A recent judgment of the Court of Pisa, No. 800 of 13 June 2026, addresses a topic of particular interest for companies: the delicate balance between the protection of employees’ privacy, employer controls and the admissibility of evidence collected through company tools.
The case
The matter originated from the discovery of a potential conflict of interest involving an employee who had worked for the company for many years in the active invoicing department. The employee informed the employer only at a later stage that her son had held the position of director in a supplier company of the same employer. This circumstance led the company to investigate the situation further, considering that the lack of timely disclosure could be indicative of the employee’s involvement in the supplier company’s activities, in a manner incompatible with the duties of fairness and transparency incumbent on employees.
Considering these elements, the company initiated an internal verification process that initially concerned external documentary sources and made it possible to identify further links between the employee, her son and certain individuals involved in the management of the supplier company. The findings of the investigation then led the employer to broaden the checks by accessing the employee’s company email account.
The analysis of the emails carried out using specific keywords and with reference to a defined time period, revealed elements which, according to the company, confirmed that the employee’s involvement in the supplier company’s activities was broader than she had declared. Because of these findings, the company initiated disciplinary proceedings, which ended with dismissal for just cause.
The Court’s decision
The decision addresses a particularly topical issue: the relationship between defensive controls, privacy protection and the admissibility of evidence collected through company digital tools.
According to the Judge, access to the email account does not amount to a generalized control over work activity, but rather to a defensive control in the strict sense, aimed at verifying a specific suspicion of misconduct that had already emerged on the basis of objective elements acquired during the preliminary checks. In this regard, the Court refers to the settled case law of the Court of Cassation, according to which such controls are permitted when they are based on concrete indications of misconduct, are targeted and are carried out after the suspicion has arisen.
In the reconstruction endorsed by the Judge, the suspicion does not arise from the examination of the email account but predates it and originates from the information that emerged following the documentary checks carried out by the company. This very circumstance makes it possible to qualify access to the email account as an investigative tool aimed at verifying specific facts, rather than as an indiscriminate monitoring activity concerning the employee. The Court also gives weight to the concrete manner in which the control was carried out. The analysis of company communications was in fact limited to specific keywords, confined to a defined time period and performed by authorized persons. These elements led the Judge to consider the principle of proportionality to have been respected, excluding the possibility that the investigation had been massive or exploratory in nature.
A further aspect highlighted in the decision concerns the system of company rules adopted by the employer. The Court notes that the employee had been informed in advance, through the company ICT policy, of the rules governing the use of IT tools and of the possibility that checks could be carried out on them. According to the Judge, the presence of an adequate information notice and the employee’s prior acceptance of the policy are elements capable of satisfying the conditions required under Article 4 of the Workers’ Statute and data protection legislation.
Particularly significant is also the position taken by the Court on the relationship between the GDPR and disciplinary proceedings. While acknowledging the complaints submitted to the Italian Data Protection Authority in relation to the retention of company data, the Judge draws a clear distinction between the possible unlawfulness of certain processing activities from an administrative standpoint and the admissibility of evidence in employment litigation. In other words, any issues relating to data retention do not automatically render the acquired documentation inadmissible, where access to the data takes place in the context of a defensive investigation deemed legitimate and proportionate.
In light of these considerations, the Court concludes that the evidence collected through access to the email account may be lawfully used in the disciplinary proceedings and therefore proceeds to examine the merits of the allegations raised against the employee. Once the validity of the evidence acquired had been recognized, the Judge found that the breach of the duties of loyalty, fairness and transparency had been established and confirmed the lawfulness of the dismissal for just cause.
However, the ruling should not be read as meaning that privacy legislation is generally irrelevant in the context of company investigations. The Court merely states that any issues in the management of personal data do not automatically render the evidence collected in disciplinary proceedings inadmissible, where access to the data took place in the context of legitimate and proportionate defensive control. This does not mean, however, that the same conduct is devoid of consequences from the separate standpoint of personal data protection. On the contrary, any breaches of the GDPR and national legislation may continue to be relevant independently from an administrative and sanctioning perspective, exposing the company to measures by the supervisory authority and to the further liabilities provided for by the legal system.
