the emergence of that specific suspicion. It pointed out that in the present case, the suspicion arose in November 2022, but the controller examined correspondence dating back as far as approximately two years earlier. It held that the investigation was therefore retrospective and relied on data that had already been systematically collected and retained before any specific suspicion arose. It noted that the use of keywords, filters and a balancing assessment did not remedy this. With regard to the internal investigation, the DPA referred to Italian Supreme Court case law according to which defensive controls may be carried out where there is a well-founded suspicion of unlawful conduct, provided that an appropriate balance is struck between the employer’s interests and the employee’s dignity and privacy, and that the control concerns data acquired after the suspicion arose. It pointed out that in the present case, the suspicion arose in November 2022, but the controller examined correspondence dating back as far as approximately two years earlier. It held that the investigation was therefore retrospective and relied on data that had already been systematically collected and retained before any specific suspicion arose. It noted that the use of keywords, filters and a balancing assessment did not remedy this. In addition, the DPA held that the controller’s stated purposes were formulated too generally to justify retaining the complete correspondence of all employees throughout their employment and for an additional five years. It concluded that the controller’s practice lacked an appropriate legal basis under [[Article 6 GDPR]] and infringed the principles of purpose limitation under Article 5(1)(b) GDPR, data minimisation under Article 5(1)(c) GDPR and storage limitation under [[Article 5 GDPR|Article 5(1)(e) GDPR]]. In addition, the DPA held that the controller’s stated purposes were formulated too generally to justify retaining the complete correspondence of all employees throughout their employment and for an additional five years. The DPA concluded that no appropriate legal basis under [[Article 6 GDPR]] applied because the controller had not demonstrated that its extensive retention was necessary for a specific and predetermined purpose. It further found that the controller infringed the principles of purpose limitation under Article 5(1)(b) GDPR, data minimisation under Article 5(1)(c) GDPR and storage limitation under [[Article 5 GDPR|Article 5(1)(e) GDPR]]. The DPA further rejected the controller’s position that employees should have no expectation of confidentiality in relation to communications and files stored on company systems. It held that both the content of emails and their metadata concerned correspondence protected by the right to privacy and secrecy of communications. It stressed that employees retain a reasonable expectation of privacy in the workplace. The DPA distinguished between the email service itself, which may constitute a tool used by employees to perform their work, and the separate systems used to systematically collect, retain and process email content and metadata. These systems operate independently of the employee’s ordinary use of email and may enable the employer to reconstruct the employee’s activities. It noted that this possibility was confirmed by the controller’s own policies. The DPA concluded that the systematic retention and subsequent use of the data enabled the controller to reconstruct and monitor employees’ activities. It further found that this monitoring had been carried out without the safeguards required under Italian labour law. It ruled that the controller infringed [[Article 5 GDPR|Article 5(1)(a) GDPR]] and [[Article 88 GDPR]], together with Article 114 of the Italian Data Protection Code. The DPA further rejected the controller’s position that employees should have no expectation of confidentiality in relation to communications and files stored on company systems. It held that both the content of emails and their metadata concerned correspondence protected by the right to privacy and secrecy of communications. It stressed that employees retain a reasonable expectation of privacy in the workplace. The DPA distinguished between the email service itself, which may constitute a tool used by employees to perform their work, and the separate systems used to systematically collect, retain and process email content and metadata. These systems operate independently of the employee’s ordinary use of email and may enable the employer to reconstruct the employee’s activities. It noted that this possibility was confirmed by the controller’s own policies. The DPA concluded that the systematic retention and subsequent use of the data enabled the controller to reconstruct and monitor employees’ activities. It further found that this monitoring had been carried out without the safeguards required under Italian labour law. It ruled that the controller infringed [[Article 5 GDPR|Article 5(1)(a) GDPR]] and [[Article 88 GDPR]], together with Article 114 of the Italian Data Protection Code. The DPA also found unlawful the controller’s policy allowing, even with the former employee’s consent, their email address to remain active for up to 30 days and permitting incoming messages or the contents of the mailbox to be forwarded or transferred to another employee for broadly defined service needs. The DPA also held that the controller’s policy was unlawful insofar as it allowed a former employee’s email address to remain active for up to 30 days, even with their consent, and permitted incoming messages or mailbox contents to be forwarded or transferred to another employee on the basis of broadly defined service needs. Finally, the DPA held that the controller had not demonstrated how and when the two data subjects had been informed about the processing. It noted that its policies did not sufficiently specify the purposes and legal bases for retaining emails and logs. It pointed out that even its revised policy did not adequately explain the specific purposes of the processing. It held that the controller therefore infringed the transparency principle under [[Article 5 GDPR|Article 5(1)(a) GDPR]] and its information obligations under [[Article 13 GDPR]]. Finally, the DPA held that the controller had not demonstrated how and when the two data subjects had been informed about the processing. It noted that its policies did not sufficiently specify the purposes and legal bases for retaining emails and logs. It pointed out that even its revised policy did not adequately explain the specific purposes of the processing. It held that the controller therefore infringed the transparency principle under [[Article 5 GDPR|Article 5(1)(a) GDPR]] and its information obligations under [[Article 13 GDPR]]. The DPA imposed a fine of €460,000 and prohibited the controller from accessing the email data collected and retained on its corporate systems. The DPA imposed a fine of €460,000 and prohibited the controller from accessing the email data that had been unlawfully collected and retained on its corporate systems. == Comment == == Comment ==","The Italian Data Protection Authority (Garante) has fined a company €460,000 for unlawfully accessing and using employee email correspondence in disciplinary proceedings. The DPA found that the company's investigation was retrospective, examining emails dating back two years before a suspicion arose, violating GDPR principles of purpose limitation, data minimisation, and storage limitation. The authority also ruled that employees retain a reasonable expectation of privacy in the workplace, and the company's monitoring practices lacked proper safeguards and transparency.","Italian DPA fines company €460K for unlawful employee email monitoring.","Help Garante per la protezione dei dati personali (Italy) - 476\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 07:38, 10 August 2026 view sourceDs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators272 editsm Tag: Visual edit← Older edit Latest revision as of 13:11, 11 August 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators272 editsmTag: Visual edit (5 intermediate revisions by the same user not shown)Line 125: Line 125: The data subjects also filed subsequent complaints arguing that the controller had accessed their previous email correspondence and used the messages in the disciplinary proceedings against them. They alleged that the controller had collected at least 18 emails sent or received through one data subject’s account, dating from November 2020 to January 2022, and 94 emails sent or received through the other data subject’s account, some dating back to April 2020. The correspondence also included emails exchanged with personal email accounts and third parties.The data subjects also filed subsequent complaints arguing that the controller had accessed their previous email correspondence and used the messages in the disciplinary proceedings against them. They alleged that the controller had collected at least 18 emails sent or received through one data subject’s account, dating from November 2020 to January 2022, and 94 emails sent or received through the other data subject’s account, some dating back to April 2020. The correspondence also included emails exchanged with personal email accounts and third parties. The controller stated that, following internal reports received in November 2022 concerning possible serious misconduct by the two data subjects, it decided to conduct an internal investigation. According to the controller, the investigation was limited to their corporate email accounts, used predefined filters and keywords and was conducted following a balancing assessment and consultation with its DPO. It maintained that the investigation constituted a defensive control intended solely to investigate possible unlawful conduct and protect corporate assets, not to systematically monitor its employees. The controller further relied on its internal policy, which mentioned that employees should not expect confidentiality in relation to communications, messages or files created, received or stored through company systems.The controller stated that, following internal reports received in November 2022 concerning possible serious misconduct by the two data subjects, it decided to conduct an internal investigation. The controller characterised these checks as “defensive controls”, namely targeted checks intended to verify suspected serious unlawful conduct by the employees and to protect corporate assets. According to the controller, the investigation was limited to their corporate email accounts, used predefined filters and keywords and was conducted following a balancing assessment and consultation with its DPO. It maintained that the investigation constituted a defensive control intended solely to investigate possible unlawful conduct and protect corporate assets, not to systematically monitor its employees. The controller further relied on its internal policy, which mentioned that all messages sent or received on the email system that pertained to the performance of work duties were and remained its property and that the company email account might be subject to monitoring by the controller. Regarding the unanswered requests, the controller argued that the data subjects had neither expressly requested the deletion of specific personal data nor referred to any provision of the GDPR. It stated that the accounts had already been deactivated on 16 February 2023 and permanently deleted on 27 April 2023, and that no one had accessed them following their deactivation. The controller also maintained that, because litigation concerning their dismissals was pending, the relevant emails had to be retained in order to protect its right of defence. Regarding the unanswered requests, the controller argued that the data subjects had neither expressly requested the deletion of specific personal data nor referred to any provision of the GDPR. It stated that the accounts had already been deactivated on 16 February 2023 and permanently deleted on 27 April 2023, and that no one had accessed them following their deactivation. The controller also maintained that, because litigation concerning their dismissals was pending, the relevant emails had to be retained in order to protect its right of defence. Line 135: Line 135: === Holding ====== Holding === Regarding the data subjects’ requests, the DPA held that both an individualised corporate email address and the correspondence associated with it constituted personal data relating to the employee. According to the DPA, a request to deactivate such an account therefore amounted to a request to cease the related processing, even where the data subject did not expressly refer to the GDPR or identify a particular data subject right. It also noted that the data subjects had requested only confirmation that their accounts had been deactivated, not the deletion of the emails relied upon in the employment dispute. It stated that even where the protection of legal proceedings may justify delaying or restricting the exercise of a data subject right, the controller must provide a reasoned response within the applicable period and inform the data subject of the available administrative and judicial remedies. The DPA found that the controller therefore infringed [[Article 12 GDPR|Article 12(3) GDPR]] in conjunction with [[Article 17 GDPR]].Regarding the data subjects’ requests, the DPA held that both an individualised corporate email address and the correspondence associated with it constituted personal data relating to the employee. According to the DPA, a request to deactivate such an account therefore amounted to a request to cease the related processing, even where the data subject did not expressly refer to the GDPR or identify a particular data subject right. It stated that even where the protection of legal proceedings may justify delaying or restricting the exercise of a data subject right, the controller must provide a reasoned response within the applicable period and inform the data subject of the available administrative and judicial remedies. The DPA found that the controller therefore infringed [[Article 12 GDPR|Article 12(3) GDPR]] in conjunction with [[Article 17 GDPR]]. With regard to the internal investigation, the DPA noted that a defensive control may be permissible where there is a specific and well-founded suspicion of unlawful conduct. It emphasised that the check must concern data or conduct occurring after the emergence of that specific suspicion. It pointed out that in the present case, the suspicion arose in November 2022, but the controller examined correspondence dating back as far as approximately two years earlier. It held that the investigation was therefore retrospective and relied on data that had already been systematically collected and retained before any specific suspicion arose. It noted that the use of keywords, filters and a balancing assessment did not remedy this. With regard to the internal investigation, the DPA referred to Italian Supreme Court case law according to which defensive controls may be carried out where there is a well-founded suspicion of unlawful conduct, provided that an appropriate balance is struck between the employer’s interests and the employee’s dignity and privacy, and that the control concerns data acquired after the suspicion arose. It pointed out that in the present case, the suspicion arose in November 2022, but the controller examined correspondence dating back as far as approxi","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_476\u002F2026&diff=52664&oldid=52644","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-08-11T13:11:05+00:00","2026-08-11T14:00:22.944585+00:00",7,[18],{"name":19,"type":20},"Garante per la protezione dei dati personali","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,32,37],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":38},{"id":39,"icon":23,"name":40,"slug":41},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]