Tag:
Datore di lavoro, Privacy, trattamento dati personali
28 Nov 2024
Data protection and remote control of workers: algorithms and digital platforms are not exempt
The Italian Data Protection Authority sanctioned the company Foodinho S.r.l., a Glovo Group company, to pay a fine of EUR 5 million for unlawfully processing the personal data of more than 35,000 riders through its digital platform.
Following a complex investigation carried out ex officio by the Authority, it revealed that the company, which had already been sanctioned in 2021 for unlawful processing and violations of the provisions of the privacy legislation, was carrying out “numerous and serious violations” of the GDPR.
Among others, the company:
when de-activating or blocking the rider’s account, it automatically sent a single standard message without informing the recipient of the possibility of contesting the decision and requesting that the account be restored,
carried out automated processing of riders’ personal data without having taken the measures required by the regulations for the use of automated systems. In fact, the rider was not provided with the possibility of exercising the right to obtain human intervention, to express his or her opinion and to contest the decision taken through the system (n.b. on this point also the so-called “Transparency Decree”),
sent, without prior notice, the riders’ personal data, including their geographical location, to third-party companies. The geolocation data were collected and processed even when the rider was not working and even when the app was in the background or not active.
In addition to the numerous violations of privacy regulations pointed out by the Italian Data Protection Authority and partially reported herein, it is worth mentioning that the Authority highlighted that in this case, the company “while carrying out an activity of systematic control of the work performed by the riders, through the settings and functions of technological tools that operate remotely (digital platform, app, communication recording systems), […], did not comply with the provisions established by Article 4, paragraph 1, of Law no. 300/1970, as it did not verify that the tools used are attributable to the purposes strictly allowed by the law (organizational and production needs, work safety and protection of the environment, and protection of the environment) nor did it activate the guarantee procedure provided for in the event of the existence of one of the aforementioned purposes (collective agreement entered into with trade union representatives or, failing that, authorization by the Italian Labor Inspectorate)”.
In other words, the company, in addition to implementing technical and organizational security measures aimed at eliminating breaches and ceasing unlawful processing of personal data, must also take appropriate measures to comply with the provisions of the Workers’ Statute on remote control of employees.
In 2026, De Luca & Partners marks an extraordinary milestone: its 50th anniversary. For half a century, the Firm has stood alongside businesses, guiding them through the evolution…
With Order No. 13722 of 11 May 2026, the Labour Section of the Italian Supreme Court of Cassation (Corte di Cassazione) held that an employee’s repeated lateness, resulting…
During our webinar “Pay Transparency Has Arrived: the Revolution in Compensation Between New Obligations for Companies and New Rights for Workers”, the speakers Claudia Cerbone, Managing Associate, and…
With the recent order no. 13731 of May 11, 2026, the Court of Cassation ruled on the validity and effectiveness of a dismissal notification sent via e-mail. The…
The Official Gazette has published Decree-Law No. 62 of 30 April 2026, entitled “Urgent Provisions on Fair Pay, Employment Incentives and the Fight Against Digital Labour Exploitation”, which…
With Decision No. 167/2026 of 12 March 2026, the Italian Data Protection Authority (“Garante per la protezione dei dati personali”) once again addressed the issue of video surveillance,…