Categories: Insights, Practice

Tag: Garante Privacy, GDPR


31 May 2021

Data Protection Authority: the employer must properly inform employees about the company systems used

In its 15 April 2021 injunction order, the Italian Data Protection Authority fined a company operating in the manufacturing sector for failing to punctually and adequately inform the employees about the features of a computer system. In doing so, the company unlawfully processed workers’ data beyond the limits set by the authorisation of the local labour inspectorate and the purposes indicated in the provided policies. 

The complaint and investigation

The Data Protection Authority intervened following the complaint lodged by the FIOM CGIL, on behalf of some workers, requesting the adoption of an investigation and compliance measure against the employer company. It was alleged that the company’s system required a personal password on the workstation before starting work, which made it possible to store the data of individual workers relating to stoppages and production throughout the working day. Since the data collected relates to the work of individual employees following authentication with the password, the company, in the union’s opinion, collected data through this system and for purposes other than those outlined in the privacy policy.

As a result of the investigation carried out by the Data Protection Authority, it emerged that the computer system coexisted with the previous work organisation method, based on the completion of paper forms in which the names of employees were revealed in plain text. The forms were stored and recorded on the software, but without any form of separation, thus contradicting the privacy policies on the system functioning and the authorisation issued by the Labour Inspectorate, which had expressly prohibited using the data collected for disciplinary purposes. It had emerged that the data collected through this tool had been used to verify the truthfulness of the statements made by an employee during disciplinary proceedings initiated against them.

In addition, it emerged that there were irregularities in the retention periods of the data collected and processed, which, according to the company’s statement, should have been commensurate with what was necessary for the “monitoring/evaluating production cycles.”

The Data Protection Authority’s decision

In the light of the information gathered, the Data Protection Authority ordered the definitive limitation of the processing operations carried out using the data collected through this system, ordering the company (i) to bring its organisation and processing operations in line with Regulation (EU) 2016/679, including by updating the privacy policy provided to the employees concerned, (ii) adopt appropriate measures to segregate the data collected using paper forms and software and (iii) pay €40,000 as a financial penalty for the violations found.

Other related insights:

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

6 Feb 2026

Pay equity and transparency: draft implementing decree presented

Italy is among the first Member States to have adopted the draft implementing legislative decree of EU Directive 2023/970, which yesterday received its initial approval from the Council…

30 Jan 2026

A conviction for stalking can justify dismissal for just cause

With Ordinance No. 32952 of 17 December 2025, the Italian Supreme Court, Labour Section, ruled that a final conviction for stalking and abuse can justify dismissal for just…

30 Jan 2026

We continue to be a Great Place to Work!

For the third consecutive year, De Luca & Partners has been awarded the prestigious Great Place to Work® certification, a significant recognition of the value we place on…

29 Jan 2026

Italian Supreme Court: Employer Monitoring and the Use of Corporate Chats for Disciplinary Purposes

Corporate chats “intended for work-related communications by employees accessing them through company accounts constitute work tools, pursuant to Article 4, paragraph 2, of Law No. 300 of 1970,…

28 Jan 2026

Anti-union conduct: the Supreme Court moves beyond formalism and focuses on substance

With order no. 789 of 14 January 2026, the Italian Supreme Court addressed the issue of anti-union conduct by employers in relation to information and consultation obligations on…

27 Jan 2026

DID YOU KNOW THAT… the use of artificial intelligence may justify a dismissal for objective justified reason?

With Judgment No. 9135 of November 19, 2025, the Labour Section of the Court of Rome held that the dismissal for objective justified reason (i.e. “giustificato motivo oggettivo”,…