Categories: Insights, Practice · News

Tag: account di posta aziendale, Controlli email


27 Apr 2026

Management of corporate email after termination of employment: the Italian Data Protection Authority extends the right of access to all emails in the individual email account 

An employee may access the messages in their corporate email account and the documents stored on their computer after the termination of employment. Any limitations must be justified by specific and proven reasons, such as the protection of trade secrets”. This was established by the Italian Data Protection Authority (i.e. “Garante per la protezione dei dati personali”) in a decision issued on 12 March 2026 and published on 15 April 2026. 

Following the termination of his employment relationship, the former employee requested the company to access his personal documents and folders stored on his computer, as well as the contents of his individual corporate email account. Initially, the company allowed only partial access, permitting the retrieval of files from the desktop but not from the email account, allegedly for technical reasons. At a later meeting, the company provided only the correspondence deemed “strictly personal” (such as exchanges with family members, tax certificates and expense reimbursements), excluding all communications related to work activities. 

Faced with this limitation, the data subject formally submitted a request for access under Article 15 of Regulation (EU) 2016/679 (GDPR), asking for a copy of all emails contained in his corporate account from a certain date. The company replied that the request fell outside the scope of the right of access, arguing that the information contained in the email account was its property and that access should be limited to the employee’s personal data only. 

The Authority found this approach to be non-compliant with the applicable legislation, reaffirming that the data subject’s right of access extends to all personal data relating to them, regardless of whether such data is classified as personal or professional: 

The content of email messages – as well as the external data of communications and any attachments – relates to forms of correspondence protected by confidentiality guarantees, also at a constitutional level, whose purpose is to safeguard the essential core of human dignity and the full development of personality within social formations”. 

Accordingly, communications transmitted through an individualised account, even if work-related, constitute personal data of the account holder. The company’s claim that such communications were under its “full and exclusive control” was deemed an “erroneous assumption”. 

The Authority also found unlawful the redaction and anonymisation activities carried out by the company. While the GDPR allows limitations to the right of access in order to protect the rights and freedoms of others (including trade secrets), the data controller must demonstrate a real and concrete risk of harm. In this case, the company failed to provide evidence supporting such risk, and the redaction of third-party data appeared unnecessary, as the information was already known to the complainant. 

The decision also highlights further shortcomings in terms of compliance. The Authority identified deficiencies in the transparency of the privacy notices and found the data retention periods adopted by the company (five years for emails and 12 months for browsing data) to be disproportionate in relation to the stated purposes. 

In light of the violations identified, the Authority imposed an administrative fine of EUR 50,000 and ordered the company to grant full access to the requested data, as well as to update its privacy notices and internal policies.

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

3 Aug 2026

Pay Transparency: the first requests from employees are starting to arrive (Il Sole 24 Ore, 3 august 2026 – Vittorio De Luca)

Two months after the decree. Since Legislative Decree 96/2026 came into force on 7 June, according to a flash survey conducted by GIDP, 8% of HR directors have…

30 Jul 2026

Corporate controls and data protection: what balance?

A recent judgment of the Court of Pisa, No. 800 of 13 June 2026, addresses a topic of particular interest for companies: the delicate balance between the protection…

30 Jul 2026

Unfair dismissal and reinstatement: the employee must repay the payment in lieu of notice

With order no. 22187 of 28 June 2026, the Italian Supreme Court addressed the issue of whether payment in lieu of notice paid to an employee must be…

30 Jul 2026

Did you know that… an employee’s natural incapacity does not prevent the time limit for challenging a dismissal from running?

In judgment no. 23486 of 18 July 2026, the Joint Chambers of the Italian Supreme Court (i.e. “Corte di Cassazione”) held that the natural incapacity of an employee…

22 Jul 2026

An employee may not steer clients toward a competitor before resigning (Camera di Commercio Francese in Italia, 22 July 2026 – Vittorio De Luca, Silvia Zulato)

With Order No. 1723 of 26 May 2026, the Italian Supreme Court (Corte di Cassazione) confirmed the liability of an employee who, prior to the termination of his…

20 Jul 2026

Access to Naspi (Top24 Lavoro Ai – Il Sole 24 Ore, 20 July 2026 – Vittorio De Luca e Alessandra Zilla)

Regulatory Framework  The New Social Insurance for Employment (NASpI), introduced by Legislative Decree No. 22 of 4 March 2015, is the primary income support scheme for employees who…