Operational notes Regulation

Sentiment analysis on employees in chat: what the Italian Garante just stopped

6 min read

Hands typing on a laptop keyboard in an office
Every message typed in a corporate chat can end up, without the author knowing, in a stress index.

On 14 May 2026 the Italian Data Protection Authority (Garante per la protezione dei dati personali) formally warned Myndoor S.r.l., a company selling a plug-in for Slack and Microsoft Teams that reads employees’ emotional state by analysing the language of corporate chats (decision no. 342/2026, doc-web 10255494). The detail that should give every HR department pause is not the ban itself: it is the threshold. The system generates an aggregate stress report from as few as 10 active users. Two small teams adopting it — just to “take the pulse” on workload — are enough for a company to obtain, should it ever look, a stress map of its own people. The uncomfortable thesis here: the risk is not whether a vendor will one day widen the feature set into individual-level access — that is almost inevitable in a SaaS product that lives on new features. The risk is that, for as long as the data crosses a third party’s server outside the company perimeter, the promise “we can’t see it” is not verifiable by the party who would actually answer for it: the employer.

What is banned (and what is not)

Even though the system examined gave the employer no access to any individual employee’s data, it still processes — the Garante wrote — information about employees’ emotional sphere that “cannot be made available” to the company: the decision cites Articles 5, 6 and 9 of Regulation (EU) 2016/679 (GDPR), Articles 24-25 on accountability and privacy by design, Article 88 on processing in the employment context, Articles 2-ter and 113 of the Italian Data Protection Code (Legislative Decree 196/2003), and Articles 5 and 8 of the Workers’ Statute (Law no. 300 of 20 May 1970) on the prohibition of investigations unrelated to professional aptitude. But the provision that actually settles the matter is absolute: Article 5(1)(f) of Regulation (EU) 2024/1689 (the AI Act) prohibits the use of AI systems to infer a person’s emotions in the workplace, save for the sole exceptions of medical or safety purposes. It has been in force since 2 February 2025: not a future deadline, an already-established fact, punishable by fines of up to €35 million or 7% of worldwide turnover (Article 99(3) AI Act).

The scenario our clients describe

The HR manager downloads an “employee wellbeing” app from the Teams marketplace to catch burnout before resignations happen. A well-meaning team leader installs it without going through legal: it does not process medical records, so it “doesn’t look like” sensitive data. Months later, an internal audit — or an employee’s complaint to the works council — discovers the tool has been running for months across forty people and produces a weekly stress index per department, already circulated at two management meetings. Two things now apply at once: the AI Act, which makes the system unlawful in itself; and Article 4 of the Workers’ Statute, which — since this is a tool capable of enabling remote monitoring of employees’ activity — would in any case have required an agreement with the company’s trade union representatives or, failing that, authorisation from the relevant territorial office of the National Labour Inspectorate, before installation, not after the fact emerges.

Brussels’ postponement saves no one

Not all AI touching employees is banned like sentiment analysis: most HR systems — CV screening, candidate evaluation, task assignment based on behaviour, decisions on promotion or dismissal — are classified as high-risk under point 4 of Annex III to the AI Act, with an obligation on the employer (Article 26(7)) to inform workers’ representatives and the affected workers before putting the system into service. These specific obligations, for “standalone” Annex III systems, have been postponed to 2 December 2027 by the Digital Omnibus approved in June. But reading that postponement as a pause is wrong twice over: sentiment analysis remains banned today, because the Article 5 prohibition was never part of the package that was pushed back; and the same substantive obligations — informing workers in writing, negotiating with trade union representatives — have already been Italian law since 2022, regardless of Brussels. Article 4 of Legislative Decree no. 104 of 27 June 2022 inserted Article 1-bis into Legislative Decree 152/1997, requiring every worker to be informed of the logic, purpose and categories of data of any automated decision-making or monitoring system used in the employment relationship. Europe’s 2027 calendar is a floor, not a ceiling: anyone waiting for that date to bring HR systems into line will find they have already been out of compliance for years under Italian law.

Closing the gap by design

The thread linking the Myndoor case, Article 4 of the Workers’ Statute and Annex III of the AI Act is structural, not bureaucratic. Every time data about employees — an emotion, a stress level, a performance rating — leaves the company perimeter to sit on a SaaS vendor’s server, the employer loses, by definition, control over who else can see it, what it will be reused for, and which jurisdiction it will land in if a foreign authority requests it. This is why we build differently: an on-premise AI, in a dedicated environment disconnected from the web, does not promise to meet these requirements — it meets them by design, because employee data never leaves the perimeter the employer controls and can show to an inspector, a union or a judge. That is the principle our platform is built on, and the reason every operational trial starts from data that stays yours — not from a subscription to an external service that no vendor, however well-intentioned, can truly guarantee is isolated.

What to do now

  1. Map every AI plug-in connected to Slack, Teams or corporate email, not just the “official” systems: shadow AI is governed by mapping it, not banning it.
  2. Distinguish the two regimes: sentiment and emotion recognition are banned outright, nothing to negotiate; systems that manage and evaluate employees are high-risk, with disclosure obligations on the way.
  3. Before any installation touching people’s behaviour or performance, go through the trade union representatives (or the Labour Inspectorate) and update the disclosure required under Article 1-bis of Legislative Decree 152/1997.
  4. Ask your DPO for a map of “people data” currently flowing to external cloud vendors: it is the same inventory the AI Act register requires — as does Italy’s own AI law, which asks the same thing for employment. Do it once, for both.

Want to know which tools already connected to your corporate chats cross this line? Half an hour with one of our experts for the first map.

Sources