Alessandro Del Ninno
News
Italian Data Protection Authority: corporate emails and defensive controls; Piaggio fined €460,000 for the systematic retention of employees’ emails.
DATA PROTECTION
29/07/2026

The Italian Data Protection Authority has fined Piaggio & C. S.p.A. €460,000, ruling that the processing of data relating to employees’ work emails was unlawful and prohibiting the company from accessing the content collected and stored on its systems. The investigation, launched following complaints from two former employees, established that the company had accessed a total of 112 emails — 18 relating to a female employee and 94 to a male employee — to verify the validity of suspicions regarding alleged unlawful conduct. The search had also been carried out on communications dating back approximately two years before the suspicion arose and had involved messages passing through company email accounts and, in some cases, correspondence with personal accounts and third parties.

The Data Protection Authority referred to the case law of the Court of Cassation, according to which technological monitoring aimed at protecting company assets or investigating unlawful conduct may be permitted, where there is a well-founded suspicion, only provided that an appropriate balance is struck with the employee’s dignity and privacy. One point, however, is crucial: defensive monitoring must relate to data acquired after the suspicion arose. It cannot therefore be used to legitimise retrospective searches of a large volume of communications systematically collected before concrete evidence of a possible offence emerged. In the case under consideration, the search had instead been extended backwards to approximately two years prior.

The establishment of an internal procedure, keywords, search filters or a balancing test is therefore not, in itself, sufficient to render access to email lawful. It must first be verified that the data were collected and stored lawfully and that the monitoring complies with the temporal and substantive limits established by employment law and case law. The investigation was made possible by a system that provided for the backup of emails for the entire duration of the employment relationship and for up to five years after its termination, in addition to the retention of email logs for six months. According to the Data Protection Authority, the systematic collection of emails and metadata over such extended periods made it possible to reconstruct employees’ activities and enabled remote monitoring in the absence of the safeguards provided for in Article 4 of the Workers’ Statute, as referred to in Article 114 of the Privacy Code. The processing was therefore deemed to be contrary to the principles of lawfulness, purpose limitation, data minimisation and storage limitation set out in the GDPR. The Authority also reiterated that email archives must be protected by organisational and technological measures that prevent access by anyone other than the account holder, unless the holder expressly requests access for support purposes.

Further infringements concerned transparency. The company’s policies did not specify with sufficient precision the purposes and legal grounds for retaining emails and the associated logs. Merely indicating the retention periods is not sufficient: employees must be informed in advance and in a comprehensible manner about the reasons for the processing, the legal bases and the specific procedures for any checks.

Furthermore, the company had failed to respond to requests from former employees seeking confirmation that their individual accounts had been deactivated. The Data Protection Authority clarified that such a request constitutes the exercise of rights recognised by the GDPR, even when the data subject does not expressly refer to a specific legal provision.

The ruling requires companies to review not only their email access procedures, but the entire architecture for the collection and retention of data generated by work tools.

The decision confirms that retrospective monitoring cannot remedy the prior, blanket and disproportionate collection of correspondence. For businesses, the management of corporate email must be designed from the outset in accordance with the principles of data minimisation, privacy by design and accountability, avoiding the creation of archives that allow for the indiscriminate reconstruction of work activity.