Italian DPA Fines Cosmint for Unlawful Processing of Former Employee's Personal Data
Cosmint S.p.A. violated GDPR by opening and emptying a former employee's locker without lawful basis, destroying its contents, and recording the process on a smartphone — all of which constituted unlawful personal data processing. The root cause was a failure to understand that physical items belonging to an individual can constitute personal data, and that any interaction with them must comply with data protection principles. This case highlights that GDPR obligations extend well beyond digital systems and into physical workplace actions. Organizations that lack clear, GDPR-aligned off-boarding procedures expose themselves to regulatory fines and reputational harm even through seemingly routine administrative actions.
Tactical Insight
Immediate actions
- Establish a formal, GDPR-compliant off-boarding procedure that defines lawful steps for handling a departing employee's physical belongings.
- Prohibit unauthorized recording (audio, video, or photo) of personal property or employee spaces without a documented lawful basis and proper notice.
Long-term improvements
- Train HR and facilities staff on GDPR obligations as they apply to physical assets, locker access, and personal property of employees.
- Appoint a designated data protection contact (or DPO) to review and approve any off-boarding actions that involve access to an employee's personal space or belongings.
- Document all off-boarding activities in a formal record of processing activities (RoPA) to demonstrate accountability under GDPR Article 5.
Governance & oversight measures
- Conduct periodic audits of HR and facilities policies to ensure alignment with current GDPR requirements and DPA guidance.
- Require written managerial sign-off and legal review before any access to a former employee's locker, desk, or personal workspace is carried out.