The Italian data protection authority (Garante) has fined Piaggio & C. S.p.A. €460,000 over its handling of two former employees' company email. The decision is relevant under many aspects discussed by the authority in terms of GDPR rights management and employee monitoring, in particular in case of suspected misconduct. Two elements are very important because almost always complicated to manage for businesses: when an employee's request to have their company mailbox deactivated counts as exercising a GDPR right, and how long email backups may be kept.
The Case in Short
Two employees were dismissed by the company and, in order to build the disciplinary charges, the company accessed their individual company mailboxes and extracted around 112 messages in total. In this case, the investigation into the employees' emails was triggered by the suspicion of misconduct, and from that moment the search ran backwards, reaching roughly two years further back.
The company conducted the search with many good practices, such as search criteria and methods defined in advance, a balancing test, extraction limited to pre-identified keywords within a defined time window, the external provider appointed as processor under Art. 28 GDPR, a data protection impact assessment (DPIA), and a segregated backup accessible only through the provider and only on the company's specific instruction.
Apparently, it was not enough in this case for the Italian DPA, which after initiating an investigation decided to fine the company €460,000.
Let's analyse the main issues.
When Asking for Email Account Deactivation Is To Be Seen As Exercising a GDPR Right
The two complainants asked twice for confirmation that their individual company accounts had been deactivated. The company did not reply. To the authority, they explained that, among other reasons, erasure was impossible, because those emails were central evidence in the pending employment litigation.
The Garante rejected all of it, saying that asking for deactivation means asking for processing to stop. The decision states this as settled practice: a request to deactivate an individualised account, whether or not accompanied by a request to erase the emails in it, amounts to a request that all processing carried out on the data subject's personal data up to that point should cease. As abundantly explained in the EDPB guidelines and further case law, the form of the request is irrelevant.
The most useful point for practitioners is what happened next: the defence was lost through silence.
The Italian Privacy Code allows Arts. 15 to 22 GDPR to be delayed, limited or excluded where their exercise would cause actual and concrete prejudice to defensive investigations or to the exercise of a right in judicial proceedings. But it requires a reasoned communication to the data subject, made without delay. Piaggio took the view that the matter belonged inside the litigation already under way and said nothing to the data subjects.
How Long Email Backups and Logs May Be Kept
Piaggio retained mail in backup for the entire duration of the employment relationship plus a further five years after termination, and mailbox access logs for six months. The monitoring was possible precisely because of the systematic collection and retention of employees' email data. Through those operations, the decision reasons, the controller is able to reconstruct its employees' activity and monitor it, without the safeguards required under Art. 88 GDPR, which refers to the more specific and more protective rules laid down in national employment law.
Even if emails are work tools, a systematic collection that enables this level of control of employee activities clearly falls within the scope of labour law limitations on employee monitoring. The systems and programmes that enable the collection, retention and processing of data derived from email use are not indispensable to performing the work, and they operate entirely independently of the user's normal activity. The distinction is between the mail client, which is the work tool, and the backup, logging and e-discovery layer around it, which is not.
Piaggio's IT policy listed internal investigation and asserting or defending a right in court among the purposes of ICT monitoring and reserved to the company the right to review files and messages, including ones already deleted.
During the investigation, email retention periods were cut from five years to three months after termination, and log retention to 21 days, aligning with the Garante's guidance document on email metadata.
The decisive point here is that the retention period was clearly excessive, but more than this it was not properly justified: a long retention period is not defended by declaring it in the IT policies of the company. It is defended by justifying it. And the legitimate interests assessment needs to exist before the collection, not be reconstructed in a defence submission.
Defensive Controls
On investigative monitoring, the Garante applies the test developed by the Italian Supreme Court. That test permits technological controls aimed at protecting interests extraneous to the employment relationship or preventing unlawful conduct, where there is a well-founded suspicion, provided interests are properly balanced and provided the control concerns data acquired after the suspicion arose.
The temporal reference point deserves precision, because it is exactly where the defence failed. Piaggio argued that its controls were ex post because they were ordered after the misconduct had been committed. The Garante's answer is that the decisive moment is the emergence of the suspicion, not of the conduct: the control may only reach data and behaviour postdating the suspicion and cannot operate retroactively. A search reaching two years into the past is not a defensive control. It is retrospective surveillance; made possible by an archive the employer should not have been able to reach.
Conclusion
The company was fined €460,000. Aggravating factors included the nature of the processing, which involved the systematic recording and retention of employees' communications, employees being expressly described in the decision as vulnerable data subjects; the extended retention period; a policy providing as a general matter for retention with access available for a range of purposes; and the fact that a reply to the rights request came only after the authority had opened its file. Piaggio consulted its data protection officer (DPO), ran a balancing test, filtered by keyword, appointed a processor and carried out a DPIA, and was still fined.
This is because an archive kept for five years after termination and reachable by the employer is a monitoring capability whatever the policy calls it, and the permission to run a defensive control opens when the suspicion arises, not when the misconduct occurred, so a search that reaches backwards falls outside it. Stating retention periods without stating their purposes did the rest.
Which points to another lesson to be learned: bring in your DPO or privacy counsel when retention and access to the mail archive are being designed, before the first search in any internal investigation rather than after the material is gathered, and as soon as a rights request arrives from a departing employee while litigation is pending. All three are cheap to get right in advance and impossible to repair afterwards.
No comments