Garante per la protezione dei dati personali (Italy) - 476/2026
Italy's Garante fines Piaggio €460,000 for unlawful workplace monitoring and delayed data deactivation.
Summary
The Italian Data Protection Authority (Garante) has fined Piaggio €460,000 for unlawfully monitoring employees' emails and logs, and for failing to respond promptly to account deactivation requests. The company retained and examined a significant number of emails from two former employees, which the Garante deemed an unlawful workplace monitoring practice. Additionally, Piaggio did not respond within the statutory deadline to requests confirming the deactivation of corporate email accounts.
Full text
Help Garante per la protezione dei dati personali (Italy) - 476/2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 09:51, 6 August 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators256 edits Tag: Decisions [1.0] (No difference) Latest revision as of 09:51, 6 August 2026 Garante per la protezione dei dati personali - 476/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 12(3) GDPR Article 17 GDPR Article 6 GDPR Article 5(1)(b) GDPR Article 5(1)(c) GDPR Article 5(1)(e) GDPR Article 5(1)(a) GDPR Article 88 GDPR Article 114 of Italian Data Protection Code (Codice in materia di protezione dei dati personali) Type: Complaint Outcome: Upheld Started: 17.07.2023 Decided: 18.06.2026 Published: Fine: 460000.0 EUR Parties: Piaggio National Case Number/Name: 476/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: GPDP (in IT) Initial Contributor: ds The DPA fined Piaggio €460,000 after finding that its long-term retention and examination of employees’ emails and logs enabled unlawful workplace monitoring and that it had failed to respond to account deactivation requests. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts Two former employees (the data subjects) of Piaggio (the controller) were dismissed for just cause in March 2023. Following the termination of their employment, they asked the controller to confirm that the individualised corporate email accounts assigned to them had been deactivated. The controller did not respond within the one-month deadline under Article 12(3) GDPR and they reiterated their request. The controller again did not respond within the statutory period and the data subjects lodged complaints with the Italian DPA (Garante). The data subjects also filed subsequent complaints arguing that the controller had accessed their previous email correspondence and used the messages in the disciplinary proceedings against them. They alleged that the controller had collected at least 18 emails sent or received through one data subject’s account, dating from November 2020 to January 2022, and 94 emails sent or received through the other data subject’s account, some dating back to April 2020. The correspondence also included emails exchanged with personal email accounts and third parties. The controller stated that, following internal reports received in November 2022 concerning possible serious misconduct by the two data subjects, it decided to conduct an internal investigation. According to the controller, the investigation was limited to their corporate email accounts, used predefined filters and keywords and was conducted following a balancing assessment and consultation with its DPO. It maintained that the investigation constituted a defensive control intended solely to investigate possible unlawful conduct and protect corporate assets, not to systematically monitor its employees. The controller further relied on its internal policy, which mentioned that employees should not expect confidentiality in relation to communications, messages or files created, received or stored through company systems. Regarding the unanswered requests, the controller argued that the data subjects had neither expressly requested the deletion of specific personal data nor referred to any provision of the GDPR. It stated that the accounts had already been deactivated on 16 February 2023 and permanently deleted on 27 April 2023, and that no one had accessed them following their deactivation. The controller also maintained that, because litigation concerning their dismissals was pending, the relevant emails had to be retained in order to protect its right of defence. Furthermore, the controller stated that it retained backups of corporate emails throughout the employment relationship and for an additional five years following its termination, while the related email logs were retained for six months. It argued that these periods were necessary for information security, business continuity, responding to potential claims and defending its interests before courts or public authorities. It also argued that the corporate email constituted a tool used by employees to perform their work and that retaining email during the employment relationship therefore did not require a prior trade-union agreement under Article 4 of the Italian Workers’ Statute. After the proceedings began, the controller reduced the retention period for emails to three months following termination of employment and the retention period for logs to 21 days. It also revised its internal policies and adopted additional technical and organisational measures. Holding Regarding the data subjects’ requests, the DPA held that both an individualised corporate email address and the correspondence associated with it constituted personal data relating to the employee. According to the DPA, a request to deactivate such an account therefore amounted to a request to cease the related processing, even where the data subject did not expressly refer to the GDPR or identify a particular data subject right. It also noted that the data subjects had requested only confirmation that their accounts had been deactivated, not the deletion of the emails relied upon in the employment dispute. It stated that even where the protection of legal proceedings may justify delaying or restricting the exercise of a data subject right, the controller must provide a reasoned response within the applicable period and inform the data subject of the available administrative and judicial remedies. The DPA found that the controller therefore infringed Article 12(3) GDPR in conjunction with Article 17 GDPR. With regard to the internal investigation, the DPA noted that a defensive control may be permissible where there is a specific and well-founded suspicion of unlawful conduct. It emphasised that the check must concern data or conduct occurring after the emergence of that specific suspicion. It pointed out that in the present case, the suspicion arose in November 2022, but the controller examined correspondence dating back as far as approximately two years earlier. It held that the investigation was therefore retrospective and relied on data that had already been systematically collected and retained before any specific suspicion arose. It noted that the use of keywords, filters and a balancing assessment did not remedy this. In addition, the DPA held that the controller’s stated purposes were formulated too generally to justify retaining the complete correspondence of all employees throughout their employment and for an additional five years. It concluded that the controller’s practice lacked an appropriate legal basis under Article 6 GDPR and infringed the principles of purpose limitation under Article 5(1)(b), data minimisation under Article 5(1)(c) and storage limitation under Article 5(1)(e) GDPR. The DPA further rejected the controller’s position that employees should have no expectation of confidentiality in relation to communications and files stored on company systems. It held that both the content of emails and their metadata concerned correspondence protected by the right to privacy and secrecy of communications. It stressed that employees retain a reasonable expectation of privacy in the workplace. The DPA distinguished between the email service itself, which may constitute a tool used by employees to perform their work, and the separate systems used to systematically collect, retain and process email content and metadata. These systems operate independently of the employee’s ordinary use of email and may enable the employer to reconstruct the employee’s activities. It noted that this possibility was confirmed b