[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fG-ZGYtRjpqiOIVh4RRTd0HjPzJps5aUMkzEGdIIhf8M":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"e76c8a07-7128-4c52-907a-941fe9ced6dd","italian-dpa-fines-la-patria-39k-for-ignoring-employee-gdpr-access-rights","36d8158a-1747-4ed8-aeaf-0f6aa98a5dd8","Italian DPA Fines La Patria €39K for Ignoring Employee GDPR Access Rights","La Patria S.p.A. failed on two fronts: it did not properly respond to an employee's data subject access request (DSAR) related to disciplinary proceedings, and it neglected to provide a privacy notice for GPS tracking data collected through fleet management systems. This case highlights that organizations cannot dismiss DSARs simply because they lack an explicit GDPR citation — the obligation to respond is triggered by the nature of the request, not its legal framing. Failing to inform individuals why a request is refused compounds the violation by denying people meaningful recourse. The €39,000 fine serves as a reminder that employee data rights — including location data from workplace tools — carry the same legal weight as those of any other data subject.","**Immediate actions:**\n- Audit all active or pending data subject access requests to ensure timely, GDPR-compliant responses regardless of how the request was worded.\n- Issue or update privacy notices for all employee monitoring tools (GPS, fleet management, biometrics) to satisfy Articles 13\u002F14 transparency requirements.\n\n**Process & Policy improvements:**\n- Establish a formal DSAR intake procedure that identifies, triages, and tracks requests with documented response deadlines and refusal justifications.\n- Train HR and legal teams to recognize data subject rights requests in any form (email, letter, verbal) and escalate them to the data protection function promptly.\n- Develop a data inventory (Article 30 record) that maps all employee data processing activities, including third-party fleet or monitoring systems, to their corresponding lawful bases and notices.\n\n**Long-term governance:**\n- Appoint or empower a Data Protection Officer (DPO) with authority to review disciplinary and HR processes for GDPR compliance before they are initiated.\n- Conduct annual GDPR compliance reviews of employee-facing data processing activities, including workplace monitoring technologies.",[12,13,14,15,16,17,18,19,20],"GDPR Article 12 — Transparent information and modalities","GDPR Article 13 — Information to be provided where personal data are collected from the data subject","GDPR Article 15 — Right of access by the data subject","GDPR Article 30 — Records of processing activities","NIST SP 800-53 IP-1 (Individual Access)","NIST SP 800-53 TR-2 (System of Records Notices and Privacy Act Statements)","CIS Control 3 — Data Protection","ISO\u002FIEC 27701:2019 — Privacy Information Management","ITIL — Service Request Management (for DSAR handling workflows)","published","2026-09-23T08:20:25.043156+00:00","2026-09-23T08:20:24.768+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_585\u002F2026&diff=53170&oldid=53118","garante-per-la-protezione-dei-dati-personali-italy-585-2026-627ab4","Garante per la protezione dei dati personali (Italy) - 585\u002F2026",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":42,"name":43,"slug":44,"description":45,"color":46},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]