Back to all lessons
Awareness Lessons
2 weeks ago

Italian DPA Fines Controller €5,000 for Unlawful Employee Data Disclosure to Employer

A controller unlawfully forwarded a data subject's personal complaint — including their identity and unrelated disciplinary history — to their employer without a valid legal basis, violating GDPR Articles 5 and 6. This breach demonstrates a fundamental failure to apply purpose limitation and data minimization principles before sharing personal information with third parties. The disclosure exposed the individual to potential workplace harm and highlights how informal or ad hoc data sharing decisions, made without proper legal review, can constitute serious GDPR violations. Organizations must treat every act of data disclosure as a deliberate, documented decision grounded in a legitimate legal basis.

Tactical Insight

Immediate actions

  • Establish a mandatory legal basis review checklist that staff must complete before sharing any personal data with third parties, including employers.
  • Audit all current data-sharing practices and workflows to identify instances where personal data is disclosed without documented legal justification.

Process & Policy improvements

  • Implement a Data Sharing Agreement (DSA) or formal authorization process for any disclosure of personal data to external parties.
  • Train all staff handling personal data on GDPR principles — especially purpose limitation, data minimization, and lawful basis — with role-specific scenarios.
  • Create a clear escalation path to the Data Protection Officer (DPO) for any non-routine data disclosure requests before action is taken.

Detection & Accountability measures

  • Maintain detailed logs of all third-party data disclosures, including the legal basis cited, date, recipient, and data categories shared.
  • Conduct periodic internal audits or DPO reviews of data-sharing incidents to detect and correct unlawful disclosure patterns before regulatory action occurs.