Categories: Insights · News

Tag: #dati personali, compliance, Controlli email, dipendenti, GDPR


2 Jan 2023

Employer monitoring: monitoring of employee e-mail metadata unlawful

It is unlawful to monitor the metadata of company e-mails assigned to employees that do not guarantee adequate protection of confidentiality and are carried out in breach of the rules limiting remote monitoring of workers. This was established by the Italian Data Protection Authority (Autorità Garante per la protezione dei dati personali – the Italian ‘DPA’), which, in an Injunction Order of 1 December 2022, imposed a fine of EUR 100,000 on the Lazio Region.

The preliminary investigation

The case arose from a report submitted to the Italian DPA by an independent trade union organisation that complained about the monitoring by the administration, which was the controller, of the e-mails of staff working in the offices of the regional lawyer’s office.

The monitoring, initiated as part of an internal investigation aimed at verifying a suspected disclosure of information protected by official secrecy, turned out to include information on times, recipients, subject matter of communications and size of attachments, the so-called ‘metadata’, of some employees who had been sending messages to a specific trade union. According to the investigation’s findings, it had been possible to monitor this information because, ‘as a matter of practice’ email traffic data were retained ‘for generic IT security purposes for 180 days’ before being permanently deleted.

The Italian DPA’s Order

On the basis of the investigation’s findings, the Italian DPA clarified, among other things, that:

  • in breach of the principles of ‘lawfulness, fairness and transparency’, employees had not been provided with information on the processing of personal data in accordance with Articles 12 and 13 of the GDPR. And, as the Italian DPA noted, the fulfilment of the information obligations ‘constitutes a specific precondition for the lawful use of the data collected through technological tools, by the employer, including for all purposes related to the employment relationship (Article 4, paragraph 3, of Italian Law No 300/1970)’;
  • given that ‘the generalised collection and extensive retention of e-mail metadata […] are not instrumental to the “employee’s work performance”, such data processing may entail an – albeit indirect – remote monitoring of the employees’ activities. Therefore, the employer breached not only the existing data protection legislation but also the regulations on remote monitoring of employees;
  • the processing and monitoring carried out enabled the employer to acquire information on the employees’ private lives or on matters that were not in any way relevant to the assessment of their professional suitability;
  • the processing of the metadata was carried out in breach of principles of data protection law, namely the principles of retention limitation, of data protection by design and by default, as well as of the principle of accountability;
  • the processing of metadata was carried out in the absence of a prior data protection impact assessment.

On the basis of all of the above, the Italian DPA, in addition to ordering payment of the aforementioned administrative sanction, prohibited the employer, the controller, from any further processing operation applied to the (meta)data relating to the use of employees’ e-mails retained for a period exceeding seven days from the date of their collection, ordered the deletion of the data already collected and retained beyond the latter period and also ordered the publication of the order on its institutional website.

Other related insights:

An employer can monitor its employee’s corporate email account

Dismissal for just cause: monitoring the company chat without adequate information is unlawful

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

17 Mar 2026

Equal pay: green light for the decree on pay equality and wage transparency (People are People, 16 marzo 2026 – Claudia Cerbone, Martina De Angeli)

Claudia Cerbone and Martina De Angeli, professionals at the De Luca & Partners firm, author this article dedicated to the draft legislative decree approved last February 5 by…

16 Mar 2026

Illegitimacy of staff leasing due to violation of the principle of temporariness (Top 24 Lavoro, 27 febbraio 2026 – Vittorio De Luca, Alessandra Zilla)

With judgment no. 4493 of December 19, 2025, the Court of Milan addressed the issue of indefinite-term labor supply (so-called staff leasing). In particular, the Court clarified that,…

10 Mar 2026

The transfer of the employee is lawful when there is incompatibility with the company environment (Camera di Commercio Italo-Francese, 10 marzo 2026 – Vittorio De Luca, Silvia Zulato)

With Order No. 4198 of 25 February 2026, the Italian Supreme Court (Court of Cassation) – Labour Section – reaffirmed that a situation of environmental incompatibility may justify…

3 Mar 2026

Employee monitoring: when “bossware” becomes a legal risk (Agenda Digitale, 2 marzo 2026 – Martina De Angeli)

Monitoring workers through digital tools is a rapidly expanding practice, accelerated by the spread of remote work and the digital transformation of companies. Before adopting these systems, however,…

3 Mar 2026

Melismelis signs the campaign for the 50th anniversary of De Luca & Partners

For the historic labor law firm, the agency developed the 50th-anniversary logo and advertising campaign, managed online and offline media planning, and renewed the website’s visual identity. Milan,…

27 Feb 2026

Dismissals: the Corte costituzionale grants broader discretion to judges and greater scope for reinstatement (I Focus del Sole 24 Ore, 26 febbraio 2026 – Vittorio De Luca e Alessandra Zilla)

The regulation of dismissals continues to represent one of the central pillars of Italian labour law, an area of constant tension between freedom of economic initiative and the…