Site icon De Luca & Partners

Corporate e-mail and defensive monitoring: when the GDPR and employment law lead to different outcomes 

The Piaggio case clearly illustrates how the same set of facts can give rise to profoundly different assessments depending on the perspective adopted. In its decision of 13 June 2026, the Court of Pisa held that the monitoring of an employee’s corporate email account was lawful and upheld the dismissal imposed by the employer. Just a few days later, however, the Italian Data Protection Authority (Garante per la protezione dei dati personali) criticized the company’s email management and retention practices, imposing a fine of €460,000 on Piaggio.

At the center of the case were several emails obtained during an internal investigation involving two employees who had been dismissed in 2023, as well as a system for retaining email messages and related logs that was found to be inconsistent with the principles governing the protection of personal data.

At first glance, the two decisions appear irreconcilable. In reality, however, the contrast highlights an often overlooked aspect: the lawfulness of a monitoring activity from an employment law perspective does not necessarily coincide with the lawfulness of the personal data processing that enabled such monitoring.

In this case, the Court of Pisa emphasized the nature of the corporate email account as a work tool under Article 4(2) of the Italian Workers’ Statute, finding that the targeted monitoring was legitimate as it had been carried out in response to a well-founded suspicion of misconduct and was aimed at protecting the company’s assets and the employee’s duty of loyalty. From this perspective, the court focused on the admissibility of the evidence obtained and on the proportionality of the monitoring in relation to the misconduct alleged.

The Data Protection Authority adopted a different perspective. Rather than assessing only the specific access to the emails, the Authority examined the entire system governing the management of the corporate email account, focusing on the retention, collection, and subsequent consultation of business-related data. In particular, it criticized the company’s practice of retaining employees’ emails for the entire duration of their employment relationship and for five years after its termination, thereby making it possible to reconstruct the individuals’ activities retrospectively. According to both the Authority and the Italian Supreme Court, so-called “defensive checks in the strict sense” may only concern data collected after a well-founded suspicion of misconduct has arisen. In the present case, however, some of the emails relied upon had been collected and retained long before any such suspicion emerged.

Without addressing the merits of the two proceedings, it is worth noting that this case demonstrates how the assessment of the lawfulness of monitoring corporate email accounts cannot be limited to the moment of accessing the information. Rather, it must extend to the entire data processing lifecycle, including the methods of collection, retention, and subsequent consultation of the information.

The decisions of the Court of Pisa and the Data Protection Authority appear to reflect different levels of assessment. While the employment court focused its analysis on the legitimacy of the monitoring activity and the admissibility of its findings for disciplinary purposes, the Authority examined the processing operation as a whole, paying particular attention to the legal basis for data retention and the compatibility of the relevant management practices with the principles of the GDPR.

In this context, particular importance must be attached to a number of organizational and documentary measures, including the definition of policies governing the use of company tools, the correct identification of retention periods, the transparency of information provided to employees, and the regulation of monitoring activities that may be carried out through work tools. Although these matters have traditionally been viewed as falling within the scope of privacy compliance, they increasingly affect the management of disciplinary proceedings and internal investigations as well.

The case confirms the growing interaction between employment law and data protection law. The assessments carried out by employment courts and supervisory authorities pursue different objectives and are based on criteria that do not necessarily overlap. As a result, the lawfulness of a particular activity under one framework does not automatically ensure compliance under the other. For this reason, corporate processes involving IT tools and employee monitoring now require an integrated approach capable of balancing the organization’s legitimate interests, the safeguards established by the Workers’ Statute, and the obligations arising from data protection legislation.

Exit mobile version