Skip to content
Enforcement · Garante per la protezione dei dati personali (Italy) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Garante per la protezione dei dati personali (Italy) · 462/2026

The case involves a worker (the data subject), his former employer (the controller), and the staffing agency that had provided the company with the worker.

How it connects

65 of 78 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Supervision Right of Access
C-175/20 SIA 'SS' v Valsts ieņēmumu dienests In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a… CJEU ·Fifth Chamber Feb 24, 2022 Personal Data Material scope (GDPR) Criminal Data
C-740/22 Endemol Shine Finland Oy In Case C-740/22, the Court of Justice of the European Union (Sixth Chamber) ruled on a preliminary reference from the Itä-Suomen hovioikeus (Court of Appeal, Eastern Finland)… CJEU ·Sixth Chamber Mar 7, 2024 Criminal Data Personal Data Special Categories of Data
HvJ EU 9 januari 2025, C‑394/23 (Mousse) Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20… HvJ EU 9 januari 2025, C‑394/23 (Mousse). ·CJEU Jan 9, 2025 Right to Object Personal Data Controllers
15625/2026 Cass.Civ. - 15625/2026 Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its… Supreme Court May 21, 2026 DPIA Privacy Impact Assessment Privacy by Design

Full text 78 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

[Web Doc. No. 10268633] Decision of June 18, 2026 Register of Decisions No. 462 of June 18, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, members; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter, the “Regulation”); HAVING REGARD TO the Code on Data Protection, containing provisions for the adaptation of national law to Regulation (EU) 2016/679 (Legislative Decree No. 196 of June 30, 2003, as amended by Legislative Decree No. 101 of August 10, 2018, hereinafter the “Code”); HAVING REGARD TO the complaint filed by Mr. ; HAVING EXAMINED the documentation on file; HAVING REGARD TO the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority’s Regulation No.

§

1/2000; RAPPORTEUR: Prof. Ginevra Cerrina Feroni; PREAMBLE 1. The complaint against the Company and the preliminary investigation. In a complaint dated April 18, 2024, formalized on January 29, 2025, Mr. A. (hereinafter, the Company), with particular reference to the opening of his personal locker after the termination of his employment, in his absence, and the subsequent seizure and destruction of its contents. A. would end on December 31,December 2023, his employment with Cosmint would be terminated, he spoke with a representative of the aforementioned staffing agency regarding the procedures for emptying the locker that had been assigned to him during his employment. According to the account, the complainant was only able to visit the company’s headquarters on January 31, 2024, due to urgent family matters related to his father’s health, of which he had informed the staffing agency. It was only on that occasion that he learned that, in the meantime, the locker had been opened and emptied of its contents, and that those contents were no longer available because they had been thrown away after being removed.

§

, the user company under the temporary staffing contract, in which the companies were requested to provide information pursuant to Article 157 of the Code regarding the facts subject to the complaint. XX, in its response dated April 15, 2025, stated that: - in a temporary staffing arrangement, the staffing agency is not responsible for what occurs on the user company’s premises; (note dated 4/15/2025, p. 2); - pursuant to Art. 4 of the Code of Conduct for the Temporary Employment Agency Sector, “an independent data controller relationship (Data Controller-Data Controller) is established between the temporary staffing agency and the client company (Client), as both parties determine the purposes and methods of their own data processing” (cited note, p. 2); - that said, and in light of the general terms and conditions of the temporary staffing contract entered into in this specific case between the parties, it is clear that it is the responsibility of the user company “to define and implement the procedures related to the return of company property provided to the temporary worker” (cited note, p.

§

3); - “XX took all possible measures to enable the [complainant] to collect his personal belongings, for the sole purpose of facilitating dialogue between the [complainant] and [the Company]” (cited note, p. 3); - “Once the employment contract had ended, XX had no obligations toward the [complainant], essentially becoming a third party in relation to him. […] Whenever the [complainant] confirmed an appointment to collect his personal belongings, Account Specialist XX would contact the Security office and the user’s security guards to inform them of the entry of an individual who was—by that point—no longer authorized to access the premises” (cited note, p. 4); - “On December 29, 2023, Account Specialist XX informed the [complainant] that his employment contract would not be renewed and would therefore terminate on December 31, 2023. […] On the same day […] the [complainant] reported his sick leave by submitting the relevant medical certificate […] covering the period from December 29 to December 31, 2023; On December 30, 2023, Account Specialist XX reminded the [complainant] that he would need to schedule an appointment in January to collect his personal belongings from his locker” (cited note, p.

§

4); - The XX representative then notified the Company’s security office via email that the complainant would come to the company to return his badge and empty his locker on January 3, the 11th, and the 15th of January, respectively—dates that were subsequently canceled by the complainant via WhatsApp messages; on January 29, 2024, the complainant contacted the XX representative again, stating that he would come to the company on January 31; therefore; “on January 31, 2024, the XX Account Specialist again informed the Cosmint Security Office of the arrival of the [complainant] […] to return his badge and collect his personal belongings from his locker”; (cited note, p. A. headquarters and had learned there that his locker had already been emptied […]. The Account Specialist […] - despite the absence of any obligation to do so, but solely out of a spirit of cooperation and good faith - sent a request for clarification/information to Cosmint’s Security Department and security guards […].

§

No response was received” (cited note, p. 6); - “it should be noted that Cosmint did not in any way inform XX that it would proceed to open the locker even in the employee’s absence, nor, more generally, that opening lockers was a practice adopted by the client company” (cited note, p. 6). Since, however, Cosmint did not provide any response to the request for information made pursuant to Art. 157 of the Code—which was sent via certified email and duly delivered— the Authority has delegated the Special Unit for Privacy and Technological Fraud of the Guardia di Finanza to serve notice of the initiation of proceedings for the adoption of corrective and punitive measures pursuant to Article 166, paragraph 5, of the Code (in relation to the provisions of Article 166, paragraph 2, of the Code for the violation of Article 157), as well as to obtain a response regarding the facts subject to the complaint, within the time limits already set forth in the request for information dated March 27, 2025.

§

The Task Force, having visited the Company’s registered office on July 9, 2025, served the notice of the initiation of proceedings and obtained the requested information regarding the facts subject to the complaint, drafting a specific report on the operations carried out. In its response to the request, Cosmint stated that: - “As a multinational company, we receive dozens of certified emails (PEC) per day; our staff […] either overlooked the one sent by the Authority or did not realize that we were required to respond” (report of actions taken on July 9, 2025, p. 3); - “All our employees, upon joining the workforce, are recipients of a locker intended exclusively for storing clothing. , p. 3); - Regarding the use of the locker, the employee is informed verbally that the locker “is intended solely for storing clothing and nothing else, such as personal items or, even less so, valuables for which the Company assumes no responsibility” (cited minutes, p.

§

3); - “All lockers are assigned to employees on a personal basis. […] The claimant’s locker, like all the others, was locked with a padlock he owned, and only the claimant had the keys to it” (minutes cited above, p. 3); - the staffing agency provides communications to its employees “regarding any matter not directly related to the performance of work duties […]. In particular, XX stated to the undersigned that on December 29, 2023, he had notified the worker […] of the termination of the contract, simultaneously instructing him to empty his locker and return the work clothing provided by Cosmint. […] XX had also notified Cosmint’s security department to ensure the employee would have access on January 3, 2024 […]. On January 3, the employee asked XX to reschedule the appointment, as he was unable to attend. A second appointment was then scheduled for January 11, which was also missed. Similarly, the employee did not show up for the next two appointments he had scheduled with XX on January 15 and January 31.

§

” (cited minutes, pp. 3–4); - “The locker was opened on 01/30/24, in the presence of Cosmint’s Security Manager […], Cosmint’s Safety Coordinator […], a Cosmint maintenance worker […], and Cosmint’s General Services Coordinator […]” (cited report, p. 4) … [and] was motivated by the need to free up space for incoming workers” (cited report, p. 4); - “Upon opening the locker, a video was recorded for the protection of our company, which clearly showed that the items alleged by the complainant were not inside the locker. The video was recorded by the person who was, at the time, the security coordinator (a position entrusted to a contractor […] using her personal smartphone. Today, our company no longer works with the company that previously handled security,” so it is no longer possible to retrieve the video (cited minutes, p. 4); - “It should be noted that approximately 550 workers use the Cosmint locker room and that there is significant employee turnover, especially at certain times of the year” (cited minutes, p.

§

4); - “The following items were found: company-owned property (finished products) […], which were destroyed since they could no longer be placed on the market, […]; Items for strictly personal/intimate use […], which the company could not reasonably store, even for hygiene reasons” (cited report, p. 4). 2. The initiation of proceedings for the adoption of corrective measures and the Company’s submissions. A. with a notice of alleged violations of the Regulation regarding the facts that are the subject of the complaint, with reference to Articles 5, para 1, subparagraphs (a) and (c); Article 6, para 1, subparagraphs (b) and (c), and para 2; Article 9, para 2, subparagraph (b); and Article 13 of the Regulation. In its defense briefs submitted on September 26, 2025, the Company stated that: - “Communications regarding the termination of the employment relationship and the related operational procedures were handled exclusively by XX, without prejudice to the Company’s full cooperation in ensuring the orderly conduct of business activities” (note dated September 26, 2025, p.

§

2); - “With regard to the alleged violation of Article 157 of the Code, the Company wishes to clarify that the failure to respond was due exclusively to a mere oversight, without any purpose to evade compliance […] The Company has arranged for a weekly internal summary report to be prepared, listing all relevant certified email (PEC) communications,” (note cited above, p. 3); - “Individual lockers have been installed on company premises and made available to employees exclusively for work-related purposes […] and are not intended for personal use or the storage of valuables. For the latter, however, the Company provides designated spaces for the safekeeping of valuables other than clothing” (cited note, p. 3); - the employee “is responsible for locking the locker with a padlock, and the corresponding keys remain in his or her exclusive possession. The Company has never had access to the contents of the lockers, nor has it ever opened or inspected them” (cited note, p.

§

4); - “In the present case, the time elapsed between XX’s first request to the data subject to clear out the locker and the actual clearing of the locker was approximately one month, during which the [complainant] initially postponed the agreed-upon appointments repeatedly and, after two weeks of silence, went on his own to the Company’s headquarters to clear out the locker” (cited note, p. 4); - “On December 29, 2023, XX, […], urged the [complainant] to empty the locker, which was needed for assignment to new employees, reiterating the urgency of doing so by December 30, 2023 (his last day of work). The [complainant], however, stated that he did not wish to return on his last day of work and, therefore, would not vacate the locker immediately. Subsequently, on January 3, 2024, XX summoned the [complainant] to return his ID card and clear out his locker, but the appointment was postponed at the employee’s request due to family reasons.

§

A new meeting was scheduled for January 11, 2024, but it was not attended, nor was the subsequent appointment on January 15, 2024, which was justified […] on the basis of vague personal reasons” (see cited note, p. 4); - “The Company objects that the Regulation is inapplicable ratione materiae, since the processing of the data at issue (i) was carried out by the Company without the use of automated tools and (ii) the processed data were not contained in a filing system, nor were they intended to be” (see cited note, p. ’ (see cited note, pp. 5–6) “No inventory was made of the items found in the cabinet, nor was the relevant information documented or otherwise archived in a filing system. ” (see cited note, p. 6); - with regard to the concept of “personal data” pursuant to Art. 4(1) of the Regulation, the Company stated that “the items found inside the company locker do not in any way constitute ‘personal data,’ much less special categories of personal data within the meaning of Article 9 of the Regulation, as they are merely tangible objects incapable of identifying, directly or indirectly, their respective owner.

§

The discovery of undergarments or other items, in fact, does not in and of itself imply the processing of personal data within the meaning of Article 4 of the Regulation” (see cited note, pp. 7–8); - “Specific instructions on the use of lockers have always been provided verbally to all staff upon hiring, assignment, or commencement of work; in any case, [the Company] promptly took steps to formalize—and implement—a specific internal policy regarding the rules for the use of company lockers, so as to fully incorporate the Authority’s observations […]; the above is shared with staffing agencies in order to coordinate with them regarding the procedures and timeframes for the use and vacating of company lockers” (see cited note, p. ” (see cited note, p. ” (see cited note, p. 10); - in conclusion, the Company requested that the Court “ascertain and declare that the conditions and requirements set forth in the Regulation—and in particular in the combined provisions of articles 2(1) and 4—do not exist for the purposes of applying the relevant provisions to the case at hand; or, in any event, to “determine that the Company’s conduct complies with the Regulation and with Italian laws governing data protection” (see cited note, p.

§

11) 3. The outcome of the preliminary investigation and the proceedings for the adoption of corrective and sanctioning measures. 1 The applicable legal framework. A private employer may lawfully process (Article 5(1)(a) of the Regulation) the personal data of employees—including data relating to “special categories of personal data”—as a general rule, if the processing is necessary “to comply with a legal obligation to which the controller is subject” or, in the case of the processing of “general” personal data, if the processing is necessary “for the performance of a contract to which the data subject is a party or for the implementation of precontractual measures taken at the data subject’s request” (Articles 6(1)(b) and (c), 2, and 3, and Article 9(2)(b) and (4)). The controller is also required to comply with the general principles governing data processing, in particular those of “lawfulness, fairness, and transparency” and “data minimisation” (Articles 5, para 1, subparagraphs (a) and (c) of the Regulation).

§

Pursuant to Article 13 of the Regulation, the controller is required to provide the data subject, prior to the commencement of processing, with information on the essential characteristics of the processing itself, as set forth in that article. 2. Preliminary Issues: Controller Status and Applicability of the Regulation to the Facts Subject to the Complaint. A. acted as the controller (Article 4(7) of the Regulation), in that it made available to the complainant (and other employees), within company premises designated for that purpose, a lockable locker in which to store their personal belongings and, following the termination of the employment relationship, opened the locker and removed and destroyed the items contained therein, thereby determining the processing purposes and means, using the staffing agency exclusively to maintain contact with the complainant. ” The interpretation proposed by the Company cannot be accepted.

§

” In the present case, the Company directed that on January 30, 2024, four employees (the Security Manager, the safety coordinator, a maintenance worker, and the general services coordinator) proceed, in the absence of the data subject, to open the complainant’s personal locker—which was locked with a padlock whose keys were in the complainant’s sole possession—inspect its contents, while also documenting the operations with a video recording intended to “protect the […] company,” and, after emptying the locker, to destroy its contents (see report of operations performed on July 9, 2025, p. 4). Therefore, based on the Company’s statement—made with its own accountability—to the Special Unit for Privacy and Technological Fraud of the Guardia di Finanza, the argument set forth in the defense briefs cannot be accepted, namely that “no inventory was made of the items found in the locker, nor was the relevant information documented or otherwise added to the filing system” (defense briefs dated September 26, 2025, p.

§

6). On the contrary, opening the locker entailed an inspection of its contents, which, according to the Company’s own statement, also consisted of “[i]tems for strictly personal/intimate use” (see the aforementioned report, p. 4). , by way of example, a change of underwear, medications, sanitary pads, cosmetics), from which it is certainly possible to derive information regarding a natural person—identified as the locker’s assignee—relating to the data subject’s personal circumstances (including health) or personal situations, habits, and/or preferences. ” In this regard, it should be noted that the Data Protection Authority, in a ruling concerning a specific case, has in the past deemed unlawful the requirement for employees to “display on their work desks strictly personal items such as medications, medical devices, sanitary pads, wet wipes, which the employee uses during the course of their work […] without the option of placing such items inside cases or other small containers to conceal them from the view of others (colleagues and supervisors), thereby allowing them to indirectly learn of personal circumstances or situations, or information regarding health status unrelated to the content of the work performance and detrimental to the employee’s dignity and confidentiality” (Provision No.

§

235 of November 26, 2020, web doc. No. 9509515). Furthermore, given that, pursuant to Art. ” The Company’s conduct—consisting of the recording of video footage from the locker previously assigned to the complainant—constituted the processing of personal data. On the other hand, the concept of “processing of personal data” has a broad scope, as evidenced by the phrase “any operation” followed by a non-exhaustive list of possible processing operations, significantly preceded by the word “such as” (see Court of Justice, judgements of February 22, 2022, Case C-175/20, and June 22, 2023, Case C-579/21), therefore, the Company’s conduct as described falls under “any other form of making available” and the subsequent “destruction” of personal data obtained from the contents of the locker. In this context, Article 2(1) of the Regulation must be read and correctly interpreted, insofar as it provides that the Regulation itself “applies to the fully or partially automated processing of personal data and to the non-automated processing of personal data contained in a filing system or intended to be included in such a system,” given that the concept of “filing system” must also be understood in a broad sense (see Court of Justice, judgement of July 10, 2018, C-25/17).

§

In the present case, opening the locker and inspecting its contents and the items found therein, as well as recording—via video footage intended to inventory the items found for the Company’s protection—therefore constituted the processing of personal data. 3. Lack of a notice regarding the use of the locker: violation of Article 13 of the Regulation. , in its capacity as controller, carried out certain processing operations concerning the complainant that do not comply with the regulations governing data protection. In this regard, it should be noted that, unless the act constitutes a more serious offense, anyone who, in proceedings before the Data Protection Authority, falsely declares or attests to facts or circumstances, or produces false documents or records, is liable pursuant to Art. ” In particular, it has emerged that upon termination of the employment relationship with the complainant—which had originally been established through a temporary staffing contract— the staffing agency XX (which had also notified the complainant on December 29, 2023, via WhatsApp, that the contract, set to expire on the following December 31, would not be renewed by the user) had asked the complainant to go to the Company’s premises (the user under the temporary staffing contract) to, among other things, empty the personal locker used by the employee during work hours.

§

Following the complainant’s cancellation of three scheduled appointments to visit the company’s premises (due, as he explained to the staffing agency, to the need to attend to the health of his father, who had been hospitalized in a different region), on January 3, January 11, and January 15, 2024, the staffing agency, on January 31, 2024, following an agreement with the complainant, notified the Company—using the same procedures as before—that the data subject would come in that very morning to empty his locker. However, on January 30, 2024, that is, the day before the scheduled appointment at the company’s premises, opened the locker in the absence of the data subject and in the presence of four employees and contractors, inspected its contents, which were removed, and subsequently disposed of the locker. With regard to the facts at issue in this proceeding, it has been established, first of all, that the Company did not establish any internal regulations regarding the proper use of the company locker to be provided to employees, even though it is a piece of furniture that, although reserved for the exclusive use of the employees themselves —also considering that employees secure the lockers with a padlock whose keys remain in the employee’s exclusive possession—is nonetheless located within the company’s premises (specifically the locker rooms), for purposes related to the organization of work at the company (use of work clothing to perform job duties).

§

The need to provide instructions and information regarding the use of furnishings located in company spaces used to store employees’ strictly personal items (non-work clothing and other personal effects used for commuting to work or during permitted breaks from work) also stems from the fact that such items, as already discussed in the previous paragraph, are capable of revealing information about the individual, based on the aforementioned definitions of “personal data” and “processing” contained in the Regulation (see Articles 4(1) and (2)). According to the findings of the preliminary investigation, no information was provided to the complainant or the other data subjects, except orally—and thus in a manner (which, moreover, was not documented) that failed to meet the transparency requirements inherent in the field of personal data protection. This was the case, moreover, despite the presence of a large number of data subjects involved (“approximately 550 workers use the Cosmint locker room”) and a work organization characterized by “significant turnover […], especially at certain times of the year,” resulting in the need for rapid rotation in the use of the lockers located within the locker rooms.

§

Furthermore, the fact that the Company “does not consider itself responsible” for the fate of any valuables stored in the lockers and that it would not have permitted the storage of “personal items” in the lockers should have been communicated to employees in advance through a notice clearly setting forth the rules and permitted use of the lockers, as well as the timing and procedures for emptying them following the termination of employment. In addition to the lack of general information regarding the use of lockers—which should have been provided to the complainant and other employees before the lockers were made available—in this specific case, the Company failed to notify the employee that he needed to regain possession of the locker urgently and, consequently, to set a deadline by which it was absolutely necessary to empty it. In this regard, in fact, the representative of XX, who acted as an intermediary—“for the sole purpose of facilitating dialogue” — between the complainant and the Company, stated that on December 30, 2023, he “reminded the [complainant] that he would have to schedule an appointment in January to retrieve his personal belongings from the locker” (emphasis added).

§

” Therefore, based on a review of the case file, there is no evidence that “the data subject could reasonably have expected the Company to take action to clear out the locker, given the time that had elapsed since XX’s initial request and his lack of cooperation,” as argued by the Company in its defense briefs. In any case, even after the locker had been opened and emptied, the Company did not deem it necessary to inform the data subject of what had happened, neither by contacting the former employee directly nor through the staffing agency, which, on the other hand, on the day following the emptying of the locker (January 31, 2024) first sent an email to notify that the complainant would be coming to the company (XX’s response dated April 15, 2025, Exh. M)) and, subsequently, after learning from the latter—who had gone to the company as agreed with XX—that the locker had already been opened and emptied, a second email asking how it would be possible to “recover his personal belongings” (reply XX cited above, Exh.

§

O), without receiving a reply. Based on the documentary evidence, there is therefore no indication that the complainant, “after two weeks of silence, went on his own to the Company’s headquarters to clear out the locker,” given that the appointment on January 31, 2024, had been arranged with the staffing agency and communicated by the latter to the Company. The Company’s conduct therefore did not comply with the provisions of the regulations governing data protection, which require the controller to provide information in advance regarding the main aspects of the processing (Art. 13 of the Regulation). Within the context of the employment relationship, the obligation to provide the data subject with information regarding the processing operations carried out or intended to be carried out by the controller/employer is also an expression of the general principle of fairness (Article 5, para 1, subparagraph (a) of the Regulation), a principle that has been violated in the present case precisely because of the absence of any attempt to notify the data subject that the Company would proceed to open and empty the locker and of the decision to destroy the items found therein, rather than, at the very least, to keep them available to the former employee.

§

4. Data processing without a legal basis and in violation of the principles of data minimisation and proportionality. m. (see Attachment 2, report of operations performed on July 9, 2025). The employee, having gone to the Company’s premises on January 31, learned that the locker previously assigned to him had been opened, its contents removed, and destroyed. With regard to this conduct, it should be noted that the resulting processing of personal data—through the collection of information, following the opening of the locker, regarding its contents and the personal effects stored therein—took place without a legal basis. Given that, within the context of the employment relationship, personal data relating to employees may generally be processed by the controller/employer only to the extent necessary to properly execute the employment relationship or to comply with provisions contained in laws, regulations, contracts, and collective bargaining agreements (see Articles 6(1)(b) and (c), 6(2), and 9(2)(b) of the Regulation, with respect to so-called special categories of data), in the present case, also in light of the absence of regulations regarding the provision of lockers intended to be locked with devices (padlocks) under the exclusive control of the employee, none of the legal bases indicated in the relevant provisions are applicable.

§

Nor can the Company’s argument, put forward in its defense briefs, be accepted—namely, that the processing, “even if it constituted processing subject to the application of the Regulation, is […] attributable to the legitimate interest of the controller, pursuant to Article 6, para 1(f) of the Regulation […] consisting of the need to ensure the proper management and availability of company spaces for current employees and to prevent the unauthorized occupation of lockers by individuals whose employment has been terminated” (defense briefs dated September 26, 2025, p. 10). ” Therefore, the Regulation requires that the controller, prior to commencing processing, conduct a “balancing test” against the data subject rights and freedoms. 0, Adopted on October 8, 2024, point 9; see, on this point, Provision No. 288 of May 21, 2025, web doc. No. 2. and Provision No. 137 of April 15, 2021, web doc.

§

No. ). , paragraphs 102–126, where—among other things—it is clarified that the necessity of the processing for the pursuit of the legitimate interest must also be assessed in light of the principle of data minimization, given that the controller must verify that “the legitimate interest in processing the data pursued cannot reasonably be achieved just as effectively by other means that are less detrimental to the fundamental rights of the data subjects, in particular the rights to respect for private life and to data protection guaranteed by Articles 7 and 8 of the Charter”). The Court of Justice has, furthermore, repeatedly held that the interests and data subject rights may override the interests of the controller where personal data are processed in circumstances in which the data subjects could not reasonably expect such processing (see judgement of October 4, 2024, Case C-621-22, KNLTB, para.

§

45), and in the present case, the data subject could not have expected that the locker would be opened in his absence prior to the appointment agreed upon with the staffing agency. Finally, based on the general principles of data minimization and proportionality in processing (see Art. 5(1)(c) of the Regulation), the data controller is required to perform data processing for specific and legitimate purposes in a manner that has the least impact on data subject rights, taking into account their legitimate expectations. In the present case, the stated need to allow other employees to use the lockers cannot result in the elimination of all confidentiality and personal space, nor in the destruction of personal belongings belonging to the data subject. While acknowledging that the case file contains conflicting statements between the parties regarding the contents of the locker itself, the Company has in any event stated that, among the items found, there were “items for strictly personal/intimate use, […] whose storage by the company was not feasible, even for hygiene reasons” (report of operations carried out on July 9, 2025, p.

§

4). This therefore confirms that the opening of the locker inevitably involved the processing of personal data, which was unnecessary in relation to the purposes pursued and disproportionate. Furthermore, exposing such items to the scrutiny of others entails an unjustified infringement of the space of confidentiality and intimacy in the workplace, allowing third parties to learn information normally kept confidential by the data subjects in their personal lives, resulting in a violation of human dignity, understood as “a constitutional value that permeates positive law” (see Court, July 17, 2000, No. 293; Art. 1, Charter of Fundamental Rights of the European Union; Article 1 of the Code; see also Article 88(2) of the Regulation). During the proceedings, it was not possible to ascertain the exact and complete contents of the locker at the time it was opened; consequently, it cannot be determined whether, among the data processed—even though they pertained to “strictly personal/intimate use”— there is information that also falls within the category of “special categories of personal data” identified in Article 9(1) of the Regulation.

§

Consequently, the allegation regarding the violation of Article 9(2)(b) of the Regulation must be dismissed. For the reasons set forth above, the Company violated the obligation to process data under appropriate conditions of lawfulness as provided for by the Regulation (see Articles 6(1), para 1), subparagraphs (b) and (c), and para 2), as well as the principles of data minimization and proportionality (Articles 5(1)(c) of the Regulation). 4. Conclusions: Declaration of the unlawfulness of the processing. Corrective measures pursuant to Art. 58(2) of the Regulation. For the reasons set forth above, the Authority considers that the statements, documentation, and explanations provided by the controller during the preliminary investigation do not address the findings notified by the Office in the notice initiating the proceedings; they are therefore insufficient to allow for the dismissal of this proceeding, and none of the cases provided for in Art.

11 of the Data Protection Authority’s Regulation

§

No. 1/2019 apply. The processing of personal data carried out by the Company—specifically, the opening of the company locker assigned to the complainant in his absence, the seizure of the locker’s contents, and their subsequent destruction, is in fact unlawful under Articles 5(1)(a) and (c), 6(1)(b) and (c) and (2), and 13 of the Regulation. A violation of Article 157 of the Code has also been established, in relation to the provisions of Article 166, paragraph 2, of the Code, as notified to the Company on July 9, 2025, by the Special Unit for Privacy and Technological Fraud of the Guardia di Finanza. The violation, established as described in the reasoning, cannot be considered “minor,” as claimed by the Company, given the nature of the multiple violations found, which concerned the general principles of data processing (lawfulness and fairness, transparency, data minimisation), the provisions regarding information notices and the Data Protection Authority’s power to request information from the controller.

§

The Authority also took into account the average level of severity of the violation in light of all relevant factors in this specific case, and in particular the nature, severity, and duration of the violation, considering the nature, the subject matter or processing purpose in question, as well as the number of data subjects affected by the breach and the extent of the harm they suffered. The Authority also took into account the criteria relating to whether the violation was intentional or negligent, the categories of personal data affected by the violation, and the manner in which the supervisory authority became aware of the violation (see Art. 83, para. 2, and Recital 148 of the Regulation). Therefore, in view of the corrective powers conferred by Article 58(2) of the Regulation, an administrative fine is hereby imposed pursuant to Article 83 of the Regulation, commensurate with the circumstances of the specific case (Article 58, (2)(i) of the Regulation).

§

5. Adoption of the injunction order for the imposition of the administrative fine and ancillary penalties (Articles 58(2)(i) and 83 of the Regulation; Article 166, paragraph 7, of the Code). A. has violated Articles 5, para 1, subparagraphs (a) and (c), 6(1)(b) and (c), (2), and 13 of the Regulation, and Article 157, in conjunction with Article 166(2) of the Code. For the violation of the aforementioned provisions, the administrative fine provided for in Article 83, para 5, subparagraphs (a) and (b) of the Regulation shall be imposed, through the adoption of an injunction order (Article 18, Law No. 689 of November 24, 1981). The Data Protection Authority, pursuant to Article 58, para 2, subparagraph i) of the Regulation and Article 166 of the Code, has the power to impose an administrative fine as provided for in Article 83 of the Regulation, by issuing an injunction order (Art. 18 of Law No.

§

, which has been found to be unlawful, as set forth above Considering that paragraph 3 of Art 83 of the Regulation must be applied, which provides that “If, in relation to the same processing operation or to related processing operations, a controller […] infringes, intentionally or negligently, several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the most serious infringement,” the total amount of the fine is calculated so as not to exceed the maximum amount provided for in Art. 83, para. 5. With regard to the factors listed in Art. 83(2) of the Regulation for the purposes of imposing the administrative fine and determining its amount—and given that the severity of the violation is considered high, and taking into account that the fine must “in any event [be] effective, proportionate, and dissuasive” (Article 83(1) of the Regulation), it is noted that, in the present case, the following circumstances were taken into account: a) with regard to the nature of the violation, it concerned cases subject to more severe penalties pursuant to Art.

§

83(5) of the Regulation (general principles of processing, provisions regarding the privacy notice); b) still regarding the nature of the violation, the following was taken into account—within the scope of the offenses subject to more severe penalties under Article 83(5) of the Regulation, pursuant to the provisions of Article 166(2) of the Code— the violation of the obligation to respond to requests for information from the supervisory authority; c) with regard to the severity of the violation, the nature of the processing—which involved the seizure and subsequent destruction of personal belongings contained in a company locker made available exclusively to the data subject—was taken into account; d) with regard to the duration of the violation, this factor is not quantifiable in the present case; e) with regard to whether the violation was intentional or negligent and the degree of the data controller’s accountability, consideration was given to the Company’s conduct and its degree of accountability, as it proceeded with the seizure and subsequent destruction of the data subject’s personal belongings, despite being aware that discussions were underway, with the employee, through the staffing agency, to agree on the time for the locker to be cleared; f) in the Company’s favor, its cooperation with the supervisory authority and its decision to adopt a general policy and specific forms regarding the use of company lockers were taken into account.

§

It is also considered that, in the present case, taking into account the aforementioned principles of effectiveness, proportionality, and deterrence to which the Authority must adhere in determining the amount of the sanction (Art. 83(1) of the Regulation), first and foremost, the economic circumstances of the offender, determined on the basis of the Company’s revenue as reported in the regular financial statements for the year 2024, the most recent available. A. an administrative fine in the amount of 6,600 (six thousand six hundred) euros. In this context, it is deemed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, this section containing the injunction order must be published on the Data Protection Authority’s website. This is in light of the nature of the violations found, which concerned the general principles of fairness and transparency in processing and the conditions for the lawfulness of the processing itself, as well as the controller’s obligation to respond to requests for information and the production of documents made by the supervisory authority.

§

, pursuant to Article 58, para 2, subparagraph i) of the Regulation, to pay the sum of 6,600 (six thousand six hundred) euros as an administrative fine for the violations indicated in this order; THEREFORE ORDERS the aforementioned Company to pay the aforementioned sum of 6,600 (six thousand six hundred), in accordance with the procedures set forth in the attachment, within 30 days of the service of this order, failing which the necessary enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981. Please note that the offender retains the right to settle the dispute by paying—again in accordance with the procedures set forth in the attachment—an amount equal to half of the imposed penalty, within the time limit set forth in Article 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, provided for the filing of an appeal as indicated below (Article 166, paragraph 8, of the Code); ORDERS - pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No.

§

1/2019, the publication of this injunction order on the Data Protection Authority’s website; - pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Data Protection Authority’s Regulation No. 1/2019, the publication of this order on the Data Protection Authority’s website; - pursuant to Article 17 of Regulation No. 1/2019, the recording of the violations and the measures adopted in accordance with Article 58, para 2 of the Regulation, in the Authority’s internal register provided for by Article 57, para 1, letter u) of the Regulation. Pursuant to Article 78 of the Regulation, as well as Article 152 of the Code and Article 10 of Legislative Decree No. 150/2011, an appeal against this decision may be filed with the ordinary courts by submitting a petition to the ordinary court of the jurisdiction specified in the aforementioned Art 10, within thirty days from the date of notification of the decision, or within sixty days if the appellant resides abroad.

§

Rome, June 18, 2026 THE PRESIDENT Stanzione THE RAPPORTEUR Cerrina Feroni THE SECRETARY GENERAL Montuori [Web Doc. No. 10268633] Decision of June 18, 2026 Register of Decisions No. 462 of June 18, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, members; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter, the “Regulation”); HAVING REGARD TO the Code on Data Protection, containing provisions for the adaptation of national law to Regulation (EU) 2016/679 (Legislative Decree No. 196 of June 30, 2003, as amended by Legislative Decree No. 101 of August 10, 2018, hereinafter the “Code”); HAVING REGARD TO the complaint filed by Mr. ; HAVING EXAMINED the documentation on file; HAVING REGARD TO the observations made by the Secretary General pursuant to Art.

15 of the Data Protection Authority’s Regulation

§

No. 1/2000; RAPPORTEUR: Prof. Ginevra Cerrina Feroni; PREAMBLE 1. The complaint against the Company and the preliminary investigation. In a complaint dated April 18, 2024, formalized on January 29, 2025, Mr. A. (hereinafter, the Company), with particular reference to the opening of his personal locker after the termination of his employment, in his absence, and the subsequent seizure and destruction of its contents. A. would end on December 31,December 2023, his employment with Cosmint would end, he spoke with a representative of the aforementioned staffing agency regarding the procedures for emptying the locker that had been assigned to him during his employment. According to the account, the complainant was only able to visit the company’s headquarters on January 31, 2024, due to urgent family matters related to his father’s health, of which he had informed the staffing agency.

§

It was only on that occasion that he learned that, in the meantime, the locker had been opened and emptied of its contents, and that those contents were no longer available because they had been thrown away after being removed. , the user company under the temporary staffing contract, in which the companies were requested to provide information pursuant to Article 157 of the Code regarding the facts subject to the complaint. XX, in its response dated April 15, 2025, stated that: - in a temporary staffing arrangement, the staffing agency is not responsible for what occurs on the user company’s premises; (note dated 4/15/2025, p. 2); - pursuant to Art. 4 of the Code of Conduct for the Temporary Employment Agency Sector, “an independent data controller relationship (Data Controller-Data Controller) is established between the temporary staffing agency and the user company (Client), as both parties determine the purposes and methods of their own processing” (cited note, p.

§

2); - that said, and in light of the general terms and conditions of the temporary staffing contract entered into in this specific case between the parties, it is clear that it is the responsibility of the user company “to define and implement the procedures related to the return of company property provided to the temporary worker” (cited note, p. 3); - “XX took all possible measures to enable the [complainant] to collect his personal belongings, for the sole purpose of facilitating dialogue between the [complainant] and [the Company]” (cited note, p. 3); - “Once the employment contract had ended, XX had no obligations toward the [complainant], essentially becoming a third party in relation to him. […] Whenever the [complainant] confirmed an appointment to collect his personal belongings, Account Specialist XX would contact the Security office and the user’s security guards to inform them of the entry of an individual who was—by that point—no longer authorized to access the premises” (cited note, p.

§

4); - “On December 29, 2023, Account Specialist XX informed the [complainant] that his employment contract would not be renewed and would therefore terminate on December 31, 2023. […] On the same day […] the [complainant] reported his sick leave by submitting the relevant medical certificate […] covering the period from December 29 to December 31, 2023; On December 30, 2023, Account Specialist XX reminded the [complainant] that he would need to schedule an appointment in January to collect his personal belongings from his locker” (cited note, p. 4); - The XX representative then notified the Company’s security office via email that the complainant would be coming to the company to return his badge and empty his locker on January 3, the 11th, and the 15th of January, respectively—dates that were subsequently canceled by the complainant via WhatsApp messages; on January 29, 2024, the complainant contacted the XX representative again, stating that he would come to the company on January 31; therefore; “on January 31, 2024, the XX Account Specialist proceeded to once again inform the Cosmint Security Office of the arrival of the [complainant] […] to return his badge and collect his personal belongings from his locker”; (cited note, p.

§

A. headquarters and had learned there that his locker had already been emptied […]. The Account Specialist […] - despite the absence of any obligation to do so, but solely out of a spirit of cooperation and good faith - sent a request for clarification/information to Cosmint’s Security Department and security guards […]. No response was received” (cited note, p. 6); - “it should be noted that Cosmint did not in any way inform XX that it would proceed to open the locker even in the employee’s absence, nor, more generally, that opening lockers was a practice adopted by the client company” (cited note, p. 6). Since, however, Cosmint did not provide any response to the request for information made pursuant to Article 157 of the Code—which was sent via certified email and duly delivered— the Authority has delegated the Special Unit for Privacy and Technological Fraud of the Guardia di Finanza to serve notice of the initiation of proceedings for the adoption of corrective and punitive measures pursuant to Article 166, paragraph 5, of the Code (in relation to the provisions of Article 166, paragraph 2, of the Code for the violation of Article 157), as well as to gather evidence regarding the facts subject to the complaint, within the timeframes already specified in the request for information dated March 27, 2025.

§

The Task Force, having visited the Company’s registered office on July 9, 2025, served the notice of the initiation of proceedings and obtained the requested information regarding the facts that were the subject of the complaint, drawing up a specific report of the operations carried out. In its response to the request, Cosmint stated that: - “As a multinational company, we receive dozens of certified emails (PEC) per day; our staff […] either overlooked the one sent by the Authority or did not realize that we were required to respond” (report of actions taken on July 9, 2025, p. 3); - “All our employees, upon joining the workforce, are recipients of a locker intended exclusively for storing clothing. , p. 3); - Regarding the use of the locker, the employee is informed verbally that the locker “is intended solely for storing clothing and nothing else, such as personal items or, even less so, valuables for which the Company assumes no responsibility” (cited minutes, p.

§

3); - “All lockers are assigned to employees on a personal basis. […] The claimant’s locker, like all the others, was locked with a padlock belonging to him, and only the claimant had the keys to it” (minutes cited above, p. 3); - the staffing agency provides communications to its employees “regarding any matter not directly related to the performance of work duties […]. In particular, XX stated to the undersigned that on December 29, 2023, he had notified the worker […] of the termination of the contract, simultaneously instructing him to empty his locker and return the work clothing provided by Cosmint. […] XX had also notified Cosmint’s security department to ensure the employee’s access on January 3, 2024 […]. On January 3, the employee asked XX to reschedule the appointment, as he was unable to attend. A second appointment was then scheduled for January 11, which was also missed. Similarly, the employee did not show up for the next two appointments he had scheduled with XX on January 15 and January 31.

§

” (cited minutes, pp. 3–4); - “The locker was opened on 01/30/24, in the presence of Cosmint’s Security Manager […], Cosmint’s Safety Coordinator […], a Cosmint maintenance worker […], and Cosmint’s General Services Coordinator […]” (cited report, p. 4) … [and] was motivated by the need to free up space for incoming workers” (cited report, p. 4); - “Upon opening the locker, a video was recorded for the protection of our company, which clearly showed that the items alleged by the complainant were not inside the locker. The video was recorded by the person who was, at the time, the security coordinator (a position entrusted to a contractor […] using her personal smartphone. Today, our company no longer works with the company that previously handled security,” so it is no longer possible to retrieve the video (cited minutes, p. 4); - “It should be noted that approximately 550 workers use the Cosmint locker room and that there is significant employee turnover, especially at certain times of the year” (cited minutes, p.

§

4); - “The following items were found: company-owned property (finished products) […], which were destroyed since they could no longer be placed on the market, […]; Items for strictly personal/intimate use […], which the company could not reasonably store, even for hygiene reasons” (cited report, p. 4). 2. The initiation of proceedings for the adoption of corrective measures and the Company’s submissions. A. with a notice of alleged violations of the Regulation regarding the facts that are the subject of the complaint, with reference to Articles 5, para 1, subparagraphs (a) and (c); Article 6, para 1, subparagraphs (b) and (c), and para 2; Article 9, para 2, subparagraph (b); and Article 13 of the Regulation. In its defense briefs submitted on September 26, 2025, the Company stated that: - “Communications regarding the termination of the employment relationship and the related operational procedures were handled exclusively by XX, without prejudice to the Company’s full cooperation in ensuring the orderly conduct of business activities” (note dated September 26, 2025, p.

§

2); - “With regard to the alleged violation of Article 157 of the Code, the Company wishes to clarify that the failure to respond was due exclusively to a mere oversight, without any purpose to evade compliance […] The Company has arranged for a weekly internal summary report to be prepared, listing all relevant certified email (PEC) communications,” (note cited above, p. 3); - “Individual lockers have been installed on company premises and made available to employees exclusively for work-related purposes […] and are not intended for personal use or the storage of valuables. For the latter, however, the Company provides designated spaces for the safekeeping of valuables other than clothing” (cited note, p. 3); - the employee “is responsible for locking the locker with a padlock, and the corresponding keys remain in his or her exclusive possession. The Company has never had access to the contents of the lockers, nor has it ever opened or inspected them” (cited note, p.

§

4); - “In the present case, the time elapsed between XX’s first request to the data subject to clear out the locker and the actual clearing of the locker was approximately one month, during which the [complainant] initially postponed the agreed-upon appointments repeatedly and, after two weeks of silence, went on his own to the Company’s headquarters to clear out the locker” (cited note, p. 4); - “On December 29, 2023, XX, […], urged the [complainant] to empty the locker, which was needed for assignment to new employees, reiterating the urgency of doing so by December 30, 2023 (his last day of work). The [complainant], however, stated that he did not wish to return on his last day of work and, therefore, would not vacate the locker immediately. Subsequently, on January 3, 2024, XX summoned the [complainant] to return his ID card and clear out his locker, but the appointment was postponed at the employee’s request due to family reasons.

§

A new meeting was scheduled for January 11, 2024, but it was not attended, nor was the subsequent appointment on January 15, 2024, which was justified […] on the basis of vague personal reasons” (see cited note, p. 4); - “The Company objects that the Regulation is inapplicable ratione materiae, since the processing of the data at issue (i) was carried out by the Company without the use of automated tools and (ii) the processed data were not contained in a filing system, nor were they intended to be” (see cited note, p. ’ (see cited note, pp. 5–6) “No inventory was made of the items found in the cabinet, nor was the relevant information documented or otherwise archived in a filing system. ” (see cited note, p. 6); - with regard to the concept of “personal data” pursuant to Art. 4(1) of the Regulation, the Company stated that “the items found inside the company locker do not in any way constitute ‘personal data,’ much less special categories of personal data within the meaning of Art.

§

9 of the Regulation, as they are merely tangible objects incapable of identifying, directly or indirectly, their respective owner. The discovery of undergarments or other items, in fact, does not in and of itself imply the processing of personal data within the meaning of Article 4 of the Regulation” (see cited note, pp. 7–8); - “Specific instructions on the use of lockers have always been provided verbally to all staff upon hiring, assignment, or commencement of work; in any case, [the Company] promptly took steps to formalize—and implement—a specific internal policy regarding the rules for the use of company lockers, so as to fully incorporate the Authority’s observations […]; the above is shared with staffing agencies in order to coordinate with them regarding the procedures and timeframes for the use and vacating of company lockers” (see cited note, p. ” (see cited note, p. ” (see cited note, p.

§

10); - in conclusion, the Company requested that the Court “ascertain and declare that the conditions and requirements set forth in the Regulation—and in particular in the combined provisions of articles 2(1) and 4—do not exist for the purposes of applying the relevant provisions to the case at hand; or, in any event, to “determine that the Company’s conduct complies with the Regulation and with Italian laws governing data protection” (see cited note, p. 11) 3. The outcome of the preliminary investigation and the proceedings for the adoption of corrective and sanctioning measures. 1 The applicable legal framework. A private employer may lawfully process (Article 5(1)(a) of the Regulation) the personal data of employees—including data relating to “special categories”—as a general rule, if the processing is necessary “to comply with a legal obligation to which the controller is subject” or, in the case of the processing of “general” personal data, if the processing is necessary “for the performance of a contract to which the data subject is a party or for the implementation of precontractual measures taken at the data subject’s request” (Articles 6(1)(b) and (c), 2, and 3, and Article 9(2)(b) and (4)).

§

The controller is also required to comply with the general principles governing data processing, in particular those of “lawfulness, fairness, and transparency” and “data minimisation” (Article 5, para 1, subparagraphs (a) and (c) of the Regulation). Pursuant to Article 13 of the Regulation, the controller is required to provide the data subject, prior to the commencement of processing, with information on the essential characteristics of the processing itself, as set forth in that article. 2. Preliminary Issues: Controller Status and Applicability of the Regulation to the Facts Subject to the Complaint. A. acted as the controller (Article 4(7) of the Regulation), in that it made available to the complainant (and other employees), within company premises designated for that purpose, a lockable locker in which to store their personal belongings and, following the termination of the employment relationship, opened the locker and removed and destroyed the items contained therein, thereby determining the processing purpose and means, using the staffing agency exclusively to maintain contact with the complainant.

§

That said, it should be noted preliminarily that the Company argued, in its defense briefs, that the conduct at issue in the proceedings initiated before the Data Protection Authority does not fall within the scope of processing to which the Regulation applies pursuant to Art. 2, para. ” The interpretation proposed by the Company cannot be accepted. ” In the present case, the Company directed that on January 30, 2024, four employees (the Security Manager, the safety coordinator, a maintenance worker, and the general services coordinator) proceed, in the absence of the data subject, to open the complainant’s personal locker—which was locked with a padlock whose keys were in the complainant’s sole possession—inspect its contents, while also documenting the operations with a video recording intended to “protect the […] company,” and, after emptying the locker, to destroy its contents (see report of operations performed on July 9, 2025, p.

§

4). Therefore, based on the Company’s statement—made with its own accountability—to the Special Unit for Privacy and Technological Fraud of the Guardia di Finanza, the argument set forth in the defense briefs cannot be accepted, namely that “no inventory was made of the items found in the locker, nor was the relevant information documented or otherwise added to the filing system” (defense briefs dated September 26, 2025, p. 6). On the contrary, opening the locker entailed an inspection of its contents, which, according to the Company’s own statement, also consisted of “[i]tems for strictly personal/intimate use” (see the aforementioned report, p. 4). , by way of example, a change of underwear, medications, sanitary pads, cosmetics), from which it is certainly possible to derive information regarding a natural person—identified as the locker’s assignee—relating to the data subject’s personal circumstances (including health) or personal situations, habits, and/or preferences.

§

” In this regard, it should be noted that the Data Protection Authority, in a ruling concerning a specific case, has in the past deemed unlawful the requirement for employees to “display on their work desks strictly personal items such as medications, medical devices, sanitary pads, wet wipes, which the employee uses during the course of their work […] without the option of placing such items inside cases or other small containers to conceal them from the view of others (colleagues and supervisors), thereby allowing them to indirectly learn of personal circumstances or situations, or information regarding health status unrelated to the content of the work performance and detrimental to the employee’s dignity and confidentiality” (Provision No. 235 of November 26, 2020, web doc. No. 9509515). ” The Company’s conduct—consisting of the recording of video footage from the locker previously assigned to the complainant—constituted the processing of personal data.

§

On the other hand, the concept of “processing of personal data” has a broad scope, as evidenced by the phrase “any operation” followed by a non-exhaustive list of possible processing operations, significantly preceded by the word “such as” (see Court of Justice, judgements of February 22, 2022, lawsuit C-175/20, and June 22, 2023, lawsuit C-579/21), therefore, the Company’s conduct as described falls under “any other form of making available” and the subsequent “destruction” of personal data obtained from the contents of the locker. In this context, Article 2(1) of the Regulation must be read and correctly interpreted, insofar as it provides that the Regulation itself “applies to the fully or partially automated processing of personal data and to the non-automated processing of personal data contained in a filing system or intended to be included in such a system,” given that the concept of “filing system” must also be understood in a broad sense (see Court of Justice, judgement of July 10, 2018, C-25/17).

§

In the present case, opening the locker and inspecting its contents and the items found therein, as well as recording—via video footage intended to inventory the items found for the Company’s protection—therefore constituted the processing of personal data. 3. Lack of a notice regarding the use of the locker: violation of Article 13 of the Regulation. , in its capacity as controller, carried out certain processing operations concerning the complainant that do not comply with the regulations governing data protection. In this regard, it should be noted that, unless the act constitutes a more serious offense, anyone who, in proceedings before the Data Protection Authority, falsely declares or attests to facts or circumstances, or produces false documents or records, is liable pursuant to Art. ” In particular, it has emerged that upon termination of the employment relationship with the complainant—which had originally been established through a temporary staffing contract— the staffing agency XX (which had also notified the complainant on December 29, 2023, via WhatsApp, that the contract, set to expire on December 31, would not be renewed by the user) had asked the complainant to go to the Company’s premises (the user in the temporary staffing contract) to, among other things, empty the personal locker used by the employee during work hours.

§

Following the complainant’s cancellation of three scheduled appointments to visit the company’s premises (due, as he explained to the staffing agency, to the need to attend to the health of his father, who had been hospitalized in a different region), on January 3, January 11, and January 15, 2024, the staffing agency, on January 31, 2024, following an agreement with the complainant, notified the Company—using the same procedures as before—that the data subject would come in that very morning to empty his locker. However, on January 30, 2024, that is, the day before the scheduled appointment at the company’s premises, opened the locker in the absence of the data subject and in the presence of four employees and contractors, inspected its contents, which were removed, and subsequently disposed of the locker. With regard to the facts at issue in this proceeding, it has been established, first of all, that the Company did not establish any internal regulations regarding the proper use of the company locker to be provided to employees, even though it is a piece of furniture that, although reserved for the exclusive use of the employees themselves —also considering that employees secure the lockers with a padlock whose keys remain in the employee’s exclusive possession—is nonetheless located within the company premises (specifically in the locker rooms), for purposes related to the organization of work at the company (use of work clothing to perform job duties).

§

The need to provide instructions and information regarding the use of furnishings located in company spaces used to store employees’ strictly personal items (non-work clothing and other personal effects used for commuting to work or during permitted breaks from work) also stems from the fact that such items, as already discussed in the previous paragraph, are capable of revealing information about the individual, based on the aforementioned definitions of “personal data” and “processing” contained in the Regulation (see Articles 4(1) and (2)). According to the findings of the preliminary investigation, no information was provided to the complainant or the other data subjects, except orally—and thus in a manner (which, moreover, was not documented) that failed to meet the transparency requirements inherent in the field of personal data protection. This was the case, moreover, despite the presence of a large number of data subjects involved (“approximately 550 workers use the Cosmint locker room”) and a work organization characterized by “significant turnover […], especially at certain times of the year,” resulting in the need for rapid rotation in the use of the lockers located within the locker rooms.

§

Furthermore, the fact that the Company “does not consider itself responsible” for the fate of any valuables stored in the lockers and that it would not have permitted the storage of “personal items” in the lockers should have been communicated to employees in advance through a notice clearly setting forth the rules and permitted use of the lockers, as well as the timing and procedures for emptying them following the termination of employment. In addition to the lack of general information regarding the use of lockers—which should have been provided to the complainant and other employees before the lockers were made available—in this specific case, the Company failed to notify the employee that he needed to regain possession of the locker urgently and, consequently, to set a deadline by which it was absolutely necessary to empty it. In this regard, in fact, the representative of XX, who acted as an intermediary—“for the sole purpose of facilitating dialogue” — between the complainant and the Company, stated that on December 30, 2023, he “reminded the [complainant] that he would have to schedule an appointment in January to retrieve his personal belongings from the locker” (emphasis added).

§

” Therefore, based on a review of the case file, there is no evidence that “the data subject could reasonably have expected the Company to take action to clear out the locker, given the time that had elapsed since XX’s initial request and his lack of cooperation,” as argued by the Company in its defense briefs. In any case, even after the locker had been opened and emptied, the Company did not deem it necessary to inform the data subject of the incident, neither by contacting the former employee directly nor through the staffing agency, which, on the other hand, on the day following the emptying of the locker (January 31, 2024) first sent an email to notify that the complainant would be coming to the company (XX’s response dated April 15, 2025, Exh. M)) and, subsequently, after learning from the latter—who had gone to the company as agreed with XX—that the locker had already been opened and emptied, a second email asking how it would be possible to “recover his personal belongings” (reply XX cited above, Exh.

§

O), without receiving a reply. Based on the documentary evidence, there is therefore no indication that the complainant, “after two weeks of silence, went on his own to the Company’s headquarters to clear out the locker,” given that the appointment on January 31, 2024, had been arranged with the staffing agency and communicated by the latter to the Company. The Company’s conduct therefore did not comply with the provisions of the regulations governing data protection, which require the controller to provide information in advance regarding the main aspects of the processing (Art. 13 of the Regulation). Within the context of the employment relationship, the obligation to provide the data subject with information regarding the processing operations carried out or intended to be carried out by the controller/employer is also an expression of the general principle of fairness (Article 5, para 1, subparagraph (a) of the Regulation), a principle that has been violated in the present case precisely because of the absence of any attempt to notify the data subject that the Company would proceed to open and empty the locker and of the decision to destroy the items found therein, rather than, at the very least, to keep them available to the former employee.

§

4. Data processing without a legal basis and in violation of the principles of data minimisation and proportionality. m. on the morning of January 31 (see Attachment 2, report of operations performed on July 9, 2025). The employee, having gone to the Company’s premises on January 31, learned that the locker previously assigned to him had been opened, its contents removed, and destroyed. With regard to this conduct, it should be noted that the resulting processing of personal data—through the collection of information, following the opening of the locker, regarding its contents and the personal effects stored therein—took place without a legal basis. Given that, within the context of the employment relationship, personal data relating to employees may generally be processed by the controller/employer only to the extent necessary to properly execute the employment relationship or to comply with provisions contained in laws, regulations, contracts, and collective bargaining agreements (see Articles 6(1)(b) and (c), 6(2), and 9(2)(b) of the Regulation, with respect to so-called special categories of data), in the present case, also in light of the absence of regulations regarding the provision of lockers intended to be locked with devices (padlocks) under the exclusive control of the employee, none of the legal bases indicated in the relevant provisions are applicable.

§

Nor can the Company’s argument, put forward in its defense briefs, be accepted—namely, that the processing, “even if it constituted processing subject to the application of the Regulation, is […] attributable to the legitimate interest of the controller, pursuant to Art. 6, para 1(f) of the Regulation […] consisting of the need to ensure the proper management and availability of company spaces for current employees and to prevent the unauthorized occupation of lockers by individuals whose employment relationship has ended” (defense briefs dated September 26, 2025, p. 10). ” Therefore, the Regulation requires that the controller, prior to commencing processing, conduct a “balancing test” against the data subject rights and freedoms. 0, Adopted on October 8, 2024, point 9; see, on this point, Provision No. 288 of May 21, 2025, web doc. No. 2. and Provision No. 137 of April 15, 2021, web doc.

§

No. ). , paragraphs 102–126, where—among other things—it is clarified that the necessity of the processing for the pursuit of the legitimate interest must also be assessed in light of the principle of data minimization, given that the controller must verify that “the legitimate interest in processing the data pursued cannot reasonably be achieved just as effectively by other means that are less detrimental to the fundamental rights of the data subjects, in particular the rights to respect for private life and to data protection guaranteed by Articles 7 and 8 of the Charter”). The Court of Justice has, furthermore, repeatedly held that the interests and fundamental rights of the data subject may override the interests of the controller where personal data are processed in circumstances in which the data subjects could not reasonably expect such processing (see judgement of October 4, 2024, Case C-621-22, KNLTB, para.

§

45), and in the present case, the data subject could not have expected that the locker would be opened in his absence prior to the appointment agreed upon with the staffing agency. Finally, based on the general principles of data minimization and proportionality in processing (see Art. 5(1)(c) of the Regulation), the data controller is required to perform data processing for specific and legitimate purposes in a manner that has the least impact on data subject rights, taking into account their legitimate expectations. In the present case, the stated need to allow other employees to use the lockers cannot result in the elimination of all confidentiality and personal space, nor in the destruction of personal belongings belonging to the data subject. While acknowledging that the case file contains conflicting statements between the parties regarding the contents of the locker itself, the Company has in any event stated that, among the items found, there were “items for strictly personal/intimate use, […] whose storage by the company was not feasible, even for hygiene reasons” (report of operations carried out on July 9, 2025, p.

§

4). This therefore confirms that the opening of the locker inevitably involved the processing of personal data, which was unnecessary in relation to the purposes pursued and disproportionate. Furthermore, exposing such items to the scrutiny of others entails an unjustified infringement of the space of confidentiality and intimacy in the workplace, allowing third parties to learn information normally kept confidential by the data subjects in their personal lives, resulting in a violation of human dignity, understood as “a constitutional value that permeates positive law” (see Court, July 17, 2000, No. 293; Art. 1, Charter of Fundamental Rights of the European Union; Article 1 of the Code; see also Article 88(2) of the Regulation). During the proceedings, it was not possible to ascertain the exact and complete contents of the locker at the time it was opened; consequently, it cannot be determined whether, among the data processed—even though they pertained to “strictly personal/intimate use”— there is information that also falls within the category of “special categories of personal data” identified in Article 9(1) of the Regulation.

§

Consequently, the allegation regarding the violation of Article 9(2)(b) of the Regulation must be dismissed. For the reasons set forth above, the Company violated the obligation to process data under appropriate conditions of lawfulness as provided for by the Regulation (see Articles 6(1), para 1), subparagraphs (b) and (c), and para 2), as well as the principles of data minimization and proportionality (Articles 5(1)(c) of the Regulation). 4. Conclusions: Declaration of the unlawfulness of the processing. Corrective measures pursuant to Article 58(2) of the Regulation. For the reasons set forth above, the Authority considers that the statements, documentation, and explanations provided by the controller during the preliminary investigation do not address the findings notified by the Office in the notice initiating the proceedings; they are therefore insufficient to allow for the dismissal of this proceeding, and none of the cases provided for in Art.

11 of the Data Protection Authority’s Regulation

§

No. 1/2019 apply. The processing of personal data carried out by the Company—specifically, the opening of the company locker assigned to the complainant in his absence, the seizure of the locker’s contents, and their subsequent destruction, is in fact unlawful under Articles 5(1)(a) and (c), 6(1)(b) and (c) and (2), and 13 of the Regulation. A violation of Article 157 of the Code has also been established, in relation to the provisions of Article 166, paragraph 2, of the Code, as notified to the Company on July 9, 2025, by the Special Unit for Privacy and Technological Fraud of the Guardia di Finanza. The violation, established as described in the reasoning, cannot be considered “minor,” as claimed by the Company, given the nature of the multiple violations found, which concerned the general principles of data processing (lawfulness and fairness, transparency, data minimisation), the provisions regarding information notices and the Data Protection Authority’s power to request information from the controller.

§

The Authority also took into account the average level of severity of the violation in light of all relevant factors in this specific case, and in particular the nature, severity, and duration of the violation, considering the nature, the subject matter or processing purpose in question, as well as the number of data subjects affected by the breach and the extent of the harm they suffered. The Authority also took into account the criteria relating to whether the violation was intentional or negligent, the categories of data affected by the violation, and the manner in which the supervisory authority became aware of the violation (see Art. 83, para. 2, and Recital 148 of the Regulation). Therefore, in view of the corrective powers conferred by Article 58(2) of the Regulation, an administrative fine is hereby imposed pursuant to Article 83 of the Regulation, commensurate with the circumstances of the specific case (Article 58, (2)(i) of the Regulation).

§

5. Adoption of the injunction order for the imposition of the administrative fine and ancillary penalties (Articles 58(2)(i) and 83 of the Regulation; Article 166, paragraph 7, of the Code). A. has violated Articles 5, para 1, subparagraphs (a) and (c), 6(1)(b) and (c), (2), and 13 of the Regulation, and Article 157, in conjunction with Article 166(2) of the Code. For the violation of the aforementioned provisions, the administrative fine provided for in Article 83, para 5, subparagraphs (a) and (b) of the Regulation shall be imposed, through the adoption of an injunction order (Article 18, Law No. 689 of November 24, 1981). The Data Protection Authority, pursuant to Article 58, para 2, subparagraph i) of the Regulation and Article 166 of the Code, has the power to impose an administrative fine as provided for in Article 83 of the Regulation, by issuing an injunction order (Art. 18 of Law No.

§

, which has been found to be unlawful, as set forth above Considering that paragraph 3 of Art 83 of the Regulation must be applied, which provides that “If, in relation to the same processing operation or to related processing operations, a controller […] infringes, intentionally or negligently, several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the most serious infringement,” the total amount of the fine is calculated so as not to exceed the maximum amount provided for in Art. 83, para. 5. With regard to the factors listed in Art. 83(2) of the Regulation for the purposes of imposing the administrative fine and determining its amount—and given that the severity of the violation is considered high, and taking into account that the fine must “in any event [be] effective, proportionate, and dissuasive” (Article 83(1) of the Regulation), it is noted that, in the present case, the following circumstances were taken into account: a) with regard to the nature of the violation, it concerned cases subject to more severe penalties pursuant to Article 83(5) of the Regulation (general principles of processing, provisions regarding the privacy notice); b) still regarding the nature of the violation, the following was taken into account—within the scope of the offenses subject to more severe penalties under Article 83(5) of the Regulation, pursuant to the provisions of Article 166(2) of the Code— the violation of the obligation to respond to requests for information from the supervisory authority; c) with regard to the severity of the violation, the nature of the processing—which involved the seizure and subsequent destruction of personal belongings contained in a company locker made available exclusively to the data subject—was taken into account; d) with regard to the duration of the violation, this factor is not quantifiable in the present case; e) with regard to whether the violation was intentional or negligent and the degree of the data controller’s accountability, consideration was given to the Company’s conduct and its degree of accountability, as it proceeded with the seizure and subsequent destruction of the data subject’s personal belongings, despite being aware that discussions were underway, with the employee, through the staffing agency, to agree on the time for the locker to be cleared; f) in the Company’s favor, its cooperation with the supervisory authority and its decision to adopt a general policy and specific forms regarding the use of company lockers were taken into account.

§

It is also considered that, in the present case, taking into account the aforementioned principles of effectiveness, proportionality, and deterrence to which the Authority must adhere in determining the amount of the sanction (Art. 83(1) of the Regulation), first and foremost, the economic circumstances of the offender, determined on the basis of the Company’s revenue as reported in the regular financial statements for the year 2024, the most recent available. A. an administrative fine in the amount of 6,600 (six thousand six hundred) euros. In this context, it is deemed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, this section containing the injunction order must be published on the Data Protection Authority’s website. This is in light of the nature of the violations found, which concerned the general principles of fairness and transparency in processing and the conditions for the lawfulness of the processing itself, as well as the controller’s obligation to respond to requests for information and the production of documents made by the supervisory authority.

§

, pursuant to Article 58, para 2, subparagraph i) of the Regulation, to pay the sum of 6,600 (six thousand six hundred) euros as an administrative fine for the violations indicated in this order; THEREFORE ORDERS the aforementioned Company to pay the aforementioned sum of 6,600 (six thousand six hundred), in accordance with the procedures set forth in the attachment, within 30 days of the service of this order, failing which the necessary enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981. Please note that the offender retains the right to settle the dispute by paying—again in accordance with the procedures set forth in the attachment—an amount equal to half of the imposed penalty, within the time limit set forth in Article 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, provided for the filing of an appeal as indicated below (Article 166, paragraph 8, of the Code); ORDERS - pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No.

§

1/2019, the publication of this injunction order on the Data Protection Authority’s website; - pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Data Protection Authority’s Regulation No. 1/2019, the publication of this order on the Data Protection Authority’s website; - pursuant to Article 17 of Regulation No. 1/2019, the recording of the violations and the measures adopted in accordance with Article 58, para 2 of the Regulation, in the Authority’s internal register provided for by Article 57, para 1, letter u) of the Regulation. Pursuant to Article 78 of the Regulation, as well as Article 152 of the Code and Article 10 of Legislative Decree No. 150/2011, an appeal against this decision may be filed with the ordinary courts by submitting a petition to the ordinary court of the jurisdiction specified in the aforementioned Art 10, within thirty days from the date of notification of the decision, or within sixty days if the appellant resides abroad. Rome, June 18, 2026 THE PRESIDENT Stanzione THE RAPPORTEUR Cerrina Feroni THE SECRETARY GENERAL Montuori