Italy's data protection authority fined Piaggio & C. S.p.A. 460,000 euros on 18 June 2026 after finding the scooter manufacturer had reached back through years of archived company email to build disciplinary cases against two employees, then failed to answer their requests to confirm the accounts had been switched off.

The decision, registered as provvedimento n. 476 and carrying the internal reference doc. web n. 10272529, was adopted in Rome by a panel comprising president Pasquale Stanzione, vice president Ginevra Cerrina Feroni and member Agostino Ghiglia, with Luigi Montuori as secretary general. Ghiglia acted as rapporteur. The text was flagged in the authority's newsletter of 29 July 2026.

Alongside the monetary penalty, the Garante per la Protezione dei Dati Personali issued a prohibition under Article 58(2)(f) of the General Data Protection Regulation barring the company from accessing the content of data collected and held on its systems in connection with corporate email. Payment falls due within 30 days of notification. Under Article 166(8) of Italy's data protection code, the company retains the option of settling for half the amount, 230,000 euros, within the period allowed for lodging an appeal.

What the two former employees complained about

The proceeding began with complaints lodged under Article 77 of the GDPR on 17 July 2023 by a man and a woman, acting through their lawyers. Both had worked at Piaggio until their dismissal for just cause, communicated by letter dated 2 March 2023.

Their first grievance was procedural. Having challenged the dismissals, they asked the company to confirm that their individualised corporate mailboxes had been deactivated. The decision records those challenges as dated 26 April 2023 in its opening narrative and as letters dated 23 April 2023 in the section setting out the findings, a discrepancy the published text does not resolve. The requests were repeated by certified email on 31 May 2023, with an explicit warning that any continued activation of the accounts after the end of the employment relationship would amount to a further and serious intrusion on privacy. The company did not reply within the one-month window set by Article 12(3).

A second set of complaints followed on 14 September 2023. This time the allegation was substantive: that Piaggio had accessed correspondence passing through the two individualised mailboxes during the employment relationship, harvested large numbers of messages, and used them in disciplinary proceedings.

The volumes are set out in the disciplinary charges filed with the authority. In the woman's case, the company acquired, processed and used at least 18 messages that had passed through her corporate mailbox between November 2020 and January 2022. In the man's case, the figure was 94 messages, with collection running back to April 2020. The complainants also stated that the exchange captured messages that had transited their personal email accounts and had been exchanged with third parties.

Piaggio's account of the investigation

Responding to a request for information issued on 19 December 2023 under Article 157 of the national code, the company replied on 17 January 2024 with a detailed chronology.

The two mailboxes were deactivated, with access made impossible, at 08:54 on 16 February 2023, following the disciplinary charges and a precautionary suspension. The mailboxes themselves were deleted on 27 April 2023. Both operations, the company said, were performed manually by its ICT function rather than by the automated off-boarding routine, because the trigger was disciplinary rather than an ordinary termination. Access logs are retained for six months, so no log record of the relevant period remained available.

On the origin of the investigation, Piaggio described a specific sequence. Internal reports had raised concerns about the conduct of the two employees. On 24 November 2022, the Lead Independent Director, acting as the company's legal representative, consulted a group that included the Data Protection Officer to decide whether an internal inquiry was warranted. The company then opted for what Italian labour law practice calls controlli difensivi, defensive controls in the strict sense, applied solely to the two corporate mailboxes and justified by reference to the protection of company assets under Article 4 of Law 300/1970.

The method was described as deliberately constrained. Criteria and modalities were defined in advance and a balancing test carried out. The chosen approach involved gradual extraction of data from the two mailboxes, limited to filters and keywords identified beforehand and confined to a bounded time window, in order to restrict the exercise to relevant data under principles of proportionality, necessity, relevance and non-excessiveness.

Retrieval was outsourced. According to the company, a third party was appointed as processor under Article 28 of the GDPR and instructed by email dated 29 November 2023, which the decision itself corrects to 2022. Access ran through the company server and reached only corporate email accounts, with no access to the work computers used by the two individuals. Neither Piaggio's ICT function nor the processor saw the content of the extracted messages, the company stated. Material judged relevant was held by Internal Audit for the three months needed to complete the controls and evaluate the results, then irreversibly deleted.

On the unanswered access requests, Piaggio argued that deactivation and closure had already been carried out on the stated timetable, and that, given the litigation already underway, any response belonged inside the judicial proceedings themselves.

Five years of backup, and the argument for it

The retention practice sat at the centre of the case. Piaggio told the authority that email messages were saved in backup for the entire duration of the employment contract and for a further five years after it ended, a period documented in its off-boarding guidelines.

In defence memoranda filed on 18 October 2024 under Article 18 of Law 689/1981, the company set out the reasoning. Corporate email, it argued, is a tool used by the worker to perform the job and therefore falls under the second paragraph of Article 4 of the Workers' Statute, outside the procedural guarantees that attach to remote monitoring instruments. Because email is the principal working tool of anyone doing office work, continuous deletion would prevent employees from carrying out their duties, and so messages have to be kept for the whole relationship without any need for a union agreement.

The five-year tail was framed as an accountability choice serving information security and business continuity, and as the means by which the company could answer challenges or requests from authorities and defend itself in court.

Two further details emerged from the internal documents. Messages that employees permanently delete from the trash folder are removed from Piaggio's backup server after one year. Everything else remains: the IT policy states that all messages composed, sent or received on the email system in connection with work duties are and remain company property, and that the corporate mailbox may be subject to company control.

Page 16 of that policy lists five purposes for which Piaggio reserves the right to run checks on ICT resources: production, organisation and management of ICT resources and of the company's commercial activity; information security and verification that ICT resources function; ensuring correct use of resources and compliance with applicable law, company policies and the Code of Ethics; internal investigation activity aimed exclusively at establishing unlawful conduct by the user; and asserting or defending a right in court.

The backup itself, the company said, is completely segregated from other corporate information and managed by a supplier appointed as processor. That supplier can never reach the messages except on specific instruction from Piaggio, and the company's own system administrators cannot access the backup other than through the supplier.

Two changes were announced during the proceeding. Retention of email data after termination was cut from five years to three months, described by the company as the minimum needed for the lay-off procedure and to allow a departing employee to request access or contest a dismissal. Log retention was brought into line with the Garante's guidance document on email management software and metadata processing, adopted on 6 June 2024 as provvedimento n. 364, producing a new practice of deleting logs every 21 days.

Where the reasoning turned

The authority accepted neither of the company's two principal defences.

On the rights requests, it held that a demand for confirmation that an individualised corporate account has been deactivated falls squarely within Articles 15 and following of the regulation. An individualised corporate address, and the content of the mail held in the account, constitute personal data relating to the worker, because communications passing through such an account are inevitably attributable to the account holder. A request to deactivate that account therefore amounts to a request to cease every processing activity carried out on the data subject's personal data up to that point. The decision cites three recent precedents on the same point: provvedimento n. 427 of 17 July 2025, n. 754 of 18 December 2025 and n. 82 of 12 February 2026.

The absence of any citation of the GDPR in the requests made no difference. The authority pointed to the European Data Protection Board's Guidelines 1/2022 on data subject rights, dated 28 March 2023, which state that a controller cannot refuse to supply data on the ground that the request omitted its legal basis, and that the regulation imposes no formal requirements on how a request is made.

The argument that erasure would have destroyed evidence in the Pisa labour proceedings also failed, and on a narrow point: the requests had asked only for confirmation of deactivation, not for deletion of the messages already gathered. Beyond that, Article 2-undecies of the national code, mirroring Article 23 of the regulation, does allow rights to be delayed, limited or excluded where their exercise would cause actual and concrete prejudice to the exercise of a right in court. What it requires is a reasoned communication, made without delay, to the person concerned. Article 12(4) sets the same obligation in general terms, with a one-month outer limit. Neither was met.

The timing problem in the defensive controls

The second and heavier finding concerned the investigation itself.

The Garante noted that pronouncing on the theory of defensive controls, a construct of case law applied inconsistently across judgments, does not fall within its remit. It then applied the test the Court of Cassation has settled on: technological checks aimed at protecting assets extraneous to the employment relationship, or at preventing unlawful conduct, are permitted in the presence of a well-founded suspicion, provided the balance between company interests and worker dignity is properly struck, and provided the control concerns data acquired after the suspicion arose. The decision cites Cass. n. 25732 of 22 September 2021, Cass. n. 18168 of 26 June 2023 and Cass. n. 32283 of 11 December 2025, alongside Cass. n. 34092 of 12 November 2021.

That condition failed on the facts. The suspicion crystallised in November 2022. The data collected were chronologically earlier, with the sweep running backwards roughly two years. What made the retrospective search possible was the systematic backup regime itself.

The authority also rejected the framing in paragraph 9.3 of the company policy, under which users were told they were to have no expectation of confidentiality regarding any communication, message, file or material created, stored, received or sent through ICT resources, including via personal devices. Message content and the external data of communications, the decision states, attract secrecy guarantees protected by Articles 2 and 15 of the Italian Constitution. That external data is enumerated: sender and recipient addresses, the IP addresses of the servers or clients involved in routing, times of sending, transmission and receipt, message size, the presence of attachments, and the subject line.

Four judgments of the European Court of Human Rights are invoked in support: Niemietz v Germany of 16 December 1992, Copland v United Kingdom of 3 April 2007, Barbulescu v Romania of 5 September 2017 and Antovic and Mirkovic v Montenegro of 28 November 2017. The common thread is that Article 8 of the European Convention protects private life without drawing a line between the private and the professional sphere.

On the classification question, the authority restated a position it has taken repeatedly: systems and programs that collect, store and process data drawn from email use are not indispensable for performing work and operate entirely independently of the user's normal activity. They therefore sit inside Article 4(1) of Law 300/1970, which lists the permitted purposes exhaustively and conditions their use on a union agreement or public authorisation. Article 114 of the national code makes compliance with that provision a condition of lawfulness for processing in the employment context.

The transparency gap

A third finding concerned information notices. Piaggio produced two documents dating from 2022, the off-boarding guidelines and the ICT policy, but supplied no clarification about earlier versions or about how the two complainants had been informed of the processing. Article 13 requires that information be given at the moment personal data are obtained.

Read together, the documents describe the processing operations but do not state their purposes, and specifically not the purposes and grounds for retaining email and the associated logs. The Article 29 Working Party transparency guidelines of 29 November 2017 require the legal basis to be specified alongside the purpose, and require retention periods to be expressed in a way that lets an individual work out, for a given situation, how long the data will be held. A generic statement that data will be kept as long as necessary does not meet that standard.

The revised internet and email regulation filed with the defence memoranda indicates retention periods concisely and clearly, including an automatic backup cycle of eight hours, but still omits the purposes. The violation was confirmed.

One further practice drew criticism. The policy allowed a departing employee's mailbox to remain active for up to 30 days with the user's consent, forwarding messages to another mailbox nominated by that person's manager, or transferring mailbox content to another user for proven service needs. Given how generically those service needs were expressed, the authority found the arrangement contrary to data protection rules, pointing to five earlier decisions on the same theme. The approach it has consistently endorsed is removal of the account after deactivation, coupled with automatic systems that inform third-party senders and provide alternative professional addresses, plus measures preventing anyone from viewing incoming messages while that system runs.

How the figure was reached

The violations were found under Articles 5(1)(a), (b), (c) and (e), 6, 12, 13, 17 and 88 of the regulation, together with Article 114 of the code. Article 83(5)(a) and (d) supplied the sanction bracket, and Article 83(3) was applied so that the combined total does not exceed the ceiling for the most serious single violation.

Weighing the amount, the authority treated the systematic recording and retention of employee communications and their logs as an aggravating feature, describing employees as vulnerable data subjects. Duration counted twice: the response to the rights requests arrived only after the Authority opened its inquiry, and the retention period covered the whole employment relationship plus a further stretch after it ended. The degree of responsibility reflected a general policy of retaining employee mail with the possibility of access for multiple purposes.

Cooperation was credited. The authority recorded as positive the changes made to retention periods in company systems, the additional technical measures, and the revisions to employee-facing documents. The absence of prior relevant violations also counted in the company's favour. Economic condition was assessed on turnover as reported in the 2025 annual accounts. Piaggio & C. S.p.A. is headquartered at Viale Rinaldo Piaggio in Pontedera, in the province of Pisa.

The decision was ordered published on the Garante's website on the ground that the conduct was particularly harmful to the rights of the individuals concerned. Appeal lies to the ordinary courts within 30 days of communication, or 60 days for a party resident abroad.

Why this matters beyond Pontedera

The case is narrow in its facts and broad in its implications for anyone running marketing, agency or publishing operations inside the European Union, where corporate mailboxes double as the record of client relationships, campaign approvals and creative sign-off.

Three points carry across. The first is that retention creates capability, and capability creates exposure. Piaggio did not build a monitoring system; it built a backup. The authority's finding turns on the fact that a backup covering the entire employment relationship made a two-year retrospective search technically possible, and that the search then happened. Retention schedules written for continuity and legal defence become, in the authority's reading, the infrastructure of surveillance.

The second is the treatment of metadata. Sender and recipient addresses, timestamps, message size, attachment presence and subject lines are all named in the decision as forms of correspondence carrying constitutional protection. That is the same category of external data that email service providers, marketing automation platforms and security tools log by default. France's regulator moved on adjacent ground when it set final rules on email tracking pixels, treating the mailbox as a personal communication space reachable only after authentication.

The third is the reliability of internal policy language as a defence. A clause telling staff they have no expectation of confidentiality on company systems did not survive contact with Article 8 of the European Convention. Nor did the characterisation of email as a mere work tool exempt from procedural safeguards.

Italian enforcement has been unusually active on the boundary between employment and data protection. The Garante warned an AI startup that a Slack stress-detection plug-in risked breaching GDPR Article 9 and EU AI Act prohibitions in May 2026, resting part of the analysis on the same Article 88 route into national labour law. In April 2026 the same authority fined Intesa Sanpaolo 31.8 million euros after one employee accessed 3,573 customer accounts over two yearswithout justification, and it had already fined the bank 17.6 million euros for profiling 2.4 million customers ahead of an account transfer. The common thread is internal access to data the organisation already holds legitimately.

The wider European pattern points the same way. France's Conseil d'Etat cut Amazon's warehouse monitoring fine from 32 million to 15 million euros in December 2025 while upholding the data minimisation finding, holding that the company had not established why each disputed productivity indicator needed a 31-day retention period. Poland's regulator imposed a 3.89 million euro penalty on McDonald's over processor oversight failures that exposed employee scheduling data. In each case the disputed element was not collection at the outset but what happened to the data afterwards.

Enforcement outcomes remain contested. Analysis published in May 2026 found that close to 40 percent of the 7.1 billion euros in announced GDPR fines have been annulled or are under active legal challenge, a record that includes a Rome tribunal annulling the Garante's 15 million euro fine against OpenAI on jurisdictional grounds in March 2026. The European Data Protection Board recorded 1.15 billion euros in fines across national authorities during 2025. Against that backdrop, a mid-six-figure penalty against a domestic manufacturer with no cross-border establishment question is comparatively durable, which is part of what makes the reasoning worth reading.

One drafting inconsistency in the published text deserves noting. Section 5 of the decision refers to the sanctioned entity as "Piaggio & C. S.p.A. s.r.l.", combining two incompatible company forms; every other reference, including the operative part, uses S.p.A. The same section also cites "Regolamento del Garante n. 1/20129" twice, a year that does not exist.

Timeline

  • April 2020 - Earliest messages later collected from the male complainant's corporate mailbox
  • November 2020 - Start of the period covered by the collection from the female complainant's mailbox
  • January 2022 - End of that period
  • 24 November 2022 - Piaggio's Lead Independent Director consults the Data Protection Officer on opening an internal inquiry
  • 29 November 2022 - External processor instructed to carry out the targeted email retrieval
  • 16 February 2023 - Both corporate mailboxes deactivated at 08:54 following disciplinary charges and precautionary suspension
  • 2 March 2023 - Dismissal letters issued for just cause
  • 23 or 26 April 2023 - First requests for confirmation of account deactivation, dated inconsistently in the decision
  • 27 April 2023 - Mailboxes deleted manually
  • 31 May 2023 - Requests repeated by certified email; no reply follows
  • 17 July 2023 - First complaints filed with the Garante under Article 77
  • 14 September 2023 - Second complaints filed, alleging unlawful access to correspondence
  • 19 December 2023 - Authority issues request for information under Article 157
  • 17 January 2024 - Piaggio responds with its chronology and legal position
  • 3 May 2024 - Complainants confirm the Pisa proceedings concern only the dismissals
  • 6 June 2024 - Garante adopts provvedimento n. 364 on email management software and metadata
  • 3 September 2024 - Sanctioning proceeding formally opened
  • 18 October 2024 - Defence memoranda filed; retention cut from five years to three months, log deletion set at 21 days
  • 6 December 2024 - Company hearing held
  • 24 December 2025 - France's Conseil d'Etat reduces Amazon's warehouse monitoring fine to 15 million euros
  • 8 April 2026 - Garante fines Intesa Sanpaolo 31.8 million euros over unauthorised employee access
  • 14 April 2026 - EDPB annual report records 1.15 billion euros in 2025 fines
  • 29 May 2026 - Garante warns AI startup over Slack stress-detection plug-in
  • 18 June 2026 - Provvedimento n. 476 adopted in Rome; 460,000 euro fine and processing ban imposed
  • 29 July 2026 - Decision flagged in the Garante's newsletter

Summary

Who. Italy's Garante per la Protezione dei Dati Personali, sitting with president Pasquale Stanzione, vice president Ginevra Cerrina Feroni, member and rapporteur Agostino Ghiglia and secretary general Luigi Montuori, against Piaggio & C. S.p.A. of Pontedera. Two former employees, dismissed for just cause in March 2023, brought the complaints.

What. A 460,000 euro administrative fine plus a prohibition on accessing the content of data collected and stored on company systems in connection with corporate email. The authority found breaches of Articles 5(1)(a), (b), (c) and (e), 6, 12, 13, 17 and 88 of the GDPR and Article 114 of Italy's data protection code. The company retrieved 94 messages from one mailbox and at least 18 from the other, reaching back roughly two years before the suspicion that prompted the inquiry, and left requests to confirm account deactivation unanswered.

When. Provvedimento n. 476 was adopted on 18 June 2026 and flagged in the authority's newsletter on 29 July 2026. The underlying events run from April 2020 to the December 2024 hearing. Payment is due within 30 days of notification, with a settlement option at half the sum inside the appeal window.

Where. Rome, with the company headquartered at Viale Rinaldo Piaggio in Pontedera, province of Pisa. Parallel labour proceedings on the dismissals sit before the Tribunal of Pisa.

Why. The defensive controls captured data predating the suspicion, which the Court of Cassation treats as the decisive condition for lawfulness. A five-year post-termination backup made that retrospective reach possible. Information notices described the processing but not its purposes, and the requests for confirmation of deactivation were treated as data subject requests that went unanswered.