[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f0BO3j24L57Qd8oIhKvyebEdksTb1wxUYMfU9ApFwULs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"5fab694c-36cd-4649-82d5-1f2411230c00","italian-dpa-fines-company-20000-for-ignoring-employee-data-access-rights-and-gps-transparency-failur","e35a5692-0a3e-4517-ab53-21951508b411","Italian DPA Fines Company €20,000 for Ignoring Employee Data Access Rights and GPS Transparency Failures","This case highlights two compounding GDPR failures: the company did not properly respond to employees' data subject access requests (DSARs), and it failed to transparently inform employees that their vehicle GPS data was being collected and processed. Dismissing DSARs as 'labor law matters' rather than GDPR obligations is a common but costly misunderstanding — the GDPR applies regardless of the underlying business context. GPS tracking of employees is particularly sensitive personal data that requires clear, upfront disclosure in privacy notices. This case demonstrates that inadequate transparency and unresponsiveness to data rights are independently enforceable violations, not minor procedural oversights.","**Immediate actions:**\n- Audit all active employee data processing activities (including GPS\u002Ffleet tracking) and verify they are documented in accessible privacy notices.\n- Establish a formal DSAR intake and response process with clear ownership, tracking, and a 30-day SLA aligned to GDPR Article 12.\n\n**Long-term improvements:**\n- Train HR, Legal, and Operations teams to recognize and correctly classify incoming data subject requests, regardless of the stated purpose of the requestor.\n- Embed privacy-by-design reviews into any fleet management, monitoring, or HR technology procurement to ensure transparency obligations are met before deployment.\n- Maintain a Record of Processing Activities (RoPA) under GDPR Article 30 that explicitly includes employee monitoring systems such as GPS tracking.\n\n**Detection & oversight measures:**\n- Schedule periodic internal audits of DSAR response logs to identify missed, delayed, or incorrectly refused requests.\n- Assign a Data Protection Officer (DPO) or privacy lead with authority to review employee-facing privacy notices annually for completeness and accuracy.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 5(1)(a) – Lawfulness, fairness and transparency","GDPR Article 12 – Transparent information and communication","GDPR Article 13 – Information to be provided at the time of data collection","GDPR Article 15 – Right of access by the data subject","GDPR Article 30 – Records of processing activities","NIST Privacy Framework PR.PO-P1 – Policies and procedures for data processing","NIST SP 800-53 IP-1 – Consent","NIST SP 800-53 IP-2 – Individual Access","CIS Control 3 – Data Protection","ISO\u002FIEC 27701:2019 – Privacy Information Management (PIMS)","ITIL Service Management – Request Fulfilment Process","published","2026-09-23T11:20:23.4802+00:00","2026-09-23T11:20:23.2+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_585\u002F2026&diff=53174&oldid=53170","garante-per-la-protezione-dei-dati-personali-italy-585-2026-d95e10","Garante per la protezione dei dati personali (Italy) - 585\u002F2026",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]