Categories: Insights, Publications · News, Publications

Tag: Dismissal, Licenziamento


27 Nov 2025

IT monitoring and dismissal: the role of prior information in ensuring the legitimacy of disciplinary charges

With judgment no. 28365 of 27 October 2025, the Italian Supreme Court – Labor Division – addressed the balance between an employer’s monitoring powers and employees’ rights to data protection and privacy. The Italian Supreme Court confirmed the legitimacy of a dismissal for just cause imposed on an employee who had disclosed personal data, information, and company documents. The disciplinary charges were based on findings emerging from checks carried out by the employer on the company laptop assigned to the employee.

The Court of Appeal held that the employer’s activity complied with Article 4 of Italian Law no. 300/1970 (i.e. “Statuto dei lavoratori”), as the company had demonstrated that adequate prior information had been provided to the employee “through dissemination of the corporate policy governing the use of IT equipment”. According to that policy, “the employer informed […] employees of the possibility of carrying out checks and inspections in the event of detected anomalies, in compliance with the applicable legislation, reserving the right, where non-compliant conduct was identified, to apply the contractual provisions governing disciplinary measures”.

The Italian Supreme Court agreed, stating that the employer had fulfilled the requirements of Article 4 of Law no. 300/1970 by providing employees with prior and adequate information regarding the possibility of carrying out checks on company IT tools.

What are the implications for employers?

  • Updating, or where absent, drafting corporate policies and regulations defining the correct use of work tools assigned to employees, and clearly informing them of the types and modalities of monitoring activities carried out by the employer, in full compliance with the Workers’ Statute and data protection law.
  • Establishing clear and precise rules on the use of corporate email accounts and Internet access, as well as on prohibited activities, such as downloading audio or video files unrelated to work.
  • Identifying, through specific appointments, the individuals responsible for and expressly authorised to carry out monitoring activities, ensuring they receive appropriate operational instructions and training.
  • Defining information and log retention policies in accordance with applicable law, the guidelines of the Data Protection Authority, and internal corporate policies.

What are the consequences of non-compliance?

The consequences for employers are twofold. On the one hand, the company risks exposure to significant sanctions under data protection law for unlawful processing of personal data. On the other hand, any information collected in breach of the law becomes entirely unusable for all purposes connected with the employment relationship, including the possibility of grounding disciplinary action on such evidence.

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

1 Oct 2026

Corporate e-mail and defensive monitoring: when the GDPR and employment law lead to different outcomes 

The Piaggio case clearly illustrates how the same set of facts can give rise to profoundly different assessments depending on the perspective adopted. In its decision of 13…

1 Oct 2026

NASpI and Reinstatement: the Employee’s Election Causes Loss of the Benefit 

Headnote   In its recent judgment No. 24981 of 3 September 2026, the Italian Supreme Court held that, where a dismissal is set aside with an order of reinstatement…

1 Oct 2026

Did you know that… testimony given in court may have disciplinary relevance and, in the most serious cases, justify dismissal? 

The Italian Supreme Court, Labour Section, by order no. 25687 of 22 September 2026, addressed the issue of the disciplinary relevance of statements made by an employee in…

29 Sep 2026

Shadow AI in the workplace: how to govern risks, data, and security (Agenda digitale, 29 September 2026 – Vittorio De Luca and Martina De Angeli)

The spread of artificial intelligence tools used without corporate authorization exposes businesses to risks involving personal data, confidential information, know-how, and cybersecurity. To govern Shadow AI, organizations need…

24 Sep 2026

The concept of “territorial scope” in a non-compete agreement (Top24 Lavoro Ai – Il Sole 24 Ore, 24 September 2026 – Vittorio De Luca and Alessandro Ferrari)

Interpretative issues in light of the most recent case law on the nullity of non-compete agreements due to the indeterminacy of territorial scope By an order issued on…

16 Sep 2026

Did you know that… repeated violations of company procedures may justify the dismissal of a store manager?

The Italian Supreme Court (Labour Section), in Order No. 25231 of 11 September 2026, upheld the lawfulness of the dismissal for just cause of a store manager who…