Categorie: Insights, Normativa · News

Tag: Dismissal, GDPR, Licenziamento, Privacy


3 Lug 2025

E-mail aziendale e navigazione Internet: il Garante Privacy emette la prima sanzione per conservazione illegittima dei metadati delle mail aziendali e dei log di navigazione

The employer may collect employees’ Internet browsing logs and email metadata only under specific conditions and safeguards. This was affirmed by the Italian Data Protection Authority (i.e. “Garante Privacy”) when imposing a €50,000 fine on the Lombardy Region” (Provision No. 243 of April 29, 2025).

As stated on the Authority’s official website, this ruling follows an inspection aimed at verifying the Region’s compliance with privacy regulations concerning the processing of employee data. The measure comes almost a year after the publication of the guidance document titled “Programs and IT services for managing e-mail in the workplace and the processing of metadata” (Provision No. 364 of June 6, 2024).

Although this case specifically involved public administration, it is worth clarifying that all findings, observations, and clarifications issued by the Authority fully apply to private-sector data controllers as well.

Metadata and Internet browsing logs

“Metadata” refers to information related to the sending, receiving, and routing of messages. This may include the sender’s and recipient’s email addresses, IP addresses of the servers or clients involved in message routing, timestamps of sending, retransmission or receipt, message size, presence and size of any attachments, and, in certain cases depending on the email management system used, even the subject of the sent or received message.

Browsing logs, on the other hand, allow tracking of activities during web navigation and contain data such as visited IP addresses, URLs of opened web pages, connection times and durations, type of device and browser used, as well as any downloads or uploads performed.

The June 6, 2024, guidance clarifies that the maximum retention period for such data is 21 days. Any retention beyond this period is permissible only under specific conditions that justify the extension, and, in any case, one of the safeguards provided by Italian law under Article 4 of Law No. 300/1970 (the Workers’ Statute) must be satisfied: (i) an agreement with trade unions or, failing that, (ii) authorization from the local Labour Inspectorate.

This is because all such information allows the employer to identify behavioral patterns, understand workers’ relationships and habits, and infer elements such as performance and productivity. In other words, it may amount to indirect remote monitoring of employees’ activities.

Violations detected and sanctions imposed

During the Authority’s inspection, it emerged that the Region retained:

  • E-mail metadata for 90 days — violation resulting in a €20,000 fine for unlawful data processing,
  • Internet browsing logs for 12 months — violation resulting in a €25,000 fine,
  • Help desk ticket registry data for 10 years — violation resulting in a €5,000 fine.

Recommended actions to ensure compliance with current legislation?

  • Provide information notices to all data subjects concerned.
  • Conduct a legitimate interest assessment and a data protection impact assessment to evaluate and mitigate risks.
  • Define data retention periods in line with current legislation and the Authority’s guidelines or, where specific needs arise (which must be justified and demonstrated), fulfill one of the safeguard conditions under Article 4 of the Workers’ Statute.
  • Update and align internal documentation accordingly.
  • Restrict access to such data exclusively to specifically authorized personnel.
  • Respect the principle of data minimization and implement adequate security measures, such as encrypting metadata and logs.
  • Update contracts with third-party providers to ensure compliance with Article 28 of the GDPR.
  • Continuously monitor compliance levels and, where necessary, implement appropriate updates and improvements.

Other related Insights:

Iscriviti alla newsletter

Contattaci

Hai bisogno di informazioni? Scrivici e il nostro team di esperti ti risponderà il prima possibile.

Compila il form

Altre news e insights

8 Giu 2026

Il sistematico ritardo del dipendente può giustificare il licenziamento per giusta causa (Camera di Commercio Francese in Italia – Vittorio De Luca, Silvia Zulato)

Con l’ordinanza n. 13722 dell’11 maggio 2026, la Corte di Cassazione, Sezione Lavoro, ha stabilito che il reiterato ritardo del dipendente, con conseguente mancato rispetto delle scadenze e…

4 Giu 2026

Webinar “È arrivata la Pay Transparency: la rivoluzione delle retribuzioni tra nuovi obblighi per le aziende e nuovi diritti per i lavoratori” – HR Virtual Breakfast

In occasione del nostro webinar “È arrivata la Pay Transparency: la rivoluzione delle retribuzioni tra nuovi obblighi per le aziende e nuovi diritti per i lavoratori”, i relatori…

29 Mag 2026

Comunicazione del licenziamento: la mail ordinaria è sufficiente se il lavoratore ne ha conoscenza

Con la recente ordinanza n. 13731 dell’11 maggio 2026, la Corte di Cassazione si è pronunciata in merito alla validità ed efficacia di una comunicazione del licenziamento avvenuta…

29 Mag 2026

Lo sai che… il c.d. “Decreto 1° maggio” introduce nuove misure in materia di salario “giusto”, incentivi all’occupazione e lavoro tramite piattaforme digitali? 

È stato pubblicato in Gazzetta Ufficiale il Decreto-Legge 30 aprile 2026, n. 62, recante “Disposizioni urgenti in materia di salario giusto, incentivi all’occupazione e contrasto al caporalato digitale”,…

29 Mag 2026

Videosorveglianza e protezione dei dati personali: il Garante ribadisce l’obbligo di trasparenza

Con il provvedimento n. 167/2026 del 12 marzo 2026, il Garante per la protezione dei dati personali è tornato a pronunciarsi sul tema della videosorveglianza, ribadendo alcuni principi…

20 Mag 2026

Webinar “Decreto 1° maggio: le principali novità” – Un Caffè HR con De Luca & Partners

In occasione del nostro webinar "Un Caffè HR con De Luca Partners", i relatoriSilvia Zulato, Senior Associate e Alessandro Riccardo Polli, Divisione Consulenza del Lavoro​​ di HR Capital…