Garante per la protezione dei dati personali (Italy) - 554/2026
Italian DPA fines company €6,500 for failing to deactivate accounts and inadequate privacy information.
Summary
The Italian Data Protection Authority (Garante per la protezione dei dati personali) has fined Top Secret Investigazioni e sicurezza s.r.l. €6,500 for violating GDPR. The company failed to deactivate former employees' company accounts and provide adequate information about data processing operations. An investigation revealed that email forwarding was not functioning correctly for eight months, leading to a violation of data minimization and storage limitation principles.
Full text
Help Garante per la protezione dei dati personali (Italy) - 554/2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 12:20, 10 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators62 edits Tag: Decisions [1.0] (No difference) Latest revision as of 12:20, 10 September 2026 Garante per la protezione dei dati personali - 554/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 5(1)(c) GDPR Article 5(1)(e) GDPR Article 13 GDPR Type: Complaint Outcome: n/a Started: Decided: Published: Fine: 6500.0 EUR Parties: Top Secret Investigazioni e sicurezza s.r.l. National Case Number/Name: 554/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined a controller €6.500 for failing to deactivate data subjects company accounts following their termination and providing inadequate information about its processing operations. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The data subjects filed a complaint claiming that Top Secret Investigazioni e sicurezza s.r.l. (the controller) violated the protection of personal data, as a result of failing to deactivate individualised company accounts following termination of employment, and not providing adequate information as to the controller’s processing operations. The DPA initiated an investigation and found that a union settlement agreement was signed between the data subjects and the controller establishing that the accounts would be deactivated, and an automated reply would be set up redirecting the emails to another account which was not to be linked with the data subjects themselves. The controller’s engineer, tasked with investigating the validity of the complaints, stated that the accounts were merely placeholders used to respond to specific requests, not active email accounts, and confirmed that no processing was being undertaken by the controller. The engineer further clarified that whilst messages sent to the accounts were meant to be forwarded by a server to an auto responder subsystem, due to a configuration error, the automatic responder was not functioning as intended and forwarding was not happening. Holding In light of its investigation the DPA held as regards the forwarding which took place over a period of 8 months the controller was not able to sufficiently justify the retention or forwarding of the emails. The DPA found that these operations were deemed incompatible with the principles of lawfulness, data minimisation and storage limitation. Furthermore, the DPA held that the controller violated its transparency obligations as it did not adequately update the privacy policy signed by the data subjects, and internal regulations which addressed what would happen with email addresses after employees are terminated. The DPA held the controller in violation of Articles 5(1)(a), (c) and (e) GDPR and Article 13 GDPR and thus imposed a €6.500 fine on the controller. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10287400] Decision of July 23, 2026 Register of Decisions No. 554 of July 23, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, President; Prof. Ginevra Cerrina Feroni, Vice President; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter, the “Regulation”); HAVING REGARD TO the Code on Data Protection, containing provisions for the adaptation of national law to Regulation (EU) 2016/679 (Legislative Decree No. 196 of June 30, 2003, as amended by Legislative Decree No. 101 of August 10, 2018, hereinafter referred to as the “Code”); HAVING REGARD TO the complaint filed pursuant to Art. 77 of the Regulation by Messrs. XX and XX against Top Secret Investigazioni e Sicurezza s.r.l.; HAVING EXAMINED the documentation on file; HAVING CONSIDERED the observations made by the Acting Secretary General pursuant to Article 15 of the Data Protection Authority’s Regulation No. 1/2000; RAPPORTEUR: Prof. Ginevra Cerrina Feroni; PREAMBLE 1. The complaint filed with the Data Protection Authority and the preliminary investigation initiated by the Office. In a complaint filed with this Authority on April 14, 2022, supplemented by two subsequent communications dated January 27, 2023, and April 5, 2023, Mr. XX and Mr. XX, through their attorney, Mr. XX, alleged a violation of personal data protection regulations by Top Secret Investigazioni e Sicurezza s.r.l. (hereinafter “the Company”), specifically regarding the failure to deactivate individual company email accounts (XX and XX) following the termination of employment—with incoming messages being redirected to another account—as well as the failure to provide information regarding the processing of personal data. In support of their complaint, they submitted to the record several emails that the Company had sent in response to messages addressed to the aforementioned accounts. By letter dated July 6, 2023, this Office issued a request for information to the Company, pursuant to Article 157 of the Code, in order to gather relevant information for evaluating the matters raised in the complaint. In response to this request, the Company submitted its observations via a letter dated July 28, 2023, stating that: - “On February 7, 2020, [the complainants] both signed a union settlement agreement with Top Secret Investigazioni e Sicurezza srl, which stipulated that the aforementioned company deactivate the complainants’ corporate accounts by February 29, 2020 “by inserting an automated reply message redirecting the User to another entity or account in no way traceable” to the complainants themselves”; - “as noted by Engineer XX, who was tasked with conducting an investigation into the technical validity of the complainants’ grievances (…) these are merely “placeholders,” used solely to respond to specific requests from senders, and not active email “accounts”—that is, spaces reserved and used to receive emails—such that no data processing activity (e.g., even simple viewing) was ever carried out by the data controller”; - “Proof of the foregoing is the response forwarded to me by the provider, which specified that both of the aforementioned mailboxes were deleted on February 28, 2020—that is, prior to the deadline established by the labor conciliation agreement”; - “Engineer (…) also noted that any communication sent to the aforementioned addresses was simply forwarded by the OVH server to the autoresponder subsystem, which handled the request and sent an automatic reply message to the sender”; - “Due to a configuration error, the literal content of the message did not correspond to what actually occurred, since the autoresponder was not configured to forward the email to another address (which is instead the function of a forwarder)”; - “It follows that no data processing activities were carried out by Top Secret Investigazioni e Sicurezza S.r.l. in relation to the aforementioned accounts (…), as they were permanently deleted before the deadline set forth in the employment agreement, nor is there any evidence to the contrary.” Furthermore, the Company submitted copies of the personal data processing notices, signed by the former employees upon their hiring (specifically on December 8, 2011, and May 12, 2010), and a copy of the “Internal Company Regulati