Italian DPA Fines La Patria €39K for Ignoring Employee GDPR Access Rights
La Patria S.p.A. failed on two fronts: it did not properly respond to an employee's data subject access request (DSAR) related to disciplinary proceedings, and it neglected to provide a privacy notice for GPS tracking data collected through fleet management systems. This case highlights that organizations cannot dismiss DSARs simply because they lack an explicit GDPR citation — the obligation to respond is triggered by the nature of the request, not its legal framing. Failing to inform individuals why a request is refused compounds the violation by denying people meaningful recourse. The €39,000 fine serves as a reminder that employee data rights — including location data from workplace tools — carry the same legal weight as those of any other data subject.
Tactical Insight
Immediate actions
- Audit all active or pending data subject access requests to ensure timely, GDPR-compliant responses regardless of how the request was worded.
- Issue or update privacy notices for all employee monitoring tools (GPS, fleet management, biometrics) to satisfy Articles 13/14 transparency requirements.
Process & Policy improvements
- Establish a formal DSAR intake procedure that identifies, triages, and tracks requests with documented response deadlines and refusal justifications.
- Train HR and legal teams to recognize data subject rights requests in any form (email, letter, verbal) and escalate them to the data protection function promptly.
- Develop a data inventory (Article 30 record) that maps all employee data processing activities, including third-party fleet or monitoring systems, to their corresponding lawful bases and notices.
Long-term governance
- Appoint or empower a Data Protection Officer (DPO) with authority to review disciplinary and HR processes for GDPR compliance before they are initiated.
- Conduct annual GDPR compliance reviews of employee-facing data processing activities, including workplace monitoring technologies.