Share This Article
Employee email monitoring can expose companies operating in Italy to heavy GDPR fines, even when it uncovers genuine misconduct.
That is the blunt message of a new decision of the Italian Data Protection Authority which imposed a fine of EUR 460,000. And it does not concern a single business. It reaches anyone operating in Italy.
On paper, the case is a textbook internal investigation. Two employees suspected of serious wrongdoing. The company searches their mailboxes, finds the evidence, dismisses them for just cause. Yet the Garante found the whole exercise unlawful, banned any further access to the data, and issued the fine.
So let’s look at what happened, why the decision is so contested, and what companies should actually do.
The case in a nutshell
Both employees were dismissed for just cause on 2 March 2023. During the relationship, after some internal reports, the company decided to run so-called “defensive controls” on their individual corporate mailboxes.
According to the company, the exercise was carefully built. There was a consultation with the DPO, defined criteria, a balancing test, the appointment of a processor, and an extraction limited to pre-set keywords. Still, the timeframe was wide. Very wide.
The disciplinary charges showed the acquisition of at least 18 emails from one mailbox (November 2020 to January 2022) and 94 emails from the other, going back to April 2020. On top of that, the emails stayed in backup for the entire employment relationship, plus five years after termination. Access logs, six months.
Why the Garante sanctioned employee email monitoring
The Garante found a breach of Articles 5, 6, 12, 13, 17 and 88 GDPR and Article 114 of the Italian Privacy Code. Three points deserve attention.
The “ex post” trap
This is the heart of the decision. The Garante recalls that a defensive control is admissible only on data acquired after the suspicion arises. Here, though, the correspondence collected predated it by almost two years.
In my daily practice, this is the most critical issue. As a rule, misconduct is already complete by the time you start to suspect it. So if you can only look forward, proving the conduct becomes almost impossible. The conclusion reached by the Garante would just expose businesses to much higher risks than breach of data protection rules, also in terms of potential criminal liability for lack of detection of employees’ misconducts.
Email as protected correspondence
The Garante treats the individual mailbox and its content as personal data of the employee, covered by secrecy guarantees of constitutional rank (Articles 2 and 15 of the Constitution) and Convention rank (Article 8 ECHR, from Niemietz to Barbulescu) as if it belonged to employees like their personal email account.
This conclusion ignores that a work email account is a tool provide by the company to enable the working activity where information about the company, including confidential information and trade secrets are contained. It is not a personal account to be used for the private life of an individual and should not be subject the same limitations applicable to it. An appropriate balance between employees’ and employers’ rights should be identified.
The short circuit with the labour courts
And here comes the paradox. On the very same facts, the labour courts took the opposite path, upholding the dismissal and treating the Garante’s reasoning as beside the point.
The real risk I see clients face is exactly this misalignment. On one side, an authority that fines. On the other, courts that value the proof of the wrongdoing. And, in between, the danger that privacy becomes a shield for those who acted in bad faith which is exponentially becoming the case.
The Garante should take a decision that adequately balances privacy rights with business needs. Taking positions that either cannot be implemented or would expose companies to higher risks is inconsistent with the rationale behind data protection legislation that is principle based since it needs to be adjusted to the specific scenarios.
What companies should do
The fine, however, stands. That makes disciplined employee email monitoring a board-level issue, not just an HR detail. Beyond the debate, the decision gives concrete, actionable guidance you can apply now:
- Set short, well-reasoned retention periods, before litigation and not once the proceeding has started.
- Always reply, and within the deadline, to access or deactivation requests. Here, silence became a breach in its own right.
- Scope internal investigations narrowly: suspicion, timeframe, keywords and a documented balancing test.
- Segregate backups and appoint a processor, so no one inside the company roams the archive freely.
- Build off-boarding around account deactivation, with automatic notices to third parties, not indefinite storage of live accounts.
My take
I don’t share the reasoning of the Garante; it protects the worker yet overlooks the balance with the equally legitimate rights of the business.
Full compliance with the Garante’s approach may create a serious risk: no longer being able to challenge employees’ misconduct at all. So where full compliance is not viable, go for a documented, proportionate solution that holds up before both the Authority and the courts.
On a similar topic, you can read the article The Italian Garante Sets (Almost) No Limits to Former Employees’ Email Access.

