[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fb_uw5stHjab5E1cdcRNnXO40Q5D_cAXID-yDnTPHzME":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"dd7bc726-36d0-40cf-9a2f-7c7429f5631f","italian-health-agency-fined-for-excessive-employee-vehicle-tracking","ca2a0883-9f4a-4b04-9b38-b90d2dba4675","Italian Health Agency Fined for Excessive Employee Vehicle Tracking","The Liguria Health Protection Agency violated GDPR data minimization principles by continuously tracking employees via a vehicle monitoring system at excessively frequent intervals, going far beyond what was necessary for legitimate operational purposes. Compounding the violation, the agency improperly leveraged this tracking data in disciplinary proceedings, extending the harm beyond mere over-collection. This case highlights that even when organizations fulfill their transparency obligations (informing employees of monitoring), they can still breach privacy law by collecting more data than is strictly necessary. It serves as a critical reminder that lawful monitoring must be proportionate, purpose-limited, and not repurposed for unintended uses. Failure to align surveillance practices with data protection law exposes public bodies to regulatory fines and reputational damage.","**Immediate actions:**\n- Audit all existing employee monitoring systems to assess whether data collection frequency and scope is proportionate to the stated business purpose.\n- Cease using monitoring data collected for operational purposes (e.g., fleet management) in disciplinary or HR proceedings without a separate, documented legal basis.\n\n**Policy & governance improvements:**\n- Establish a formal Data Protection Impact Assessment (DPIA) process mandatory for any employee monitoring technology before deployment.\n- Define and document explicit retention limits and access controls for employee tracking data, ensuring it is deleted when no longer needed.\n- Create a clear internal policy distinguishing permitted uses of monitoring data from prohibited secondary uses.\n\n**Long-term compliance measures:**\n- Train HR, legal, and operational managers on GDPR principles—especially data minimization and purpose limitation—as they apply to workplace monitoring.\n- Schedule periodic reviews (at least annually) of all active monitoring systems to verify ongoing compliance with proportionality requirements.\n- Engage the Data Protection Officer (DPO) proactively when considering any expansion or repurposing of employee monitoring capabilities.",[12,13,14,15,16,17,18,19,20],"GDPR Article 5(1)(b) – Purpose limitation","GDPR Article 5(1)(c) – Data minimization","GDPR Article 13 – Transparency and information obligations","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","NIST SP 800-53 PT-2 (Purpose Specification)","NIST SP 800-53 PT-3 (Personally Identifiable Information Processing)","CIS Control 3 – Data Protection","ISO\u002FIEC 29151 – Code of Practice for PII Protection","ITIL Service Design – Information Security Management","published","2026-07-07T10:20:19.176527+00:00","2026-07-07T10:20:19.06+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_382\u002F2026&diff=52075&oldid=0","garante-per-la-protezione-dei-dati-personali-italy-382-2026-5b2800","Garante per la protezione dei dati personali (Italy) - 382\u002F2026",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]