The Italian authority sanctions a municipality for its processing of email metadata in the professional context

Retention of employees' email metadata, even for a limited period of 21 days, does not fall under the exception of "tools used by the worker" if the purposes go beyond merely ensuring the functioning of the service and aim, for example, at analyzing security incidents. Such processing then requires compliance with procedural safeguards provided by labor law (union agreement or administrative authorization), in accordance with Article 88 of the GDPR and national law.

Facts and context

The Italian Data Protection Authority (GPDP) has today published a sanction decision against the municipality of Chivasso for breaches related to the retention and processing of its employees' email metadata.

The case originated from a complaint by an employee regarding the municipality's internal policy which provided for the logging of email metadata without defining a retention period.

Reasons for the decision

The authority found several breaches against the municipality:

  • Obligation to respect specific rules in the employment context (Article 88 of the GDPR): The authority considered that the generalized collection and retention of email metadata, even for a period of 21 days, could not be qualified as an activity related to a "tool used by the worker to perform their work" within the meaning of national law (Art. 4, paragraph 2, of Law No. 300/1970). Indeed, the purposes declared by the municipality, such as the analysis of security incidents, went beyond the mere necessity to ensure the functioning of the service. Consequently, this processing fell under the general regime of remote control (Art. 4, paragraph 1, of Law No. 300/1970), which imposes specific procedural safeguards (collective agreement or administrative authorization), which were not implemented by the municipality.
  • Obligation of lawfulness of processing (Article 6 of the GDPR): Failure to comply with the safeguards provided by national law regarding employee monitoring, as required by Article 88 of the GDPR, rendered the processing of metadata unlawful. The authority recalled that compliance with Article 4 of Law No. 300/1970 constitutes a condition of lawfulness for such processing in the employment context in Italy.
  • Obligation of transparency and fairness (Article 5, paragraph 1, point a) of the GDPR): The municipality's initial internal policy did not specify any retention period for metadata, thus failing its transparency obligation. Moreover, the justifications subsequently provided, described as "technically imprecise" by the municipality itself, were deemed non-compliant with the fairness principle as they did not reflect the real nature of the processing.
  • Obligation to inform data subjects (Article 13 of the GDPR): The information provided to employees was incomplete as it did not indicate the retention period of email metadata, an essential piece of information. The subsequent update of this information on the intranet was insufficient to remedy the initial breach.

Authority's decision

Consequently, the authority imposed a fine on the municipality of Chivasso.

Lessons learned

This decision reminds that:

  • The qualification of "work tool" for email does not automatically extend to the generalized collection of its metadata for security purposes that go beyond the strict technical functioning of the service.
  • A limited retention period for metadata (e.g., 21 days) is lawful without specific procedural safeguards only if the purpose is limited to ensuring the basic functioning and security of the system, and not for broader purposes such as incident analysis.
  • The information provided to employees about the processing of their data, notably retention periods, must be complete and transparent from the outset; a subsequent correction does not remedy the initial breach.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire