Back to Feed
PolicySep 23, 2026

Garante per la protezione dei dati personali (Italy) - 585/2026

Italian DPA fines company €20,000 for GDPR violations related to employee access requests and GPS data.

Summary

The Italian Data Protection Authority (Garante) fined a company €20,000 for failing to properly respond to two employee access requests and for not informing employees about the processing of their vehicle's GPS data. The company argued the requests were related to labor law defense, not GDPR, and that GPS data was only for fleet management. The DPA found these defenses insufficient.

Full text

Help Garante per la protezione dei dati personali (Italy) - 585/2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 07:41, 23 September 2026 view sourceMba (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators984 editsm Tag: Visual edit← Older edit Latest revision as of 08:19, 23 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators91 editsmTag: Visual edit Line 92: Line 92: }}}} The DPA fined a controller €20,000 for insufficiently responding to two access requests, by not providing suitable nor correct information. The DPA fined a controller €20,000 for insufficiently responding to two access requests by one of its employees, and for not informing its employees about the processing of their vehicles’ GPS data. == English Summary ==== English Summary == Line 101: Line 101: In its defence, the controller submitted that the data subject requested access to the documentation pertaining to the disciplinary proceedings, referencing national labour law, and made no reference to the GDPR. Therefore, the requests were interpreted as part of the data subject’s right to a defence under national labour law, and the controller found it sufficient to deal with it as such. The controller explained that had the data subject made evident that the request was an exercise of their data subject rights, namely the right to access under [[Article 15 GDPR]], they would have allowed for a response compliant with the GDPR.In its defence, the controller submitted that the data subject requested access to the documentation pertaining to the disciplinary proceedings, referencing national labour law, and made no reference to the GDPR. Therefore, the requests were interpreted as part of the data subject’s right to a defence under national labour law, and the controller found it sufficient to deal with it as such. The controller explained that had the data subject made evident that the request was an exercise of their data subject rights, namely the right to access under [[Article 15 GDPR]], they would have allowed for a response compliant with the GDPR. As regards the GPS data, the controller explained that the GPS devices were intended for fleet management, and active and passive safety of the drivers, and that no data directly related to the drivers was processed. Thus, in order for the controller to have complied with this request they would have had to access the system and undertake processing which they had not done before. As a result of the use of the GPS for the above-mentioned purposes, in good faith the controller did not have a privacy notice concerning the processing of data via the GPS.As regards the GPS data, the controller explained that the GPS devices were intended for fleet management, and active and passive safety of the drivers, and that no data directly related to the drivers was processed. Thus, in order for the controller to have complied with this request they would have had to access the system, and undertake processing which they had not done before. As a result of the above-mentioned use of the GPS, the controller decided not include a privacy notice concerning the processing of data via the GPS. Finally, the controller claimed that the data subject did not suffer any harm.Finally, the controller claimed that the data subject did not suffer any harm. Latest revision as of 08:19, 23 September 2026 Garante per la protezione dei dati personali - 585/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 12 GDPR Article 13 GDPR Article 15 GDPR Type: Complaint Outcome: Upheld Started: Decided: Published: Fine: 39000.0 EUR Parties: La Patria S.p.A. National Case Number/Name: 585/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined a controller €20,000 for insufficiently responding to two access requests by one of its employees, and for not informing its employees about the processing of their vehicles’ GPS data. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The data subject, a security guard of La Patria S.p.A. (the controller), complained to the DPA about the lack of response by the controller to two access requests regarding the disciplinary proceedings which led to his dismissal. Particularly, the data subject requested to review and obtain a copy of all documentation, including GPS data, license plate number, and case file. In its defence, the controller submitted that the data subject requested access to the documentation pertaining to the disciplinary proceedings, referencing national labour law, and made no reference to the GDPR. Therefore, the requests were interpreted as part of the data subject’s right to a defence under national labour law, and the controller found it sufficient to deal with it as such. The controller explained that had the data subject made evident that the request was an exercise of their data subject rights, namely the right to access under Article 15 GDPR, they would have allowed for a response compliant with the GDPR. As regards the GPS data, the controller explained that the GPS devices were intended for fleet management, and active and passive safety of the drivers, and that no data directly related to the drivers was processed. Thus, in order for the controller to have complied with this request they would have had to access the system, and undertake processing which they had not done before. As a result of the above-mentioned use of the GPS, the controller decided not include a privacy notice concerning the processing of data via the GPS. Finally, the controller claimed that the data subject did not suffer any harm. Holding The DPA found that the inadequate response provided by the controller to the data subjects access requests violated Article 12 and Article 15 GDPR. The DPA held that the fact that the data subject did not refer to GDPR provisions in their request, despite having made the subject matter clear, and lacked reference to harm suffered, was not sufficient to alleviate the controller of their obligations to respond. The DPA clarified that where a controller is unable to comply with an access request, they must still inform the data subject of the reasons for refusal and their right to a judicial remedy against the DPA. The DPA further found a violation of Article 13 GDPR, for not providing a privacy notice regarding the geolocation data to its employees. This resulted in inadequate information about the processing operations. The DPA clarified that geolocation data can be indirectly linked to the individual using the car, and thus constitutes personal data processing. In that regard, the controller should have gone beyond offering a mere description, and disclosed the processing operations being carried out and their corresponding compliance with the GDPR. As a result of the foregoing violations, the DPA fined the controller €39,000. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10297306] Decision of August 6, 2026 Register of Decisions No. 585 of August 6, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Claudio Filippi, Deputy Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter, the “Regulation”); HAVING REGARD TO

Entities

Garante per la protezione dei dati personali (vendor)GPS (product)