The Italian Data Protection Authority (GPDP) has fined Piaggio & C. SpA €460,000 after finding the company unlawfully collected, stored, and accessed employee emails.
The investigation began after two former employees complained that Piaggio had accessed their company email accounts during internal disciplinary investigations.
GPDP found that the company collected 112 emails from the two employees. Some of those messages were up to two years old and had been stored long before the company suspected any wrongdoing.
GPDP also discovered that Piaggio routinely backed up employee emails throughout employment and kept them for up to five years after employees left the company. Email access logs were also retained for six months.
According to GPDP, storing emails for such long periods made it possible to reconstruct employee activity and remotely monitor workers. This breached several GDPR rules, including data minimization, storage limitation, transparency, and lawful processing. Employees were also not given clear information about how long their emails would be kept or why that data was retained.
To comply with privacy and data protection regulations, Piaggio has updated some of its practices. It has reduced its email retention period after employment ends from five years to three months. It has also shortened email log retention from six months to 21 days to align with the GPDP’s guidance.
