Enforcement decision by the Italian DPA — no hostile actormedium
Piaggio, EUR 460,000: when the mail backup becomes an archive for monitoring staff
The Italian Data Protection Authority has fined Piaggio & C. Spa EUR 460,000. The investigation, opened on complaints from two former employees, established that the company had accessed their corporate mailboxes during employment, obtaining 112 emails in total to check alleged misconduct — some dating from roughly two years before the suspicion arose. The heart of the decision is not the access itself: it is the retention that made it possible, backups kept for the whole employment and up to five years after, logs for six months. The Authority declared the processing unlawful and barred the company from accessing the data collected.
The suspicion came afterwards
One detail in this decision explains, on its own, why the Authority stepped in. The company accessed two employees' corporate mailboxes to check whether alleged misconduct had occurred. In some cases the emails obtained dated from roughly two years before that suspicion arose.
Pause on that sentence, because the whole decision is in it. If a company can read two-year-old mail today, that mail still existed. And if it still existed, it is not because of the suspicion: it is because of a retention policy decided earlier, when nothing was suspected about those people. The monitoring was not born when it was carried out. It was born when it was made possible.
The Authority fined Piaggio & C. Spa EUR 460,000 for breaches concerning the management of corporate mailboxes, data retention and employee monitoring. The proceedings began with complaints from two former employees.
The numbers in the decision
The Authority identifies three distinct issues, and they are worth keeping apart because they answer different questions.
The first is retention. The monitoring was made possible by the systematic collection and retention of email data through backups kept for the entire employment relationship and up to five years after it ended, plus the related logs for six months. The Authority finds those periods excessive.
The second is the nature of the processing. The processing carried out, the Authority writes, proved capable of reconstructing employees' activity and of amounting to remote monitoring. That phrasing moves the question from the GDPR to the Italian Workers' Statute: an archive that lets you reconstruct what a person did over time is a monitoring instrument, regardless of having been built for backups.
The third is information. The Authority finds shortcomings in what employees were told about the purposes and legal bases of the processing, and holds the company responsible for failing to respond to the former employees' requests to confirm that their accounts had been deactivated.
Beyond the fine, the Authority declared the processing of corporate email data unlawful and barred Piaggio from accessing the data collected and stored on its systems.
Why it concerns almost everyone
This is not a decision about an exotic case. The configuration penalised here — mail backups kept for years, access logs retained, the technical ability to read it all back — is the default configuration in a great many companies, and it was almost never chosen: it was inherited from whoever installed the system, or from the belief that keeping is always safer than deleting.
- 01Backups for continuitya technical choice, made once, never revisited
- 02A queryable archivean unintended but real consequence
- 03Remote monitoringwhen that archive is read to check on a person
The distinction the decision imposes is between availability for operational continuity and accessibility for individual reconstruction. A backup exists to restore a service after a failure or an attack: a legitimate function and, from a security standpoint, indispensable. The problem starts when the same backup becomes an archive searchable by person, by period, by keyword. At that point the purpose has changed, and with it the legal basis, the privacy notice and the limits set by employment law.
Three questions for Monday
How long do you keep it, and who decided. Not "what the policy says": what actually survives, counting backups, secondary archives, mail system snapshots and logs. In practice the real number is almost always higher than the written one, because the policy talks about the mailbox and the backups live somewhere else.
What happens to the mailbox when someone leaves. In the Piaggio case, one of the findings is precisely the failure to answer a request to confirm deactivation. It is a simple question many organisations cannot answer in writing: the mailbox is disabled, the content has been removed, any forwarding to a colleague is temporary and senders are told what.
Who can access it, under what procedure, and who records that. Accessing an employee's mail is never a neutral technical act. If it happens, it needs a written procedure, a defined scope, a traceable justification and oversight — and staff must know about it beforehand, not have it explained afterwards.
A note on what this dossier does not contain: it is based on the summary published by the Authority in newsletter no. 550 and on the decision of 18 June 2026 cited there. We have no information on the company's defence beyond what the Authority reports, nor on any appeal. The principle, though, does not depend on the outcome: retention is not a neutral space where data waits. It is already processing, and it has to be justified as such.