[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fn2t3KIlhD33S01LUI0YYdrHn8hqzPCXFtBvASjA_Ab8":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"0c6e66ff-74e0-46ef-97fe-293bb2584604","Garante per la protezione dei dati personali (Italy) - 476\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-476-2026-61924d","word GDPR added in holding ← Older revision Revision as of 07:38, 10 August 2026 Line 135: Line 135: === Holding === === Holding === Regarding the data subjects’ requests, the DPA held that both an individualised corporate email address and the correspondence associated with it constituted personal data relating to the employee. According to the DPA, a request to deactivate such an account therefore amounted to a request to cease the related processing, even where the data subject did not expressly refer to the GDPR or identify a particular data subject right. It also noted that the data subjects had requested only confirmation that their accounts had been deactivated, not the deletion of the emails relied upon in the employment dispute. It stated that even where the protection of legal proceedings may justify delaying or restricting the exercise of a data subject right, the controller must provide a reasoned response within the applicable period and inform the data subject of the available administrative and judicial remedies. The DPA found that the controller therefore infringed [[Article 12 GDPR|Article 12(3) GDPR]] in conjunction with [[Article 17 GDPR|Article 17 GDPR]]. Regarding the data subjects’ requests, the DPA held that both an individualised corporate email address and the correspondence associated with it constituted personal data relating to the employee. According to the DPA, a request to deactivate such an account therefore amounted to a request to cease the related processing, even where the data subject did not expressly refer to the GDPR or identify a particular data subject right. It also noted that the data subjects had requested only confirmation that their accounts had been deactivated, not the deletion of the emails relied upon in the employment dispute. It stated that even where the protection of legal proceedings may justify delaying or restricting the exercise of a data subject right, the controller must provide a reasoned response within the applicable period and inform the data subject of the available administrative and judicial remedies. The DPA found that the controller therefore infringed [[Article 12 GDPR|Article 12(3) GDPR]] in conjunction with [[Article 17 GDPR]]. With regard to the internal investigation, the DPA noted that a defensive control may be permissible where there is a specific and well-founded suspicion of unlawful conduct. It emphasised that the check must concern data or conduct occurring after the emergence of that specific suspicion. It pointed out that in the present case, the suspicion arose in November 2022, but the controller examined correspondence dating back as far as approximately two years earlier. It held that the investigation was therefore retrospective and relied on data that had already been systematically collected and retained before any specific suspicion arose. It noted that the use of keywords, filters and a balancing assessment did not remedy this. With regard to the internal investigation, the DPA noted that a defensive control may be permissible where there is a specific and well-founded suspicion of unlawful conduct. It emphasised that the check must concern data or conduct occurring after the emergence of that specific suspicion. It pointed out that in the present case, the suspicion arose in November 2022, but the controller examined correspondence dating back as far as approximately two years earlier. It held that the investigation was therefore retrospective and relied on data that had already been systematically collected and retained before any specific suspicion arose. It noted that the use of keywords, filters and a balancing assessment did not remedy this. In addition, the DPA held that the controller’s stated purposes were formulated too generally to justify retaining the complete correspondence of all employees throughout their employment and for an additional five years. It concluded that the controller’s practice lacked an appropriate legal basis under [[Article 6 GDPR|Article 6 GDPR]] and infringed the principles of purpose limitation under Article 5(1)(b), data minimisation under Article 5(1)(c) and storage limitation under [[Article 5 GDPR|Article 5(1)(e) GDPR]]. In addition, the DPA held that the controller’s stated purposes were formulated too generally to justify retaining the complete correspondence of all employees throughout their employment and for an additional five years. It concluded that the controller’s practice lacked an appropriate legal basis under [[Article 6 GDPR]] and infringed the principles of purpose limitation under Article 5(1)(b) GDPR, data minimisation under Article 5(1)(c) GDPR and storage limitation under [[Article 5 GDPR|Article 5(1)(e) GDPR]]. The DPA further rejected the controller’s position that employees should have no expectation of confidentiality in relation to communications and files stored on company systems. It held that both the content of emails and their metadata concerned correspondence protected by the right to privacy and secrecy of communications. It stressed that employees retain a reasonable expectation of privacy in the workplace. The DPA distinguished between the email service itself, which may constitute a tool used by employees to perform their work, and the separate systems used to systematically collect, retain and process email content and metadata. These systems operate independently of the employee’s ordinary use of email and may enable the employer to reconstruct the employee’s activities. It noted that this possibility was confirmed by the controller’s own policies. The DPA concluded that the systematic retention and subsequent use of the data enabled the controller to reconstruct and monitor employees’ activities. It further found that this monitoring had been carried out without the safeguards required under Italian labour law. It ruled that the controller infringed [[Article 5 GDPR|Article 5(1)(a) GDPR]] and [[Article 88 GDPR|Article 88 GDPR]], together with Article 114 of the Italian Data Protection Code. The DPA further rejected the controller’s position that employees should have no expectation of confidentiality in relation to communications and files stored on company systems. It held that both the content of emails and their metadata concerned correspondence protected by the right to privacy and secrecy of communications. It stressed that employees retain a reasonable expectation of privacy in the workplace. The DPA distinguished between the email service itself, which may constitute a tool used by employees to perform their work, and the separate systems used to systematically collect, retain and process email content and metadata. These systems operate independently of the employee’s ordinary use of email and may enable the employer to reconstruct the employee’s activities. It noted that this possibility was confirmed by the controller’s own policies. The DPA concluded that the systematic retention and subsequent use of the data enabled the controller to reconstruct and monitor employees’ activities. It further found that this monitoring had been carried out without the safeguards required under Italian labour law. It ruled that the controller infringed [[Article 5 GDPR|Article 5(1)(a) GDPR]] and [[Article 88 GDPR]], together with Article 114 of the Italian Data Protection Code. The DPA also found unlawful the controller’s policy allowing, even with the former employee’s consent, their email address to remain active for up to 30 days and permitting incoming messages or the contents of the mailbox to be forwarded or transferred to another employee for broadly defined service needs. The DPA also found unlawful the controller’s policy allowing, even with the former employee’s consent, their email address to remain active for up to 30 days and permitting incoming messages or the contents of the mailbox to be forwarded or transferred to another employee for broadly defined service needs. Finally, the DPA held that the controller had not demonstrated how and when the two data subjects had been informed about the processing. It noted that its policies did not sufficiently specify the purposes and legal bases for retaining emails and logs. It pointed out that even its revised policy did not adequately explain the specific purposes of the processing. It held that the controller therefore infringed the transparency principle under [[Article 5 GDPR|Article 5(1)(a) GDPR]] and its information obligations under [[Article 13 GDPR|Article 13 GDPR]]. Finally, the DPA held that the controller had not demonstrated how and when the two data subjects had been informed about the processing. It noted that its policies did not sufficiently specify the purposes and legal bases for retaining emails and logs. It pointed out that even its revised policy did not adequately explain the specific purposes of the processing. It held that the controller therefore infringed the transparency principle under [[Article 5 GDPR|Article 5(1)(a) GDPR]] and its information obligations under [[Article 13 GDPR]]. The DPA imposed a fine of €460,000 and prohibited the controller from accessing the email data collected and retained on its corporate systems. The DPA imposed a fine of €460,000 and prohibited the controller from accessing the email data collected and retained on its corporate systems.","The Italian Data Protection Authority (Garante) has fined a company €460,000 for violating GDPR. The DPA found that the company unlawfully monitored employee emails by retaining correspondence for too long and conducting retrospective investigations without a clear suspicion. The company also infringed on data subject rights and transparency obligations.","Italian DPA fines company €460K for unlawful employee email monitoring and data retention.","Help Garante per la protezione dei dati personali (Italy) - 476\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 09:51, 6 August 2026 view sourceDs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators260 edits Tag: Decisions [1.0] Latest revision as of 07:38, 10 August 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators260 editsm Tag: Visual edit Line 135: Line 135: === Holding ====== Holding === Regarding the data subjects’ requests, the DPA held that both an individualised corporate email address and the correspondence associated with it constituted personal data relating to the employee. According to the DPA, a request to deactivate such an account therefore amounted to a request to cease the related processing, even where the data subject did not expressly refer to the GDPR or identify a particular data subject right. It also noted that the data subjects had requested only confirmation that their accounts had been deactivated, not the deletion of the emails relied upon in the employment dispute. It stated that even where the protection of legal proceedings may justify delaying or restricting the exercise of a data subject right, the controller must provide a reasoned response within the applicable period and inform the data subject of the available administrative and judicial remedies. The DPA found that the controller therefore infringed [[Article 12 GDPR|Article 12(3) GDPR]] in conjunction with [[Article 17 GDPR|Article 17 GDPR]].Regarding the data subjects’ requests, the DPA held that both an individualised corporate email address and the correspondence associated with it constituted personal data relating to the employee. According to the DPA, a request to deactivate such an account therefore amounted to a request to cease the related processing, even where the data subject did not expressly refer to the GDPR or identify a particular data subject right. It also noted that the data subjects had requested only confirmation that their accounts had been deactivated, not the deletion of the emails relied upon in the employment dispute. It stated that even where the protection of legal proceedings may justify delaying or restricting the exercise of a data subject right, the controller must provide a reasoned response within the applicable period and inform the data subject of the available administrative and judicial remedies. The DPA found that the controller therefore infringed [[Article 12 GDPR|Article 12(3) GDPR]] in conjunction with [[Article 17 GDPR]]. With regard to the internal investigation, the DPA noted that a defensive control may be permissible where there is a specific and well-founded suspicion of unlawful conduct. It emphasised that the check must concern data or conduct occurring after the emergence of that specific suspicion. It pointed out that in the present case, the suspicion arose in November 2022, but the controller examined correspondence dating back as far as approximately two years earlier. It held that the investigation was therefore retrospective and relied on data that had already been systematically collected and retained before any specific suspicion arose. It noted that the use of keywords, filters and a balancing assessment did not remedy this. With regard to the internal investigation, the DPA noted that a defensive control may be permissible where there is a specific and well-founded suspicion of unlawful conduct. It emphasised that the check must concern data or conduct occurring after the emergence of that specific suspicion. It pointed out that in the present case, the suspicion arose in November 2022, but the controller examined correspondence dating back as far as approximately two years earlier. It held that the investigation was therefore retrospective and relied on data that had already been systematically collected and retained before any specific suspicion arose. It noted that the use of keywords, filters and a balancing assessment did not remedy this. In addition, the DPA held that the controller’s stated purposes were formulated too generally to justify retaining the complete correspondence of all employees throughout their employment and for an additional five years. It concluded that the controller’s practice lacked an appropriate legal basis under [[Article 6 GDPR|Article 6 GDPR]] and infringed the principles of purpose limitation under Article 5(1)(b), data minimisation under Article 5(1)(c) and storage limitation under [[Article 5 GDPR|Article 5(1)(e) GDPR]]. In addition, the DPA held that the controller’s stated purposes were formulated too generally to justify retaining the complete correspondence of all employees throughout their employment and for an additional five years. It concluded that the controller’s practice lacked an appropriate legal basis under [[Article 6 GDPR]] and infringed the principles of purpose limitation under Article 5(1)(b) GDPR, data minimisation under Article 5(1)(c) GDPR and storage limitation under [[Article 5 GDPR|Article 5(1)(e) GDPR]]. The DPA further rejected the controller’s position that employees should have no expectation of confidentiality in relation to communications and files stored on company systems. It held that both the content of emails and their metadata concerned correspondence protected by the right to privacy and secrecy of communications. It stressed that employees retain a reasonable expectation of privacy in the workplace. The DPA distinguished between the email service itself, which may constitute a tool used by employees to perform their work, and the separate systems used to systematically collect, retain and process email content and metadata. These systems operate independently of the employee’s ordinary use of email and may enable the employer to reconstruct the employee’s activities. It noted that this possibility was confirmed by the controller’s own policies. The DPA concluded that the systematic retention and subsequent use of the data enabled the controller to reconstruct and monitor employees’ activities. It further found that this monitoring had been carried out without the safeguards required under Italian labour law. It ruled that the controller infringed [[Article 5 GDPR|Article 5(1)(a) GDPR]] and [[Article 88 GDPR|Article 88 GDPR]], together with Article 114 of the Italian Data Protection Code.The DPA further rejected the controller’s position that employees should have no expectation of confidentiality in relation to communications and files stored on company systems. It held that both the content of emails and their metadata concerned correspondence protected by the right to privacy and secrecy of communications. It stressed that employees retain a reasonable expectation of privacy in the workplace. The DPA distinguished between the email service itself, which may constitute a tool used by employees to perform their work, and the separate systems used to systematically collect, retain and process email content and metadata. These systems operate independently of the employee’s ordinary use of email and may enable the employer to reconstruct the employee’s activities. It noted that this possibility was confirmed by the controller’s own policies. The DPA concluded that the systematic retention and subsequent use of the data enabled the controller to reconstruct and monitor employees’ activities. It further found that this monitoring had been carried out without the safeguards required under Italian labour law. It ruled that the controller infringed [[Article 5 GDPR|Article 5(1)(a) GDPR]] and [[Article 88 GDPR]], together with Article 114 of the Italian Data Protection Code. The DPA also found unlawful the controller’s policy allowing, even with the former employee’s consent, their email address to remain active for up to 30 days and permitting incoming messages or the co","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_476\u002F2026&diff=52644&oldid=52634","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-08-10T07:38:26+00:00","2026-08-10T08:00:10.68831+00:00",8,[18],{"name":19,"type":20},"Garante per la protezione dei dati personali","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,32,37,39],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":38},{"id":21,"icon":23,"name":24,"slug":25},{"category":40},{"id":41,"icon":23,"name":42,"slug":43},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]