Awareness Lessons
last week
Piaggio Fined €460K for Unlawful Employee Email Monitoring and Delayed Account Deactivation
Piaggio violated Italian and EU data protection law by retaining and examining a substantial volume of emails belonging to former employees, constituting unlawful workplace surveillance. The company also failed to deactivate corporate email accounts within the legally required timeframe, extending unnecessary access and data exposure risks. These failures highlight a common gap between IT offboarding procedures and legal data minimisation obligations. The case underscores that monitoring employee communications — even after departure — requires a clear legal basis, proportionality, and transparent policy, none of which were adequately demonstrated here.
Tactical Insight
Immediate actions
- Establish and enforce a documented offboarding checklist that mandates email account deactivation within a defined, legally compliant window (e.g., 24–72 hours after departure).
- Conduct an immediate audit of all retained former-employee email archives and delete or anonymise data that lacks a documented legal basis for retention.
Policy & Governance improvements
- Define and publish a clear, GDPR-compliant workplace monitoring policy that specifies what data is collected, for how long, and under what legal basis, ensuring employee transparency.
- Implement a formal Data Retention Schedule covering employee communications, with automated deletion triggers tied to employment end dates.
- Require Data Protection Impact Assessments (DPIAs) before introducing or continuing any employee monitoring practices.
Detection & Oversight measures
- Assign the Data Protection Officer (DPO) oversight responsibility for offboarding workflows, with periodic reporting on compliance with account deactivation SLAs.
- Implement automated alerting when former-employee accounts remain active beyond the approved retention window.