Awareness Lessons
2 months ago
Italian DPA Fines Company for Unlawful Retrospective Employee Email Surveillance
A company conducting an internal investigation accessed two years of employee email correspondence without prior suspicion of misconduct, violating core GDPR principles of purpose limitation, data minimisation, and storage limitation. This retrospective, blanket surveillance of employee communications goes far beyond what is necessary or proportionate for a legitimate investigation. Additionally, the company failed to properly handle data subject requests related to account deactivation, breaching GDPR Articles 12 and 17. This case highlights that even internal investigations must be scoped, proportionate, and governed by clear data handling policies to remain lawful.
Tactical Insight
Immediate actions
- Define and document a formal, GDPR-compliant internal investigation policy that restricts access to employee data to the minimum necessary scope and timeframe.
- Establish a dedicated process for responding to data subject requests (access, erasure, account deactivation) within GDPR-mandated timeframes.
Long-term improvements
- Implement data retention schedules for employee communications that enforce automatic deletion after legally justified periods.
- Train HR, Legal, and IT teams on lawful bases and proportionality requirements before initiating any employee monitoring or investigation.
- Embed Privacy Impact Assessments (PIAs) as a mandatory step before launching any internal investigation involving personal data.
Governance & oversight
- Appoint or engage a Data Protection Officer (DPO) to review and approve investigation procedures before employee data is accessed.
- Conduct annual audits of access controls on email and communication systems to ensure only authorised roles can retrieve historical correspondence.