The Italian authority sanctions a municipality for accessing an employee's mailbox during prolonged absence

The Italian authority sanctions a municipality for accessing an employee's mailbox during prolonged absence, ruling that the employer should have implemented preventive technical and organizational measures to ensure service continuity without infringing on the confidentiality of the employee's correspondence.

Facts and context

The Italian data protection authority (Garante per la protezione dei dati personali - GPDP) has today published a sanction decision against the municipality of Terralba for breaches related to accessing the professional mailbox of an absent employee.

The case originated from a complaint by an employee who, upon returning from a long sick leave, found that the municipality had accessed his computer by changing his password for reasons of service continuity.

Reasons for the decision

The authority found several GDPR violations, considering that the municipality had not implemented the necessary safeguards to protect its employees' data in such a context.

  • Obligation of lawfulness, fairness and transparency (Article 5(1)(a) of the GDPR and Article 6 of the GDPR): The authority ruled that forced access to the employee's mailbox, even motivated by the need to ensure administrative continuity, was unlawful. It recalls that electronic correspondence benefits from confidentiality guarantees, including in the professional context, and that the employer cannot access it outside a predefined and transparent legal framework. The municipality did not demonstrate the existence of a valid legal basis for such intrusion, violating fundamental processing principles.
  • Obligation to implement data protection by design and by default (Article 25 of the GDPR) and accountability of the controller (Article 24 of the GDPR): The authority emphasized that the employer should have implemented technical and organizational measures to manage an employee's absence without accessing their individual mailbox. The existence of shared folders, invoked by the municipality, proved insufficient. The GPDP considered that alternative solutions, such as delegation systems or functional mailboxes, should have been planned from the design stage to ensure business continuity while respecting the rights of data subjects.
  • Obligation to comply with specific rules in the employment context (Article 88 of the GDPR): The authority recalled that the processing of employee data must comply with more specific national provisions protecting the dignity, legitimate interests, and fundamental rights of workers. In this case, access to the mailbox was deemed non-compliant with these safeguards, notably those provided by Article 113 of the Italian Data Protection Code, which prohibits collecting data irrelevant to professional activity.

Authority's decision

Consequently, the authority imposed a fine on the municipality of Terralba. The amount is not specified in the excerpt of the decision.

Lessons learned

This decision reminds that:

  • The necessity to ensure business continuity does not constitute a sufficient legal basis to justify indiscriminate access to an absent employee's mailbox.
  • Employers must implement, from the design stage, organizational and technical measures (such as absence management policies, functional mailboxes, or clear delegation systems) to avoid accessing individual employee accounts.
  • Prior and transparent information to employees about the conditions and modalities of any potential access to their professional tools is an essential condition for the lawfulness of such processing.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire