Skip to main content
ShareEmailLinkedInXWhatappsFacebook
feedback
Share

Italian DPA fines security company EUR 39 000 for violations concerning employees’ data

Background information

  • Date of final decision: 6 August 2026
  • National case
  • Controller: La Patria S.p.A.
  • Legal Reference(s): Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject), Article 13 (Information to be provided where personal data are collected from the data subject) and Article 15 (Right to access by the data subject)
  • Decision: Administrative fine
  • Key words: Data subjects rights, Fines

Summary of the Decision

Origin of the case

The Italian Data Protection Authority (DPA) initiated an investigation following a complaint lodged by a former employee of La Patria S.p.A., a security and technological security company. The complainant claimed that the company had failed to respond to two requests to access documentation concerning disciplinary proceedings against him, including data collected through a GPS system installed on the company vehicle assigned to him. The employee had requested access to the documentation in order to defend himself in disciplinary proceedings which subsequently resulted in his dismissal.

Key Findings

The Garante, the Italian DPA, found that the company had failed to adequately respond to the employee’s access requests. The DPA clarified that a data subject does not need to expressly refer to the GDPR for a request to qualify as an exercise of the right of access. Furthermore, where a controller decides not to comply with a request, it must inform the data subject of the reasons and of the possibility of lodging a complaint or seeking a judicial remedy..

They also found that the company had failed to provide employees with appropriate information on the processing of geolocation data collected through GPS systems installed on company vehicles. Such data constitute personal data because the vehicle’s location can be indirectly linked to the employee driving it.

In addition, the company’s privacy notices incorrectly referred to the processing of special categories of personal data, including information concerning philosophical beliefs and sex life, although the company did not actually process such data.

Decision

The Garante imposed a total administrative fine of EUR 39 000 on La Patria S.p.A. for infringements of Articles 12, 13 and 15 GDPR. The total fine consisted of EUR 22 000 for the infringements concerning the exercise of the right of access and EUR17 000 EUR for the infringements concerning the information provided to employees.

When determining the fine, the Italian DPA took into account, among other factors, that the company had taken steps during the proceedings to bring its processing activities into compliance with the GDPR. In particular, it provided employees with appropriate information concerning the processing of geolocation data and removed incorrect references to special categories of personal data from its privacy notice.

No further corrective measures were imposed, as the infringements had ceased and the company had already taken measures to remedy the identified shortcomings.

For further information: