[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxDu3BYzgxLykaZUX5XHPPkCoutW0yaPxUTNrikKFpZQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"b66df222-4b9c-4060-a261-04a21bfb776d","italian-dpa-fines-employer-6600-for-unlawfully-accessing-former-employees-locker","671a3f8c-cd6e-4eb3-a042-ad07ebf4e1a9","Italian DPA Fines Employer €6,600 for Unlawfully Accessing Former Employee's Locker","A company in Italy was fined €6,600 after opening and emptying a former employee's personal locker without their presence or consent, an act the Garante ruled constituted unlawful personal data processing under GDPR. The root failure was the organization's lack of clear policies governing how personal belongings and associated data are handled during and after employment termination. This case illustrates that 'personal data' extends beyond digital records — physical items stored by an employee can carry personal information subject to GDPR protections. Organizations that fail to apply lawfulness, transparency, and data minimization principles to offboarding processes expose themselves to regulatory penalties even in seemingly routine operational tasks.","**Immediate actions:**\n- Establish a written, GDPR-compliant offboarding procedure that covers the handling of all employee property, including physical lockers and personal effects.\n- Ensure former employees are notified in advance and given the opportunity to be present — or represented — when personal storage areas are accessed.\n\n**Long-term improvements:**\n- Train HR and facilities management teams on GDPR obligations, emphasizing that personal data extends to physical items and spaces.\n- Implement a documented retention and return policy for employee belongings that defines lawful bases and required transparency steps.\n- Conduct periodic audits of offboarding practices to verify compliance with data protection policies.\n\n**Governance & oversight measures:**\n- Assign a Data Protection Officer (DPO) or designated privacy lead to review and approve offboarding procedures before implementation.\n- Maintain records of all actions taken on former employee property as part of your Article 30 processing activity records.",[12,13,14,15,16,17,18,19,20],"GDPR Article 5(1)(a) – Lawfulness, fairness, and transparency","GDPR Article 5(1)(c) – Data minimisation","GDPR Article 6 – Lawfulness of processing","GDPR Article 13\u002F14 – Transparency obligations","GDPR Article 30 – Records of processing activities","NIST Privacy Framework PR.PO-P1 – Policies and procedures for data processing","CIS Control 3 – Data Protection","ISO\u002FIEC 27001:2022 Annex A 6.5 – Responsibilities after termination or change of employment","ITIL Service Transition – Offboarding and asset management practices","published","2026-07-29T02:20:36.949629+00:00","2026-07-29T02:20:36.64+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_462\u002F2026&diff=52527&oldid=52520","garante-per-la-protezione-dei-dati-personali-italy-462-2026-99fcfe","Garante per la protezione dei dati personali (Italy) - 462\u002F2026",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":42,"name":43,"slug":44,"description":45,"color":46},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]