Accessing a dismissed employee's company email account can violate privacy laws and data protection regulations

09 february 2026

According to the Italian Data Protection Authority, the content of emails, contact data related to communications, and any attachments fall within the notion of correspondence. Therefore emails are  protected by the right to confidentiality, in compliance with the Italian Constitution, which protect safeguards human dignity and the full development of the individual in social relationships.

Hence, Italian Data Protection Authority (Garante per la protezione dei dati personali), imposed a €40,000 fine on a company for violating the confidentiality of a former CEO’s email account after the termination of the employment relationship (resolution. 754 of December 18th,  2025)

In the complaint, the employee stated that after receiving a disciplinary notice followed by dismissal, the company denied him access to his corporate email mailbox, which remained active. By exercising his rights under the GDPR, he asked the company to disable the email account, forward the messages received in the meantime to his personal email address, and activate an automatic reply informing senders of the new email address. However, this request—properly submitted in accordance with the GDPR—was not fulfilled.

During the investigation, the Authority found that the company not only continued to receive emails addressed to the former employee, but even forwarded them to another corporate email account. This improper practice continued for about two months, exceeding the 30-day limit set by the company’s internal rules.

In determining the amount of the fine, the Authority considered the nature and duration of the violations, the failure to respond to the employee’s request to exercise his rights, and the absence of previous privacy law violations by the company.

 

News archive

 

Firm news

apr2

02/04/2026

L’Autorità Garante della Concorrenza e del Mercato ha irrogato a Revolut Securities Europe UAB, società del gruppo che offre servizi d’investimento in Europa, e alla Revolut Group Holdings Ltd sanzioni per oltre 11 milioni di euro per pratiche commerciali

L’Autorità ha multato le due società per 5 milioni di euro per violazione degli articoli 20, 21 e 22 del Codice del Consumo: hanno infatti omesso di fornire ai clienti, già

apr1

01/04/2026

Messaggi Vocali WhatsAppe responsabilita' disciplinare del lavoratore

Va escluso che l'acquisizione dei messaggi vocali possa essere ricondotta a un legittimo esercizio dei poteri di controllo datoriale ai sensi dell'art. 4 dello Statuto dei Lavoratori, trattandosi

mar31

31/03/2026

Save the date: Virtual Meeting 15 aprile 2026

Il prossimo 15 aprile 2026 ore 9.00, International Institute of Communications ospitera' l'evento trilaterale (Australia, Italia e UK) sulla protezione dei minori in ambiente digitale.   Questo

Lawyer News