Alessandro Del Ninno
Conferences
Corporate Policies for the Processing of Employees’ Personal Data: Governance, Technological Controls, and the Management of Digital Work Tools
Practical Workshop organized for Finlombarda S.p.A. - 23 February 2026.
23/02/2026
Corporate Policies for the Processing of Employees’ Personal Data: Governance, Technological Controls, and the Management of Digital Work Tools

Alessandro Del Ninno delivered a presentation at Finlombarda S.p.A. focusing on corporate policies governing the processing of employees’ personal data, with particular attention to the practical implications of the GDPR within organisational and technological environments.

During the session, Attorney Del Ninno outlined the European and national regulatory framework applicable to the processing of employees’ personal data, highlighting the specific position of workers as individuals potentially exposed to risks affecting the effective protection of their rights within the employment relationship. In this context, particular attention was devoted to the legal basis for processing, the limits on the use of consent, the requirements of transparency, proportionality and data minimisation, as well as the role of the Data Protection Impact Assessment (DPIA) in cases involving more intrusive processing operations or systematic monitoring.

The presentation also examined the main rules governing the use of technologies in the workplace, including the monitoring of IT resources, the use of digital work tools and the safeguards that must be ensured in order to protect employees’ rights.

A specific focus was devoted to the management of corporate e-mail systems, emphasising the need to adopt clear and structured internal policies regulating the assignment of e-mail accounts, rules governing their use, the management of technical metadata, the conditions under which access to mailboxes may occur, and the procedures for deactivating accounts upon termination of the employment relationship.

The presentation provided participants with practical guidance for designing corporate policies that are consistent with data protection law, labour law requirements and organisational cybersecurity needs, highlighting the importance of effective coordination between legal, HR and IT functions in the governance of digital workplace technologies.