What changes for data controllers after the Italian DPA's decision

Italian Data Protection Authority (Garante) issues key guidance on employee DSARs and workplace data processing

07 August 2026

Publication

Loading...

Listen to our publication

0:00 / 0:00

DSARs, email and remote monitoring: what changes for data controllers after the Italian DPA's decision of 12 March 2026.

By decision no. 165 of 12 March 2026 (doc. web no. 10233328), the Italian Data Protection Authority (the "Garante" or the "Authority") imposed a fine of EUR 50,000 on an insurance company, following a proceeding initiated upon a complaint by a former employee alleging an inadequate response to his data subject access request (DSAR) under Article 15 GDPR. The decision provides guidance of general scope on the handling of DSARs in the employment context, email and backup retention practices, limitations on invoking trade secrets to restrict the right of access, as well as implications regarding remote monitoring and the processing of metadata.

1. The case

The case originated from a former employee's request to access personal documents and folders on his PC and in the individualised corporate email account used during the employment relationship. During several meetings held at the company's premises, the employer allowed the recovery of personal documents from the desktop, but restricted access to the email account: initially for technical reasons, and subsequently by handing over only correspondence deemed "strictly personal" (exchanges with family members, tax certificates, expense reports), while excluding messages relating to professional activities. The former employee then submitted a formal request under Article 15 GDPR, requesting a copy of all emails from 1 March 2021 onwards. The correspondence was eventually delivered, but "stripped of many elements".

The investigation further revealed that, upon termination of the employment relationship, email databases were deactivated and then deleted from online systems within 14 days, but their contents remained stored in the backup system for a period of five years. The company justified this retention period on the grounds that it needed to preserve its information assets in connection with the supervisory activities to which it is subject, taking into account the limitation periods applicable to the insurance sector.

2. Key issues identified by the Garante

All emails on an individualised account constitute personal data

The Garante found that the practice of pre-screening email content to distinguish between "personal" and "work-related" communications and restricting access to the former was contrary to the GDPR. Referring to the case law of the European Court of Human Rights (including Bărbulescu v. Romania [GC], 05/09/2017 and Copland v. UK, 03/04/2007), the Authority clarified that electronic communications exchanged in the workplace fall within the notions of "private life" and "correspondence" under Article 8 ECHR. Therefore, in light of the definitions of "personal data" and "processing" under Article 4 GDPR, communications transiting through an individualised account are inevitably attributable as personal data of the account holder, regardless of whether their content is work-related or personal. Accordingly, employers cannot restrict disclosure by drawing an ex ante distinction between personal and professional emails.

Strict limits on invoking trade secrets.

Article 15(4) GDPR permits controllers to restrict access in order to protect the rights and freedoms of others, including trade secrets and confidential business information (Recital 63). However, the Garante held that such restrictions cannot be based on generic or abstract references to the risk of prejudice. The controller must be able to demonstrate, on the specific facts, that the rights or freedoms of others would actually be harmed by the disclosure of particular communications. In this case, the redaction and anonymisation carried out on the correspondence was held to be unlawful, as the company had failed to produce any factual evidence demonstrating that access could result in serious prejudice to trade secrets. Moreover, the Garante observed that the third-party data contained in the communications had already been known to the data subject during the employment relationship, rendering the redaction unnecessary. This results in a significant increase in the evidentiary burden on controllers seeking to rely on this exception.

3. Email and metadata retention

Email backup: long-term retention is unlawful

The Garante established that the five-year backup of email mailbox contents was not contemplated in any of the information documents provided to employees, resulting in a breach of the principles of fairness and transparency (Article 5(1)(a) GDPR) and of the obligation to provide information (Article 13 GDPR). In this regard, the decision highlights an operationally critical aspect: the company's various information documents contained evident inconsistencies regarding retention periods and purposes. The employee privacy notice generically indicated a ten-year data retention period from the end of the employment relationship; the IT usage rules referred to a retention period that could "vary significantly depending on: purposes, type of data processed, legal obligations"; while the actual backup was five years, justified by the need to preserve information assets in connection with supervisory activities. None of these documents expressly mentioned the backup activity. The retention for such an extended period was also held to be unlawful for breach of the principles of data minimisation, purpose limitation and storage limitation (Article 5(1)(b), (c) and (e) GDPR), being neither necessary nor proportionate. The company's defence that retention in "non-online" mode, without further processing, ensured that the content would not be accessed, was expressly rejected by the Garante: storage is in itself a processing operation within the meaning of Article 4(2) GDPR, irrespective of whether the data are actually accessed. The Garante further reiterated a principle established in its prior decisions (decision no. 732/2024, decision no. 263/2023, decision no. 53/2018): email systems are inherently unsuitable for long-term document retention. Business-critical information must be migrated to dedicated document management systems capable of ensuring authenticity, integrity, reliability, legibility and retrievability. The company was accordingly directed to implement technical and organisational measures that are less intrusive for the privacy of data subjects, thereby avoiding access to the content of communications received on accounts assigned to employees.

Metadata and logs: remote monitoring and sector-specific rules

The decision extended its analysis to Internet browsing logs retained by the company for 12 months, the processing of which was likewise held to be unlawful for breach of the principles of data minimisation and storage limitation. The Garante stressed that both the email backup and the retention of browsing logs are instruments potentially capable of enabling remote monitoring of employee activity, regardless of whether monitoring was actually carried out. The mere provision for the possibility of monitoring in corporate policies and the potential monitoring capability of the tool trigger the obligation to activate the procedural safeguards laid down by Article 4 of Law no. 300/1970 (the Workers' Statute), referred to by Article 114 of the Italian Privacy Code as a condition for lawful processing. In this case, the company had neither verified the existence of the exhaustive purposes specified by the statute, nor activated the required procedure (trade union agreement or authorisation from the Labour Office).

In line with the Guidance Document of 6 June 2024 (doc. web no. 10026277), the retention of email metadata (MTA server logs, sender and recipient email addresses, IP addresses, send/receive timestamps, message size, subject line) should not exceed 21 days for the purposes of the exception under Article 4(2) of Law no. 300/1970 (work tools). Retention for a longer period is only permitted where specific conditions are demonstrated, in application of the accountability principle, and where the period exceeds what is strictly necessary for the operation of the infrastructure, the processing falls within the scope of Article 4(1), with the corresponding procedural safeguards.

4. Fine and corrective measures

The Garante declared the processing unlawful for breach of Articles 5(1)(a), (b), (c) and (e), 12, 13, 15 and 88 GDPR and Article 114 of the Italian Privacy Code, imposing an administrative fine of EUR 50,000. As corrective measures, it ordered the company to: (i) grant the complainant full access to the contents of the correspondence on the individualised corporate email account; (ii) bring its corporate policies and processing activities into compliance with data protection law, within 90 days of notification of the decision. It is worth noting that in an analogous but broader case (decision of 9 October 2025, no. 591, doc. web no. 10185435), the Garante imposed a fine of EUR 500,000, demonstrating the increasingly rigorous enforcement trend in this area.

5. Critical analysis of the decision

While the Garante's interpretive approach is internally consistent, the decision raises aspects that warrant critical reflection from the standpoint of its practical application.

The right of access as an asymmetric document acquisition tool. The premise that every communication transiting through an individualised account constitutes personal data of the account holder is unassailable as a matter of definition. However, the undifferentiated application of this principle in the post-termination context risks transforming the right of access under Article 15 GDPR — whose typical function is to enable the data subject to know which data concerning them are processed and for what purposes — into a tool for the wholesale acquisition of corporate correspondence. Emails with clients, suppliers, colleagues and in-house counsel may contain information whose circulation outside the corporate perimeter creates concrete rather than merely abstract risks, particularly given that the former employee, once in possession of a copy of the mailbox, is subject to confidentiality and non-compete obligations that are difficult to enforce ex post.

Going beyond CJEU case law: access to data vs. access to documents

A further critical aspect concerns the tension between the Garante's approach and the case law of the Court of Justice of the European Union. In its judgment of 4 May 2023, Case C-487/21, F.F. v. Österreichische Datenschutzbehörde and CRIF GmbH, the CJEU clarified that Article 15(3) GDPR confers on the data subject the right to obtain a "faithful and intelligible reproduction of all" personal data undergoing processing. However, the Court drew a fundamental distinction: the term "copy" refers to the personal data, not to the documents as such (paragraph 32). The right to obtain copies of extracts from documents or even entire documents exists only "if the provision of such a copy is essential in order to enable the data subject to exercise effectively the rights conferred on him or her by that regulation, it being necessary to take into account, in that regard, the rights and freedoms of others" (paragraph 45). The Court further specified that, where a conflict arises between the right of access and the rights of third parties, "a balance must be struck between the rights and freedoms at issue" and that "means of communicating personal data that do not infringe the rights or freedoms of others must be chosen" (paragraph 44). In the decision under review, the Garante appears to go beyond this framework, imposing full access to the entire contents of the email mailbox without applying the essentiality test established by the CJEU and without conducting the balancing exercise with the rights of others as required by the Court. The Garante's approach effectively equates access to personal data with access to the entire document (the email) containing them, whereas the CJEU permits such an extension only on a subsidiary and conditional basis. This raises the question whether the obligation to deliver to the former employee a complete copy of all correspondence — including communications of predominantly corporate content — is consistent with the principle that the right of access under Article 15 GDPR does not automatically translate into a right to the return of documents, but has as its primary object the personal data contained therein.

The evidentiary burden on the controller

The evidentiary standard imposed by the Garante for invoking the restriction under Article 15(4) GDPR creates a paradox: the controller would need to demonstrate ex ante that the disclosure of a specific communication would cause concrete harm to the rights of others or to trade secrets. Trade and industrial secrets have, by definition, a value that depends on their non-disclosure: it is therefore structurally difficult to prove, communication by communication, that disclosure will produce concrete prejudice without in the process revealing the very information one seeks to protect.

The alternative document retention obligation

The Garante's indication that operational continuity must be ensured through dedicated document management systems — rather than through email backup — presupposes that every organisation is capable of implementing and maintaining a document management system able to intercept, classify and archive all relevant documentation in a timely manner. For most companies, the email system remains in practice the primary document archive for structural, economic and organisational reasons. The imposition of dedicated systems as the only lawful alternative, in the absence of a corresponding legal obligation to archive with the characteristics required by the Authority, raises questions about the proportionality of the prescription relative to the actual organisational capabilities of controllers.

The open questions can thus be reduced to three aspects: (i) the risk that the right of access, applied in an undifferentiated manner to the post-termination context, may become a tool for document acquisition exceeding its typical function; (ii) the evidentiary paradox facing the controller in attempting to demonstrate the concrete prejudice arising from access to communications containing trade secrets; (iii) the proportionality of the obligation to adopt dedicated document management systems in the absence of a corresponding legal requirement. It remains to be seen whether future interventions by the Authority — or a possible judicial review of the decision — will provide more specific guidance on the balance between the right of access and the protection of trade secrets in the particular context of the termination of the employment relationship.

Actions that employers should take. In light of the decision and the established regulatory framework, organisations operating in Italy should consider the following actions:

  1. Review DSAR response frameworks. Implement internal procedures ensuring timely and comprehensive responses, without drawing prior distinctions between personal and work-related emails. Prepare internal guidelines for HR and IT staff on the correct handling of Article 15 GDPR requests, including the involvement of the DPO.

  2. Review email and backup retention practices. Reduce email backup retention periods to the minimum necessary. Eliminate mass and indiscriminate backup of mailbox contents. Adequately document the purposes and legal bases for retention.

  3. Adopt dedicated document management systems. Migrate business-critical information from email to document management systems ensuring authenticity, integrity, reliability, legibility and retrievability, as required by the Garante.

  4. Metadata retention compliance. Verify that email metadata (server logs) are not retained for a period exceeding 21 days, unless specific technical or organisational needs are adequately documented. Where longer retention is required, activate the procedural safeguards under Article 4(1) of Law no. 300/1970, namely prior agreement with the works council or prior authorisation from the Labour Office.

  5. Activate remote monitoring safeguards. Assess whether email backup and browsing log retention are capable, even only potentially, of enabling remote monitoring. If so, activate the procedure required by Article 4(1) of Law no. 300/1970 (trade union agreement or authorisation from the Labour Office).

  6. Update privacy notices and corporate policies. Ensure that privacy notices and IT usage policies accurately reflect actual data retention and processing practices, including retention periods, purposes and legal bases, eliminating discrepancies between the various documents.

  7. Structured "document exit" procedures. Establish a formalised procedure for managing the email account upon termination of the employment relationship, providing for: (i) the data subject's access to their mailbox in the presence of a company representative to recover correspondence; (ii) a review assisted by the DPO and/or in-house counsel of communications containing confidential information, with documentation of the selection criteria applied; (iii) the definitive deletion of residual content within a reasonable timeframe.

  8. Evidentiary risk management. Where the controller intends to rely on the exception under Article 15(4) GDPR to restrict access, prepare specific and concrete documentary evidence of the prejudice arising from disclosure, avoiding generic invocations of trade secrets or harm to the rights and freedoms of third parties.

The full text of the decision is available here.

This document (and any information accessed through links in this document) is provided for information purposes only and does not constitute legal advice. Professional legal advice should be obtained before taking or refraining from any action as a result of the contents of this document.