[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-J7Y_IR6mikSFjG0RfKN-3-bIdUxDWdblMEz859gTp4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"50e0ef2c-eb66-41e6-8e93-53fb22f99177","italian-dpa-fines-company-for-unlawful-retrospective-employee-email-surveillance","2aaeb152-eb65-4195-b281-58a47e3d1ba5","Italian DPA Fines Company for Unlawful Retrospective Employee Email Surveillance","A company conducting an internal investigation accessed two years of employee email correspondence without prior suspicion of misconduct, violating core GDPR principles of purpose limitation, data minimisation, and storage limitation. This retrospective, blanket surveillance of employee communications goes far beyond what is necessary or proportionate for a legitimate investigation. Additionally, the company failed to properly handle data subject requests related to account deactivation, breaching GDPR Articles 12 and 17. This case highlights that even internal investigations must be scoped, proportionate, and governed by clear data handling policies to remain lawful.","**Immediate actions:**\n- Define and document a formal, GDPR-compliant internal investigation policy that restricts access to employee data to the minimum necessary scope and timeframe.\n- Establish a dedicated process for responding to data subject requests (access, erasure, account deactivation) within GDPR-mandated timeframes.\n\n**Long-term improvements:**\n- Implement data retention schedules for employee communications that enforce automatic deletion after legally justified periods.\n- Train HR, Legal, and IT teams on lawful bases and proportionality requirements before initiating any employee monitoring or investigation.\n- Embed Privacy Impact Assessments (PIAs) as a mandatory step before launching any internal investigation involving personal data.\n\n**Governance & oversight:**\n- Appoint or engage a Data Protection Officer (DPO) to review and approve investigation procedures before employee data is accessed.\n- Conduct annual audits of access controls on email and communication systems to ensure only authorised roles can retrieve historical correspondence.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 5(1)(b) – Purpose Limitation","GDPR Article 5(1)(c) – Data Minimisation","GDPR Article 5(1)(e) – Storage Limitation","GDPR Article 12 – Transparent Information and Communication","GDPR Article 17 – Right to Erasure","NIST SP 800-53 AC-3 – Access Enforcement","NIST SP 800-53 IP-2 – Individual Participation and Redress","CIS Control 3 – Data Protection","CIS Control 6 – Access Control Management","ISO\u002FIEC 27701 – Privacy Information Management","ITIL – Service Request Management (for data subject request handling)","published","2026-08-11T12:20:20.086493+00:00","2026-08-11T12:20:19.77+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_476\u002F2026&diff=52662&oldid=52644","garante-per-la-protezione-dei-dati-personali-italy-476-2026-0831c6","Garante per la protezione dei dati personali (Italy) - 476\u002F2026",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]