Categories: Insights, Practice · News

Tag: account di posta aziendale, Controlli email


27 Apr 2026

Management of corporate email after termination of employment: the Italian Data Protection Authority extends the right of access to all emails in the individual email account 

An employee may access the messages in their corporate email account and the documents stored on their computer after the termination of employment. Any limitations must be justified by specific and proven reasons, such as the protection of trade secrets”. This was established by the Italian Data Protection Authority (i.e. “Garante per la protezione dei dati personali”) in a decision issued on 12 March 2026 and published on 15 April 2026. 

Following the termination of his employment relationship, the former employee requested the company to access his personal documents and folders stored on his computer, as well as the contents of his individual corporate email account. Initially, the company allowed only partial access, permitting the retrieval of files from the desktop but not from the email account, allegedly for technical reasons. At a later meeting, the company provided only the correspondence deemed “strictly personal” (such as exchanges with family members, tax certificates and expense reimbursements), excluding all communications related to work activities. 

Faced with this limitation, the data subject formally submitted a request for access under Article 15 of Regulation (EU) 2016/679 (GDPR), asking for a copy of all emails contained in his corporate account from a certain date. The company replied that the request fell outside the scope of the right of access, arguing that the information contained in the email account was its property and that access should be limited to the employee’s personal data only. 

The Authority found this approach to be non-compliant with the applicable legislation, reaffirming that the data subject’s right of access extends to all personal data relating to them, regardless of whether such data is classified as personal or professional: 

The content of email messages – as well as the external data of communications and any attachments – relates to forms of correspondence protected by confidentiality guarantees, also at a constitutional level, whose purpose is to safeguard the essential core of human dignity and the full development of personality within social formations”. 

Accordingly, communications transmitted through an individualised account, even if work-related, constitute personal data of the account holder. The company’s claim that such communications were under its “full and exclusive control” was deemed an “erroneous assumption”. 

The Authority also found unlawful the redaction and anonymisation activities carried out by the company. While the GDPR allows limitations to the right of access in order to protect the rights and freedoms of others (including trade secrets), the data controller must demonstrate a real and concrete risk of harm. In this case, the company failed to provide evidence supporting such risk, and the redaction of third-party data appeared unnecessary, as the information was already known to the complainant. 

The decision also highlights further shortcomings in terms of compliance. The Authority identified deficiencies in the transparency of the privacy notices and found the data retention periods adopted by the company (five years for emails and 12 months for browsing data) to be disproportionate in relation to the stated purposes. 

In light of the violations identified, the Authority imposed an administrative fine of EUR 50,000 and ordered the company to grant full access to the requested data, as well as to update its privacy notices and internal policies.

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

30 Apr 2026

Webinar “Bonuses: What Do You Need to Know About Objectives?” – HR Coffee with De Luca & Partners

Yesterday, during our first webinar “HR Coffee with De Luca & Partners", the speakers Vittorio De Luca, Managing Partner, and Alessandra Zilla, Managing Associate at De Luca &…

27 Apr 2026

Unemployment benefits and resignation following transfer beyond 50 km: distance alone is not sufficient, employer’s breach must be proven  

With order no. 10559 of 21 April 2026, the Italian Supreme Court addressed the issue of unemployment benefits (i.e. “NASpI”) in the context of resignations for just cause following…

27 Apr 2026

DID YOU KNOW THAT… the probationary period clause is null and void if the duties are described in generic terms? 

The Court of Milan, with judgment no. 683 of 3 April 2026, reaffirmed that a probationary clause (i.e. “patto di prova”) is valid only if it contains a specific indication of the duties subject to…

17 Apr 2026

Criminal penalties are being introduced for those who fail to protect remote workers (The Platform, 17 April 2026 – Vittorio De Luca e Martina De Angeli)

The provision amends Legislative Decree 81/2008 by introducing a new Article 3, paragraph 7-bis, which makes compliance with safety obligations conditional upon the delivery—at least annually—of a written…

15 Apr 2026

Dismissal deemed valid based on a message sent in a WhatsApp chat (Camera di Commercio Italo-Francese – Vittorio De Luca, Silvia Zulato)

With Order No. 7982 of March 31, 2026, the Italian Supreme Court (Labour Section) held that a message sent within a private chat may constitute just cause for…

13 Apr 2026

De Luca & Partners, the boutique turns 50 years old (MAG – Legalcommunity, 13 April 2026 – Vincenzo De Luca, Vittorio De Luca e Roberta Padula)

It was 1976 when labor lawyer Vincenzo De Luca decided to open his firm in Milan. He came from Barletta and rented a small office in Largo Corsia…