Back to all lessons
Awareness Lessons
3 weeks ago

Italian DPA Fines Company €20,000 for Ignoring Employee Data Access Rights and GPS Transparency Failures

This case highlights two compounding GDPR failures: the company did not properly respond to employees' data subject access requests (DSARs), and it failed to transparently inform employees that their vehicle GPS data was being collected and processed. Dismissing DSARs as 'labor law matters' rather than GDPR obligations is a common but costly misunderstanding — the GDPR applies regardless of the underlying business context. GPS tracking of employees is particularly sensitive personal data that requires clear, upfront disclosure in privacy notices. This case demonstrates that inadequate transparency and unresponsiveness to data rights are independently enforceable violations, not minor procedural oversights.

Tactical Insight

Immediate actions

  • Audit all active employee data processing activities (including GPS/fleet tracking) and verify they are documented in accessible privacy notices.
  • Establish a formal DSAR intake and response process with clear ownership, tracking, and a 30-day SLA aligned to GDPR Article 12.

Long-term improvements

  • Train HR, Legal, and Operations teams to recognize and correctly classify incoming data subject requests, regardless of the stated purpose of the requestor.
  • Embed privacy-by-design reviews into any fleet management, monitoring, or HR technology procurement to ensure transparency obligations are met before deployment.
  • Maintain a Record of Processing Activities (RoPA) under GDPR Article 30 that explicitly includes employee monitoring systems such as GPS tracking.

Detection & oversight measures

  • Schedule periodic internal audits of DSAR response logs to identify missed, delayed, or incorrectly refused requests.
  • Assign a Data Protection Officer (DPO) or privacy lead with authority to review employee-facing privacy notices annually for completeness and accuracy.