[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fFGDtXHwzgwGYrwANi5-6H5BuaSl2OaFZNvvsGM-P_5E":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"43c8d800-5e49-4621-919e-372bbdbe1092","italian-dpa-fines-cosmint-for-unlawful-processing-of-former-employees-personal-data","61f3b54a-1e86-4df8-90a3-a401f3f132cb","Italian DPA Fines Cosmint for Unlawful Processing of Former Employee's Personal Data","Cosmint S.p.A. violated GDPR by opening and emptying a former employee's locker without lawful basis, destroying its contents, and recording the process on a smartphone — all of which constituted unlawful personal data processing. The root cause was a failure to understand that physical items belonging to an individual can constitute personal data, and that any interaction with them must comply with data protection principles. This case highlights that GDPR obligations extend well beyond digital systems and into physical workplace actions. Organizations that lack clear, GDPR-aligned off-boarding procedures expose themselves to regulatory fines and reputational harm even through seemingly routine administrative actions.","**Immediate actions:**\n- Establish a formal, GDPR-compliant off-boarding procedure that defines lawful steps for handling a departing employee's physical belongings.\n- Prohibit unauthorized recording (audio, video, or photo) of personal property or employee spaces without a documented lawful basis and proper notice.\n\n**Long-term improvements:**\n- Train HR and facilities staff on GDPR obligations as they apply to physical assets, locker access, and personal property of employees.\n- Appoint a designated data protection contact (or DPO) to review and approve any off-boarding actions that involve access to an employee's personal space or belongings.\n- Document all off-boarding activities in a formal record of processing activities (RoPA) to demonstrate accountability under GDPR Article 5.\n\n**Governance & oversight measures:**\n- Conduct periodic audits of HR and facilities policies to ensure alignment with current GDPR requirements and DPA guidance.\n- Require written managerial sign-off and legal review before any access to a former employee's locker, desk, or personal workspace is carried out.",[12,13,14,15,16,17,18,19,20],"GDPR Article 5 – Principles relating to processing of personal data","GDPR Article 6 – Lawfulness of processing","GDPR Article 13\u002F14 – Transparency and information obligations","GDPR Article 24 – Responsibility of the controller","NIST SP 800-53 PS-4 (Personnel Termination)","NIST SP 800-53 IP-1 (Privacy Policy and Procedures)","CIS Control 14 – Security Awareness and Skills Training","ISO\u002FIEC 27001:2022 Annex A 6.5 – Responsibilities after termination or change of employment","ITIL Service Transition – Off-boarding and asset return processes","published","2026-07-29T00:20:47.987403+00:00","2026-07-29T00:20:47.872+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_462\u002F2026&diff=52520&oldid=0","garante-per-la-protezione-dei-dati-personali-italy-462-2026-3b0cb4","Garante per la protezione dei dati personali (Italy) - 462\u002F2026",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":42,"name":43,"slug":44,"description":45,"color":46},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]