# Garante per la protezione dei dati personali (Italy) - 476/2026

- Type: Enforcement
- Source: Garante per la protezione dei dati personali (Italy)
- Date: 2026-06-18
- Original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_476/2026
- Canonical: https://overview.legal/posts/187480

## Summary

Facts — Two former employees (the data subjects) of Piaggio (the controller) were dismissed for just cause in March 2023. Following the termination of their employment, they asked the controller to confirm that the individualised corporate email accounts assigned to them had been deactivated. The controller did not respond within the one-month deadline under Article 12(3) GDPR and they reiterated their request. The controller again did not respond within the statutory period and the data subjects lodged complaints with the Italian DPA (Garante). The data subjects also filed subsequent complaints arguing that the controller had accessed their previous email correspondence and used the messages in the disciplinary proceedings against them. They alleged that the controller had collected at least 18 emails sent or received through one data subject’s account, dating from November 2020 to January 2022, and 94 emails sent or received through the other data subject’s account, some dating back to April 2020. The correspondence also included emails exchanged with personal email accounts and third parties. The controller stated that, following internal reports received in November 2022 concerning possible serious misconduct by the two data subjects, it decided to conduct an internal investigation. According to the controller, the investigation was limited to their corporate email accounts, used predefined filters and keywords and was conducted following a balancing assessment and consultation with its DPO. It maintained that the investigation constituted a defensive control intended solely to investigate possible unlawful conduct and protect corporate assets, not to systematically monitor its employees. The controller further relied on its internal policy, which mentioned that employees should not expect confidentiality in relation to communications, messages or files created, received or stored through company systems. Regarding the unanswered requests, the controller argued that the data subjects had neither expressly requested the deletion of specific personal data nor referred to any provision of the GDPR. It stated that the accounts had already been deactivated on 16 February 2023 and permanently deleted on 27 April 2023, and that no one had accessed them following their deactivation. The controller also maintained that, because litigation concerning their dismissals was pending, the relevant emails had to be retained in order to protect its right of defence. Furthermore, the controller stated that it retained backups of corporate emails throughout the employment relationship and for an additional five years following its termination, while the related email logs were retained for six months. It argued that these periods were necessary for information security, business continuity, responding to potential claims and defending its interests before courts or public authorities. It also argued that the corporate email constituted a tool used by employees to perform their work and that retaining email during the employment relationship therefore did not require a prior trade-union agreement under Article 4 of the Italian Workers’ Statute. After the proceedings began, the controller reduced the retention period for emails to three months following termination of employment and the retention period for logs to 21 days. It also revised its internal policies and adopted additional technical and organisational measures. Holding — Regarding the data subjects’ requests, the DPA held that both an individualised corporate email address and the correspondence associated with it constituted personal data relating to the employee. According to the DPA, a request to deactivate such an account therefore amounted to a request to cease the related processing, even where the data subject did not expressly refer to the GDPR or identify a particular data subject right. It also noted that the data subjects had requested only confirmation that their accounts had been deactivated, not the deletion of the emails relied upon in the employment dispute. It stated that even where the protection of legal proceedings may justify delaying or restricting the exercise of a data subject right, the controller must provide a reasoned response within the applicable period and inform the data subject of the available administrative and judicial remedies. The DPA found that the controller therefore infringed Article 12(3) GDPR in conjunction with Article 17 GDPR. With regard to the internal investigation, the DPA noted that a defensive control may be permissible where there is a specific and well-founded suspicion of unlawful conduct. It emphasised that the check must concern data or conduct occurring after the emergence of that specific suspicion. It pointed out that in the present case, the suspicion arose in November 2022, but the controller examined correspondence dating back as far as approximately two years earlier. It held that the investigation was therefore retrospective and relied on data that had already been systematically collected and retained before any specific suspicion arose. It noted that the use of keywords, filters and a balancing assessment did not remedy this. In addition, the DPA held that the controller’s stated purposes were formulated too generally to justify retaining the complete correspondence of all employees throughout their employment and for an additional five years. It concluded that the controller’s practice lacked an appropriate legal basis under Article 6 GDPR and infringed the principles of purpose limitation under Article 5(1)(b), data minimisation under Article 5(1)(c) and storage limitation under Article 5(1)(e) GDPR. The DPA further rejected the controller’s position that employees should have no expectation of confidentiality in relation to communications and files stored on company systems. It held that both the content of emails and their metadata concerned correspondence protected by the right to privacy and secrecy of communications. It stressed that employees retain a reasonable expectation of privacy in the workplace. The DPA distinguished between the email service itself, which may constitute a tool used by employees to perform their work, and the separate systems used to systematically collect, retain and process email content and metadata. These systems operate independently of the employee’s ordinary use of email and may enable the employer to reconstruct the employee’s activities. It noted that this possibility was confirmed by the controller’s own policies. The DPA concluded that the systematic retention and subsequent use of the data enabled the controller to reconstruct and monitor employees’ activities. It further found that this monitoring had been carried out without the safeguards required under Italian labour law. It ruled that the controller infringed Article 5(1)(a) GDPR and Article 88 GDPR, together with Article 114 of the Italian Data Protection Code. The DPA also found unlawful the controller’s policy allowing, even with the former employee’s consent, their email address to remain active for up to 30 days and permitting incoming messages or the contents of the mailbox to be forwarded or transferred to another employee for broadly defined service needs. Finally, the DPA held that the controller had not demonstrated how and when the two data subjects had been informed about the processing. It noted that its policies did not sufficiently specify the purposes and legal bases for retaining emails and logs. It pointed out that even its revised policy did not adequately explain the specific purposes of the processing. It held that the controller therefore infringed the transparency principle under Article 5(1)(a) GDPR and its information obligations under Article 13 GDPR. The DPA imposed a fine of €460,000 and prohibited the controller from accessing the email data collected and retained on its corporate systems.

## Full text

SEE ALSO Newsletter of July 29, 2026 [Web Doc. No. 10272529] Decision of June 18, 2026 Register of Decisions No. 476 of June 18, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter, the “Regulation”); HAVING REGARD TO the Personal Data Protection Code, containing provisions for the adaptation of national law to Regulation (EU) 2016/679 (Legislative Decree No. 196 of June 30, 2003, as amended by Legislative Decree No. 101 of August 10, 2018, hereinafter the “Code”); HAVING REGARD TO the complaint filed pursuant to Art. 77 of the Regulation by Mr. XX and Ms. XX against Piaggio & C. S.p.A.; HAVING EXAMINED the documentation on file; HAVING CONSIDERED the observations made by the Acting Secretary General pursuant to Art. 15 of the Data Protection Authority’s Regulation No. 1/2000; RAPPORTEUR: Dr. Agostino Ghiglia; PREAMBLE 1. The complaints filed with the Data Protection Authority and the preliminary investigation initiated by the Office. In the complaints filed with this Authority on July 17, 2023, through their attorneys, Mr. XX and Ms. X alleged a violation of personal data protection regulations by Piaggio & C. S.p.A. (hereinafter “the Company”), where they had been employed until their termination for just cause, which was communicated to them by letter dated March 2, 2023. Specifically, the representatives of the complainants stated that they had asked the Company to confirm that the personalized corporate email accounts they had used during their employment had been deactivated, as part of their appeals against their respective terminations, dated April 26, 2023. These requests were reiterated via certified email (PEC) on May 31, 2023, and although they were duly sent to the Company’s certified email address, no response was received within the time limits specified in Art. 12, para. 3, of the Regulation. In subsequent complaints filed with the Authority on September 14, 2023, the complainants alleged that the Company, during the course of their employment, had accessed correspondence in transit on their individual corporate email accounts (XX and XX), and had collected numerous emails that had passed through those accounts and the complainants’ personal email inboxes, subsequently using them in disciplinary proceedings. Specifically, based on the findings of the disciplinary charges served on them (and included in the case file), it appeared that the Company had “collected, processed, and used at least 18 emails in total (…) that passed through the complainant’s corporate email account during the period from November 2020 to January 2022” (complaint by Ms. XX); that it had “collected, processed, and used a total of 94 emails that passed through the complainant’s company email account” (complaint by Mr. XX). “This email exchange also involved many emails that passed through the … personal email account” and were exchanged with third parties. The Office, therefore, issued a request for information to the Company, pursuant to Article 157 of the Code, inviting it to provide comments regarding the matters raised in the complaints, with particular reference to the legal grounds underlying the access granted to the two complainants’ company email accounts (note dated December 19, 2023). The Company responded in a letter dated January 17, 2024, stating that: - “The complainants’ company email accounts were deactivated, rendering their email inboxes inaccessible, on February 16, 2023, at 8:54 a.m., following allegations of disciplinary violations and a concurrent precautionary suspension. On April 27, 2023, the complainants’ company email accounts were deleted”; - “As of the date the accounts were deactivated (February 16, 2023), no one has had access to the complainants’ company email accounts. Access logs for corporate email accounts are retained for 6 months, in accordance with the principle of data storage limitation. The logs relating to access to the complainants’ corporate email accounts are therefore not available, as the accounts were deactivated and have thus been inaccessible for more than 6 months”; - “The Company has adopted, at the group level, a specific procedure for managing the termination of employment of staff members/employees (Attachment 2), as well as internal guidelines that detail the ‘off-boarding’ process for company personnel (Attachment 3)”; - “Once the employment relationship with a contractor or employee has ended, the company email address assigned to them is immediately deactivated. After a maximum period of 30 days from the termination of the employment or contract relationship, the email accounts are deleted, with the option to retrieve their contents for an additional 30 days and only upon request by the employee or contractor. After 30 days, the accounts are permanently deleted”; - “With regard to the email accounts of the two complainants, they were deactivated on February 16, 2023, following the issuance of a disciplinary charge for misconduct (…); therefore, not as a result of the ordinary termination of the employment relationship. The deactivation of the company email accounts was performed manually by the company’s IT department, and their erasure was also carried out manually on April 27, 2023, more than 30 days after the automatic deadline calculated by the system managing the company email accounts in the event of ordinary termination of employment”; - with regard to access to the company accounts, “following several internal reports alleging misconduct by the two complainants, on November 24, 2022, the Lead Independent Director, the Company’s representative (…) consulted, among others, with the Data Protection Officer (…), in order to determine whether to proceed with specific internal investigative activities aimed at verifying the validity of the suspicion of specific and serious unlawful conduct attributable to the two complainants to the detriment of the Company”; - therefore, “it was decided to implement defensive controls in the strict sense exclusively on the two complainants’ corporate email accounts for the purpose of protecting the company’s assets pursuant to Art. 4 of Law 300/1970 (“Defensive Measures”), following the establishment of the criteria and procedures for action (Annex 4), as well as a balancing test (…)” Based on the outcome of which, “it was determined that the most appropriate method for achieving the established purposes and the one most respectful of the principle of data minimisation consisted of the gradual extraction of data from the two complainants’ email accounts, limited to pre-identified filters and keywords, and within a limited time frame (…), in order to define the operational scope of the investigation and to restrict it solely to relevant data based on the principles of proportionality and necessity, relevance, fairness, and non-excess”; - “The defensive checks, far from constituting a form of systematic monitoring or Surveillance of work performance, were ordered by the Company after the two complainants had committed the offense—that is, ex post—for the purpose of ascertaining it”; - “The actual retrieval of specific emails from the company server was carried out by assigning XX as the processor pursuant to Art. 28 of the GDPR. XX was instructed by the controller to perform the processing via email dated November 29, 2023 (corrected to 2022). The Company provided the processor with instructions and criteria to be followed in extracting data from the two complainants’ email accounts (…). XX accessed the data via the company server and only the company email accounts: therefore, no access was made to the company computers used by the two complainants”; - “Neither Piaggio’s ICT department nor XX had access to the content of the extracted emails. (…) The data collected as a result of accessing the two complainants’ corporate email accounts and deemed relevant for the purposes of defensive audits were retained by the Internal Audit department only for the time necessary to conduct the defensive audits and evaluate the related findings (3 months) and were then irreversibly deleted (…)”. With regard to the failure to respond to the requests to exercise rights submitted by the complainants, which remained unanswered, the Company further stated that: - “the deactivation and closure of the accounts had already been implemented within the scheduled timeframe (accounts deactivated and made inaccessible on February 16, 2023, and permanent erasure of the accounts on April 27, 2023)”; - “given the ongoing litigation with the complainants (…) the response to the aforementioned requests should be handled within the framework of the legal proceedings themselves.” With regard, however, to the procedures and storage periods for messages in transit on company accounts, the Company stated that: - “Email messages are backed up for the entire duration of the employment contract and for an additional 5 (five) years following its termination,” as also documented in the Off-Boarding Guidelines (Appendix 3 to the aforementioned note); - “All Company employees are informed in a clear and transparent manner regarding: (i) the rules, criteria, and procedures for accessing and using the Company’s information system and related data and applications through the Company policy on the proper use of IT tools; (ii) the conditions, procedures, and purpose for which the Company reserves the right to conduct corporate audits of the corporate tools and services made available to employees for the performance of their work on behalf of the Company; (iii) the rules and methodologies aimed at preventing IT-related crimes,” as documented in the “Policies for the Proper Use of Information & Communication Technology Tools.” Before proceeding with its assessment, the Office issued a request to the complainants to verify the applicability, in this specific case, of the provision set forth in Art. 140-bis of the Code, in light of the simultaneous filing of appeals before the judicial authorities. In a communication dated May 3, 2024, the data subjects stated that the appeals filed with the Labor Division of the Court of Pisa concerned solely the challenge to their respective dismissals, with a request for a declaration of nullity or annulment of the dismissal order. 2. The initiation of proceedings for the adoption of corrective and sanctioning measures by the Authority. In light of the foregoing, the Office notified the Company of the initiation of sanction proceedings, pursuant to Article 166, paragraph 5, of the Code, for violations of Articles 5, para 1, subparagraphs (a), (b), (c) and (e), 6, 12, 13, 17, and 88 of the Regulation, and Art 114 of the Code (note dated September 3, 2024). On October 18, 2024, the Company submitted its defense briefs pursuant to Art. 18 of Law No. 689/1981, in which it argued, with regard to the failure to respond to the request to exercise rights, that the requests made by the data subjects did not fall within the scope of Articles 15 et seq. of the Regulation. “In fact, the data subjects did not request the erasure of specific personal data relating to them, nor the cessation of a particular processing operation concerning their data. They therefore did not exercise the right to erasure under Article 17 of the GDPR. The 30-day deadline for responding to the data subject provided for in Article 12 of the GDPR did not, therefore, apply in this case.” In any event, even if one were to assume that the data subjects had requested the erasure of the emails stored on the company server, “Piaggio would not have been able to comply with the request in any case, since the exercise of the right to erasure must be weighed against the adequacy and relevance of the data in relation to the processing purpose.” “In this case, the former employees’ emails constitute crucial evidence in the labor proceedings before the Court of Pisa. The erasure of these emails would therefore have compromised Piaggio’s ability to defend itself in the litigation that the former employees had already stated they intended to initiate by challenging the terminations out of court.” With regard, however, to the management and storage of email logs, the Company observed, as a preliminary matter, that corporate email constitutes “a tool used by the employee to perform their work” and, as such, falls within the scope of application of the second paragraph of Article 4 of the Workers’ Statute. Therefore, considering that “Email is now the primary work tool for all those who perform office work (…), the continuous erasure of emails would prevent these employees from carrying out their duties without disruption (…). Consequently, email must be stored throughout the entire employment relationship without any need for a union agreement.” Given, therefore, that the Company has established, with a view to accountability, a storage period for employees’ email of 5 years following the termination of employment, the Company has argued that this period serves the purpose of protecting the security of corporate information and ensuring business operations, while at the same time allowing the Company “to respond to any disputes and/or requests from authorities and thus defend itself in court.” Furthermore, as indicated in the document containing the Off-Boarding Guidelines (Exhibit 4 to the defense briefs, p. 2), emails that employees permanently delete from the trash are also deleted from Piaggio’s backup server after one year. As for emails not deleted by employees, the IT Policy (Exhibit 3 to the pleadings) clarifies that all messages composed, sent, or received on the email system that pertain to the performance of work duties are and remain the property of the Company, and that the company email account may be subject to monitoring by the Company. In particular, “Piaggio reserves the right to conduct audits and inspections of ICT Resources for the following purposes: a) for the production, organization, and management of ICT Resources, and the management of Piaggio’s business operations; b) for cybersecurity purposes and to verify the functionality of ICT Resources; c) to ensure the proper use of ICT resources and compliance with applicable regulations, company policies, and the Code of Ethics; d) for internal investigations aimed exclusively at ascertaining unlawful conduct by the User; e) to assert or defend a right in court” (page 16 of the Policies). With regard to the backup of correspondence in transit on company accounts assigned to employees, the Company specified that this “is completely segregated from other company information and is managed by the provider (…), who has been specifically appointed as the processor” (Exhibit 11 to the briefs), and that “the procedure stipulates that the provider may never access emails except upon specific instruction from Piaggio, provided in accordance with and within the limits of the provisions of privacy regulations and the IT Policy. The Company’s system administrators cannot access the backup except through the provider.” Therefore, in recital 1, given that the Company does not use email as a document repository but exclusively as a work tool for its employees, the Company has clarified that it has never accessed employees’ emails after the termination of their employment. In fact, even in the case at hand, “access was granted while the employment relationship was still in effect, in compliance with privacy regulations and only following an assessment by the Company, in consultation with the DPO, of any risks and impacts on the data subjects,” as evidenced by the DPIA attached to the briefs. While the Company maintains that storage of emails beyond the termination of employment is a legitimate practice—as it is supported by corporate security needs and causes no harm to the data subjects—it stated, in its defense briefs, that it had reduced the five-year storage period for email to 3 months following the termination of employment, “the minimum period necessary for the layoff procedure and to allow the data subject to request access and/or contest any dismissal.” With regard to the alleged violation of Article 4 of Law No. 300/1970, the Company ruled out that “the storage of email beyond the termination of employment may be relevant for the purposes of the aforementioned provision, which concerns the protection of the employee and the possible monitoring of the employee during the employment relationship.” With regard to the storage period for email access logs, the Company noted that, following the publication of the Guidance Document titled “IT Programs and Services for Email Management in the Workplace and the Processing of Metadata,” adopted by the Data Protection Authority on June 6, 2024 (Provision No. 364, Web Doc. No. 10026277), the storage periods were reduced in accordance with the provided guidelines, implementing a new company policy that now requires the erasure of logs every 21 days. Finally, with regard to the violation concerning the lack of information and transparency regarding the processing and storage of email logs and the emails themselves, the Company noted that both the Guidelines on Transparency and the provisions adopted by the Authority in similar circumstances “do not require that the notices to data subjects specify the exact reason for choosing the retention period and, therefore, detail the logical reasoning behind that choice.” Therefore, it considers that it has complied with the transparency obligations set forth in Art. 5(1)(a) and Art. 13 of the Regulation. In any case, “in order to ensure even greater transparency toward its employees regarding the processing of their data, Piaggio has updated its Regulation on the Use of the Internet and Email,” “specifying the automatic backup cycle interval (i.e., 8 hours), explaining that if an email is permanently deleted within the 8-hour interval, it will not be included in the backup and will no longer be recoverable,” and that if an email is permanently deleted from the user’s trash folder “it will also be deleted from the company’s backup one year after erasure.” On December 6, 2024, a hearing was held with the Company, during which the points already extensively argued in the defense briefs were reiterated. 3. The outcome of the preliminary investigation and the proceedings for the adoption of corrective and sanctioning measures pursuant to Article 58, para 2, of the Regulation. Following an examination of the statements made by the party during the proceedings, as well as the documentation obtained, it has been established that the Company, identified as the controller pursuant to Article 4(7) of the Regulation, carried out processing operations that did not comply with the regulations governing data protection. In this regard, it should be noted that, unless the act constitutes a more serious offense, any person who, in proceedings before the Data Protection Authority, falsely declares or attests to facts or circumstances, or produces false documents or records, shall be liable pursuant to Art. 168 of the Code, “False Statements to the Data Protection Authority and Interruption of the Performance of the Authority’s Duties or the Exercise of Its Powers.” 3.1. Violation of Articles 12(3) and 17 of the Regulation. First, it has been established that the complainants requested confirmation from the Company, on two separate occasions, that their individual corporate email accounts had been deactivated following the termination of their employment. These requests were motivated by the need to know the status of the aforementioned accounts, having observed that the Company had accessed them to retrieve emails in order to bring disciplinary charges against them. The initial requests were therefore made as part of the appeals against the terminations (in letters dated April 23, 2023), while subsequent requests were resubmitted on May 31, 2023, with an explicit warning that any continued activation of the accounts following the termination of employment could constitute a “clear, extremely serious, and unjustified (further) violation of privacy.” This means, on the one hand, that the requests—although they did not contain explicit references to the provisions of the Regulation regarding the exercise of rights—must in any case be interpreted in light of the applicable provisions on the processing of personal data, precisely in light of the violations arising from the continued processing of personal data related to the complainants’ email accounts. Incidentally, in light of the clarifications provided by the EDPB in Guidelines 1/2022 on the rights of data subjects, dated March 28, 2023, “The controller may not, therefore, refuse to provide the data by citing the failure to specify the legal basis for the request, in particular the lack of a specific reference to the right of access or to the GDPR,” especially considering that “the GDPR does not impose any requirements on data subjects regarding the form of an access request for personal data” (see, in this regard, para 3.1.1, point 50, and para 3.1.2, point 52 of the aforementioned Guidelines). On the other hand, it must be noted that, contrary to the party’s assertion, requests concerning the deactivation of individualized company email accounts fully fall within the scope of the rights granted to data subjects under Articles 15 et seq. of the Regulation. This is because the individualized corporate email address (i.e., one assigned to a specific employee), as well as the content of the emails in the account, constitute personal data relating to the employee in question. In particular, communications passing through an individualized account are inevitably attributable to the personal data of the account holder. Therefore, as the Authority has consistently recognized in its decisions, a request to deactivate a personalized account (whether or not accompanied by a request for erasure of the emails contained therein) amounts to a request to cease all processing activities that have been carried out up to that point, on the data subject’s personal data (see, among the most recent, Decision No. 427 of July 17, 2025, web doc. No. 10182762; Order No. 754 of December 18, 2025, Web Doc. No. 10213574; Order No. 82 of February 12, 2026, Web Doc. No. 10230220). In the case at hand, among other things, the requests submitted by the data subjects were aimed exclusively at confirming the erasure of the individualized corporate accounts and did not also seek the deletion of the emails that had been obtained by the Company through its investigative activities. It follows, therefore, that the Company’s argument is unfounded—namely, that in any event, the request for erasure could not be granted because it would have restricted the legitimate exercise of the right to defense in the proceedings following the challenge to the terminations; a right of defense that was based precisely on the use, in court, of the correspondence exchanged by the complainants through their company email accounts. However, with regard to limitations on the data subject rights, Article 2-undecies of the Code, in accordance with the provisions of Article 23 of the Regulation, provides that “The rights referred to in Articles 15 through 22 of the Regulation may not be exercised by submitting a request to the controller or by filing a complaint pursuant to Article 77 of the Regulation if the exercise of such rights could result in actual and concrete harm: […] e) to the conduct of defense investigations or the exercise of a right in court.” In such cases, “The exercise of those rights may […] be delayed, restricted, or excluded by means of a reasoned notification provided without delay to the data subject, unless such notification would undermine the purpose of the restriction, for as long and to the extent that this constitutes a necessary and proportionate measure, taking into account the data subject rights and legitimate interests of the data subject.” Furthermore, pursuant to Article 12(4) of the Regulation, “if the controller does not comply with the data subject’s request, the controller shall inform the data subject without undue delay, and at the latest within one month of receiving the request, of the reasons for the failure to comply and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.” Therefore, in light of the foregoing and, above all, the provisions of the Regulation, the Company’s violation of the provision set forth in Art 12, para 3, in conjunction with Art 17 of the Regulation, must be confirmed. 3.2. Violation of Articles 5(1)(a), (b), (c), and (e), 88 of the Regulation, and 114 of the Code. It has been established that the Company accessed the complainants’ email accounts during the course of their employment, and that it acquired and collected “at least 18 emails in total (…) that passed through the complainant’s company email account during the period from November 2020 to January 2022” and “as many as 94 emails in total that passed through the complainant’s company email account,” starting in April 2020. According to the Company’s statements during the preliminary investigation, this activity was carried out in order to “verify the validity of the suspicion of specific and serious unlawful conduct attributable to the two complainants to the detriment of the Company” (note dated January 17, 2024) and, therefore, as part of so-called “defensive audits,” which were carried out after identifying criteria and procedures and conducting a balancing test (Exhibit 5 to the note dated January 17, 2024, and Exhibit 2 to the defense briefs dated October 18, 2024). In any case, the Company considered this monitoring activity to be legitimate, as it is provided for and regulated in its internal documents for the pursuit of various purposes (including that of “internal investigations aimed exclusively at ascertaining unlawful conduct by the User”—IT Policy, para. 9.3), as it was carried out in compliance with the principles governing data protection, as well as the prohibition on monitoring work activities set forth in Art. 4 of Law No. 300/1970. With regard to the investigation of the two complainants’ individual email accounts, carried out by the Company as part of so-called “defensive monitoring” and aimed at retrieving emails that would provide evidence of unlawful conduct, given that it is not within the Authority’s purview to rule on the so-called “theory of defensive monitoring,” which is a purely jurisprudential construct and, moreover, subject to inconsistent application (see, on this subject, Decision No. 137 of April 15, 2021, web doc. No. 9670738, Decision No. 409 of December 1, 2022, Web Doc. No. 9833530), reference is made to the principle reaffirmed in various judicial rulings, according to which “with regard to so-called ‘defensive systems,’ even after the amendment of Article 4 of the Workers’ Statute by Article 23 of Legislative Decree No. 151 of 2015, monitoring—including technological monitoring—implemented by the employer to protect assets unrelated to the employment relationship or to prevent unlawful conduct, in the presence of a well-founded suspicion that an offense has been committed, provided that a proper balance is ensured between the need to protect the company’s interests and assets, related to the freedom of economic initiative, and the essential protections of the employee’s dignity and confidentiality, provided that the monitoring concerns data collected after the suspicion arose” (see Court of Cassation No. 25732 of September 22, 2021; Supreme Court Case No. 18168 of June 26, 2023; Supreme Court Case No. 32283 of December 11, 2025). The decisive factor for the admissibility of the monitoring, according to the Supreme Court’s guidelines, is therefore that the audit be conducted ex post, that is, regarding conduct that took place after the suspicion of wrongdoing arose (on this point, see also Supreme Court Case No. 34092 of November 12, 2021). It is clear that, in the present case, this condition is not met, as it has been established that the data acquired by the Company predate the emergence of suspicion of the alleged offense: in fact, the collection of data relating to the correspondence exchanged by the two complainants was carried out retroactively, going back approximately two years. From the perspective of personal data protection, the monitoring activity carried out by the Company on the two complainants’ email accounts was made possible by the systematic collection and storage of data relating to employees’ email correspondence, which, as provided for in the offboarding guidelines submitted to the court, is backed up for the entire duration of the employment relationship and for up to five years following its termination. As stated by the Company during the preliminary investigation, storage applies not only to email messages but also to the email logs themselves, which are stored for a period of 6 months (note dated January 17, 2024). As for the specific reasons for establishing such an extended period of storage, in the absence of precise indications in the relevant documents regarding the purposes pursued, the Company stated that email is not used as a document repository but exclusively as a work tool for its employees; Meanwhile, the storage of email logs for 6 months was justified by the need to ensure the security of the IT systems (see note dated October 18, 2024). In its defense briefs dated October 18, 2024, the Company reported that, following the initiation of the proceedings, it had made substantial changes to the storage periods for these categories of data. Specifically, the storage period for email data has been reduced from five years to three months following the termination of employment. The Authority welcomes the changes made, noting, however, that the storage of email must be strictly limited to access by the account holder only. Therefore, organizational and technological measures must be adopted to prevent access to the filing system by anyone other than the account holder, unless the account holder explicitly makes a request for access for support purposes (see, in this regard, Provision No. 613 of October 9, 2025, web doc. No. 10185435; and Provision No. 153 of February 1, 2018, web doc. No. 8159221). This is because the content of email messages, as well as the external data associated with the communications (including email logs—such as the sender’s and recipient’s email addresses, the IP addresses of the servers or clients involved in routing the message, the times of sending, transmission, or receipt, the message size, the presence of any attachments, and the subject line of the sent or received message) pertain to forms of correspondence protected by guarantees of confidentiality that are also constitutionally protected (Articles 2 and 15 of the Constitution), with respect to which the Data Protection Authority has therefore held that, in both public and private work contexts, there is a legitimate expectation of confidentiality regarding the messages that are the subject of such correspondence (see point 5.2(b) of Provision No. 13 of March 1, 2007, containing Guidelines for Email and the Internet, Web Doc. No. 1387522; and in relation to specific cases, most recently, Provision No. 613 of October 9, 2025, Web Doc. No. 10185435). This also takes into account the case law established by the European Court of Human Rights, according to which the protection of private life extends to the workplace as well, given that it is precisely in the course of performing work and/or professional activities that relationships develop in which the employee’s personality is expressed. Given that the boundary between the workplace/professional sphere and the strictly private sphere cannot always be clearly drawn, the Court considers Art 8 of the European Convention on Human Rights—which protects private life—to be applicable without distinguishing between the private and professional spheres (see Niemietz v. Germany, Dec. 16, 1992 (Application No. 13710/88), esp. para. 29; Copland v. the United Kingdom, April 3, 2007 (Application No. 62617/00), see para. 41; Barbulescu v. Romania [GC], September 5, 2017 (Application No. 61496/08), see para. 70–73; Antovi and Mirkovi v. Montenegro, November 28, 2017 (Application No. 70838/13), see para. 41–42). Precisely in light of the principles cited above, the provisions of para 9 cannot be accepted.3. of the Policy, which states that data subjects, in their capacity as Users, “shall have no expectation of confidentiality with respect to any communication, message, file, or material created, stored, received, or sent through ICT Resources, including via personal devices.” This approach is also influenced by the party’s interpretation regarding the nature of email, which is understood as a “work tool” and, as such, excluded from the scope of application of the enhanced safeguards provided for in Art. 4, paragraph 1, of Law No. 300/1970 (in contrast to the provision in paragraph 2, which states that “the provision in paragraph 1 does not apply to tools used by the employee to perform their work […]”). On this point, the Authority reiterates its position, already expressed in various decisions, according to which the systems and programs that enable the collection, storage, and processing of data derived from the use of email and the internet connection (the latter not at issue in the present case) are not indispensable for the performance of work and operate entirely independently of the user’s normal activities (i.e., without any impact on or interference with the employee’s work) (on this point, see: Decision No. 613 of October 9, 2025, Web Doc. No. 10185435; Decision No. 384 of October 28, 2021, Web Doc. No. 9722661; Provision No. 190 of May 13, 2021, Web Doc. No. 9669974; Provision No. 479 of November 16, 2017, Web Doc. No. 7355533; see also INL Circulars No. 4/2017 dated July 26, 2017, and No. 2/2016 dated November 7, 2016). With regard to the storage periods for email logs, the Company also stated in the aforementioned defense briefs that, in compliance with the guidelines provided by the Authority in the ruling titled “Guidance Document. IT Programs and Services for Email Management in the Workplace and the Processing of Metadata,” adopted on June 6, 2024 (web doc. No. 10026277), has implemented a new company policy that provides for the erasure of logs every 21 days. We also welcome this further amendment to the company’s policies and the technical and organizational measures implemented, taking into account that, in accordance with the general principle of storage limitation set forth in Article 5, para 1, subparagraph (e) of the Regulation, the controller must identify a timeframe appropriate to the objective of detecting and mitigating any security incidents, promptly adopting the necessary countermeasures. It remains clear, in any case, that the processing activities carried out prior to the aforementioned changes took place without the appropriate basis of lawfulness pursuant to Article 6 of the Regulation, and in violation of the principles of purpose limitation, data minimisation, and storage limitation set forth in Art 5(1)(b), (c), and (e) of the Regulation. In fact, given that the employer, as the controller, may generally process employees’ personal data only if such processing is necessary for the management of the employment relationship itself or if it is necessary to fulfill specific obligations or tasks imposed by applicable sector-specific regulations (see Articles 5(1)(a), 6, and 9 of the Regulation), it has been established in the present case that the processing activities were carried out without a valid basis for the processing that is lawful. Furthermore, it must be considered that the data in question were processed by the Company for a considerable period of time and without predetermined purposes, in violation of the general principle of data minimisation, according to which personal data must be “adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed” (Art 5(1)(c) of the Regulation) and which embodies the principle of proportionality. Finally, it should be noted that, again in the Policy, supplementing the provisions of the Guidelines regarding the management of email following the termination of employment, the Company informs data subjects that, subject to the User’s consent, it is possible to keep the outgoing employee’s email address active for a period not exceeding 30 days by forwarding emails to another email account designated by the User’s supervisor, or to transfer the contents of the email account to another User, for proven service needs. This practice, especially given the extremely vague nature of the “service needs” cited, is contrary to the provisions on personal data protection, as reiterated by the Data Protection Authority on numerous occasions—not only through general provisions (including, among others, the aforementioned Guidelines for Email and the Internet), but also in numerous decisions adopted in relation to specific cases (see Decision No. 758 of December 18, 2025, web doc. No. 10213574; No. 140 of March 7, 2024, web doc. No. 10009004; Decision No. 732 of November 27, 2024, web doc. No. 10101221; Order No. 263 of June 22, 2023, web doc. No. 9920814; Order No. 255 of July 21, 2022, Web Doc. No. 9809466), which emphasize that, to safeguard potential and legitimate needs for business continuity, following the termination of the employment relationship, the owner must ensure the removal of the account, after deactivating it and simultaneously implementing automated systems designed to notify third-party senders and provide them with alternative contact information related to the employee’s professional activities, while also taking appropriate measures to prevent the display of incoming messages during the period in which such automated system is in operation. That said, the Company’s interpretation set forth in its defense briefs cannot be considered correct, as it ruled out that the mere storage of email and logs could constitute a form of monitoring of work activities, given what subsequently occurred in this specific case. In fact, the documentation prepared by the Company (including the aforementioned Policies for the Proper Use of Information and Communication Technology Tools) contains detailed regulations on how to conduct monitoring, which is carried out “periodically” on the use of email, the network, and computers “to verify that their use is balanced and consistent with the company’s activities, and to ensure compliance with applicable regulations, company policies, and the Code of Ethics” (Sections 7.1.2 and 7.1.3 of the Policies). More specifically and in greater detail, in para 9 of the aforementioned Policies, the Company informs data subjects that verification and monitoring activities regarding ICT Resources are carried out for various purposes, including “production, organization, and management of ICT Resources,” “for cybersecurity purposes and to verify the functionality of ICT resources,” as well as “for internal investigations” and “to assert or defend a right in court.” As for the methods by which these controls are implemented, the internal regulations provide for “access to company systems and the extraction of files and/or email messages for investigative and legal defense purposes through the use of search criteria, filters, and/or other e -Discovery tools that ensure confidentiality and proportionality,” “access to company tools via dedicated verification software,” and “monitoring of suspicious behavior and activities” (see IT Policy, para. 9). As part of these controls, the Company even reserves “the right to review files and messages stored in ICT Resources or that have already been deleted” (…), for various purposes, including “to investigate unlawful conduct and to exercise or defend a right in court” (para 9 of the aforementioned Policy). In light of the findings set forth in this ruling, as well as based on the company’s practices described in the documents on file, it is therefore concluded that the processing activities described above, carried out through the systematic collection and storage of company emails and related logs, were conducted in violation of the principle of lawfulness of processing set forth in Article 5, para 1, subparagraph (a), of the Regulation. This is because, through the operations described above, the data controller can reconstruct (as in fact occurred) the activities of their employees and exercise control over them, in the absence of the safeguards established within the employment relationship, pursuant to Art. 88 of the Regulation, which refers to the more specific and protective provisions on labor matters set forth in national law. Specifically, Article 114 of the Code (“Guarantees Regarding Remote Monitoring”) identifies the provision set forth in Article 4 of Law No. 300/1970 as a condition for the lawfulness of personal data processing carried out in the context of the employment relationship (in this regard, see certain decisions adopted in connection with specific cases: Decision No. 255 of July 21, 2022, Web Doc. No. 9809466; Decision No. 190 of May 13, 2021, Web Doc. No. 9669974; Decision No. 53 of February 1, 2018, Web Doc. No. 8159221; Order No. 303 of July 13, 2016, Web Doc. No. 5408460). Considering, therefore, that Article 4, paragraph 1, of Law No. 300/1970 strictly defines the purposes (namely, organizational, productive, workplace safety, and protection of company assets) for which such tools—which also enable remote monitoring of employees’ activities—may be used in the workplace, while establishing specific procedural safeguards (trade union agreement or public authorization), it is noted that, in the case at hand, the processing was carried out in violation of the provisions of the law. 3.3. Violation of Articles 5(1)(a) and 13 of the Regulation. It also appears that, starting in 2022, the Company prepared certain informational documents that were produced as part of the preliminary investigation, consisting of the Off-Boarding Guidelines and the Policy for the Proper Use of Information and Communication Technology Tools. However, no clarification was provided regarding previous versions of these documents or the manner in which the two complainants were informed of the processing activities carried out. In this regard, it should be noted that, pursuant to Art. 13 of the Regulation, the notice must instead be provided to data subjects “at the time the personal data are collected.” This approach is consistent with the data controller’s obligation to indicate, in advance and in a transparent manner, the monitoring activities that may be carried out; the purpose of which is to enable the data subject to be fully aware of the types of processing operations that may be carried out by the controller, including by drawing, within a framework of lawfulness and proportionality, on data collected in the course of work activities. In any case, a joint review of these documents—which describe the processing operations carried out, including those involving the IT tools made available to employees by the Company—reveals no indication of the purposes of such processing; more specifically, there is no indication of the purposes and grounds for email storage and related logs. In this regard, the Guidelines on Transparency, adopted on November 29, 2017, by the Article 29 Data Protection Working Party, clarify that “In addition to defining the processing purposes for which personal data are intended, the relevant legal basis invoked pursuant to Article 6 must be specified.” In cases where processing is carried out on the basis of the controller’s legitimate interest, that specific interest “must be identified for the benefit of the data subject. Best practice dictates that the controller may also provide the data subject with information derived from the balancing test, which must be conducted as the legal basis for the processing prior to collecting the data subjects’ personal data in order to rely on Article 6(1)(f).” With regard to the data storage period, this (or the criteria for determining it) “may be dictated by factors such as legal obligations or industry guidelines, but should be specified in a manner that allows the data subject to determine, based on their specific situation, the expected retention period for the specific data or purposes. It is not sufficient for the controller to state in general terms that personal data will be stored for as long as necessary for the legitimate processing purposes. Where relevant, different storage periods should be established for different categories of data and/or processing purposes, including, where applicable, archiving periods.” The “Regulation for the Use of the Internet and Email,” submitted with the defense briefs to supplement the previous Policy, while concisely and sufficiently clearly indicating the storage periods for data relating to email and logs, still lacks information regarding the purposes of such processing activities. Therefore, the violation of the provisions of Articles 5(1)(a) and 13 of the Regulation is confirmed, pursuant to which the controller is required to provide the data subject in advance with all information regarding the essential characteristics of the processing. 4. Conclusions: Declaration that the processing is unlawful. Corrective measures pursuant to Art. 58(2) of the Regulation. For the reasons set forth above, the Authority considers that the statements made by the controller during the investigation do not address the findings notified by the Office in the notice initiating the proceedings and are therefore insufficient to warrant the dismissal of this proceeding; furthermore, with respect to these aspects, any of the cases provided for in Art. 11 of the Data Protection Authority’s Regulation No. 1/2019. The processing of personal data carried out by Piaggio & C. S.p.A. is unlawful, under the terms set forth above, as it was carried out in violation of Articles 5(1)(a), (b), (c) and (e), 6, 12, 13, 17, and 88 of the Regulation and Art 114 of the Code. The violation ascertained as described in the grounds cannot be considered “minor,” given the nature of the violation, which concerned the general principles of data processing (lawfulness, data minimisation, and storage limitation) and the more specific provisions regarding remote monitoring, in addition to the data subject rights. Therefore, in view of the corrective powers conferred by Article 58(2) of the Regulation, the processing of unlawfully collected data is hereby prohibited, and an administrative fine is imposed pursuant to Article 83 of the Regulation, commensurate with the circumstances of the specific case (Article 58(2)(f) and (i) of the Regulation). Finally, it is considered that the conditions set forth in Art. 17 of the Data Protection Authority’s Regulation No. 1/2019 are met. 5. Adoption of the injunction ordering the imposition of the administrative fine and ancillary sanctions (Articles 58(2)(i) and 83 of the Regulation; Article 166(7) of the Code). The outcome of the proceedings shows that Piaggio & C. S.p.A. s.r.l. has violated Articles 5(1)(a), (b), (c), and (e), 6, 12, 13, 17, and 88 of the Regulation, as well as Article 114 of the Code. For the violation of the aforementioned provisions, the administrative fine provided for in Article 83, para 5, subparagraphs (a) and (d) of the Regulation shall be imposed. The Authority, pursuant to Article 58, para 2, subparagraph (i) of the Regulation and Article 166 of the Code, has the power to impose an administrative fine provided for in Article 83 of the Regulation, by issuing an injunction order (Article 18. Law No. 689 of November 24, 1981), in connection with the processing of personal data carried out by Piaggio & C. S.p.A., which has been found to be unlawful, as set forth above. Considering that paragraph 3 of Art 83 of the Regulation must be applied, which provides that “If, in relation to the same processing or related processing operations, a controller […] intentionally or negligently infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the most serious infringement,” the total amount of the fine is calculated so as not to exceed the maximum amount provided for in Art. 83, para. 5. With regard to the factors listed in Article 83(2) of the Regulation for the purposes of applying the administrative fine and determining its amount, and taking into account that the fine must “in any event [be] effective, proportionate, and dissuasive” (Article 83(1) of the Regulation), it is noted that, in the present case, the following circumstances were taken into account: - with regard to the nature and severity of the violation, the violations committed that concerned the provisions on the exercise of rights, the general principles of processing, and more specific provisions on remote monitoring were considered relevant; in particular, the nature of the processing—which involved the systematic recording and storage of communications sent by employees (vulnerable data subjects) via email and the related logs—was taken into account; - With regard to the duration of the violation, consideration was given to the fact that a response to the request to exercise rights was received only after the Authority had initiated its investigation; while the extended duration of email storage and logs (the entire duration of the employment relationship plus an additional period following its termination) was deemed relevant; - with regard to whether the violation was intentional or negligent and the degree of the data controller’s accountability, the Company’s conduct was taken into account, as it generally provided for the storage of data contained in its employees’ emails with the possibility of accessing them for a variety of purposes; - In the Company’s favor, account was taken of the cooperation provided during the proceedings, aimed at remedying the violations found and mitigating their negative effects; in particular, the changes made to its IT systems regarding data storage periods, the adoption of additional technical measures, and the revisions to employee information documents were viewed favorably; - the absence of any relevant prior violations committed by the data controller was also taken into account. It is also considered that the following factors are relevant in the present case, taking into account the aforementioned principles of effectiveness, proportionality, and deterrence that the Authority must adhere to when determining the amount of the fine (Art. 83(1) of the Regulation), first, the economic circumstances of the offender, determined on the basis of the Company’s turnover as reported in the financial statements for the year 2025. In light of the above factors and the assessments made, it is deemed appropriate, in this case, to impose on Piaggio & C. S.p.A. an administrative fine in the amount of 460,000.00 (four hundred sixty thousand) euros. In this context, it is also deemed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, this section containing the injunction order must be published on the Data Protection Authority’s website. This is in light of the conduct that was particularly detrimental to the data subject rights and occurred in violation of the general principles governing data protection. NOW THEREFORE, THE DATA PROTECTION AUTHORITY pursuant to Article 57, para 1, subparagraph f), of the Regulation, finds that the processing carried out by Piaggio & C. S.p.A., represented by its pro tempore legal representative, with registered office in Pontedera (PI), Viale Rinaldo Piaggio, VAT No. 01551260506, for violating Articles 5(1)(a), (b), (c), and (e), 6, 12, 13, 17, and 88 of the Regulation and Article 114 of the Code; ORDERS the aforementioned Company, pursuant to Article 58, para 2, subparagraph f) of the Regulation, to prohibit access to the content of data collected and stored on the company’s systems relating to corporate email; pursuant to Article 58, para 2, subparagraph (i) of the Regulation, the aforementioned Company to pay the sum of 460,000.00 euros (four hundred sixty thousand) as an administrative fine for the violations indicated in this order; THEREFORE ORDERS the said Company to pay the aforementioned sum of 460,000.00 euros (four hundred sixty thousand), in accordance with the procedures set forth in the attachment, within 30 days of the service of this order, failing which the necessary enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981. It is noted that, pursuant to Article 166, paragraph 8 of the Code, the offender retains the right to settle the dispute by paying —again in accordance with the procedures set forth in the attachment—of an amount equal to half of the imposed penalty within the time limit specified in Art. 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, provided for the filing of an appeal as indicated below. ORDERS - pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/20129, the publication of this injunction order on the Data Protection Authority’s website; - pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Data Protection Authority’s Regulation No. 1/20129, the publication of this order on the Data Protection Authority’s website; - Pursuant to Article 17 of Regulation No. 1/2019, the recording of the violations and the measures adopted in accordance with Article 58, para 2, of the Regulation in the Authority’s internal register provided for by Article 57, para 1, letter u), of the Regulation. Pursuant to Article 78 of the Regulation, as well as Article 152 of the Code and Article 10 of Legislative Decree No. 150/2011, an appeal against this decision may be filed with the ordinary courts by submitting a petition to the ordinary court of the location specified in the aforementioned Art 10, within thirty days from the date of notification of the decision, or within sixty days if the appellant resides abroad. Rome, June 18, 2026 THE CHAIRMAN Stanzione THE RAPPORTEUR Ghiglia THE SECRETARY GENERAL Montuori SEE ALSO Newsletter of July 29, 2026 [Web Doc. No. 10272529] Decision of June 18, 2026 Register of Decisions No. 476 of June 18, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter, the “Regulation”); HAVING REGARD TO the Code on Data Protection, containing provisions for the adaptation of national law to Regulation (EU) 2016/679 (Legislative Decree No. 196 of June 30, 2003, as amended by Legislative Decree No. 101 of August 10, 2018, hereinafter the “Code”); HAVING REGARD TO the complaint filed pursuant to Art. 77 of the Regulation by Mr. XX and Ms. XX against Piaggio & C. S.p.A.; HAVING EXAMINED the documentation on file; HAVING CONSIDERED the observations made by the Acting Secretary General pursuant to Art. 15 of the Data Protection Authority’s Regulation No. 1/2000; RAPPORTEUR: Dr. Agostino Ghiglia; PREAMBLE 1. The complaints filed with the Data Protection Authority and the preliminary investigation initiated by the Office. In the complaints filed with this Authority on July 17, 2023, through their attorneys, Mr. XX and Ms. X alleged a violation of personal data protection regulations by Piaggio & C. S.p.A. (hereinafter “the Company”), where they had been employed until their termination for just cause, which was communicated to them by letter dated March 2, 2023. Specifically, the complainants’ representatives stated that they had asked the Company to confirm that the personalized corporate email accounts they had used during their employment had been deactivated, as part of their appeals against their respective terminations, dated April 26, 2023. These requests were reiterated via certified email (PEC) on May 31, 2023, and although they were duly sent to the Company’s certified email address, no response was received within the time limits specified in Art. 12, para. 3, of the Regulation. In subsequent complaints filed with the Authority on September 14, 2023, the complainants alleged that the Company, during the course of their employment, had accessed correspondence in transit on their individual corporate email accounts (XX and XX), and had collected numerous emails that had passed through those accounts and the complainants’ personal email inboxes, subsequently using them in disciplinary proceedings. Specifically, based on the findings of the disciplinary charges served on them (and included in the case file), it appeared that the Company had “collected, processed, and used at least 18 emails in total (…) that passed through the complainant’s corporate email account during the period from November 2020 to January 2022” (complaint by Ms. XX); that it had “collected, processed, and used a total of 94 emails that passed through the complainant’s company email account” (complaint by Mr. XX). “This email exchange also involved many emails that passed through the … personal email account” and were exchanged with third parties. The Office, therefore, issued a request for information to the Company, pursuant to Article 157 of the Code, inviting it to provide comments regarding the matters raised in the complaints, with particular reference to the legal grounds underlying the access granted to the two complainants’ company email accounts (note dated December 19, 2023). The Company responded in a letter dated January 17, 2024, stating that: - “The complainants’ company email accounts were deactivated, rendering their email inboxes inaccessible, on February 16, 2023, at 8:54 a.m., following allegations of disciplinary violations and a concurrent precautionary suspension. On April 27, 2023, the complainants’ company email accounts were deleted”; - “As of the date the accounts were deactivated (February 16, 2023), no one has had access to the complainants’ company email accounts. Access logs for corporate email accounts are retained for 6 months, in accordance with the principle of data storage limitation. The logs relating to access to the complainants’ corporate email accounts are therefore not available, as the accounts were deactivated and have thus been inaccessible for more than 6 months”; - “The Company has adopted, at the group level, a specific procedure for managing the termination of employment of staff members/employees (Attachment 2), as well as internal guidelines that detail the ‘off-boarding’ process for company personnel (Attachment 3)”; - “Once the employment relationship with a contractor or employee has ended, the company email address assigned to them is immediately deactivated. After a maximum period of 30 days from the termination of the employment or contract relationship, the email accounts are deleted, with the option to retrieve their contents for an additional 30 days and only upon request by the employee or contractor. After 30 days, the accounts are permanently deleted”; - “With regard to the email accounts of the two complainants, they were deactivated on February 16, 2023, following the issuance of a disciplinary charge for misconduct (…); therefore, not as a result of the ordinary termination of the employment relationship. The deactivation of the company email accounts was performed manually by the company’s IT department, and their erasure was also carried out manually on April 27, 2023, more than 30 days after the automatic deadline calculated by the system managing the company email accounts in the event of ordinary termination of employment”; - with regard to access to the company accounts, “following several internal reports alleging misconduct by the two complainants, on November 24, 2022, the Lead Independent Director, the Company’s representative (…) consulted, among others, with the Data Protection Officer (…), in order to determine whether to proceed with specific internal investigative activities aimed at verifying the validity of the suspicion of specific and serious unlawful conduct attributable to the two complainants to the detriment of the Company”; - therefore, “it was decided to carry out defensive monitoring in the strict sense exclusively on the two complainants’ corporate email accounts for the purpose of protecting the company’s assets pursuant to Art. “4. Law No. 300 of 1970 (“Defensive Controls”), subject to the definition of the criteria and procedures for action (Annex 4), as well as a balancing test (…)” based on the outcome of which “it was determined that the most appropriate method for achieving the established purposes and best respecting the principle of data minimisation consisted of the gradual extraction of data from the two complainants’ email accounts, limited to filters and keywords identified in advance, and within a limited time frame (…), in order to define the operational scope of the investigation and to restrict it solely to relevant data based on the principles of proportionality and necessity, relevance, fairness, and non-excess”; - “The defensive checks, far from constituting a form of systematic monitoring or Surveillance of work performance, were ordered by the Company after the two complainants had committed the offense—that is, ex post—for the purpose of ascertaining it”; - “The actual retrieval of specific emails from the company server was carried out by assigning XX as the processor pursuant to Art. 28 of the GDPR. XX was instructed by the controller to perform the processing via email dated November 29, 2023 (corrected to 2022). The Company provided the processor with the instructions and criteria to be followed in extracting data from the two complainants’ email accounts (…). XX accessed the data via the company server and only the company email accounts: therefore, no access was made to the company computers used by the two complainants”; - “Neither Piaggio’s ICT department nor XX had access to the content of the extracted emails. (…) The data collected as a result of accessing the two complainants’ corporate email accounts and deemed relevant for the purposes of defensive audits were retained by the Internal Audit department only for the time necessary to conduct the defensive audits and evaluate the related findings (3 months) and were then permanently deleted (…)”. With regard to the failure to respond to the requests to exercise rights submitted by the complainants, which remained unanswered, the Company further stated that: - “the deactivation and closure of the accounts had already been implemented within the scheduled timeframe (accounts deactivated and made inaccessible on February 16, 2023, and permanent erasure of the accounts on April 27, 2023)”; - “given the ongoing litigation with the complainants (…) the response to the aforementioned requests should be handled within the framework of the legal proceedings themselves.” With regard, however, to the procedures and storage periods for messages in transit on company accounts, the Company stated that: - “Email messages are backed up for the entire duration of the employment contract and for an additional 5 (five) years following its termination,” as also documented in the Off-Boarding Guidelines (Appendix 3 to the aforementioned note); - “All Company employees are informed in a clear and transparent manner regarding: (i) the rules, criteria, and procedures for accessing and using the Company’s information system and related data and applications through the Company policy on the proper use of IT tools; (ii) the conditions, procedures, and purpose for which the Company reserves the right to conduct corporate audits of the corporate tools and services made available to employees for the performance of their work on behalf of the Company; (iii) the rules and methodologies aimed at preventing IT-related crimes,” as documented in the “Policies for the Proper Use of Information & Communication Technology Tools.” Before proceeding with its assessment, the Office issued a request to the complainants to verify the applicability, in this specific case, of the provision set forth in Art. 140-bis of the Code, in light of the simultaneous filing of appeals before the judicial authorities. In a communication dated May 3, 2024, the data subjects stated that the appeals filed with the Labor Division of the Court of Pisa concerned solely the challenge to their respective dismissals, with a request for a declaration of nullity or annulment of the dismissal order. 2. The initiation of proceedings for the adoption of corrective and disciplinary measures by the Authority. In light of the foregoing, the Office served notice on the Company of the initiation of sanction proceedings, pursuant to Article 166, paragraph 5, of the Code, for violation of Articles 5, para 1, subparagraphs a) and b), (c) and (e), 6, 12, 13, 17, and 88 of the Regulation, and Art 114 of the Code (note dated September 3, 2024). On October 18, 2024, the Company submitted its defense briefs pursuant to Article 18 of Law No. 689/1981, in which it argued, with regard to the failure to respond to the request to exercise rights, that the requests made by the data subjects did not fall within the scope of Articles 15 et seq. of the Regulation. “In fact, the data subjects did not request the erasure of specific personal data relating to them, nor the cessation of a particular processing operation concerning their data. They therefore did not exercise the right to erasure under Article 17 of the GDPR. The 30-day deadline for responding to the data subject provided for in Article 12 of the GDPR did not, therefore, apply in this case.” In any event, even if one were to assume that the data subjects had requested the erasure of the emails stored on the company server, “Piaggio would not have been able to comply with the request in any case, since the exercise of the right to erasure must be weighed against the adequacy and relevance of the data in relation to the processing purpose.” “In this case, the former employees’ emails constitute crucial evidence in the labor proceedings before the Court of Pisa. The erasure of these emails would therefore have compromised Piaggio’s ability to defend itself in the lawsuit that the former employees had already stated they intended to file by challenging the terminations out of court.” With regard, however, to the management and storage of email logs, the Company noted, as a preliminary matter, that corporate email constitutes “a tool used by the employee to perform their work” and, as such, falls within the scope of application of the second paragraph of Article 4 of the Workers’ Statute. Therefore, considering that “Email is now the primary work tool for all those who perform office work (…), the continuous erasure of emails would prevent these employees from carrying out their duties without disruption (…). Consequently, email must be stored throughout the entire employment relationship without any need for a union agreement.” Given, therefore, that the Company has established, with a view to accountability, a storage period for employees’ email of 5 years following the termination of employment, the Company has argued that this period serves the purpose of protecting the security of corporate information and ensuring business operations, while at the same time allowing the Company “to respond to any disputes and/or requests from the authorities and thus defend itself in court.” Furthermore, as indicated in the document containing the Off-Boarding Guidelines (Exhibit 4 to the defense briefs, p. 2), emails that employees permanently delete from the trash are also deleted from Piaggio’s backup server after one year. As for emails not deleted by employees, the IT Policy (Exhibit 3 to the pleadings) clarifies that all messages composed, sent, or received on the email system that pertain to the performance of work duties are and remain the property of the Company, and that the company email account may be subject to monitoring by the Company. In particular, “Piaggio reserves the right to conduct audits and inspections of ICT Resources for the following purposes: a) for the production, organization, and management of ICT Resources, and the management of Piaggio’s business operations; b) for cybersecurity purposes and to verify the functionality of ICT Resources; c) to ensure the proper use of ICT resources and compliance with applicable regulations, company policies, and the Code of Ethics; d) for internal investigations aimed exclusively at ascertaining unlawful conduct by the User; e) to assert or defend a right in court” (page 16 of the Policies). With regard to the backup of correspondence in transit on company accounts assigned to employees, the Company specified that this “is completely segregated from other company information and is managed by the provider (…), who has been specifically appointed as the processor” (Exhibit 11 to the briefs), and that “the procedure stipulates that the provider may never access emails except upon specific instruction from Piaggio, provided in accordance with and within the limits of the provisions of privacy regulations and the IT Policy. The Company’s system administrators cannot access the backup except through the provider.” Therefore, in recital, the Company does not use email as a document repository but exclusively as a work tool for its employees. The Company has clarified that it has never accessed employees’ emails after the termination of their employment. In fact, even in the case at hand, “access was granted while the employment relationship was still in effect, in compliance with privacy regulations and only after the Company, in consultation with the DPO, assessed any risks and impacts on the data subjects,” as shown in the DPIA attached to the briefs. While the Company maintains that email storage beyond the termination of employment is a legitimate practice—as it is supported by corporate security needs and causes no harm to the data subjects—it has stated, in its defense briefs, that it has reduced the five-year storage period for email to three months following the termination of employment, “the minimum period necessary for the layoff procedure and to allow the data subject to request access and/or contest any dismissal.” With regard to the alleged violation of Article 4 of Law No. 300/1970, the Company ruled out that “the storage of email beyond the termination of employment may be relevant for the purposes of the aforementioned provision, which concerns the protection of the employee and the possible monitoring of the employee during the employment relationship.” With regard to the storage period for email access logs, the Company noted that, following the publication of the Guidance Document titled “IT Programs and Services for Email Management in the Workplace and the Processing of Metadata,” adopted by the Data Protection Authority on June 6, 2024 (Provision No. 364, Web Doc. No. 10026277), the storage periods were reduced in accordance with the guidelines provided, implementing a new company policy that now requires the erasure of logs every 21 days. Finally, with regard to the violation concerning the lack of information and transparency regarding the processing and storage of email logs and the emails themselves, the Company noted that both the Guidelines on Transparency and the provisions adopted by the Authority in similar circumstances “do not require that the notices to data subjects specify the exact reason for choosing the retention period and, therefore, detail the logical reasoning behind that choice.” Therefore, it considers that it has complied with the transparency obligations set forth in Art. 5(1)(a) and Art. 13 of the Regulation. In any case, “in order to ensure even greater transparency toward its employees regarding the processing of their data, Piaggio has updated its Regulation on the Use of the Internet and Email,” “specifying the automatic backup cycle interval (i.e., 8 hours), explaining that if an email is permanently deleted within the 8-hour interval, it will not be included in the backup and will no longer be recoverable,” and that if an email is permanently deleted from the user’s trash folder “it will also be deleted from the company’s backup one year after erasure.” On December 6, 2024, a hearing was held with the Company, during which the points already extensively argued in the defense briefs were reiterated. 3. The outcome of the preliminary investigation and the proceedings for the adoption of corrective and sanctioning measures pursuant to Art 58, para 2, of the Regulation. Following an examination of the statements made by the party during the proceedings, as well as the documentation obtained, it has been established that the Company, identified as the controller pursuant to Article 4(7) of the Regulation, carried out processing operations that did not comply with the regulations governing data protection. In this regard, it should be noted that, unless the act constitutes a more serious offense, any person who, in proceedings before the Data Protection Authority, falsely declares or attests to facts or circumstances, or produces false documents or records, shall be liable pursuant to Art. 168 of the Code, “False Statements to the Data Protection Authority and Interruption of the Performance of the Authority’s Duties or the Exercise of Its Powers.” 3.1. Violation of Articles 12(3) and 17 of the Regulation. First, it has been established that the complainants requested confirmation from the Company, on two separate occasions, that their individual corporate email accounts had been deactivated following the termination of their employment. These requests were motivated by the need to know the status of the aforementioned accounts, having discovered that the Company had accessed them to obtain emails in order to bring disciplinary charges against them. The initial requests were therefore made as part of the appeals against the terminations (in letters dated April 23, 2023), while subsequent requests were resubmitted on May 31, 2023, with an explicit warning that any continued activation of the accounts following the termination of employment could constitute a “clear, extremely serious, and unjustified (further) violation of privacy.” This implies, on the one hand, that the requests—although they did not contain explicit references to the provisions of the Regulation regarding the exercise of rights—must in any case be interpreted in light of the applicable provisions on the processing of personal data, precisely in light of the violations arising from the continued processing of personal data related to the complainants’ email accounts. Furthermore, in light of the clarifications provided by the EDPB in Guidelines 1/2022 on data subject rights, dated March 28, 2023, “The controller may not, therefore, refuse to provide the data by citing the failure to specify the legal basis for the request, in particular the lack of a specific reference to the right of access or to the GDPR,” especially considering that “the GDPR does not impose any requirements on data subjects regarding the form of an access request for personal data” (see, in this regard, para 3.1.1, point 50, and para 3.1.2, point 52 of the aforementioned Guidelines). On the other hand, it must be noted that, contrary to the party’s contention, requests concerning the deactivation of individualized company email accounts fall fully within the scope of the rights granted to data subjects under Articles 15 et seq. of the Regulation. This is because the individualized corporate email address (i.e., one assigned to a specific employee), as well as the content of the emails in the account, constitute personal data relating to the employee in question. In particular, communications passing through an individualized account are inevitably attributable to the personal data of the account holder. Therefore, as the Authority has consistently recognized in its decisions, a request to deactivate a personalized account (whether or not accompanied by a request for erasure of the emails contained therein) amounts to a request to cease all processing activities that have been carried out up to that point, on the data subject’s personal data (see, among the most recent, Decision No. 427 of July 17, 2025, web doc. No. 10182762; Order No. 754 of December 18, 2025, Web Doc. No. 10213574; Order No. 82 of February 12, 2026, Web Doc. No. 10230220). In the case at hand, among other things, the requests submitted by the data subjects were aimed exclusively at confirming the erasure of the individualized corporate accounts and not at the deletion of the emails that had been obtained by the Company through its investigative activities. It follows, therefore, that the Company’s argument is unfounded—namely, that in any event, the request for erasure could not be granted because it would have restricted the legitimate exercise of the right to defense in the proceedings following the challenge to the terminations; a right of defense that was based precisely on the use, in court, of the correspondence exchanged by the complainants through their company email accounts. However, with regard to limitations on the data subject rights, Article 2-undecies of the Code, in accordance with the provisions of Article 23 of the Regulation, provides that “The rights referred to in Articles 15 through 22 of the Regulation may not be exercised by submitting a request to the controller or by filing a complaint pursuant to Article 77 of the Regulation if the exercise of such rights could result in actual and concrete harm: […] e) to the conduct of defense investigations or the exercise of a right in court.” In such cases, “The exercise of those rights may […] be delayed, restricted, or excluded by means of a reasoned notification provided without delay to the data subject, unless such notification would undermine the purpose of the restriction, for as long and to the extent that this constitutes a necessary and proportionate measure, taking into account the data subject rights and legitimate interests of the data subject.” Furthermore, pursuant to Article 12(4) of the Regulation, “if the controller does not comply with the data subject’s request, the controller shall inform the data subject without undue delay, and at the latest within one month of receiving the request, of the reasons for the failure to comply and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.” Therefore, in light of the foregoing and, above all, the provisions of the Regulation, the Company’s violation of the provision set forth in Art 12, para 3, in conjunction with Art 17 of the Regulation, must be confirmed. 3.2. Violation of Articles 5(1)(a), (b), (c), and (e), 88 of the Regulation, and 114 of the Code. It has been established that the Company accessed the complainants’ email accounts during the course of their employment and that it acquired and collected “at least 18 emails in total (…) that passed through the complainant’s company email account during the period from November 2020 to January 2022” and “as many as 94 emails in total that passed through the complainant’s company email account,” starting in April 2020. According to the Company’s statements during the preliminary investigation, this activity was carried out in order to “verify the validity of the suspicion of specific and serious unlawful conduct attributable to the two complainants to the detriment of the Company” (note dated January 17, 2024) and, therefore, as part of so-called “defensive audits,” which were conducted after identifying criteria and procedures and performing a balancing test (Exhibit 5 to the note dated January 17, 2024, and Exhibit 2 to the defense briefs dated October 18, 2024). In any case, the Company considered this monitoring activity to be legitimate, as it is provided for and regulated in its internal documents for the pursuit of various purposes (including that of “internal investigations aimed exclusively at ascertaining unlawful conduct by the User”—IT Policy, para. 9.3), as it was carried out in compliance with the principles governing data protection, as well as the prohibition on monitoring work activities set forth in Art. 4 of Law No. 300/1970. With regard to the investigation of the two complainants’ individual email accounts, carried out by the Company as part of so-called “defensive monitoring” and aimed at retrieving emails that would provide evidence of unlawful conduct, given that it is not within the Authority’s purview to rule on the so-called “theory of defensive monitoring,” which is a purely jurisprudential construct and, moreover, subject to inconsistent application (see, on this subject, Decision No. 137 of April 15, 2021, web doc. No. 9670738, Decision No. 409 of December 1, 2022, Web Doc. No. 9833530), reference is made to the principle reaffirmed in various judicial rulings, according to which “with regard to so-called ‘defensive systems,’ even after the amendment of Article 4 of the Workers’ Statute by Article 23 of Legislative Decree No. 151 of 2015, monitoring—including technological monitoring—implemented by the employer to protect assets unrelated to the employment relationship or to prevent unlawful conduct, in the presence of a well-founded suspicion that an offense has been committed, provided that a proper balance is ensured between the need to protect the company’s interests and assets, related to the freedom of economic initiative, and the essential protections of the employee’s dignity and confidentiality, provided that the monitoring concerns data collected after the suspicion arose” (see Court of Cassation No. 25732 of September 22, 2021; Supreme Court Case No. 18168 of June 26, 2023; Supreme Court Case No. 32283 of December 11, 2025). The decisive factor for the admissibility of the monitoring, according to the Supreme Court’s guidelines, is therefore that the audit be conducted ex post, that is, regarding conduct occurring after the suspicion of wrongdoing arose (on this point, see also Supreme Court Case No. 34092 of November 12, 2021). It is clear that, in the present case, this condition is not met, as it has been established that the data acquired by the Company predate the emergence of suspicion of the alleged offense: in fact, the collection of data relating to the correspondence exchanged by the two complainants was carried out retroactively, going back approximately two years. From the perspective of personal data protection, the monitoring activity carried out by the Company on the two complainants’ email accounts was made possible by the systematic collection and storage of data relating to employees’ email correspondence, which, as provided for in the offboarding guidelines submitted to the court, is backed up for the entire duration of the employment relationship and for up to five years following its termination. As stated by the Company during the preliminary investigation, storage applies not only to email messages but also to the email logs themselves, which are stored for a period of 6 months (note dated January 17, 2024). As for the specific reasons for establishing such an extended period of storage, in the absence of precise indications in the relevant documents regarding the purposes pursued, the Company stated that email is not used as a document repository but exclusively as a work tool for its employees; Meanwhile, the storage of email logs for 6 months was justified by the need to ensure the security of the IT systems (see note dated October 18, 2024). In its defense briefs dated October 18, 2024, the Company reported that, following the initiation of the proceedings, it had made substantial changes to the storage periods for these categories of data. Specifically, the storage period for email data has been reduced from five years to three months following the termination of employment. The Authority notes these changes favorably, while reiterating that access to email archives must be strictly limited to the account holder. Therefore, organizational and technological measures must be adopted to prevent access to the filing system by anyone other than the account holder, unless the account holder explicitly makes a request for access for assistance purposes (see, in this regard, Provision No. 613 of October 9, 2025, web doc. No. 10185435; and Provision No. 153 of February 1, 2018, web doc. No. 8159221). This is because the content of email messages, as well as the external data of the communications (therefore also email logs, including the sender’s and recipient’s email addresses, the IP addresses of the servers or clients involved in routing the message, the times of sending, transmission, or receipt, the message size, the presence of any attachments, and the subject line of the sent or received message) pertain to forms of correspondence protected by guarantees of confidentiality that are also constitutionally safeguarded (Articles 2 and 15 of the Constitution), with respect to which the Data Protection Authority has therefore held that, in both public and private work contexts, there is a legitimate expectation of confidentiality regarding the messages that are the subject of such correspondence (see point 5.2(b) of Provision No. 13 of March 1, 2007, containing Guidelines for Email and the Internet, Web Doc. No. 1387522; and in relation to specific cases, most recently, Provision No. 613 of October 9, 2025, Web Doc. No. 10185435). This also takes into account the case law established by the European Court of Human Rights, according to which the protection of private life extends to the workplace as well, given that it is precisely in the course of carrying out work and/or professional activities that relationships develop in which the employee’s personality is expressed. Given that the boundary between the workplace/professional sphere and the strictly private sphere cannot always be clearly drawn, the Court considers Art 8 of the European Convention on Human Rights—which protects private life without distinguishing between the private and professional spheres—to be applicable (see Niemietz v. Germany, Dec. 16, 1992 (Application No. 13710/88), esp. para. 29; Copland v. the United Kingdom, April 3, 2007 (Application No. 62617/00), see para. 41; Barbulescu v. Romania [GC], September 5, 2017 (Application No. 61496/08), see para. 70–73; Antovi and Mirkovi v. Montenegro, November 28, 2017 (Application No. 70838/13), see para. 41–42). Precisely in light of the principles cited above, the provisions of para 9 cannot be accepted.3. of the Policy, which states that data subjects, in their capacity as Users, “shall have no expectation of confidentiality with respect to any communication, message, file, or material created, stored, received, or sent through ICT Resources, including via personal devices.” This approach is also influenced by the party’s interpretation of the nature of email, which is understood as a “work tool” and, as such, excluded from the scope of application of the enhanced safeguards provided for in Art. 4, paragraph 1, of Law No. 300/1970 (in contrast to the provision in paragraph 2, which states that “the provision in paragraph 1 does not apply to tools used by the employee to perform their work […]”). On this point, the Authority reiterates its position, already expressed in various decisions, according to which the systems and programs that enable the collection, storage, and processing of data derived from the use of email and the internet connection (the latter not at issue in the case in question) are not indispensable for the performance of work and operate entirely independently of the user’s normal activities (i.e., without any impact on or interference with the employee’s work) (on this point, see: Decision No. 613 of October 9, 2025, Web Doc. No. 10185435; Decision No. 384 of October 28, 2021, Web Doc. No. 9722661; Provision No. 190 of May 13, 2021, Web Doc. No. 9669974; Provision No. 479 of November 16, 2017, Web Doc. No. 7355533; see also INL Circulars No. 4/2017 dated July 26, 2017, and No. 2/2016 dated November 7, 2016). With regard to the storage periods for email logs, the Company also stated in the aforementioned defense briefs that, in compliance with the guidelines provided by the Authority in the ruling titled “Guidance Document. IT Programs and Services for Email Management in the Workplace and the Processing of Metadata,” adopted on June 6, 2024 (web doc. No. 10026277), has implemented a new company policy that provides for the erasure of logs every 21 days. We also welcome this further amendment to the company’s policies and the technical and organizational measures implemented, taking into account that, in accordance with the general principle of storage limitation set forth in Article 5, para 1, subparagraph (e) of the Regulation, the controller must identify a timeframe appropriate to the objective of detecting and mitigating any security incidents, promptly adopting the necessary countermeasures. In any case, it remains clear that the processing activities carried out prior to the aforementioned amendments took place without the appropriate basis of lawfulness pursuant to Article 6 of the Regulation, and in violation of the principles of purpose limitation, data minimisation, and storage limitation set forth in Art 5(1)(b), (c), and (e) of the Regulation. Given that the employer, as the controller, may generally process employees’ personal data only if such processing is necessary for the management of the employment relationship itself or if it is necessary to fulfill specific obligations or tasks imposed by applicable sector-specific regulations (see Articles 5(1)(a), 6, and 9 of the Regulation), it has been established in the present case that the processing activities were carried out without a valid basis for the processing that is lawful. Furthermore, it must be considered that the data in question were processed by the Company for a considerable period of time and without predetermined purposes, in violation of the general principle of data minimisation, according to which personal data must be “adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed” (Art 5(1)(c) of the Regulation) and which embodies the principle of proportionality. Finally, it should be noted that, again in the Policy, supplementing the provisions of the Guidelines regarding the management of email following the termination of employment, the Company informs data subjects that, subject to the User’s consent, it is possible to keep the outgoing employee’s email address active for a period not exceeding 30 days by forwarding emails to another email account designated by the User’s supervisor, or to transfer the contents of the email account to another User, for proven service needs. This practice, especially given the extremely vague nature of the “service needs” cited, is contrary to the provisions on personal data protection, as reiterated by the Data Protection Authority on numerous occasions—not only through general provisions (including, among others, the aforementioned Guidelines for Email and the Internet), but also in numerous decisions adopted in relation to specific cases (see Decision No. 758 of December 18, 2025, web doc. No. 10213574; No. 140 of March 7, 2024, web doc. No. 10009004; Decision No. 732 of November 27, 2024, web doc. No. 10101221; Order No. 263 of June 22, 2023, web doc. No. 9920814; Order No. 255 of July 21, 2022, Web Doc. No. 9809466), which emphasize that, to safeguard potential and legitimate business continuity needs, after the termination of the employment relationship, the owner must arrange for the removal of the account, after deactivating it and simultaneously implementing automated systems designed to notify third-party senders and provide them with alternative contact information related to the employee’s professional activities, while also taking appropriate measures to prevent the display of incoming messages during the period in which such automated system is in operation. That said, the Company’s interpretation set forth in its defense briefs cannot be considered correct, as it ruled out that the mere storage of email and logs could constitute a form of monitoring of work activities, given what subsequently occurred in this specific case. In fact, the documentation prepared by the Company (including the aforementioned Policies for the Proper Use of Information and Communication Technology Tools) contains detailed regulations on how to conduct monitoring, which is carried out “periodically” on the use of email, the network, and computers “to verify that their use is balanced and consistent with the company’s activities, and to ensure compliance with applicable regulations, company policies, and the Code of Ethics” (Sections 7.1.2 and 7.1.3 of the Policies). More specifically and in greater detail, in para 9 of the aforementioned Policies, the Company informs data subjects that verification and monitoring activities regarding ICT Resources are carried out for various purposes, including “production, organization, and management of ICT Resources,” “for cybersecurity purposes and to verify the functionality of ICT resources,” as well as “for internal investigations” and “to assert or defend a right in court.” As for the methods by which these controls are implemented, the internal regulations provide for “access to company systems and the extraction of files and/or email messages for investigative and legal defense purposes through the use of search criteria, filters, and/or other e -Discovery tools that ensure confidentiality and proportionality,” “access to company tools via dedicated verification software,” and “monitoring of suspicious behavior and activities” (see IT Policy, para. 9). As part of these controls, the Company even reserves “the right to review files and messages stored in ICT Resources or that have already been deleted” (…), for various purposes, including “to investigate unlawful conduct and to exercise or defend a right in court” (para 9 of the aforementioned Policy). In light of the findings set forth in this ruling, as well as based on the company’s practices documented in the case file, it is therefore considered that the processing activities described above, carried out through the systematic collection and storage of company emails and related logs, were conducted in violation of the principle of lawfulness of processing set forth in Art. 5, para. 1, subparagraph a), of the Regulation. This is because, through the operations described above, the data controller can reconstruct (as in fact occurred) the activities of its employees and exercise control over them, in the absence of the safeguards established within the employment relationship, pursuant to Art. 88 of the Regulation, which refers to the more specific and protective provisions on labor matters set forth in national law. Specifically, Article 114 of the Code (“Guarantees Regarding Remote Monitoring”) identifies the provision set forth in Article 4 of Law No. 300/1970 as a condition for the lawfulness of personal data processing carried out in the context of the employment relationship (in this regard, see certain decisions adopted in connection with specific cases: Decision No. 255 of July 21, 2022, Web Doc. No. 9809466; Decision No. 190 of May 13, 2021, Web Doc. No. 9669974; Decision No. 53 of February 1, 2018, Web Doc. No. 8159221; Order No. 303 of July 13, 2016, Web Doc. No. 5408460). Considering, therefore, that Article 4, paragraph 1, of Law No. 300/1970 strictly defines the purposes (namely, organizational, productive, workplace safety, and protection of company assets) for which such tools—which also enable remote monitoring of employees’ activities—may be used in the workplace, while establishing specific procedural safeguards (trade union agreement or public authorization), it is noted that, in the case at hand, the processing was carried out in violation of the provisions of the law. 3.3. Violation of Articles 5(1)(a) and 13 of the Regulation. It also appears that, starting in 2022, the Company prepared certain informational documents that were produced as part of the preliminary investigation, consisting of the Off-Boarding Guidelines and the Policy for the Proper Use of Information and Communication Technology Tools. However, no clarification was provided regarding previous versions of these documents or the manner in which the two complainants were informed of the processing activities carried out. In this regard, it should be noted that, pursuant to Art. 13 of the Regulation, the notice must instead be provided to data subjects “at the time the personal data are collected.” This approach is consistent with the data controller’s obligation to indicate, in advance and in a transparent manner, the monitoring activities that may be carried out; the purpose of which is to enable the data subject to be fully aware of the types of processing operations that may be carried out by the controller, including by drawing, within a framework of lawfulness and proportionality, on data collected in the course of work activities. In any case, a joint review of these documents—which describe the processing operations carried out, including those involving the IT tools made available to employees by the Company—reveals no indication of the purposes of such processing; more specifically, there is no indication of the purposes and grounds for email storage and related logs. In this regard, the Guidelines on Transparency, adopted on November 29, 2017, by the Article 29 Data Protection Working Party, clarify that “In addition to defining the processing purposes for which personal data are intended, the relevant legal basis invoked pursuant to Article 6 must be specified.” In cases where processing is carried out on the basis of the controller’s legitimate interest, that specific interest “must be identified for the benefit of the data subject. Best practice dictates that the controller may also provide the data subject with information derived from the balancing test, which must be conducted as the legal basis for the processing prior to collecting the data subjects’ personal data in order to rely on Article 6(1)(f).” With regard to the data storage period, this (or the criteria for determining it) “may be dictated by factors such as legal obligations or industry guidelines, but should be specified in a manner that allows the data subject to determine, based on their specific situation, the expected retention period for the specific data or purposes. It is not sufficient for the controller to state in general terms that personal data will be stored for as long as necessary for the legitimate processing purposes. Where relevant, different retention periods should be established for different categories of data and/or processing purposes, including, where applicable, archiving periods.” The “Regulation for the Use of the Internet and Email,” submitted with the defense briefs to supplement the previous Policy, while concisely and sufficiently clearly indicating the storage periods for data related to email and logs, still lacks information regarding the purposes of such processing activities. Therefore, the violation of the provisions of Articles 5(1)(a) and 13 of the Regulation is confirmed, pursuant to which the controller is required to provide the data subject in advance with all information regarding the essential characteristics of the processing. 4. Conclusions: Declaration that the processing is unlawful. Corrective measures pursuant to Art 58(2) of the Regulation. For the reasons set forth above, the Authority considers that the statements made by the controller during the investigation do not address the findings notified by the Office in the notice initiating the proceedings and are therefore insufficient to warrant the dismissal of this proceeding; furthermore, with respect to these aspects, any of the cases provided for in Art. 11 of the Data Protection Authority’s Regulation No. 1/2019. The processing of personal data carried out by Piaggio & C. S.p.A. is unlawful, under the terms set forth above, as it was carried out in violation of Articles 5(1)(a), (b), (c) and (e), 6, 12, 13, 17, and 88 of the Regulation and Art 114 of the Code. The violation ascertained as described in the grounds cannot be considered “minor,” given the nature of the violation, which concerned the general principles of data processing (lawfulness, data minimisation, storage limitation) and the more specific provisions regarding remote monitoring, in addition to the data subject rights. Therefore, in view of the corrective powers conferred by Article 58(2) of the Regulation, the processing of unlawfully collected data is hereby prohibited, and an administrative fine is imposed pursuant to Article 83 of the Regulation, commensurate with the circumstances of the specific case (Article 58(2)(f) and (i) of the Regulation). Finally, it is considered that the conditions set forth in Art. 17 of the Data Protection Authority’s Regulation No. 1/2019 are met. 5. Adoption of the injunction ordering the imposition of the administrative fine and ancillary sanctions (Articles 58(2)(i) and 83 of the Regulation; Article 166(7) of the Code). The outcome of the proceedings shows that Piaggio & C. S.p.A. s.r.l. has violated Articles 5(1)(a), (b), (c), and (e), 6, 12, 13, 17, and 88 of the Regulation, as well as Article 114 of the Code. For the violation of the aforementioned provisions, the administrative fine provided for in Article 83, para 5, subparagraphs (a) and (d) of the Regulation shall be imposed. The Authority, pursuant to Article 58, para 2, subparagraph (i) of the Regulation and Article 166 of the Code, has the power to impose an administrative fine provided for in Article 83 of the Regulation, by issuing an injunction (Article 18. Law No. 689 of November 24, 1981), in connection with the processing of personal data carried out by Piaggio & C. S.p.A., which has been found to be unlawful, as set forth above. Considering that paragraph 3 of Art 83 of the Regulation must be applied, which provides that “If, in relation to the same processing or related processing operations, a controller […] intentionally or negligently infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the most serious infringement,” the total amount of the fine is calculated so as not to exceed the maximum amount provided for in Art. 83(5) of the Regulation. With regard to the factors listed in Art. 83(2) of the Regulation for the purposes of applying the administrative fine and determining its amount, and taking into account that the fine must “in any event [be] effective, proportionate, and dissuasive” (Article 83(1) of the Regulation), it is noted that, in the present case, the following circumstances were taken into account: - with regard to the nature and severity of the violation, the violations committed that concerned the provisions on the exercise of rights, the general principles of processing, and more specific provisions on remote monitoring were considered relevant; in particular, the nature of the processing—which involved the systematic recording and storage of communications sent by employees (vulnerable data subjects) via email and the related logs—was taken into account; - With regard to the duration of the violation, consideration was given to the fact that a response to the request to exercise rights was received only after the Authority had initiated its investigation; while the extended duration of email storage and logs (the entire duration of the employment relationship plus an additional period following its termination) was deemed significant; - with regard to whether the violation was intentional or negligent and the degree of the data controller’s accountability, the Company’s conduct was taken into account, as it generally provided for the storage of data contained in its employees’ emails with the possibility of accessing them for a variety of purposes; - In the Company’s favor, account was taken of the cooperation provided during the proceedings, aimed at remedying the violations found and mitigating their negative effects; in particular, the changes made to its IT systems regarding data storage periods, the adoption of additional technical measures, and the revisions to employee information documents were viewed favorably; - the absence of prior relevant violations committed by the data controller was also taken into account. It is further considered that the following factors are relevant in this case, taking into account the aforementioned principles of effectiveness, proportionality, and deterrence to which the Authority must adhere in determining the amount of the sanction (Art. 83(1) of the Regulation): first, the economic circumstances of the offender, determined on the basis of the Company’s turnover as reported in the financial statements for the year 2025. In light of the above factors and the assessments made, it is deemed appropriate, in this case, to impose on Piaggio & C. S.p.A. an administrative fine in the amount of 460,000.00 (four hundred sixty thousand) euros. In this context, it is also deemed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, this section containing the injunction order must be published on the Data Protection Authority’s website. This is in light of the conduct that was particularly harmful to the data subject’s rights and occurred in violation of the general principles governing the data protection process. NOW THEREFORE, THE DATA PROTECTION AUTHORITY pursuant to Article 57, para 1, subparagraph f), of the Regulation, finds that the processing carried out by Piaggio & C. S.p.A., represented by its current legal representative, with registered office in Pontedera (PI), Viale Rinaldo Piaggio, VAT No. 01551260506, for violating Articles 5(1)(a), (b), (c), and (e), 6, 12, 13, 17, and 88 of the Regulation and Article 114 of the Code; ORDERS the aforementioned Company, pursuant to Art. 58, para. 2, subparagraph f) of the Regulation, to prohibit access to the content of data collected and stored on the company’s systems relating to corporate email; pursuant to Article 58, para 2, subparagraph (i) of the Regulation, the said Company to pay the sum of 460,000.00 euros (four hundred sixty thousand) as an administrative fine for the violations indicated in this order; THEREFORE ORDERS the said Company to pay the aforementioned sum of 460,000.00 euros (four hundred sixty thousand), in accordance with the procedures set forth in the attachment, within 30 days of the service of this order, failing which the necessary enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981. It is noted that, pursuant to Article 166, paragraph 8 of the Code, the offender retains the right to settle the dispute by paying —again in accordance with the procedures set forth in the attachment—of an amount equal to half of the imposed penalty within the time limit specified in Art. 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, provided for the filing of an appeal as indicated below. ORDERS - pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/20129, the publication of this injunction order on the Data Protection Authority’s website; - pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Data Protection Authority’s Regulation No. 1/20129, the publication of this order on the Data Protection Authority’s website; - Pursuant to Article 17 of Regulation No. 1/2019, the recording of the violations and the measures adopted in accordance with Article 58, para 2, of the Regulation in the Authority’s internal register provided for by Article 57, para 1, subparagraph (u), of the Regulation. Pursuant to Article 78 of the Regulation, as well as Article 152 of the Code and Article 10 of Legislative Decree No. 150/2011, an appeal against this decision may be filed with the ordinary courts by submitting a petition to the ordinary court of the location specified in the aforementioned Art 10, within thirty days from the date of notification of the decision, or within sixty days if the appellant resides abroad. Rome, June 18, 2026 THE CHAIRMAN Stanzione THE RAPPORTEUR Ghiglia THE SECRETARY GENERAL Montuori

---
Generated by overview.legal · https://overview.legal/posts/187480 · 2026-08-06
