Categories: Insights, Legislation · News, Press review

Tag: GDPR


26 Sep 2023

Italian Data Protection Authority: employee has right to access report of investigative agency appointed by employer

With Ruling dated 6 July 2023, the Italian Data Protection Authority (Garante per la protezione dei dati personali, ‘DPA) found that data processing carried out by a public utility service company (the “Company”) was unlawful. The DPA ruled that an employer has an obligation to allow a worker to access all his or her personal data, including data contained in a report produced by an investigative agency appointed by the employer to collect information about the worker and used by the Company for disciplinary purposes.

The facts

The matter originates from a complaint submitted to the DPA by an employee who did not receive a full response to multiple requests for access to his personal data submitted to the employer Company after receiving a disciplinary complaint. The disciplinary complaint was followed by the dismissal of the worker, and contained “specific references” to conduct unrelated to the actual work activity and which therefore suggested potential monitoring “contrary to the regulations in force (condotta non iure) and detrimental to the personal legal status of others protected by law (condotta contra ius) and, consequently leading to data collected being unusable”.

The Company justified the denial of access to the personal data processed by arguing that the requests presented by the worker were too general and that he should have indicated in detail the information he wanted to access.

Furthermore, it emerged that the employee only learned of the existence and content of the investigative report when the Company entered an appearance in the proceedings appealing the dismissal before the competent judicial authorities.

The outcome of the preliminary investigation

At the time of the investigation, the DPA found that the Company, in its capacity as data Controller, carried out processing in breach of:

  • Article 15 of Regulation (EU) 2016/679 (the “GDPR”), as it made the response to the access request presented by the worker conditional on the detailed indication of the documents and information he wanted to access. The request to exercise the right of access, a right recognised to all data subjects in relation to the processing of personal data by the article in question, must be understood in general terms, including all personal data concerning the data subject, as also specified in the “Guidelines 01/2022” on Data Subject Rights (EDPB, 28 March 2023). Furthermore, the DPA reiterates that, if the data are not collected directly from the data subject, the data Controller must indicate their origin.

In this case, the Company should have provided all the data collected with the investigative report, considering that it also contained information relating to the worker but which had not been mentioned in the disciplinary complaint;

  • Article 12 of the GDPR, because a data Controller, in response to a request to exercise rights by a data subject, must facilitate their exercise by providing “information on action taken on a request […] without undue delay and in any event within one month of receipt of the request” and “if the controller does not take action on the request of the data subject, the controller shall inform the data subject without delay […] of the reasons for not taking action and on the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy”;
  • Article 5, paragraph 1, letter (a) of the GDPR, because personal data must be processed “lawfully, fairly and in a transparent manner in relation to the data subject”. The Company, in the response provided to the worker, had not in fact specified the origin of the personal data used for the disciplinary complaint.

The DPA’s decision

For all the reasons set out above, the DPA found the processing carried out by the Company in relation to Articles 5, paragraph 1, letter (a), 12 and 15 of the GDPR to be unlawful. It reiterated that “unless otherwise explicitly requested by the data subject, the request to exercise the right of access is understood in general terms, including all personal data concerning them”. The DPA therefore, ordered the employer Company to pay an administrative fine of EUR 10,000 and also ordered the publication of the Ruling on its website.

Other related insights:

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

20 May 2026

Webinar “May 1st Decree: Key Updates and what’s New” –  HR Coffee with De Luca & Partners

On the occasion of our webinar “An HR Coffee with De Luca Partners,” the speakers Silvia Zulato, Senior Associate, and Alessandro Riccardo Polli from the Labour Consulting Division…

12 May 2026

Legitimate dismissal for false attendance reporting and misuse of access system data (Camera di Commercio Francese in Italia – Vittorio De Luca, Silvia Zulato)

With Order No. 7985 of 31 March 2026, the Italian Supreme Court – Labour Section – confirmed the lawfulness of a dismissal for just cause imposed on an…

30 Apr 2026

Webinar “Bonuses: What Do You Need to Know About Objectives?” – HR Coffee with De Luca & Partners

Yesterday, during our first webinar “HR Coffee with De Luca & Partners", the speakers Vittorio De Luca, Managing Partner, and Alessandra Zilla, Managing Associate at De Luca &…

27 Apr 2026

Management of corporate email after termination of employment: the Italian Data Protection Authority extends the right of access to all emails in the individual email account 

“An employee may access the messages in their corporate email account and the documents stored on their computer after the termination of employment. Any limitations must be justified by specific…

27 Apr 2026

Unemployment benefits and resignation following transfer beyond 50 km: distance alone is not sufficient, employer’s breach must be proven  

With order no. 10559 of 21 April 2026, the Italian Supreme Court addressed the issue of unemployment benefits (i.e. “NASpI”) in the context of resignations for just cause following…

27 Apr 2026

DID YOU KNOW THAT… the probationary period clause is null and void if the duties are described in generic terms? 

The Court of Milan, with judgment no. 683 of 3 April 2026, reaffirmed that a probationary clause (i.e. “patto di prova”) is valid only if it contains a specific indication of the duties subject to…