[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fyS2k870cXBdgsJVs7Js_elBI5Ko9Wg4K4V09j--rjzA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"e934198f-931e-443b-8d2a-9b827ae5e0ef","italian-dpa-fines-employer-for-unlawfully-accessing-former-employees-locker","94345992-9c72-4805-b531-a55a48bf1603","Italian DPA Fines Employer for Unlawfully Accessing Former Employee's Locker","A company was fined €6,600 by the Italian Garante for opening and emptying a former employee's locker without their knowledge or consent, which was ruled a form of personal data processing under GDPR. The violation stemmed from a failure to apply core GDPR principles — transparency, fairness, and data minimization — in an employment context. Employers often underestimate that physical actions involving personal belongings or spaces can constitute data processing under European law. This case highlights that GDPR obligations extend beyond digital systems and that 'legitimate interest' cannot be freely invoked to override employee rights without a proportionate justification.","**Immediate actions:**\n- Establish a formal written policy governing access to employee personal spaces (lockers, desks, devices) that complies with GDPR principles.\n- Ensure any access to a departing employee's personal property is conducted with the employee present or with documented prior notice.\n\n**Long-term improvements:**\n- Train HR and management staff on GDPR obligations in the employment context, including what constitutes 'personal data processing' beyond digital records.\n- Develop offboarding procedures that include a legally reviewed checklist for handling former employee belongings, accounts, and data.\n- Conduct a Data Protection Impact Assessment (DPIA) for all HR processes involving employee personal data or physical property.\n\n**Governance & accountability measures:**\n- Appoint or consult with a Data Protection Officer (DPO) when designing HR policies that involve employee personal information.\n- Document the legal basis for any data processing activity related to employees and retain records as required under GDPR Article 30.",[12,13,14,15,16,17,18,19,20],"GDPR Article 5 (Principles relating to processing of personal data)","GDPR Article 6 (Lawfulness of processing)","GDPR Article 13 (Transparency — information to be provided)","GDPR Article 30 (Records of processing activities)","GDPR Article 35 (Data Protection Impact Assessment)","NIST SP 800-53 IP-1 (Individual Access)","NIST SP 800-53 PT-2 (Authority to Process Personally Identifiable Information)","CIS Control 3 (Data Protection)","ISO\u002FIEC 27701 Section 8.2 (Conditions for collection of PII)","published","2026-07-29T00:20:17.255543+00:00","2026-07-29T00:20:17.162+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_462\u002F2026&diff=52525&oldid=52520","garante-per-la-protezione-dei-dati-personali-italy-462-2026-8e1575","Garante per la protezione dei dati personali (Italy) - 462\u002F2026",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":42,"name":43,"slug":44,"description":45,"color":46},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]