Italy's Garante Fines Piaggio €460,000 Over Unlawful Employee Email Monitoring

Italy's Garante Fines Piaggio €460,000 Over Unlawful Employee Email Monitoring
Italy's data protection authority, the Garante per la protezione dei dati personali, fined Piaggio & C. S.p.A. €460,000 on 29 July 2026 after finding the company had accessed and retained 112 employees' corporate emails, some dating back roughly two years before any suspicion of wrongdoing, through retention practices the authority ruled unlawful under EU and Italian data protection law.
Information last verified on August 3, 2026. This is a developing story; we update it as the record changes.
Jurisdiction scope: This article covers a 29 July 2026 enforcement decision by Italy's data protection authority against an Italian company, Piaggio & C. S.p.A., under Italian and EU law. It does not describe the law of the United States or of other EU member states, and general references to GDPR principles reflect their application in this Italian decision, not a survey of enforcement elsewhere.
What Happened
The Garante announced the sanction against Piaggio in its newsletter dated 29 July 2026, reporting a €460,000 administrative fine tied to the scooter and motorcycle manufacturer's handling of employees' corporate email accounts. The proceeding traces back to complaints filed by two former Piaggio employees, who told the authority the company had accessed their work email during their employment to investigate suspected misconduct.
The Garante's inquiry found that Piaggio had acquired a total of 112 emails belonging to the two former employees, and that some of those messages dated from roughly two years before the company developed any suspicion of wrongdoing. The authority traced this reach back in time to how Piaggio managed its email systems: the company kept systematic backups of corporate mailboxes for the entire duration of an employee's tenure plus five years after termination, and it retained the related access logs for six months. The Garante found these retention periods excessive, and it found that Piaggio had not adequately informed employees about why their email was being collected and stored or what legal basis justified it (the "finalità" and "base giuridica" of the processing, in the Garante's own terminology).
The authority also cited Piaggio for failing to respond when former employees asked the company to confirm that their accounts had actually been deactivated after they left. Having found the corporate email processing unlawful, the Garante ordered Piaggio to stop accessing the data it had already collected and stored on its systems, on top of the monetary sanction. Piaggio had defended the retention by arguing corporate email is a tool employees use to do their job, placing it under the second paragraph of Article 4 of the Statuto dei Lavoratori, Italy's 1970 Workers' Statute; the Garante's decision, corroborated by Italian outlets including Federprivacy, Agenpress, and Borsa Italiana Radiocor, did not accept that this framing cured the retention and transparency failures it identified. Piaggio has publicly contested the sanction, describing it as unlawful and stating that it is preparing a legal challenge, according to reporting by Borsa Italiana Radiocor.

What the Law Actually Says
The Garante's findings rest on core principles of the GDPR (Regulation (EU) 2016/679), the EU-wide privacy law that applies directly in Italy alongside the national Codice Privacy (Legislative Decree 196/2003, as amended by Legislative Decree 101/2018 to align it with the GDPR). Article 5 of the GDPR sets out storage limitation, which requires that personal data be kept for no longer than necessary for the purposes for which it was collected, and data minimisation, which limits collection and retention to what is adequate, relevant, and necessary. A blanket backup policy that preserves every employee's email for the length of employment plus five years, applied without regard to whether any specific email is still needed, is the kind of indiscriminate retention these principles are designed to prevent. Article 5 also requires lawfulness, fairness, and transparency in processing, which Articles 6 and 13 of the GDPR flesh out by requiring a valid legal basis and clear information to the people whose data is collected.
Workplace monitoring in Italy carries an additional layer of protection under Article 4 of the Statuto dei Lavoratori (Legge 300/1970). That provision restricts an employer's use of tools capable of remotely monitoring workers' activity: tools needed for organisational or safety reasons, or to protect company assets, generally require either a prior agreement with union representatives or authorisation from the territorial labour inspectorate, and workers must be given adequate information about how any monitoring tool is used. Piaggio pointed to the statute's carve-out for tools employees use to perform their own work, which does not require that same union sign-off, but the Garante's decision found the company's actual practice, systematic email backups capable of reconstructing an employee's activity well after the fact, went beyond that narrower category. For how the GDPR and the Codice Privacy interact in Italy more broadly, see how GDPR applies alongside Italy's Codice Privacy; for the Garante's role and how a complaint like the one that triggered this case gets filed, see the Garante and how to lodge a complaint.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
The Piaggio decision reads as a straightforward application of storage-limitation and transparency principles to a common corporate practice: keeping broad, standing email backups rather than a retention schedule tied to an actual business need. What makes the case notable is not a new legal theory but the gap the Garante identified between a routine IT backup policy and what data protection law permits once that backup becomes a tool for reconstructing an employee's past conduct. Emails from roughly two years before any suspicion existed were still reachable specifically because the retention window was long and undifferentiated, which is the mechanism the storage-limitation principle exists to prevent.
The decision also illustrates how Italy's employment-specific safeguard, Article 4 of the Statuto dei Lavoratori, and the GDPR's general data protection principles operate as separate but overlapping checks on the same conduct. Piaggio's defence engaged with the Statuto dei Lavoratori's categories for whether a union agreement was required; the Garante's order shows that clearing that hurdle, if it did, would not on its own have satisfied the GDPR's retention and transparency requirements. We are not predicting how any appeal Piaggio pursues will be resolved, and this analysis does not evaluate the merits of the underlying misconduct allegations that led the company to access the emails in the first place.
How This Affects You
For employers operating in Italy, the decision is a concrete illustration that a corporate email retention policy needs a defined, justified retention period rather than an indefinite or multi-year backup window applied uniformly to all staff, and that employees need clear, upfront information about why their email is retained and on what legal basis. Accessing an employee's email to investigate specific suspected misconduct is a different question from how long that email sits in backups available to be searched later; the Garante's decision addressed the latter as much as the former.
For employees and former employees in Italy, the case shows that a complaint to the Garante is an available route when a former employer will not confirm an account has been deactivated or appears to be holding onto communications well beyond what the job required. This is general information about how Italian data protection law and the Statuto dei Lavoratori apply to workplace email, not advice about any individual's situation or dispute. For a broader look at Italian employment protections, see Italian employment law; for how Italian law treats recording and surveillance more generally, see surveillance and recording laws in Italy.
This is general legal information, not legal advice. It covers a 29 July 2026 enforcement decision by Italy's data protection authority against Piaggio & C. S.p.A. and reflects sources verified as of August 3, 2026. This is a developing story and details may change; consult a lawyer qualified in Italy (an avvocato) about your specific situation.
Related articles
- How GDPR and Italy's Codice Privacy fit together
- The Garante: Italy's data protection authority and how to complain
- Italian employment law overview
- Recording and surveillance laws in Italy
- Italian privacy law overview
Last updated: 2026-08-03. This is a developing story; details verified as of 2026-08-03.
Frequently Asked Questions
How much was Piaggio fined and when?
Italy's Garante per la protezione dei dati personali fined Piaggio & C. S.p.A. €460,000, announced in its newsletter of 29 July 2026.
What triggered the Garante's investigation into Piaggio?
Complaints from two former Piaggio employees, who said the company had accessed their corporate email during their employment. The Garante found Piaggio had acquired 112 of their emails, some dating back roughly two years before any suspicion of wrongdoing.
Why did the Garante find Piaggio's email retention unlawful?
The Garante found Piaggio kept systematic email backups for the full length of employment plus five years afterward, with access logs kept six months, retention periods it judged excessive under the GDPR's storage-limitation and data-minimisation principles, combined with inadequate information to employees about the purposes and legal basis for the processing.
Did the Garante order anything beyond the fine?
Yes. The Garante declared the corporate email processing unlawful and ordered Piaggio to stop accessing the data it had already collected and stored on its systems.
What is Article 4 of the Statuto dei Lavoratori and how does it relate to this case?
It is the provision of Italy's 1970 Workers' Statute (Legge 300/1970) governing employer use of tools that can remotely monitor employees, generally requiring a union agreement or labour-inspectorate authorisation for such tools. Piaggio argued corporate email fell under the statute's narrower carve-out for tools employees use to do their job, but the Garante's decision found the company's actual email retention practice went beyond that category.
Does this decision mean Italian employers cannot monitor corporate email at all?
No. The decision addresses Piaggio's specific retention periods and transparency failures, not a blanket ban on employer access to corporate email. Italian law permits monitoring for legitimate purposes carried out lawfully, with adequate retention limits, transparency, and, where applicable, the safeguards in Article 4 of the Statuto dei Lavoratori.
Was this a criminal case?
No. This was an administrative enforcement decision by Italy's data protection authority, the Garante per la protezione dei dati personali, resulting in a fine and a corrective order, not a criminal prosecution.
Sources and References
- Garante per la protezione dei dati personali, Newsletter del 29 luglio 2026: sanzione di 460mila euro a Piaggio & C. Spa(garanteprivacy.it).gov
- Borsa Italiana (Radiocor), Piaggio: sanzione 460mila da Garante Privacy per violazione in gestione email(borsaitaliana.it)
- Federprivacy, Dal Garante Privacy una sanzione di 460mila euro alla Piaggio per raccolta sistematica delle email dei dipendenti(federprivacy.org)
- Agenpress, Garante privacy: sanzione di 460mila a Piaggio & C. Spa, raccolta sistematica delle email dei dipendenti(agenpress.it)
- Regulation (EU) 2016/679 (GDPR), Article 5 (principles relating to processing of personal data, including storage limitation and lawfulness/transparency)(eur-lex.europa.eu).gov
- Legge 20 maggio 1970, n. 300 (Statuto dei Lavoratori), Article 4 (workplace monitoring tools)(normattiva.it).gov