Skip to content
Enforcement · Garante per la protezione dei dati personali (Italy) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Italian DPA: vehicle tracking by Liguria Health Agency lawful, information duties met

Original title: Garante per la protezione dei dati personali (Italy) - 382/2026

Summary

Facts — A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller). The data subject was employed by the Ligurian Social and Health Care Agency, however, the organisation was later merged with the controller. According to the data subject, the controller initiated discliplinary proceedings and suspended them based on data collected unlawfully through a tracking system in the company vehicle. The data subject also argued that the controller did not sufficiently inform employees that their location was being tracked through the company vehicles. The DPA received several complaints from other data subjects, and joined the complaints. The controller argued that the geolocation system was a measure to protect its assets, to optimise the management of its vehicles, and to ensure worker safety (e.g. to ensure that an employee followed the route while carrying hazardous materials). The controller argued that it did not process employees’ personal data, as it tracked the vehicles themselves and did not link the vehicle with the employee. Finally, the controller argued that the tracking was in compliance with its workers’ statutes. Holding — The DPA first stated that the controller had complied with its information obligations. Following the collective bargaining agreement, the controller informed data subjects of how their data was going to be processed. In addition, the controller had included a notice on how their location data was processed. Therefore, the DPA did not find a violation of Article 13 GDPR. The DPA found a violation of Article 5(1)(c) GDPR. The DPA found that the controller systematically and continuously monitored employees assigned company vehicles, as they were tracked at very frequent intervals without allowing them to deactivate the tracking. The DPA found this frequent tracking particularly detrimental to data subjects’ rights and freedoms, because the controller was able to access real-time information on vehicle movements. The DPA considered that the controller processed more data than necessary for its purposes, and that it risked processing data related to data subjects’ personal lives. The controller’s need to ensure that hazardous materials are transported safely did not justify continuously monitoring employees, especially because the controller later increased the interval of monitoring to every 15 minutes. Finally, the DPA dismissed the argument that the controller only tracked vehicles and not data subjects. This is because the controller could identify the data subject at any time by checking the logbook inside the vehicles. The DPA also found a violation of Articles 5(1)(a), (b), 6 and 88 GDPR. The DPA stated that a collective bargaining agreement was a necessary but not always sufficient condition for the data processing activities to be lawful. This means that the controller must comply with both labour and data protection legislation. Given the excessive amount of data processed, the DPA found that the controller did not have a legal basis to process this data. The DPA found that the controller also unlawfully further processed the location data of data subjects for disciplinary proceedings, in violation of the principle of purpose limitation. This is because the disciplinary proceedings did not specifically concern the data subject’s movements detected by the tracking system, but rather the data subject’s failure to notify potentially dangerous situations that occurred during the performance of their duties. Finally, the DPA found a violation of Articles 25 and 35 GDPR. The DPA found that the controller failed to choose a less invasive solution during the design phase. Therefore, its processing activities did not meet the requirements of privacy by design and default (Article 25 GDPR). The controller violated Article 35 GDPR by not conducting a data protection impact assessment (DPIA) before processing data subjects’ location data. The controller’s awareness of data protection issues and evidence of introducing measures to protect data subjects was not sufficient to meet this requirement. The DPA fined the controller €6,000. The DPA took into consideration the changes the controller had made during its investigations, including adjusting the interval of tracking vehicles from every 60 seconds to every 15 minutes

How it connects

Full text

[web doc. no. 10259916] Measure of May 28, 2026 Register of Measures No. 382 of May 28, 2026 THE ITALIAN DATA PROTECTION AUTHORITY IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General; CONSIDERING Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter, the "Regulation"); SEEN Legislative Decree 30 June 2003, n. 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code"); CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Data Protection Authority, approved with Resolution No. 98 of 4 April 2019, published in the Official Journal No. 106 of 8 May 2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Data Protection Authority Regulation No. 1/2019"); Having seen the documents in the file; Having seen the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Guarantor No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801; Rapporteur: Professor Ginevra Cerrina Feroni; WHEREAS 1. Introduction. On XX, Mr. XX, employed as a driver at the Ligurian Social Health Authority No. 1, now merged into the Liguria Health Authority, the latter taking over all legal relationships with the former, complained of alleged violations of personal data protection law. He stated that he had been subjected to disciplinary proceedings, which were subsequently resolved with the imposition of suspension on him, based on data acquired by the aforementioned Authority via the satellite tracking system installed in the vehicle. Company license plate XX. The interested party also highlighted that the aforementioned data had been collected in the absence of the lawful conditions set forth in Article 4 of Law No. 300 of May 20, 1970, as well as the necessary information regarding the installation of the aforementioned systems. He also pointed out the failure to display decals inside the vehicle that would have provided evidence of the vehicle's geolocation. According to the above, the interested party, who during the disciplinary proceedings had justified his travels in the aforementioned vehicle by claiming to suffer from specific medical conditions, had submitted, at the Company's request, a medical certificate detailing the medical conditions he suffered, as well as copies of the receipts for the purchase of certain medications on the days to which the disciplinary action related. Similar alleged violations of personal data protection legislation regarding the Company's use of the aforementioned satellite location system were subsequently reported by other employees of the same company. Company, which is why these issues were addressed jointly by the Authority as part of the same overall investigation, as these issues present the same subject matter and the alleged conduct was committed, from a subjective perspective, by the same Company (see Article 10, paragraph 4, of the Guarantor Regulation No. 1/2019). 2. The investigation. As part of the investigation, in a note dated 20th, the Company stated, in particular, that: - "given that the adoption of a geolocation system for company vehicles is a solution adopted by the Company to meet organizational, production, and asset protection needs, in order to optimize the management of the entire company fleet, as well as to ensure worker safety, it is noted that this Local Health Authority has complied with the requirements established by Article 10, paragraph 4, of the Guarantor Regulation No. 1/2019." 4 of the Workers' Statute" (see "minute of agreement between the Local Health Authority 1, the RSU, and the Trade Unions of the Sector […], definitively signed on July 3, 2018 by the RSU […], published in the intranet section dedicated to employees […] together with the Regulations for the use of company vehicles by employees"); - "the Guidelines for the use of GPS on company vehicles were also approved with specific resolution no. 88 of February 8, 2019 […]. This resolution is permanently available to anyone on the ASL1 "Transparent Administration" portal; - the Company "has adopted the main measures indicated by this Privacy Guarantor in the provision issued on October 4, 2011, expressly referenced in the aforementioned union agreement of July 3, 2018, and specifically, a clearly visible notice affixed to all company vehicles indicating the geolocation of the vehicle, including the vehicle [indicated in paragraph 1 of this provision], used in this specific case"; specific photographic documentation has been submitted in this regard; - the Company "tracks only the vehicles and not the personal data of the employees who use the vehicles from time to time; in fact, the vehicles are assigned to the departments to which the employees report, and not to the employees themselves. Consequently, in this case, the vehicle was returned to the employee subsequently and extemporaneously, after the vehicle's logbook, filled out and signed by the driver, had been reviewed. - "The system allows vehicles to be tracked, identifying the route taken by the vehicle, any stops, and their duration." "There is no time interval/frequency according to which the system detects the vehicle's position, as the system continuously monitors its movement." "The system does not allow employees to activate/deactivate the location feature." "Authorized persons have access to the vehicle's geographic location in real time." "The retention period, indicated in the Union Agreement, is 2 years." - In this case, "The disciplinary procedure was initiated following an anonymous phone call [...]. We then proceeded to verify whether the vehicle was actually parked where reported. Further checks were then carried out, again regarding the vehicle's stops, apparently incompatible with the planned route, which had occurred a few days prior to the report. Subsequently, the Department assigned the company car was verified and, finally, the user of the vehicle was identified. At this point, the user was asked for clarification on the stops made. - "The obligation to provide the information [to the data subject in this case] was fulfilled by affixing the geolocation notice to the rear of the vehicle [indicated in paragraph 1 of this provision], as well as by publishing on the company website the Information Notice pursuant to Art. 13 GDPR regarding the location of company vehicles, as per Annex I of the Company Regulations on Data Processing approved with Resolution No. 560/2019." - "No impact assessment pursuant to Art. 35 of the GDPR, as the specific case does not fall within the specific cases of comprehensive systematic assessment of personal aspects as provided for in paragraph 3, letter a, of the aforementioned article, and furthermore, the collection of vehicles cannot be linked to the evaluation of work performance; - regarding the Company's acquisition of the medical certificate indicating the pathologies suffered by the aforementioned data subject and a copy of the receipts for the purchase of certain medications, the Company "simply received, without requesting it, an email from the data subject dated XX at XX o'clock, without any text, and with the subject line "as agreed"; the date and time are subsequent to the hearing held the same day before the UPD. The above is clearly evident from the statements made in the minutes prepared by the UPD for that hearing. However, the report does not indicate any request from the UPD to submit medical documentation. With a note dated 20th, the Office, based on the information acquired, the investigations carried out, and the facts emerging from the investigation, notified the Company, pursuant to Article 166, paragraph 5, of the Code, of the initiation of proceedings for the adoption of the measures referred to in Article 58, paragraph 2, of the Regulation, on the basis that the processing of personal data in question had been carried out in violation of Articles 5, paragraph 1, letters a), b), c), and e), 6, 25, 35, and 88 of the Regulation, and Articles 113 and 114 of the Code. With the same note, the aforementioned data controller was invited to submit written defenses or documents to the Guarantor or to request a hearing with the Authority (Article 166, paragraphs 6 and 7, of the Code, as well as Article 18, (Section 1 of Law No. 689 of November 24, 1981). With a note dated XX, the Company submitted a defense brief, declaring, in particular, that: - "Unlike what was initially reported, following investigations conducted together with the Data Controller […], the vehicle's position is actually recorded every 60 seconds"; - "These vehicles cannot be used outside of the employee's on-duty period"; "Mixed use of the vehicles is not envisaged, as they must be used only for service purposes and, at the end of their service, be relocated to dedicated company parking spaces"; - Following the involvement of its Data Controller, "the standard retention period for the data collected via satellite geolocation in use by the Company […] is actually the default period for the system provided, namely a period of 6 months"; - "Company vehicles are used exclusively for work purposes and never for employees' personal needs, and therefore may not be used by employees outside of working hours or during breaks for personal needs." "During breaks, employees are not authorized to use company vehicles. Before taking their breaks, they must park them, preferably on company premises, clock out, take their break, and then return to work, clocking in and picking up the vehicle if necessary."Under no circumstances may the company car be used for reasons other than those inherent to the performance of ordinary service activities"; "if the driver/employee must make a longer journey, the break is guaranteed either during the journey, with the vehicle stationary, or once the vehicle has reached its destination. Therefore, the vehicle should not deviate from the route established by the service schedule." - In this specific case, "the suspension sanction imposed on the reporting employee was based on the statements made regarding the disputed stops, for untruthful statements made during the hearing and defense, and for failure to notify superiors of potentially dangerous situations that occurred while performing their duties." During the hearing, requested pursuant to Article 166, paragraph 6, of the Code and held on XX, the Company provided specific contextual information and stated, in particular, that: - "The vehicles are used exclusively for institutional purposes, therefore, in the event of breaks, drivers are required to return the vehicle to the Company's local offices; During breaks, it is therefore not possible to geolocate employees, who cannot be in the vehicle. - "In this specific case, in light of the report of the anomalous positioning of a company car in a place inappropriate for ordinary journeys made with company cars, the Company consulted the information contained in the paper logbook located inside the vehicle in question, which lists the date of use of the vehicle, the mileage traveled, the route, and the name and signature of the driver/user, only subsequently cross-referencing it with the information tracked by the computerized platform." In a note dated XX, the Company provided further information, also highlighting the performance of a data protection impact assessment pursuant to Article 35 of the Regulation with regard to the processing of data relating to the geolocation of company vehicles. Finally, it provided further information, particularly regarding the state of implementation of the technical and organizational measures necessary to ensure the overall proportionality of the processing in question, the Company, with a note of the XX, in preliminarily acknowledging that "in light of the Health Reform approved by the Liguria Region with Regional Law no. 18 of 12 December 2025, all Ligurian Health Authorities, including obviously the Ligurian Social Health Authority no. 1 (formerly ASL1), were merged into the new Liguria Health Authority (ATSL) [… which] has therefore assumed the role of Data Controller of the personal data of data subjects, pertaining to the former Ligurian Social Health Authorities (now Local Social Health Areas) Nos. 1, 2, 3, 4, and 5, as well as Liguria Salute. Specifically, the Board stated that: - "it was decided to reprogram the signal's time interval to 15 minutes, instead of the previous 60 seconds." - "the permanent and irreversible deactivation of the function for monitoring the movements of company vehicles geolocated in real time is envisaged." - "the installation of a button that allows the driver to deactivate/reactivate the vehicle's geolocation could compromise the purpose of protecting assets: in fact, the ability to deactivate the device directly from the car would make it impossible to locate the vehicle in the event of, for example, theft with any transported contents. […] It is worth remembering again that company vehicles are used exclusively for work purposes and never for employees' personal needs, and therefore cannot be used by employees outside of working hours or during breaks to meet personal needs. - "In the context of the recent regional healthcare reform mentioned above and the significant reorganization of all company bodies, it has not yet been possible to update the agreements previously entered into by the dissolved companies, pursuant to Article 4 of Law No. 300/1970; However, specific information has been prepared for the trade unions regarding the changes described above, which also improve employee rights and freedoms. 3. Outcome of the investigation. Following the investigation, it has been established that the Company has installed a satellite tracking system for company vehicles, following the signing of a specific collective agreement with the relevant trade union representatives (see the minutes of understanding dated July 3, 2018; see Articles 88 of the Regulation and 114 of the Code, in relation to Article 4 of Law No. 300 of May 20, 1970). Specific information documents have been made available to employees, which include, among other things, information on how to use the aforementioned system and how to carry out checks, including the specification that the data collected through the aforementioned system, which allows individual drivers to be traced, may be used for all purposes related to the employment relationship. including disciplinary measures (see information provided to employees pursuant to Article 13 of the Regulation; see also the "Company Regulations on Data Processing, Correct Use of Technological Work Tools Provided to Company Workers and Related Controls and Video Surveillance" and the "Guidelines for the Use of GPS Devices Installed on Company Vehicles, available on the company intranet website"). Regarding the information aspect, it was also declared on behalf of the Company, with the related assumption of responsibility for the authenticity of the declarations made, also in light of the consequences provided for by Article 168 of the Code, that vehicles subject to geolocation—including the one used in this case by the interested party—are provided with a specific notice informing the interested parties of the fact that a satellite location system is installed on the vehicle (so-called first-level notice). Regarding the fact that the Company allegedly acquired, as part of the disciplinary proceedings initiated against the interested party, documentation indicating the pathologies suffered by the aforementioned interested party and the copy of the receipts relating to the purchase of certain drugs, it is noted that, based on what has been declared, these documents were not the subject of any specific request by the Company but were sent by the interested party in order to justify his behavior in this context, nor does it appear that such information was subsequently used by the Company (see art. 2-decies of the Code; “Guidelines on the processing of personal data of workers for the purposes of managing the employment relationship in the public sector”, of 14 June 2007, published in the Official Journal of 13 July 2007, no. 161, web doc. no. 1417809, spec. point 8.2; see also, lastly, although with reference to different cases, FAQ no. 13 of the Vademecum on oncological oblivion of 9 August 2024, web doc. no. 10044898, available in https://www.gpdp.it/web/guest/home/docweb/-/docweb-display/docweb/10044898, as well as FAQ no. 12 regarding data processing in schools during the health emergency, available at https://www.garanteprivacy.it/temi/coronavirus/faq#scuola). We also acknowledge the Company's statement, after consulting the supplier company as data controller, that the retention period for data processed through the system is 6 months and not 2 years, as initially stated by the Company. Therefore, in this case, no liability arises in relation to this period. However, the documentation in the file also revealed specific instances of non-compliance with personal data protection legislation. It was also established that, in particular, the aforementioned system required the time interval for recording geographic location to be 60 seconds and allowed access to the vehicle's real-time geographic location. It is acknowledged, however, that the Company, following the preliminary investigation, has recently conducted further investigations into the overall proportionality and necessity of the processing, declaring that it has redefined the interval for recording the vehicles' geographic location, currently set at 15 minutes from the previous 60 seconds, and that it has permanently and irreversibly deactivated the real-time vehicle movement monitoring feature (see note of XX). The Company has also declared, from a perspective of accountability (Article 5, paragraph 2, of the Regulation), that "the installation of a button that allows the driver to deactivate/reactivate the vehicle's geolocation could compromise the purposes of protecting assets" (see note of XX), particularly in the event of theft of the vehicle and any transported contents, which in the case of the Company is particularly sensitive and requires special attention. 3.1. The regulations on the protection of personal data in the context of employment. With regard to the processing of personal data in the context of the employment relationship, it is generally noted that the employer may process workers' personal data, including special categories of data (see Article 9, paragraph 1, of the Regulation), when an appropriate legal basis is met, if the processing is necessary for the management of the employment relationship and to fulfill specific obligations or tasks arising from sector-specific regulations, as well as when the processing is "necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller" (Articles 6, paragraphs 1, letters c) and e), 2 and 3; 9, paragraph 2, letter b), and 4; 88 of the Regulation; 2-ter of the Code). The employer must also comply with national regulations, which "include suitable and specific measures to safeguard the human dignity, legitimate interests and fundamental rights of data subjects, in particular with regard to the transparency of processing [...] and the workplace monitoring systems” (Articles 6, paragraph 2, and 88, paragraph 2, of the Regulation). On this point, the Code, confirming the framework prior to the amendments introduced by Legislative Decree no. 101 of 10 August 2018, makes express reference to the national sector provisions that protect the dignity of people in the workplace, with particular reference to possible controls by the employer (Articles 113 “Data collection and relevance” and 114 “Guarantees regarding remote monitoring”). As a result of this reference, and taking into account Article 88, paragraph 2, of the Regulation, compliance with Articles 4 and 8 of Law no. 300 of 20 May 1970, and Article 10 of Legislative Decree no. 297/2003 (in cases where the conditions are met) constitutes a condition for the lawfulness of the processing. The employer, as data controller, is required in any case to comply with the principles of data protection (Articles 5 and 25 of the Regulation). 3.2. General principles of processing and protection of the worker's privacy. With regard to the processing of employee data carried out using vehicle location systems, it is generally noted that the Guarantor, taking into account the sensitivity of the reference context and the specific technologies used, has provided, over time, indications regarding the adoption of organizational and technological measures - related to the specific operating conditions of the systems in question - with numerous provisions, including general ones (see provision of 4 October 2011, no. 370, web doc. no. 1850581; more recently, provision of 16 January 2025, no. 7, web doc. no. 10112287; provision no. 234 of 10 June 2021, web doc. no. 9675440; provision of 19 July 2018, no. 427, web doc. no. 9039945; provision of 29 March 2021, web doc. no. 9675440). 2018, No. 181, web doc. No. 8576577; Decision of March 16, 2017, No. 138, web doc. No. 6275314; Decision of May 24, 2017, No. 247, web doc. No. 6495708). Despite the diversity of the specific cases decided with the aforementioned provisions, in general terms the Garante has applied the principles of data protection, with specific regard to those of lawfulness (also with reference to the provisions on remote monitoring pursuant to Article 4 of Law No. 300 of May 20, 1970, referred to in Article 114 of the Code), transparency, and data minimization, specifically assessing the overall necessity and proportionality of the personal data processing proposed through the use of the aforementioned technological devices in relation to the purposes pursued in each case. In this context, also taking into account the indications coming from the international framework (see Council of Europe, Recommendation of 1 April 2015, CM/Rec(2015)5, spec. princ. 16), the Guarantor has provided the data controllers with indications regarding the technical and organisational measures aimed at protecting the rights of the data subjects, consisting, as far as relevant for the purposes of this provision, in the configuration of the systems in such a way as to: exclude continuous monitoring, allowing the geographical position to be viewed by authorised persons only when strictly necessary with respect to the purposes pursued; allow, as a rule, the deactivation of the device during breaks and outside working hours; carry out, as a rule, the processing by pseudonymising personal data, using non-directly identifying information; Provide for the storage of collected data only when necessary and for retention periods proportionate to the purposes pursued, generally excluding the monitoring of routes taken (see, in this regard, also, the 20th National Labor Inspectorate note containing "operational guidelines for issuing authorizations pursuant to Article 4 of Law No. 300/1970"). With regard to the specific case, the system used by the Company, however, allowed for systematic monitoring of the movements of employees assigned to vehicles, which were detected by the system within very short timeframes (60 seconds). However, it did not allow employees to deactivate the device under certain specific conditions (for example, during breaks or, in any case, in the event of an emergency) or in the presence of the specific functionality that allows real-time access to the vehicle's geographic location, even though there is no concrete evidence of the actual use of this functionality by the designated personnel. In particular, given that the time interval for recording the geographic position of the vehicles and, therefore, of the drivers themselves, was particularly limited (60 seconds), also taking into account the necessary compliance with the regulations governing safe circulation in urban and extra-urban areas as well as the specific traffic conditions on the various routes taken from time to time, it is evident that the system used by the Company allowed the reconstructing of the employees' movements in a substantially continuous manner, giving rise to pervasive processing. Specifically, in light of the numerous measures adopted by the Authority over time and with regard to processing carried out in the workplace, it was clarified that the extremely frequent collection of data relating to the geographic location of the vehicle assigned to the employee, as was the case in this case (60 seconds), conflicts with general principles regarding the protection of personal data (see Decision No. 427 of 19 July 2018, web doc. No. 9039945, regarding the use of vehicles by employees for the collection and transport of special and hazardous substances and waste, which deemed the 120-second time interval for collecting the geographic location disproportionate). The arguments advanced during the investigation regarding the fact that the personnel involved transport hazardous materials or, in any case, organic materials subject to rapid deterioration (such as pharmaceuticals or biological samples) cannot be considered conclusive in this regard. In fact, based on the documentation in the file, it is not possible to identify any actual correlation between stringent monitoring of the driver, with very rapid detection of his geographic location, and the benefits envisaged by the Company in this regard in terms of greater integrity, conservation, and safety of the transported materials. This correlation, however, the Authority deemed to exist in radically different contexts, particularly related to police activities, including local ones, and the need to "manage any critical and emergency situations" (see provision no. 181 of March 29, 2018, web doc. no. 8576577, in relation to a preliminary assessment of the previous regulatory framework). This circumstance is also confirmed by the very fact that, based on the Company's most recent statements, the interval for recording the vehicles' geographic location has been significantly extended, currently set at 15 minutes, with a view to ensuring proportionality, accountability, and the protection of the dignity of the workers involved (see note of XX). The systematic collection of the personal data in question, resulting from the stringent frequency of recording the vehicles' geographic location, in this case was particularly detrimental to the rights and freedoms of employees, as it was specifically associated with the functionality of real-time access to vehicle movements. According to the Company's representations during the investigation, drivers cannot, in fact, use the vehicles for personal needs, outside of working hours, or during breaks for personal needs; It follows that, since breaks are not permitted while performing service on board the vehicle, "during breaks, it is therefore not possible to geolocate employees, who cannot be on the vehicle" (see note of XX; see also note of XX, according to which company vehicles "are not available to employees outside of working hours, or during breaks to attend to personal needs"). Regardless of the impact of these company provisions on the dignity and freedom of the worker, it should be noted in this regard that, although the journeys drivers are ordinarily required to complete are not particularly long, it cannot be absolutely ruled out that employees may take breaks on an ad hoc basis, even while driving the vehicle. This may be necessary in locations outside the Company's local offices, for example, due to particularly urgent reasons, or by causing a deviation from the pre-established route, including due to contingent road conditions. The processing in question, until the measures most recently implemented by the Company to ensure greater proportionality, therefore violated the principle of "data minimization" pursuant to Article 5, paragraph 1, letter c), of the Regulation. This principle requires that only "adequate, relevant, and limited" data be collected and processed, in a proportionate manner, to achieve the intended purposes ("meeting organizational, production, and asset protection needs, in order to optimize the management of the entire company fleet," "ensuring the safety of workers, especially when using the vehicle alone," and "protecting the company's fleet of vehicles from property crimes"). As the Council of Europe has long reiterated, in fact, "the introduction of equipment capable of revealing the location of employees should only occur if it proves necessary to achieve the legitimate aim pursued by the employer; in any case, the use of such equipment should not give rise to the continuous surveillance of the employee. In particular, surveillance should not represent the primary aim, but only an indirect consequence of an act necessary for the protection of production activities, health and safety, or to ensure the effective management of the company or entity. […], the employer should ensure all necessary safeguards for the employees' right to private life and to the protection of personal data" (see Council of Europe, Recommendation of 1 April 2015, CM/Rec(2015)5, spec. princ. 16). Furthermore, as reiterated in numerous similar cases by the Guarantor, the legitimate purposes pursued by the Company through the company fleet's geolocation system cannot justify any form of interference in the private lives of the employees assigned to the vehicles. Rather, these purposes must be met by implementing appropriate technical and organizational measures to prevent the collection of information unnecessary for the pursuit of organizational, security, and corporate asset protection purposes, as such information may, in some cases, also concern employees' non-work-related activities. The boundary line between the work and professional sphere and the strictly private one cannot, in fact, always be drawn clearly nor can the cancellation of any expectation of confidentiality of the interested party in the workplace be envisaged, even where the same - as in the case in question - uses a company resource, which is why the European Court of Human Rights has over time confirmed that the protection of private life (art. 8 of the European Convention on Human Rights) also extends to the workplace, where the personality and relationships of the person who works are expressed (see Judgments of the European Court of Human Rights Niemietz v. Germany, 16.12.1992 (rec. no. 13710/88), esp. para. 29; Copland v. UK, 03.04.2007 (rec. no. 62617/00), esp. para. 41; Barbulescu v. Romania [GC], 5.9.2017 (request no. 61496/08), esp. paras. 70-73 and 80; Antovic and Mirkovic v. Montenegro, 28.11.2017 (request no. 70838/13), esp. paras. 41-42). Therefore, the specific characteristics of the system used and, in particular, the operation of the geolocation functionality, characterized in particular by the described characteristics of pervasiveness and close frequency of collection, gave rise to the processing of data typically falling within the scope of application of Article 113 of the Code (cf. Articles 5, para. 1, letter a), and 6 of the Regulation; see in particular, regarding the interpretation of Articles 8 of Law No. 300 of 20 May 1970 and 10 of Legislative Decree No. 297/2003, regardless of the specific technology used, Supreme Court of Cassation, First Section, judgment no. 18302 of September 19, 2016, which confirmed the ruling no. 308 of July 21, 2011, web doc. no. 1829641). Nor can it be assumed that, starting from the processing design phase or during the selection phase, less invasive technical and organizational solutions for data subjects could not have been chosen, aimed at more effectively implementing data protection principles, particularly data minimization, by integrating the necessary safeguards into the processing in order to meet the requirements of the Regulation, protect the rights of data subjects, and ensure that, by default, only the personal data strictly necessary for the specific processing purposes pursued are processed. Even when using products or services created by third parties, the data controller must, in fact, verify compliance with the principles applicable to data processing, also with the support of the Data Protection Officer, where designated, by adopting, in compliance with the principle of accountability, appropriate technical and organizational measures and providing the necessary documented instructions to the service provider. This is also what was done in this specific case by the Company, which has recently documented that it has taken specific initiatives to ensure greater proportionality of the processing in question to protect the rights and freedoms of employees (see Articles 5, paragraph 2, 24, 25 and 32 of the Regulation). These principles have been consistently recalled by the Guarantor in the workplace context, in general documents as well as in relation to various cases, taking into account the specific characteristics of the different systems used: see, most recently, among many, provision of 29 April 2025, no. 243, web doc. no. 10134221; see Also, most recently, the "Guideline Document. Computer programs and services for managing email in the workplace and processing metadata," adopted with provision no. 364 of June 6, 2024, web doc. no. 10026277, as well as "Interpretative and applicative issues regarding data protection related to the entry into force of Legislative Decree no. 104 of June 27, 2022, regarding transparent and predictable working conditions (the so-called "Transparency Decree")," adopted with provision no. 13 December 2022, web doc. no. 9844960. In this context, the fact that the data acquired via the geolocation system in question do not directly identify the employees using the vehicles, while appreciable from a minimization perspective, cannot be considered sufficient to exclude the data controller's liability. The Company could at any time trace their identity simply by consulting the paper register located inside the vehicles, as indeed occurred in this case. Nor can the aforementioned objections be considered remedied given that, in accordance with industry regulations, the employer has signed a specific collective agreement with the relevant trade union representatives. This agreement constitutes a necessary, but not always sufficient, condition to ensure the overall lawfulness of the processing and compliance with personal data protection principles. The application experience of the Guarantor in recent years, also in light of European case law, has highlighted, in fact, how the regulatory intersection between data protection legislation (Articles 88 of the Regulation and 114, 113 and 171 of the Code) and the national provisions in the sector (Articles 4 and 8 of Law No. 300 of 20 May 1970) constitute autonomous disciplines, each equipped with its own sanctioning system, integrated through cross-references, which regulate the same conduct, as well as being designed to protect distinct and complementary legal assets (one protects the protection of the data subject's personal data, even in the delicate context of work; the other protects "interests of a collective and super-individual nature" attributable to the legal sphere of trade unions and the protection of the dignity of individual workers, in balancing with the legitimate purposes pursued by the employer/data controller - see, among many, Criminal Cassation, III Section, judgment no. 22148/2017). Consequently, the employer must not only comply with the applicable sector legislation but also with the personal data protection regulations (see, in this regard, Court of Justice of the European Union, VIII Section, judgment C-65/23 of 19 December 2024; see also decision no. 135 of 13 March 2025, web doc. no. 10128005, and, most recently, decision no. 410 of 10 July 2025, web doc. no. 10162731). For all the foregoing reasons, and given the characteristics previously associated with the system used by the Company, it is believed that in this case, the collection of detailed information on the activity of the individual monitored vehicles and indirectly on the activity of the drivers to whom the vehicles are entrusted—which occurred, in particular, through the precise detection of the position of the vehicle used at short intervals, with the possibility of monitoring the route taken in real time—gave rise to processing that violates the principles of "data minimization," "data protection by design," and "by default," as well as the more protective national provisions that prohibit employers from collecting data that is not relevant to work-related activities, in violation of Articles 5, paragraph 1, letter c), 25, and 88 of the Regulation and Article 113 of the Code (see Articles 5, paragraph 1, letter a), and 6 of the Regulation). 3.3. Personal data protection impact assessment. In this case, the processing of data relating to the geolocation of personnel using company vehicles was also carried out without a preliminary data protection impact assessment pursuant to Article 35 of the Regulation. In this regard, it should be noted that, in implementing the accountability principle (see Article 5, paragraph 2, of the Regulation), it is the responsibility of the data controller to assess whether the intended processing is likely to pose a high risk to the rights and freedoms of natural persons—due to the technologies used and considering the nature, scope, context, and purposes of the processing—requiring a prior data protection impact assessment (see recital 90 of the Regulation). Taking into account the guidance provided at the European level on this point, it should be noted, in particular, that, contrary to what the Company claims, the processing of data collected via satellite location systems entails specific risks to the rights and freedoms of data subjects in the workplace (Article 35 of the Regulation). Both in consideration of the particular "vulnerability" of data subjects in the workplace context (see recital 75 and art. 88 of the Regulation and the "Guidelines on data protection impact assessment and the criteria for determining whether processing is "likely to result in a high risk" pursuant to Regulation 2016/679", WP 248 of 4 April 2017, which, among the categories of vulnerable data subjects, expressly mention "employees") as well as the fact that in this context the use of systems that may also indirectly involve "systematic monitoring", understood as "processing used to observe, monitor or control data subjects, including data collected through networks" (see criterion no. 3 indicated in the Guidelines, cit., but see also criteria 4 and 7), may present risks - as emerged in the case in question - in terms of possible monitoring of the activity of employees (see arts. 35 and 88, par. 2, of the Regulation; see also provision 11 October 2018, no. 467, web doc. no. 9058979, annex no. 1, which expressly mentions the "processing carried out within the employment relationship using technological systems [...] from which the possibility of remotely monitoring the employees' activities arises"; see also, among others, provision no. 234 of 10 June 2021, web doc. no. 9675440). Acknowledging that the documentation produced by the Company nonetheless demonstrates a focus on data protection and highlights certain measures to protect data subjects, for example in terms of information provision, and that, albeit belatedly, in a note dated 2019, the Company acknowledged having prepared an impact assessment in this regard, it must nevertheless be concluded that, until such a document was prepared, the Company violated Article 35 of the Regulation. Conducting a data protection impact assessment—which, by its very nature, is intended to be documented in a comprehensive and coherent document, also in light of the need to demonstrate compliance with data protection regulations (Article 5, paragraph 2, of the Regulation)—would have allowed the Company to be aware of the specific risks associated with processing through the use of the geolocation system in question and to make more informed, and therefore different, decisions on technical and organizational matters. 3.4. Use of geolocation data of worker drivers for disciplinary purposes. Regarding the use of geolocation data of worker drivers for disciplinary purposes, it is recalled that, starting in 2015, the current regulatory framework allows the data collected pursuant to Article 4, paragraphs 1 and 2, of Law No. 300 of 20 May 1970, to be used by the employer "for all purposes related to the employment relationship" under certain conditions: 1) that the data collection was carried out after proper assessment of the nature of the tool used and, therefore, its applicability to Article 4, paragraph 1 or paragraph 2 of Law No. 300 of 20 May 1970; 300 (in this case, paragraph 1), with the consequent application of the specific legal regime provided by law – ensuring, in particular, with regard to the case of paragraph 1, compliance with the procedural guarantees provided; 2) that "the worker is provided with adequate information on how to use the tools and carry out the checks" (Article 4, paragraph 3, of Law No. 300 of 20 May 1970); 3) that the processing is carried out in compliance with data protection regulations (see Article 4, paragraph 3 of Law No. 300 of 20 May 1970: "in compliance with the provisions of Legislative Decree No. 196 of 30 June 2003"). The aforementioned regulatory framework therefore allows the data controller (employer) to use, in the context of further processing for the purposes of managing the employment relationship, only the information originally collected in compliance with the conditions and limits set forth in Article 300. 4 of Law No. 300 of 20 May 1970, and, more generally, within a framework of overall lawfulness. Specifically, therefore, such subsequent processing operations presuppose—in addition to, where applicable, compliance with the requirements set forth in Article 4, paragraph 1, and the need to provide data subjects with adequate information on the processing the employer reserves the right to perform—the appropriate configuration of the systems so that only necessary operations are performed and only data relevant to the primary purpose for which they were originally processed is collected, in any case respecting the general prohibition imposed on the employer against processing data irrelevant to the performance of the employer's work. In other words, further processing, pursuant to Article 4, paragraph 3, of Law No. 300 of 20 May 1970, 300, is permitted to the employer to the extent that the original collection was lawfully carried out, having regard to the main purpose and in compliance with the general principles of data protection as well as the more specific and more protective provisions to guarantee the dignity and privacy of the worker (see Articles 88 of the Regulation and 113 of the Code; these principles have been reiterated by the Guarantor in numerous provisions, albeit with regard to the use of different technologies in the workplace: see, most recently, provision of 13 March 2025, no. 135, web doc. no. 10128005; see also provision of 11 April 2024, no. 234, web doc. no. 10013356, regarding video surveillance; provision of 13 May 2021, no. 190, web doc. no. 9669974, regarding the collection of the employee's internet browsing data; provision no. 384 of October 28, 2021, web doc. no. 9722661, regarding the collection of call center operator data; provision no. 247 of May 24, 2017, web doc. no. 6495708, point 5.4. and letter e), regarding the geolocation of garbage collection vehicles; see also the aforementioned note from the National Labor Inspectorate of 20th December, especially pages 5 and 6. In this case, however, it appears that the data relating to the location of employees - originally collected and processed through the aforementioned system, with the methods described above and taking into account the settings and configuration of the system itself, in a manner that does not comply with the regulations on the protection of personal data for the aforementioned reasons (in violation of Articles 5, paragraph 1, letter c), 25, 35 and 88 of the Regulation and 113 of the Code; see paragraph 3.2 of this provision) - were subsequently used in the disciplinary proceedings against the interested party, since all the conditions required by law to allow the further lawful use of the data collected "for all purposes related to the employment relationship" were not met (see, in particular, the condition under letter c) mentioned above) and, therefore, did not comply with the requirements and conditions set out in the aforementioned sector legislation in Article 4, paragraph 3, of Law No. 20 May 1970. 300. This is also in light of the data protection system, according to which the data controller may further use, in compliance with the principle of "purpose limitation," only personal data collected lawfully and therefore in the presence of an appropriate legal basis, having previously "satisfied all the requirements for the lawfulness of the original processing" (see Cons. No. 50 and Articles 5, paragraph 1, letter b), and 6, paragraph 4, of the Regulation), and taking into account the principle of the non-usability of personal data collected and processed in violation of the relevant regulations on the processing of personal data (see Article 2-decies of the Code; see, among others, FAQ No. 13 on the subject of oblivion in cancer, web doc. No. 10044898, and FAQ No. 12 available at https://www.garanteprivacy.it/temi/coronavirus/faq#scuola). In this context, it cannot be considered relevant that, according to the Company's statement, the sanction imposed on the employee in this case does not specifically concern the movements detected by the geolocation system, but rather the "untruthful statements made during the hearing and defense" regarding the disputed parking and the "failure to notify superiors of potentially dangerous situations that occurred while performing their duties." However, the documentation in the file shows that the data in question were verified and used in the disciplinary proceedings (see note of XX, where it is stated that "we proceeded [...] to verify whether the vehicle was actually parked where indicated" and that "further checks were then carried out, again relating to the vehicle's parking stops"). In light of the foregoing considerations, it is believed that the processing carried out by the Company for disciplinary purposes in this case also occurred in violation of the principle of "purpose limitation" and in the absence of the conditions and prerequisites established by sector regulations for the lawful use of information previously collected by the employer using technological tools, in violation of Articles 5, paragraph 1, letters a) and b), 6, and 88 of the Regulation and Article 114 of the Code, in relation to Article 4, paragraph 3, of Law No. 300 of 20 May 1970. 4. Conclusions. In light of the above considerations, it is found that the statements made by the data controller during the investigation – the veracity of which may be held accountable pursuant to Article 13 of the Code – are inaccurate. 168 of the Code, although worthy of consideration, do not overcome the concerns notified by the Office with the notice initiating the proceedings and are insufficient to allow the dismissal of this proceeding, since none of the cases provided for by Article 11 of the Guarantor Regulation No. 1/2019 apply. The Office's preliminary assessments are therefore confirmed and the Company's processing of personal data relating to the geolocation of personnel using company vehicles is found to be unlawful, in violation of Articles 5, paragraph 1, letters a), b), c), 6, 25, 35, and 88 of the Regulation, as well as Articles 113 and 114 of the Code. Given that the violation of the aforementioned provisions occurred as a result of a single conduct (the same processing or related processing), Article 83, paragraph 1, applies. 3 of the Regulation, pursuant to which the total amount of the administrative pecuniary sanction does not exceed the amount specified for the most serious violation. Given that, in this case, the most serious violations, relating to Articles 5, 6, and 88 of the Regulation, are subject to the sanction provided for by Article 83, paragraph 5, of the Regulation, as also referred to in Article 166, paragraph 2, of the Code, the total amount of the sanction is to be quantified up to €20,000,000. In this context, considering, in any case, that the conduct has exhausted its effects—given that the Company has finally acknowledged having undertaken specific initiatives regarding the processing in question, in particular by extending the vehicle location tracking interval from 60 seconds to 15 minutes and permanently and irreversibly deactivating the real-time access to vehicle location (see note of XX)—the conditions for adopting further corrective measures pursuant to Article 58, paragraph 2, of the Regulation are not met, given that the processing activity in question currently presents specific characteristics that, with a view to preventing possible detrimental effects on data subjects in the sensitive workplace context, are deemed, given the current state of the measures, to be sufficient overall to ensure their proportionality and to guarantee the rights and freedoms of workers. 5. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letters i) and 83 of the Regulation; Article 166, paragraph 7, of the Code). The Guarantor, pursuant to Articles 58, paragraph 2, letters i) and 83 of the Regulation as well as Article 166 of the Code, has the power to "impose a pecuniary administrative sanction pursuant to Article 83, in addition to the [other] corrective measures referred to in this paragraph, or in place of such measures, depending on the circumstances of each individual case." Within this framework, "the [Garante] Panel shall adopt the injunction order, by which it also orders the application of the additional administrative sanction, its publication, in full or in extract, on the Garante's website pursuant to Article 166, paragraph 7, of the Code" (Article 16, paragraph 1, of the Garante Regulation No. 1/2019). In this regard, taking into account Article 83, paragraph 3, of the Regulation, in this case, violation of the aforementioned provisions is subject to the application of the pecuniary administrative sanction provided for in Article 83, paragraph 5, of the Regulation. The aforementioned administrative fine imposed, based on the circumstances of each individual case, must be determined in amount, taking due account of the factors set forth in Article 83, paragraph 2, of the Regulation. Considering that: - in general, the specific characteristics previously associated with the processing carried out by the Company, as a result of the configuration of the geolocation system for company vehicles, resulted in essentially continuous monitoring of employees; in this case, moreover, the data was used for disciplinary purposes, even though such processing was carried out in a specific work context (Article 83, paragraph 2, letter a), of the Regulation); - the violation is negligent (Article 83, paragraph 2, letter b), of the Regulation); - the processing in question concerns detailed data relating to the movements of company vehicles used by employees, as vulnerable individuals (see Article 83, paragraph 2, letter g), of the Regulation); In this case, the severity of the violation committed by the data controller is considered to be medium (see European Data Protection Board, "Guidelines 4/2022 on the calculation of administrative pecuniary sanctions under the GDPR" of 24 May 2023, point 60). That said, and considering that the data controller is a company that performs social and healthcare functions, it is believed that, for the purposes of quantifying the fine, the following mitigating circumstances should be taken into account: - the company offered full cooperation with the Authority during the investigation, also acknowledging that it has undertaken, in a particularly commendable manner, specific initiatives aimed at ensuring greater proportionality of the processing carried out (Article 83, paragraph 2, letters c) and f), of the Regulation); - there are no previous relevant violations committed by the company (Article 83, paragraph 2, letter e), of the Regulation). Based on the above factors, assessed as a whole, it is deemed appropriate to set a fine of €6,000 (six thousand/00) for violation of Articles 5, paragraph 1, letters a), b), and c), 6, 25, 35, and 88 of the Regulation, as well as Articles 113 and 114 of the Code, as an administrative fine deemed, pursuant to Article 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive. It is also deemed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Italian Data Protection Authority No. 1/2019, this chapter containing the injunction order should be published on the Italian Data Protection Authority's website. This is in consideration of the fact that the specific characteristics previously associated with the processing carried out by the Company have given rise to essentially continuous monitoring of the employees responsible for driving company vehicles, also taking into account that, in this case, the geolocation data of the vehicle used were also used for disciplinary purposes. Finally, it is noted that the conditions set out in Article 17 of Regulation No. 1/2019 are met. NOW CONSIDERING ALL THE ABOVE, THE AUTHORITY declares, pursuant to Article 57, paragraph 1, letter f), of the Regulation, the unlawfulness of the processing carried out by the Company due to violation of Articles 5, paragraph 1, letters a), b), c), 6, 25, 35, and 88 of the Regulation, as well as Articles 113 and 114 of the Code, as set out in the reasons given; ORDER The Liguria Health Authority, represented by its legal representative pro tempore, with registered office at Piazza Della Vittoria, 15 - 16121 Genoa (GE), Tax Code 02421770997, to pay the sum of €6,000 (six thousand/00) as an administrative fine for the violations indicated in the grounds. It is hereby stated that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half the imposed fine; ORDERS The aforementioned Authority, in the event of failure to settle the dispute pursuant to Article 166, paragraph 8, of the Code, to pay the sum of €6,000 (six thousand/00) according to the methods indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981; ORDERS - pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Guarantor Regulation No. 1/2019, the publication of the injunction order on the Guarantor's website; - pursuant to Article 154-bis, paragraph 3 of the Code and Article 37 of the Guarantor Regulation No. 1/2019, the publication of this order on the Authority's website; - pursuant to Article 17 of the Guarantor Regulation No. 1/2019, the recording of violations and measures adopted pursuant to Article 58, paragraph 2 of the Regulation, in the Authority's internal register provided for by Article 57, paragraph 1, letter u) of the Regulation. Pursuant to Articles 78 of the Regulation, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad. Rome, May 28, 2026 THE PRESIDENT Stanzione THE REPORTER Cerrina Feroni THE SECRETARY GENERAL Montuori [web doc. no. 10259916] Measure of May 28, 2026 Register of Measures No. 382 of May 28, 2026 THE ITALIAN DATA PROTECTION AUTHORITY IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General; SEEN Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter, the "Regulation"); SEEN Legislative Decree No. 30 June 2003 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code"); CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Data Protection Authority, approved with Resolution No. 98 of 4 April 2019, published in the Official Journal No. 106 of 8 May 2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Data Protection Authority Regulation No. 1/2019"); Having seen the documents in the file; Having seen the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Guarantor No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801; Rapporteur: Professor Ginevra Cerrina Feroni; WHEREAS 1. Introduction. On XX, Mr. XX, employed as a driver at the Ligurian Social Health Authority No. 1, now merged into the Liguria Health Authority, the latter taking over all legal relationships with the former, complained of alleged violations of personal data protection law. He stated that he had been subjected to disciplinary proceedings, which were subsequently resolved with the imposition of suspension on him, based on data acquired by the aforementioned Authority via the satellite tracking system installed in the vehicle. Company license plate XX. The interested party also highlighted that the aforementioned data was collected without the legal requirements set forth in Article 4 of Law No. 300 of May 20, 1970, as well as the necessary information regarding the installation of the aforementioned systems. He also pointed out the failure to display decals inside the vehicle that would demonstrate the vehicle's geolocation. According to the above, the interested party, who during the disciplinary proceedings justified his travels in the aforementioned vehicle by claiming to suffer from specific medical conditions, submitted, at the Company's request, a medical certificate detailing the medical conditions he suffered, as well as copies of the receipts for the purchase of certain medications on the days to which the disciplinary action related. Similar alleged violations of personal data protection legislation regarding the Company's use of the aforementioned satellite location system were subsequently reported by other employees of the same Company. Therefore, these matters were addressed jointly by the Authority as part of the same overall investigation. These issues had the same subject matter and the alleged conduct was, from a subjective perspective, committed by the same Company (see Article 10, paragraph 4, of the Guarantor Regulation No. 1/2019). 2. The investigation. As part of the investigation, in a note dated XX, the Company stated, in particular, that: - "given that the adoption of a geolocation system for company vehicles is a solution adopted by the Company to meet organizational, production, and asset protection needs, in order to optimize the management of the entire company fleet, as well as to ensure worker safety, it is noted that this Local Health Authority has complied with the requirements set forth in Article 4 of the Workers' Statute" (see "minute of understanding between Local Health Authority 1, the RSU, and the Trade Unions of the Sector [...], definitively signed on July 3, 2018 by the RSU [...], published in the intranet section dedicated to employees [...] together with the Regulations for the use of company vehicles by employees"); - "The Guidelines for the use of GPS on company vehicles were also approved with specific resolution no. 88 of February 8, 2019 [...]. This resolution is permanently available to anyone on the ASL1 "Transparent Administration" portal"; - the Company "has adopted the main measures indicated by this Privacy Guarantor in the provision issued on October 4, 2011, which is expressly referenced in the aforementioned union agreement of July 3, 2018, and specifically, a clearly visible notice affixed to all company vehicles indicating the geolocation of the vehicle, including the vehicle [indicated in paragraph 1 of this provision], used in this specific case"; in this regard, specific photographic documentation has been submitted; - the Company "tracks only the vehicles and not the personal data of the employees who use them from time to time; the vehicles are assigned to the departments to which the employees report, not to the employees themselves. Consequently, in this case, the vehicle was subsequently and extemporaneously assigned to the employee, once the vehicle's logbook, filled out and signed by the driver, had been reviewed." - "the system allows for the tracking of vehicles by identifying the route taken by the vehicle, any stops, and their duration." "there is no time interval/frequency according to which the system detects the vehicle's position, as the system continuously monitors the vehicle's movement." "the system does not allow employees to activate/deactivate the location feature." "authorized persons have the ability to access the vehicle's geographic location in real time." "the retention period, indicated in the Union Agreement, is 2 years." - In this specific case, "the disciplinary procedure was initiated following an anonymous phone call [...]. We then proceeded to verify whether the vehicle had actually been parked where reported. Further checks were then carried out, again regarding the car's stops, apparently incompatible with the planned route, which had occurred a few days prior to the report. We then verified to which Department the company car was assigned and, finally, identified the user of the vehicle. At this point, the user was asked to provide clarification on the stops made." - "The obligation to provide the information [to the data subject in this case] was fulfilled by affixing the geolocation notice to the rear of the vehicle [indicated in paragraph 1 of this provision], as well as by publishing on the company website the Information Notice pursuant to Article 13 of the GDPR regarding the location of company vehicles, as per Annex I of the Company Regulations on Data Processing approved with Resolution No. 560/2019"; - "No impact assessment pursuant to Article 35 of the GDPR was conducted as the specific case does not fall within the specific cases of comprehensive systematic assessment of personal aspects as required by paragraph 3, letter a, of the aforementioned article, and furthermore, the collection of vehicles cannot be linked to the evaluation of work performance"; - Regarding the Company's acquisition of the medical certificate detailing the conditions suffered by the aforementioned interested party and copies of the receipts for the purchase of certain medications, the Company "simply received, without requesting it, an email from the interested party dated XX at XX o'clock, without any text, and with the subject line "as agreed"; the date and time are subsequent to the hearing held the same day before the UPD. The above is clearly evident from the statements made in the minutes prepared by the UPD for that hearing. However, the minutes do not show any request from the UPD to submit medical documentation." With a note dated XX, the Office, based on the information acquired, the investigations carried out, and the facts emerging from the investigation, notified the Company, pursuant to Article 166, paragraph 5, of the Code, of the initiation of the procedure for the adoption of the measures referred to in Article 58, paragraph 1, of the Code. 2 of the Regulation, on the grounds that the processing of personal data in question had been carried out in violation of Articles 5, paragraph 1, letters a), b), c), and e), 6, 25, 35, and 88 of the Regulation and Articles 113 and 114 of the Code. With the same notice, the aforementioned data controller was invited to submit written statements or documents to the Garante or to request a hearing before the Authority (Article 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of 24 November 1981). In a note dated XX, the Company submitted a defense brief, stating, in particular, that: - "Unlike what was initially reported, following investigations conducted together with the Data Controller [...], the vehicle's position is actually recorded every 60 seconds"; - "These vehicles cannot be used outside of the employee's on-duty hours"; "Mixed-use of the vehicles is not permitted, as they must be used only for work purposes and, at the end of their service, be relocated to dedicated company parking spaces"; - Following the involvement of its Data Controller, "the standard retention period for data collected through satellite geolocation in use by the Company [...] is actually the default period for the system provided, i.e., a period of 6 months"; - "Company vehicles are used exclusively for work purposes and never for employees' personal needs, and therefore cannot be used by employees outside of working hours or during breaks for personal reasons." "personal"; "during breaks, the employee is not authorized to use the company vehicle; before taking a break, he or she must park it, preferably on company premises, clock out, take the break, and then return to work, clocking in and possibly reclaiming the vehicle. Under no circumstances may the company car be used for reasons other than those inherent to the performance of ordinary work activities"; "if the driver/employee must make a longer journey, the break is guaranteed either during the journey, with the vehicle stationary, or once the vehicle has reached its destination. Therefore, the vehicle should not deviate from the route established by the service schedule." - In this specific case, "the suspension sanction imposed on the reporting employee was based on the statements made regarding the disputed stops, for untruthful statements made during the hearing and defense, and for failure to notify superiors of potentially dangerous situations that occurred while performing their duties." During the hearing, requested pursuant to Article 166, paragraph 6, of the Code and held on XX, the Company provided specific contextual information and stated, in particular, that: - "The vehicles are used exclusively for institutional purposes, therefore, in the event of breaks, drivers are required to return the vehicle to the Company's local offices; During breaks, it is therefore not possible to geolocate employees, who cannot be in the vehicle. - "In this specific case, in light of the report of the anomalous positioning of a company car in a location inappropriate for ordinary journeys made with company cars, the Company consulted the information contained in the paper logbook located inside the vehicle in question, which lists the date of use of the vehicle, the mileage traveled, the route, and the name and signature of the driver/user. This information was then cross-referenced with the information tracked by the computerized platform." In a note dated 20th December, the Company provided further information, also indicating that a data protection impact assessment was carried out pursuant to Article 35 of the Regulation regarding the processing of data relating to the geolocation of company vehicles. Finally, providing further information, particularly regarding the implementation status of the technical and organizational measures necessary to ensure the overall proportionality of the processing in question, the Company, in a note dated 20th, preliminarily acknowledged that "in light of the Healthcare Reform approved by the Liguria Region with Regional Law No. 18 of 12 December 2025, all Ligurian Healthcare Authorities, including, of course, Ligurian Social Health Authority No. 1 (formerly ASL1), have been merged into the new Ligurian Health Authority (ATSL) [… which] has therefore assumed the role of Data Controller of the personal data of data subjects, pertaining to the former Ligurian Social Health Authorities (now Local Social Health Areas) Nos. 1, 2, 3, 4, and 5, as well as Liguria Salute", stated, specifically, that: - "it was decided to reschedule the signal detection interval to 15 minutes, instead of the previous 60 seconds"; - "the permanent and irreversible deactivation of the functionality for monitoring the movements of company vehicles geolocated in real time has been established"; - "the installation of a button that allows the driver to deactivate/reactivate the vehicle's geolocation could compromise the purpose of protecting assets: in fact, the ability to deactivate the device directly from the vehicle would make it impossible to locate the vehicle in the event, for example, of theft, including any contents transported. […] It is worth remembering again that company vehicles are used exclusively for work purposes and never for the personal needs of employees, and therefore cannot be used by employees outside of working hours or during breaks to fulfill personal needs"; - "In the context of the recent regional healthcare reform mentioned above and the significant reorganization of all corporate bodies, it has not yet been possible to update the agreements previously entered into by the dissolved companies, pursuant to Article 4 of Law No. 300/1970. However, specific information has been prepared for the trade unions regarding the changes described above, which also improve employee rights and freedoms." 3. Outcome of the investigation. Following the investigation, it was established that the Company installed a satellite tracking system for company cars, following the stipulation of a specific collective agreement with the competent trade union representatives (see the minutes of understanding dated 3 July 2018; see Articles 88 of the Regulation and 114 of the Code, in relation to Article 4 of Law No. 300 of 20 May 1970), making specific information documents available to employees, which also contain information on how to use the aforementioned system and how to carry out checks, including the specification that the data collected through the aforementioned system, through which it is possible to trace the individual drivers of the cars, can be used for all purposes related to the employment relationship, including disciplinary purposes (see information provided to employees pursuant to Article 13 of the Regulation; see also the "Company Regulations on Data Processing, Correct Use of Technological Work Tools provided to company employees and related controls and video surveillance" and the "Guidelines for the Use of GPS Devices Installed on Company Vehicles, available on the company intranet website"). Regarding the information aspect, it was also declared on behalf of the Company, with the related assumption of responsibility for the authenticity of the declarations made, also in light of the consequences provided for by Article 168 of the Code, that vehicles subject to geolocation—including the one used in this case by the interested party—are provided with a specific notice to inform interested parties of the fact that a satellite location system is installed on the vehicle (so-called first-level notice). As regards, then, the circumstance that the Company would have acquired, in the context of the disciplinary proceedings initiated against the interested party, also documentation indicating the pathologies suffered by the aforementioned interested party and the copy of the receipts relating to the purchase of certain drugs, it is noted that, based on what has been declared, such documents were not the subject of any specific request by the Company but were sent by the interested party in order to justify his behaviour in this context, nor does it appear that such information was subsequently used by the Company (see art. 2-decies of the Code; “Guidelines on the processing of personal data of workers for the purposes of managing the employment relationship in the public sector”, dated 14 June 2007, published in the Official Journal 13 July 2007, no. 161, web doc. no. 1417809, spec. point 8.2; see also, lastly, albeit with reference to different cases, FAQ no. 13 of Vademecum on cancer oblivion of August 9, 2024, web doc. no. 10044898, available at https://www.gpdp.it/web/guest/home/docweb/-/docweb-display/docweb/10044898, as well as FAQ no. 12 regarding data processing in schools during the health emergency, available at https://www.garanteprivacy.it/temi/coronavirus/faq#scuola). We also acknowledge the Company's statement, after consulting the supplier company as data controller, that the retention period for data processed through the system is 6 months and not 2 years, as initially stated by the Company. Therefore, in this case, no liability arises in relation to this situation. However, the documents in the file also revealed specific instances of non-compliance with personal data protection legislation. It was also established that, in particular, the aforementioned system required a 60-second time interval for geographic location detection and allowed access to the vehicle's geographic location in real time. It is acknowledged, however, that the Company, following the investigation, has recently conducted further investigations into the overall proportionality and necessity of the processing, declaring that it has recalculated the vehicle geographic location detection interval, now set at 15 minutes instead of the previous 60 seconds, and has also permanently and irreversibly deactivated the real-time vehicle location monitoring feature (see note of XX). The Company has also stated, from a responsibility perspective (Article 5, paragraph 2, of the Regulation), that "the installation of a button that allows the driver to deactivate/reactivate the vehicle's geolocation could compromise the purpose of protecting assets" (see note XX), particularly in the event of theft of the vehicle and any contents transported, which in the Company's case is particularly sensitive and requires special attention. 3.1. Regulations regarding the protection of personal data in the workplace. With regard to the processing of personal data in the context of the employment relationship, it is generally noted that the employer may process employees' personal data, including special categories of data (see Article 9, paragraph 1, of the Regulation), when an appropriate legal basis is met, if the processing is necessary for the management of the employment relationship and to fulfill specific obligations or tasks arising from sector-specific regulations, as well as when the processing is "necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller" (Articles 6, paragraphs 1, letters c) and e), 2 and 3; 9, paragraph 2, letter b), and 4; Article 88 of the Regulation; Article 2-ter of the Code). The employer must also comply with national regulations, which "include appropriate and specific measures to safeguard the human dignity, legitimate interests and fundamental rights of data subjects, in particular with regard to transparency of processing […] and workplace monitoring systems" (Articles 6, paragraph 2, and 88, paragraph 2, of the Regulation). On this point, the Code, confirming the framework prior to the amendments introduced by Legislative Decree no. 101 of 10 August 2018, expressly refers to the relevant national provisions that protect the dignity of individuals in the workplace, with particular reference to possible controls by the employer (Articles 113 "Data collection and relevance" and 114 "Safeguards regarding remote monitoring"). As a result of this reference, and taking into account Article 88, paragraph 2, of the Regulation, compliance with Articles 4 and 8 of Law no. 101 of 20 May 1970 is mandatory. 300, and Article 10 of Legislative Decree No. 297/2003 (where applicable) constitutes a condition for the lawfulness of processing. The employer, as data controller, is required in any case to comply with the principles of data protection (Articles 5 and 25 of the Regulation). 3.2. General principles of processing and protection of the worker's privacy. With regard to the processing of employee data carried out using vehicle location systems, it is generally noted that the Guarantor, taking into account the sensitivity of the reference context and the specific technologies used, has provided, over time, indications regarding the adoption of organizational and technological measures - related to the specific operating conditions of the systems in question - with numerous provisions, including general ones (see provision of 4 October 2011, no. 370, web doc. no. 1850581; more recently, provision of 16 January 2025, no. 7, web doc. no. 10112287; provision no. 234 of 10 June 2021, web doc. no. 9675440; provision of 19 July 2018, no. 427, web doc. no. 9039945; provision of 29 March 2021, web doc. no. 9675440). 2018, no. 181, web doc. no. 8576577; provision of 16 March 2017, no. 138, web doc. no. 6275314; provision of 24 May 2017, no. 247, web doc. no. 6495708). Despite the diversity of specific cases decided with the aforementioned provisions, in general terms the Authority has applied the principles of data protection, with specific regard to those of lawfulness (also with reference to the provisions on remote monitoring pursuant to Article 4 of Law No. 300 of 20 May 1970, referred to in Article 114 of the Code), transparency, and data minimization, specifically assessing the overall necessity and proportionality of the personal data processing proposed through the use of the aforementioned technological devices in relation to the purposes pursued in each case. In this context, also taking into account the indications coming from the international framework (see Council of Europe, Recommendation of 1 April 2015, CM/Rec(2015)5, spec. princ. 16), the Guarantor has provided the data controllers with indications regarding the technical and organisational measures aimed at protecting the rights of the data subjects, consisting, as far as relevant for the purposes of this provision, in the configuration of the systems in such a way as to: exclude continuous monitoring, allowing the geographical position to be viewed by authorised persons only when strictly necessary with respect to the purposes pursued; allow, as a rule, the deactivation of the device during breaks and outside working hours; carry out, as a rule, the processing by pseudonymising personal data, using non-directly identifying information; Provide for the storage of collected data only when necessary and for retention periods proportionate to the purposes pursued, generally excluding the monitoring of routes taken (see, in this regard, also, the 20th National Labor Inspectorate note containing "operational guidelines for issuing authorizations pursuant to Article 4 of Law No. 300/1970"). With regard to the specific case, the system used by the Company, however, allowed for systematic monitoring of the movements of employees assigned to vehicles, which were detected by the system within very short timeframes (60 seconds). However, it did not allow employees to deactivate the device under certain specific conditions (for example, during breaks or, in any case, in the event of an emergency) or in the presence of the specific functionality that allows real-time access to the vehicle's geographic location, even though there is no concrete evidence of the actual use of this functionality by the designated personnel. In particular, given that the time interval for recording the geographic position of the vehicles and, therefore, of the drivers themselves, was particularly limited (60 seconds), also taking into account the necessary compliance with the regulations governing safe circulation in urban and extra-urban areas as well as the specific traffic conditions on the various routes taken from time to time, it is evident that the system used by the Company allowed the reconstructing of the employees' movements in a substantially continuous manner, giving rise to pervasive processing. Specifically, in light of the numerous measures adopted by the Authority over time and with regard to processing carried out in the workplace, it was clarified that the extremely frequent collection of data relating to the geographic location of the vehicle assigned to the employee, as was the case in this case (60 seconds), conflicts with general principles regarding the protection of personal data (see Decision No. 427 of 19 July 2018, web doc. No. 9039945, regarding the use of vehicles by employees for the collection and transport of special and hazardous substances and waste, which deemed the 120-second time interval for collecting the geographic location disproportionate). The arguments advanced during the investigation regarding the fact that the personnel involved transport hazardous materials or, in any case, organic materials subject to rapid deterioration (such as pharmaceuticals or biological samples) cannot be considered conclusive in this regard. In fact, based on the documentation in the file, it is not possible to identify any actual correlation between stringent monitoring of the driver, with very rapid detection of his geographic location, and the benefits envisaged by the Company in this regard in terms of greater integrity, conservation, and safety of the transported materials. This correlation, however, the Authority deemed to exist in radically different contexts, particularly related to police activities, including local ones, and the need to "manage any critical and emergency situations" (see provision no. 181 of March 29, 2018, web doc. no. 8576577, in relation to a preliminary assessment of the previous regulatory framework). This circumstance is also confirmed by the very fact that, based on the Company's most recent statements, the interval for recording the vehicles' geographic location has been significantly extended, currently set at 15 minutes, with a view to ensuring proportionality, accountability, and the protection of the dignity of the workers involved (see note of XX). The systematic collection of the personal data in question, resulting from the stringent frequency of recording the vehicles' geographic location, in this case was particularly detrimental to the rights and freedoms of employees, as it was specifically associated with the functionality of real-time access to vehicle movements. According to the Company's representations during the investigation, drivers cannot, in fact, use the vehicles for personal needs, outside of working hours, or during breaks for personal needs; It follows that, since breaks are not permitted while performing service on board the vehicle, "during breaks, it is therefore not possible to geolocate employees, who cannot be on the vehicle" (see note of XX; see also note of XX, according to which company vehicles "are not available to employees outside of working hours, or during breaks to attend to personal needs"). Regardless of the impact of these company provisions on the dignity and freedom of the worker, it should be noted in this regard that, although the journeys drivers are ordinarily required to complete are not particularly long, it cannot be absolutely ruled out that employees may take breaks on an ad hoc basis, even while driving the vehicle. This may be necessary in locations outside the Company's local offices, for example, due to particularly urgent reasons, or by causing a deviation from the pre-established route, including due to contingent road conditions. The processing in question, until the measures most recently implemented by the Company to ensure greater proportionality, therefore violated the principle of "data minimization" pursuant to Article 5, paragraph 1, letter c), of the Regulation. This principle requires that only "adequate, relevant, and limited" data be collected and processed, in a proportionate manner, to achieve the intended purposes ("meeting organizational, production, and asset protection needs, in order to optimize the management of the entire company fleet," "ensuring the safety of workers, especially when using the vehicle alone," and "protecting the company's fleet of vehicles from property crimes"). As the Council of Europe has long reiterated, "the introduction of equipment capable of revealing the location of employees should only occur if it is necessary to achieve the legitimate aim pursued by the employer; in any case, the use of such equipment should not give rise to the continuous surveillance of the employee. In particular, surveillance should not be the primary purpose, but rather only an indirect consequence of an act necessary to protect production activities, health and safety, or to ensure the effective management of the business or entity. [...], the employer should ensure all necessary safeguards for employees' right to privacy and the protection of personal data" (see Council of Europe, Recommendation of 1 April 2015, CM/Rec(2015)5, esp. prin. 16). Furthermore, as reiterated in numerous similar cases by the Guarantor, the legitimate purposes pursued by the Company through the company fleet's geolocation system cannot justify any form of interference in the private lives of the employees assigned to the vehicles. Rather, these purposes must be met by implementing appropriate technical and organizational measures to prevent the collection of information unnecessary for the pursuit of organizational, security, and corporate asset protection purposes, as such information may, in some cases, also concern employees' non-work-related activities. The boundary line between the work and professional sphere and the strictly private one cannot, in fact, always be drawn clearly nor can the cancellation of any expectation of confidentiality of the interested party in the workplace be envisaged, even where the same - as in the case in question - uses a company resource, which is why the European Court of Human Rights has over time confirmed that the protection of private life (art. 8 of the European Convention on Human Rights) also extends to the workplace, where the personality and relationships of the person who works are expressed (see Judgments of the European Court of Human Rights Niemietz v. Germany, 16.12.1992 (rec. no. 13710/88), esp. para. 29; Copland v. UK, 03.04.2007 (rec. no. 62617/00), esp. para. 41; Barbulescu v. Romania [GC], 5.9.2017 (rec. no. 61496/08), spec. parr. 70-73 and 80; Antovic and Mirkovic v. Montenegro, 28.11. 2017 (rec. no. 70838/13), spec. par. 41-42). Therefore, the specific characteristics of the system used, and in particular the operation of the geolocation functionality, characterized in particular by the described characteristics of pervasiveness and close frequency of data collection, gave rise to the processing of data typically falling within the scope of Article 113 of the Code (cf. Articles 5, paragraph 1, letter a), and 6 of the Regulation; see in particular, regarding the interpretation of Articles 8 of Law No. 300 of 20 May 1970 and 10 of Legislative Decree No. 297/2003, regardless of the specific technology used, Supreme Court of Cassation, First Section, judgment No. 18302 of 19 September 2016, which confirmed Decision No. 308 of 21 July 2011, web doc. No. 1829641). Nor can it be assumed that, starting from the processing design phase or during the selection phase, less invasive technical and organizational solutions for data subjects could not have been chosen, aimed at more effectively implementing data protection principles, particularly data minimization, by integrating the necessary safeguards into the processing to meet the requirements of the Regulation, protect the rights of data subjects, and ensure that, by default, only the personal data strictly necessary for the specific processing purposes are processed. Even when using products or services created by third parties, the data controller must, in fact, verify compliance with the principles applicable to data processing, also with the support of the Data Protection Officer, where designated, by adopting, in compliance with the principle of accountability, appropriate technical and organizational measures and providing the necessary documented instructions to the service provider. This is also what was done in this specific case by the Company, which has recently documented that it has taken specific initiatives to ensure greater proportionality of the processing in question to protect the rights and freedoms of employees (see Articles 5, paragraph 2, 24, 25 and 32 of the Regulation). These principles have been consistently recalled by the Guarantor in the workplace context, in general documents as well as in relation to various cases, taking into account the specific characteristics of the different systems used: see, most recently, among many, provision of 29 April 2025, no. 243, web doc. no. 10134221; see Also, most recently, the "Guideline Document. Computer programs and services for managing email in the workplace and processing metadata," adopted with provision no. 364 of June 6, 2024, web doc. no. 10026277, as well as "Interpretative and applicative issues regarding data protection related to the entry into force of Legislative Decree no. 104 of June 27, 2022, regarding transparent and predictable working conditions (the so-called "Transparency Decree")," adopted with provision no. 13 December 2022, web doc. no. 9844960. In this context, the fact that the data acquired via the geolocation system in question do not directly identify the employees using the vehicles, while appreciable from a minimization perspective, cannot be considered sufficient to exclude the data controller's liability. The Company could at any time trace their identity simply by consulting the paper register located inside the vehicles, as indeed occurred in this case. Nor can the aforementioned objections be considered remedied given that, in accordance with industry regulations, the employer has signed a specific collective agreement with the relevant trade union representatives. This agreement constitutes a necessary, but not always sufficient, condition to ensure the overall lawfulness of the processing and compliance with personal data protection principles. The application experience of the Guarantor in recent years, also in light of European case law, has highlighted, in fact, how the regulatory intersection between data protection legislation (Articles 88 of the Regulation and 114, 113 and 171 of the Code) and the national provisions in the sector (Articles 4 and 8 of Law No. 300 of 20 May 1970) constitute autonomous disciplines, each equipped with its own sanctioning system, integrated through cross-references, which regulate the same conduct, as well as being designed to protect distinct and complementary legal assets (one protects the protection of the data subject's personal data, even in the delicate context of work; the other protects "interests of a collective and super-individual nature" attributable to the legal sphere of trade unions and the protection of the dignity of individual workers, in balancing with the legitimate purposes pursued by the employer/data controller - see, among many, Criminal Cassation, III Section, judgment no. 22148/2017). Consequently, the employer must not only comply with the applicable sector legislation but also with the personal data protection regulations (see, in this regard, Court of Justice of the European Union, VIII Section, judgment C-65/23 of 19 December 2024; see also decision no. 135 of 13 March 2025, web doc. no. 10128005, and, most recently, decision no. 410 of 10 July 2025, web doc. no. 10162731). For all the foregoing reasons, and given the characteristics previously associated with the system used by the Company, it is believed that in this case, the collection of detailed information on the activity of the individual monitored vehicles and indirectly on the activity of the drivers to whom the vehicles are entrusted—which occurred, in particular, through the precise detection of the position of the vehicle used at short intervals, with the possibility of monitoring the route taken in real time—gave rise to processing that violates the principles of "data minimization," "data protection by design," and "by default," as well as the more protective national provisions that prohibit employers from collecting data that is not relevant to work-related activities, in violation of Articles 5, paragraph 1, letter c), 25, and 88 of the Regulation and Article 113 of the Code (see Articles 5, paragraph 1, letter a), and 6 of the Regulation). 3.3. Personal data protection impact assessment. In this case, the processing of data relating to the geolocation of personnel using company vehicles was also carried out without a preliminary data protection impact assessment pursuant to Article 35 of the Regulation. In this regard, it should be noted that, in implementing the accountability principle (see Article 5, paragraph 2, of the Regulation), it is the responsibility of the data controller to assess whether the intended processing is likely to pose a high risk to the rights and freedoms of natural persons—due to the technologies used and considering the nature, scope, context, and purposes of the processing—requiring a prior data protection impact assessment (see recital 90 of the Regulation). Taking into account the guidance provided at the European level on this point, it should be noted, in particular, that, contrary to what the Company claims, the processing of data collected via satellite location systems entails specific risks to the rights and freedoms of data subjects in the workplace (Article 35 of the Regulation). Both in consideration of the particular "vulnerability" of data subjects in the workplace context (see recital 75 and art. 88 of the Regulation and the "Guidelines on data protection impact assessment and the criteria for determining whether processing is "likely to result in a high risk" pursuant to Regulation 2016/679", WP 248 of 4 April 2017, which, among the categories of vulnerable data subjects, expressly mention "employees") as well as the fact that in this context the use of systems that may also indirectly involve "systematic monitoring", understood as "processing used to observe, monitor or control data subjects, including data collected through networks" (see criterion no. 3 indicated in the Guidelines, cit., but see also criteria 4 and 7), may present risks - as emerged in the case in question - in terms of possible monitoring of the activity of employees (see arts. 35 and 88, par. 2, of the Regulation; see also provision 11 October 2018, no. 467, web doc. no. 9058979, attachment no. 1, which expressly mentions "processing carried out within the employment relationship using technological systems [...] which allow for remote monitoring of employees' activities"; see also, among others, provision no. 234 of June 10, 2021, web doc. no. 9675440). While acknowledging that the documentation produced by the Company demonstrates a focus on data protection and highlights certain measures to protect data subjects, for example in terms of information provision, and that, albeit belatedly, with a note dated 2018, the Company acknowledged having prepared an impact assessment in this regard, it must nevertheless be concluded that, until this document was prepared, the Company violated Article 35 of the Regulation. Conducting a data protection impact assessment—which, by its very nature, is intended to be documented in a coherent and coherent document, also in light of the need to demonstrate compliance with data protection regulations (Article 5, paragraph 2, of the Regulation)—would have allowed the Company to be aware of the specific risks associated with processing through the use of the geolocation system in question and to make more informed, and therefore different, technical and organizational decisions. 3.4.The use of geolocation data of worker drivers for disciplinary purposes. Regarding the use of geolocation data of worker drivers for disciplinary purposes, it is recalled that, starting in 2015, the current regulatory framework allows the data collected pursuant to Article 4, paragraphs 1 and 2, of Law No. 300 of 20 May 1970, to be used by the employer "for all purposes related to the employment relationship" under certain conditions: 1) that the data collection was carried out after proper assessment of the nature of the tool used and, therefore, its applicability to Article 4, paragraph 1 or paragraph 2 of Law No. 300 of 20 May 1970; 300 (in this case, paragraph 1), with the consequent application of the specific legal regime provided by law – ensuring, in particular, with regard to the case of paragraph 1, compliance with the procedural guarantees provided; 2) that "the worker is provided with adequate information on how to use the tools and carry out the checks" (Article 4, paragraph 3, of Law No. 300 of 20 May 1970); 3) that the processing is carried out in compliance with data protection regulations (see Article 4, paragraph 3 of Law No. 300 of 20 May 1970: "in compliance with the provisions of Legislative Decree No. 196 of 30 June 2003"). The aforementioned regulatory framework therefore allows the data controller (employer) to use, in the context of further processing for the purposes of managing the employment relationship, only the information originally collected in compliance with the conditions and limits set forth in Article 300. 4 of Law No. 300 of 20 May 1970, and, more generally, within a framework of overall lawfulness. Specifically, therefore, such subsequent processing operations presuppose—in addition to, where applicable, compliance with the requirements set forth in Article 4, paragraph 1, and the need to provide data subjects with adequate information on the processing the employer reserves the right to perform—the appropriate configuration of the systems so that only necessary operations are performed and only data relevant to the primary purpose for which they were originally processed is collected, in any case respecting the general prohibition imposed on the employer against processing data irrelevant to the performance of the employer's work. In other words, further processing, pursuant to Article 4, paragraph 3, of Law No. 300 of 20 May 1970, 300, is permitted to the employer to the extent that the original collection was lawfully carried out, having regard to the main purpose and in compliance with the general principles of data protection as well as the more specific and more protective provisions to guarantee the dignity and privacy of the worker (see Articles 88 of the Regulation and 113 of the Code; these principles have been reiterated by the Guarantor in numerous provisions, albeit with regard to the use of different technologies in the workplace: see, most recently, provision of 13 March 2025, no. 135, web doc. no. 10128005; see also provision of 11 April 2024, no. 234, web doc. no. 10013356, regarding video surveillance; provision of 13 May 2021, no. 190, web doc. no. 9669974, regarding the collection of the employee's internet browsing data; provision no. 384 of October 28, 2021, web doc. no. 9722661, regarding the collection of call center operator data; provision no. 247 of May 24, 2017, web doc. no. 6495708, point 5.4. and letter e), regarding the geolocation of garbage collection vehicles; see also the aforementioned note from the National Labor Inspectorate of 20th December, especially pages 5 and 6. In this case, however, it appears that the data relating to the location of employees - originally collected and processed through the aforementioned system, with the methods described above and taking into account the settings and configuration of the system itself, in a manner that does not comply with the regulations on the protection of personal data for the aforementioned reasons (in violation of Articles 5, paragraph 1, letter c), 25, 35 and 88 of the Regulation and 113 of the Code; see paragraph 3.2 of this provision) - were subsequently used in the disciplinary proceedings against the interested party, since all the conditions required by law to allow the further lawful use of the data collected "for all purposes related to the employment relationship" were not met (see, in particular, the condition under letter c) mentioned above) and, therefore, did not comply with the requirements and conditions set out in the aforementioned sector legislation in Article 4, paragraph 3, of Law No. 20 May 1970. 300. This is also in light of the data protection system, according to which the data controller may further use, in compliance with the principle of "purpose limitation," only personal data collected lawfully and therefore in the presence of an appropriate legal basis, having previously "satisfied all the requirements for the lawfulness of the original processing" (see Cons. No. 50 and Articles 5, paragraph 1, letter b), and 6, paragraph 4, of the Regulation), and taking into account the principle of the non-usability of personal data collected and processed in violation of the relevant regulations on the processing of personal data (see Article 2-decies of the Code; see, among others, FAQ No. 13 on the subject of oblivion in cancer, web doc. No. 10044898, and FAQ No. 12 available at https://www.garanteprivacy.it/temi/coronavirus/faq#scuola). In this context, it cannot be considered relevant that, according to the Company's statement, the sanction imposed on the employee in this case does not specifically concern the movements detected by the geolocation system, but rather the "untruthful statements made during the hearing and defense" regarding the disputed parking and the "failure to notify superiors of potentially dangerous situations that occurred while performing their duties." However, the documentation in the file shows that the data in question were verified and used in the disciplinary proceedings (see note of XX, where it is stated that "we proceeded [...] to verify whether the vehicle was actually parked where indicated" and that "further checks were then carried out, again relating to the vehicle's parking stops"). In light of the foregoing considerations, it is believed that the processing carried out by the Company for disciplinary purposes in this case also occurred in violation of the principle of "purpose limitation" and in the absence of the conditions and prerequisites established by sector regulations for the lawful use of information previously collected by the employer using technological tools, in violation of Articles 5, paragraph 1, letters a) and b), 6, and 88 of the Regulation and Article 114 of the Code, in relation to Article 4, paragraph 3, of Law No. 300 of 20 May 1970. 4. Conclusions. In light of the above considerations, it is found that the statements made by the data controller during the investigation – the veracity of which may be held accountable pursuant to Article 13 of the Code – are inaccurate. 168 of the Code, although worthy of consideration, do not overcome the concerns notified by the Office with the notice initiating the proceedings and are insufficient to allow the dismissal of this proceeding, since none of the cases provided for by Article 11 of the Guarantor Regulation No. 1/2019 apply. The Office's preliminary assessments are therefore confirmed and the Company's processing of personal data relating to the geolocation of personnel using company vehicles is found to be unlawful, in violation of Articles 5, paragraph 1, letters a), b), c), 6, 25, 35, and 88 of the Regulation, as well as Articles 113 and 114 of the Code. Given that the violation of the aforementioned provisions occurred as a result of a single conduct (the same processing or related processing), Article 83, paragraph 1, applies. 3 of the Regulation, pursuant to which the total amount of the administrative pecuniary sanction does not exceed the amount specified for the most serious violation. Given that, in this case, the most serious violations, relating to Articles 5, 6, and 88 of the Regulation, are subject to the sanction provided for by Article 83, paragraph 5, of the Regulation, as also referred to in Article 166, paragraph 2, of the Code, the total amount of the sanction is to be quantified up to €20,000,000. In this context, considering, in any case, that the conduct has exhausted its effects—given that the Company has recently acknowledged having undertaken specific initiatives regarding the processing in question, in particular by extending the vehicle location tracking interval from 60 seconds to 15 minutes and permanently and irreversibly deactivating the real-time access to vehicle location (see note of XX)—the conditions for adopting further corrective measures pursuant to Article 58, paragraph 2, of the Regulation are not met. To date, the processing activity in question exhibits specific characteristics that, with a view to preventing potential detrimental effects on data subjects in the sensitive workplace context, are deemed, given the current state of the measures, to be sufficient overall to ensure their proportionality and to guarantee the rights and freedoms of workers. 5. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letters i) and 83 of the Regulation; Article 166, paragraph 7, of the Code). The Guarantor, pursuant to Articles 58, paragraph 2, letters i) and 83 of the Regulation as well as Article 166 of the Code, has the power to “impose an administrative pecuniary sanction pursuant to Article 83, in addition to the [other] [corrective] measures referred to in this paragraph, or in place of such measures, depending on the circumstances of each individual case” and, in this context, “the [Garante] Board adopts the injunction order, with which it also orders, with regard to the application of the accessory administrative sanction, its publication, in full or in extract, on the Guarantor's website pursuant to Article 166, paragraph 7, of the Code” (Article 16, paragraph 1, of the Guarantor Regulation no. 1/2019). In this regard, taking into account Article 83, paragraph 3, of the Regulation, in this case, violation of the aforementioned provisions is subject to the application of the administrative pecuniary sanction provided for in Article 83, paragraph 5, of the Regulation. The aforementioned administrative pecuniary sanction imposed, depending on the circumstances of each individual case, must be determined in amount, taking due account of the factors set out in Article 83, paragraph 2, of the Regulation. Considering that: - in general, the specific characteristics previously associated with the processing carried out by the Company, as a result of the configuration of the geolocation system for company vehicles, resulted in substantially continuous monitoring of employees; in this case, moreover, the data were used for disciplinary purposes, even though such processing was carried out in a specific work context (Article 83, paragraph 2, letter a), of the Regulation); - the violation is negligent (Article 83, paragraph 2, letter b), of the Regulation); - the processing in question concerns detailed data relating to the travel of company vehicles used by employees, who are vulnerable individuals (see Article 83, paragraph 2, letter g), of the Regulation); In this case, the severity of the violation committed by the data controller is considered medium (see European Data Protection Board, "Guidelines 4/2022 on the calculation of administrative pecuniary sanctions under the GDPR" of May 24, 2023, point 60). That said, and bearing in mind that the data controller is a company that performs social and healthcare functions, it is believed that, for the purposes of quantifying the fine, the following mitigating circumstances should be taken into account: - the Company offered full cooperation with the Authority during the investigation, also acknowledging that it has undertaken, in a particularly commendable manner, specific initiatives aimed at ensuring greater proportionality of the processing carried out (Article 83, paragraph 2, letters c) and f), of the Regulation); - there are no previous relevant violations committed by the Company (Article 83, paragraph 2, letter e), of the Regulation). Given the above factors, assessed as a whole, it is deemed appropriate to determine the amount of the fine at €6,000 (six thousand/00) for the violation of Articles 5, paragraph 1, letter e), and 6,000 (six thousand/00). a), b) and c), 6, 25, 35, and 88 of the Regulation, as well as 113 and 114 of the Code, as an administrative pecuniary sanction deemed, pursuant to Article 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive. It is also believed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Data Protection Authority No. 1/2019, this chapter containing the injunction order should be published on the website of the Data Protection Authority. This is in consideration of the fact that the specific characteristics previously associated with the processing carried out by the Company have given rise to essentially continuous monitoring of the employees responsible for driving company vehicles, also taking into account that, in this case, the geolocation data of the vehicle used were also used for disciplinary purposes. Finally, it is noted that the conditions set forth in Article 83, paragraph 1, of the Regulation are met. 17 of Regulation No. 1/2019. NOW THEREFORE, THE GUARANTOR declares, pursuant to Article 57, paragraph 1, letter f), of the Regulation, the unlawfulness of the processing carried out by the Company due to violation of Articles 5, paragraph 1, letters a), b), c), 6, 25, 35, and 88 of the Regulation, as well as Articles 113 and 114 of the Code, within the terms set out in the reasons for the decision; ORDERS the Liguria Health Authority, represented by its legal representative pro tempore, with registered office at Piazza Della Vittoria, 15 - 16121 Genoa (GE), Tax Code 02421770997, to pay the sum of €6,000 (six thousand/00) as an administrative fine for the violations indicated in the reasons for the decision. It is hereby stated that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half the imposed fine; ORDERS the aforementioned Company, in the event of failure to settle the dispute pursuant to Article 166, paragraph 8, of the Code, to pay the sum of €6,000 (six thousand/00) according to the methods indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981; ORDERS - pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Guarantor No. 1/2019, the publication of the injunction order on the Authority's website; - pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Authority's Regulation No. 1/2019, the publication of this provision on the Authority's website; - pursuant to Article 17 of the Authority's Regulation No. 1/2019, the recording of violations and measures adopted pursuant to Article 58, paragraph 2, of the Regulation, in the Authority's internal register provided for by Article 57, paragraph 1, letter u) of the Regulation. Pursuant to Articles 78 of the Regulation, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be filed before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad. Rome, May 28, 2026 THE PRESIDENT Stanzione THE REPORTER Cerrina Feroni THE SECRETARY GENERAL Montuori

Similar Content