[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fvsoNqzWXEaaxwC4LE3S-70XPXUaVsQgnE_AT_uet-1M":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"91dd5ad3-926a-497e-9ca4-3c0ce9c82a6b","piaggio-fined-460k-for-unlawful-employee-email-monitoring-and-delayed-account-deactivation","73859843-a0cb-45f7-af86-3cb848ca3c70","Piaggio Fined €460K for Unlawful Employee Email Monitoring and Delayed Account Deactivation","Piaggio violated Italian and EU data protection law by retaining and examining a substantial volume of emails belonging to former employees, constituting unlawful workplace surveillance. The company also failed to deactivate corporate email accounts within the legally required timeframe, extending unnecessary access and data exposure risks. These failures highlight a common gap between IT offboarding procedures and legal data minimisation obligations. The case underscores that monitoring employee communications — even after departure — requires a clear legal basis, proportionality, and transparent policy, none of which were adequately demonstrated here.","**Immediate actions:**\n- Establish and enforce a documented offboarding checklist that mandates email account deactivation within a defined, legally compliant window (e.g., 24–72 hours after departure).\n- Conduct an immediate audit of all retained former-employee email archives and delete or anonymise data that lacks a documented legal basis for retention.\n\n**Policy & Governance improvements:**\n- Define and publish a clear, GDPR-compliant workplace monitoring policy that specifies what data is collected, for how long, and under what legal basis, ensuring employee transparency.\n- Implement a formal Data Retention Schedule covering employee communications, with automated deletion triggers tied to employment end dates.\n- Require Data Protection Impact Assessments (DPIAs) before introducing or continuing any employee monitoring practices.\n\n**Detection & Oversight measures:**\n- Assign the Data Protection Officer (DPO) oversight responsibility for offboarding workflows, with periodic reporting on compliance with account deactivation SLAs.\n- Implement automated alerting when former-employee accounts remain active beyond the approved retention window.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"GDPR Article 5(1)(a) – Lawfulness, fairness and transparency","GDPR Article 5(1)(e) – Storage limitation","GDPR Article 6 – Lawful basis for processing","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","GDPR Article 88 – Processing in the context of employment","CIS Control 5 – Account Management","CIS Control 3 – Data Protection","NIST SP 800-53 AC-2 – Account Management","NIST SP 800-53 MP-6 – Media Sanitization (data disposal)","NIST Privacy Framework PR.DS-P4 – Data Retention","ISO\u002FIEC 27001:2022 A.5.9 – Inventory of information and other associated assets","ISO\u002FIEC 27001:2022 A.6.5 – Responsibilities after termination or change of employment","ITIL Service Transition – Offboarding and access revocation procedures","published","2026-08-06T10:20:40.47759+00:00","2026-08-06T10:20:40.321+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_476\u002F2026&diff=52634&oldid=0","garante-per-la-protezione-dei-dati-personali-italy-476-2026-51e9b6","Garante per la protezione dei dati personali (Italy) - 476\u002F2026",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":40,"name":41,"slug":42,"description":43,"color":44},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":46,"name":47,"slug":48,"description":49,"color":50},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]