Defensive monitoring of staff email: the Piaggio case and its €460,000 fine
7 min read
On 18 June 2026 Italy’s data protection authority (Garante) fined Piaggio & C. S.p.A. €460,000. The decision — no. 476, doc. web 10272529, made public with the 29 July newsletter — began with something minimal: two former employees, dismissed for cause by letter dated 2 March 2023, had simply asked for confirmation that their company email accounts had been deactivated. No reply ever came. The inquiry that followed ended up judging something far broader: how, and since when, the Company had been reading that same correspondence.
The established facts, with dates
The two complainants asked for confirmation of deactivation in the letters challenging their dismissal, in April 2023, repeated on 31 May 2023: never answered. In September 2023 they filed a second, more specific complaint: the Company had “acquired, processed and used” their work emails to build the disciplinary case against them — 18 messages belonging to the female employee, from November 2020 to January 2022, and 94 belonging to the male employee, starting in April 2020. Piaggio confirmed the accounts were deactivated on 16 February 2023 at 8:54am, coinciding with their precautionary suspension over the disciplinary charges, and deleted on 27 April 2023 — beyond the 30 days set by the Company’s standard off-boarding procedure, because this was not an ordinary termination.
The defence: defensive checks, written criteria, a balancing test
Piaggio told the Office that, following internal reports, the Lead Independent Director — the Company’s legal representative for this purpose — consulted the Data Protection Officer on 24 November 2022 to assess whether an internal investigation into the two employees was warranted. What followed were “strict defensive checks carried out exclusively on the two complainants’ company email accounts for the purpose of protecting the Company’s assets under Article 4 of Law 300/1970”. On paper, the procedure was the right one: criteria and methods defined in advance, a balancing test on file, an instruction given on 29 November 2022 to an external processor under Article 28 GDPR who extracted the emails using keyword filters without reading their content, with data kept by Internal Audit for only three months and then, the Company says, irreversibly deleted.
Why it was not enough: the sequence of events
The Garante is clear on one point of method: it is not for the authority to rule on the “theory of defensive checks” as such, calling it “a matter of pure case law”. It does, however, apply the test the Court of Cassation has repeated for years (nos. 25732/2021, 18168/2023, 34092/2021, 32283/2025): even technological checks by an employer are permitted only if they “concern data acquired after the suspicion arose”. That is precisely the element missing here. The suspicion arose on 24 November 2022; the emails collected date back to April and November 2020 — gathered “retrospectively, up to roughly two years earlier”. Written criteria and a balancing test cannot rescue an investigation that, in its time span, looks backwards from the suspicion rather than forwards.
The tool and its memory
To justify keeping emails for five years after termination too, Piaggio argued that company email is “a tool used by the employee to carry out their work” and therefore falls under the second paragraph of Article 4 of the Workers’ Statute — the exemption that removes the need for union agreement. The Garante does not accept the next step in that argument: it restates its settled position that the systems which collect, retain and process the data generated by using email “are not indispensable to carrying out the work and operate entirely independently of the user’s normal activity”. The tool itself may sit under paragraph 2; the infrastructure that watches it, archives it and makes it searchable stays under paragraph 1, with its procedural safeguards. We had already drawn that same line — between a tool and its memory — for the logs of company AI assistants: here the Garante applies it, with a named defendant, to ordinary email. It is the same territory covered when a vendor read employees’ language in chat: you do not need an algorithm to fall under Article 4 of the Statute — a server that remembers is enough.
Retention and deactivation: what changed during the inquiry
Two figures, before and after. Email: from five years after termination down to three months, reduced in the defence submission of 18 October 2024, after the proceedings had opened. Access logs: from six months to deletion every 21 days, in line with the Garante’s 6 June 2024 guidance on email metadata in the workplace. The Garante “takes favourable note” of both corrections, but says so explicitly: what was done before remains established as unlawful. On a third point it does not budge: the practice of keeping a departing employee’s account active, with forwarding or transfer “for demonstrated business needs”, remains “contrary to the data protection rules” precisely because that formula is so generic — the account must be deactivated, with an automatic reply pointing to an alternative address, without anyone able to read incoming mail in the meantime.
The violations and the fine
The final order finds a breach of Articles 5(1)(a), (b), (c) and (e) (lawfulness, minimisation, storage limitation), 6, 12(3), 13, 17 and 88 of Regulation (EU) 2016/679, plus Article 114 of the Italian Data Protection Code — the provision that incorporates Article 4 of the Workers’ Statute wholesale as a condition of lawfulness. The Garante weighs the fine against the nature of the violations (data belonging to workers, described as “vulnerable data subjects”), their duration (years of retention, delay in responding to the complainants) and the Company’s turnover; in Piaggio’s favour it counts the cooperation shown and the corrections made during the proceedings. The outcome, under Article 83 of the Regulation: €460,000, plus a corrective measure distinct from the fine — a ban on “accessing the content of the data collected and stored on the Company’s systems relating to company email”.
What a company must be able to prove, afterwards
Doing the right things is not enough; you must be able to show them in the right order. The date the specific suspicion arose, minuted before touching a single piece of data — not reconstructed after the fact for the proceedings. The scope of the data collected, checked against that date: if a keyword filter reaches further back than the suspicion, the check reverts to surveillance. The balancing test, written down and tied to the actual case, not a standard form. And proof that access to the content was genuinely limited to whoever had to assess it — the same principle that governs the credentials of whoever administers a company AI system — with deletion that can be demonstrated to have happened, not merely declared.
How we solve this
A log that begins with a minuted suspicion and one that hoovers up everything for years “just in case” are two different systems, even if they run on the same mail server — and that difference, to survive an inspection, has to sit in the architecture, not in a policy written afterwards. That is the first axis on which we build dedicated, closed AI for large enterprises, defence, public administration and healthcare: the criteria for a defensive check, the balancing test and the retention periods become a control that runs on the systems themselves and produces, on its own, the record to be shown — the date the suspicion arose, the scope of data touched, deletion that actually happened rather than merely being declared. The second axis is what makes the first one worth having: the same architecture that keeps the log of measures separate from the content of communications also brings the organisation’s scattered data — email, HR, security, operational systems — into a single operational model, on which AI agents execute decisions with a human operator in command. Always in two delivery modes: on-premises, on self-contained machines that do not require deep integration into the client’s network, or CSIDIA’s dedicated cloud, with a dedicated VPN and a data centre in Italy that we secure directly; and always with shared management, because almost no organisation already has, in-house, someone who administers a system like this.
Could you reconstruct, with a date minuted before rather than after the fact, when the suspicion arose that triggered the last check on your staff? Half an hour with one of our experts is enough for the first map.