Accessing a dismissed employee's company email account can violate privacy laws and data protection regulations

09 febbraio 2026

According to the Italian Data Protection Authority, the content of emails, contact data related to communications, and any attachments fall within the notion of correspondence. Therefore emails are  protected by the right to confidentiality, in compliance with the Italian Constitution, which protect safeguards human dignity and the full development of the individual in social relationships.

Hence, Italian Data Protection Authority (Garante per la protezione dei dati personali), imposed a €40,000 fine on a company for violating the confidentiality of a former CEO’s email account after the termination of the employment relationship (resolution. 754 of December 18th,  2025)

In the complaint, the employee stated that after receiving a disciplinary notice followed by dismissal, the company denied him access to his corporate email mailbox, which remained active. By exercising his rights under the GDPR, he asked the company to disable the email account, forward the messages received in the meantime to his personal email address, and activate an automatic reply informing senders of the new email address. However, this request—properly submitted in accordance with the GDPR—was not fulfilled.

During the investigation, the Authority found that the company not only continued to receive emails addressed to the former employee, but even forwarded them to another corporate email account. This improper practice continued for about two months, exceeding the 30-day limit set by the company’s internal rules.

In determining the amount of the fine, the Authority considered the nature and duration of the violations, the failure to respond to the employee’s request to exercise his rights, and the absence of previous privacy law violations by the company.

Archivio news

 

News dello studio

feb9

09/02/2026

Accessing a dismissed employee's company email account can violate privacy laws and data protection regulations

According to the Italian Data Protection Authority, the content of emails, contact data related to communications, and any attachments fall within the notion of correspondence. Therefore emails are  protected

feb6

06/02/2026

Proposal for a Directive as regards simplification measures and alignment with the Cybersecurity Act

The Commission has proposed a new cybersecurity package to further strengthen the EU's cybersecurity resilience and capabilities. The package introduces measures to simplify compliance with

feb6

06/02/2026

Proposal for a Regulation for the Digital Networks Act (DNA)

The Commission proposes the Digital Networks Act (DNA), which offers a modern, simplified, and harmonised legal framework to bolster Europe's competitiveness. By strengthening digital

News Giuridiche

feb9

09/02/2026

Maternità e NASPI: quando l'onere spetta all'INPS e non al Comune

I chiarimenti sulla ripartizione dell'onere

feb9

09/02/2026

SLAPP, Italia la più colpita in Europa

Il report CASE rilancia l’urgenza di estendere

feb9

09/02/2026

Iscrizione a ruolo dell’ufficiale giudiziario anche senza contributo unificato

La cancelleria procederà poi in seguito