Public Interest and Platform Oversight
The operational management of digital gig economy platforms has transformed labor dynamics through automated algorithmic scoring, real-time geolocation tracking, and biometric authentication. Regulatory inspections into food delivery logistics examine how corporate entities manage personal data while disclaiming jurisdictional accountability. This investigation establishes the critical boundary between software architecture and statutory privacy obligations.
When automated systems evaluate worker availability, allocate order slots, or execute account deactivations without meaningful human intervention, labor autonomy becomes subordinated to opaque software metrics. Understanding these algorithmic mechanisms is essential for protecting the statutory rights of over thirty-six thousand active couriers navigating urban delivery networks. The findings document how digital platforms maintain deep algorithmic oversight while attempting to diffuse data controllership across national borders.
Corporate Structure, Platform Lineage, and Chronology
The regulatory inquiry into Foodinho S.r.l., the Italian operating subsidiary of Spanish parent company Glovoapp23 SL (later GlovoApp 23 SA), centers on a multi-year enforcement trajectory. The supervisory timeline originated with on-site inspections conducted on 16 July 2019, culminating in enforcement decision number 234 on 10 June 2021. Despite this administrative precedent, subsequent worker reports prompted renewed inspections on 13 and 14 December 2022.
Following an additional formal complaint received on 7 July 2023 regarding courier data processing via the Glovo Couriers application, supervisory authorities consolidated the proceedings. Inspectors executed targeted on-site audits at corporate offices on 26 and 27 July 2023. These inspections scrutinized backend software configurations, internal permission registries, automated communication pipelines, and the operational division between Italian management and Spanish engineering teams.
Corporate records submitted during the inquiry revealed the scale of the courier workforce operating within Italian borders. Company declarations confirmed that 36,545 active couriers had completed at least one delivery using the Glovo platform since January 2022. Furthermore, 7,405 couriers entered active service between 1 August 2022 and the conclusion of the inspection phase, underscoring the rapid turnover and massive operational scope of the delivery fleet.
Institutional and Corporate Entities
The primary entity subjected to direct regulatory scrutiny is Foodinho S.r.l., a corporate vehicle registered in Italy that operates local delivery logistics under a formal franchise agreement executed with Glovoapp23 S.L. on 1 October 2019. The contractual structure, specifically clause 18 governing personal data processing, delegates platform infrastructure while assigning local management responsibilities.
The platform infrastructure and proprietary applications—including both customer-facing applications and the Glovo Courier tool—are owned, maintained, and engineered by [[Glovo|Q59556858]] (GlovoApp 23 SA), based in Spain. The enforcement actions were executed by the Italian Data Protection Authority, [[Garante per la protezione dei dati personali|Q3758310]], with prior coordination involving the Spanish supervisory authority, the [[Agencia Española de Protección de Datos|Q4691996]].
Critical Evidence and Algorithmic Analysis
Biometric Processing and Retention Timelines
Corporate records verify that Foodinho S.r.l. initiated the collection and automated processing of biometric facial recognition data on 23 November 2020 as part of authentication testing. Although the company formally declared that it ceased collecting biometric data in July 2022, storage practices remained an active regulatory concern throughout subsequent enforcement phases.
Foodinho S.r.l. ha iniziato a trattare dati biometrici dei Corrieri in data 23 novembre 2020, nell’ambito dei primi test relativi alla procedura di autenticazione […] Foodinho S.r.l. ha smesso di utilizzare tale procedura di autenticazione e, di conseguenza, di raccogliere e trattare dati biometrici dei Corrieri a partire dal luglio 2022.
In response to administrative findings, corporate counsel submitted an updated retention policy on 5 June 2024. Under these amended terms, biometric data retention was formally capped at three months from the last order for inactive couriers, and three months from account deactivation for accounts terminated for reasons unrelated to facial recognition.
Live Tracking Permissions and Algorithmic Scoring
Internal access logs and corporate disclosures established that real-time tracking was widely accessible across the organization. On 17 March 2023, the company confirmed that exactly 65 internal employees held active authorization for the livemap.view permission, allowing direct surveillance of courier positions across urban delivery sectors.
Platform evaluations also relied on automated backend parameters that persisted long after their purported operational discontinuation. A legacy fixed rating value of 4.5 had been systematically assigned by the system backend to all couriers operating in Italy. Despite having been officially deprecated since 2021, this static metric remained active within the system architecture until its formal deletion on 10 January 2024.
A partire dal 10 gennaio 2023 [da intendersi 2024], il cd. fixed rating value (valore fisso del rating) di 4.5 assegnato ad ogni corriere è stato eliminato.
The platform utilized an Excellence Score mechanism to allocate delivery capacity and scheduling preferences. The company defended the system by claiming meaningful human supervision via manual capacity increases in specific delivery windows, asserting that an updated privacy notice adopted on 18 May 2023 fulfilled transparency requirements.
Account Deactivation and Automated Sanctions
Inspection minutes dated 1 March 2023 exposed a bifurcation in the platform disciplinary pipeline. While initial account blocks were generated and communicated through fully automated software workflows, subsequent review stages were handled through manual interventions. However, individual case reviews, including documented notifications sent to courier S.G., demonstrated instances where account actions bypassed standardized classifications entirely.
Questa fase del processo di blocco è manuale, a differenza della prima in cui la comunicazione di blocco è automatizzata […] con riferimento alla comunicazione ricevuta dal sig. [S.G.], invece, non rientra in nessuna delle precedenti casistiche.
On 15 September 2023, corporate representatives submitted formal clarifications stating that all external service vendors acted strictly as data processors on behalf of Foodinho S.r.l. Nevertheless, in formal defense briefs submitted on 11 December 2023, the company contested the jurisdiction of the Italian supervisory authority, arguing that platform architecture and core functionalities were determined solely by GlovoApp 23 SA in Spain.
Corporate defense arguments further alleged a violation of the ne bis in idem principle, claiming the 2023 proceedings duplicated the 2019 inspection that resulted in decision 234 of 2021. The supervisory authority rejected these claims, ruling that Foodinho S.r.l. operates as an independent data controller under Article 4(7) of the GDPR, determining local purposes and processing means within the Italian territory.
Transparency and Legal Framework
This investigative analysis is constructed directly from primary regulatory documentation issued in enforcement proceeding number 10074601 on 13 November 2024 by the Garante per la protezione dei dati personali. Public access and editorial reproduction of Italian administrative and regulatory records are established under Article 5 of Law 633/1941, which places official government and public administration texts in the public domain.
The administrative determinations document the compliance obligations of platform logistics companies operating across the European single market. Full source records and inspection transcripts can be verified through the official digital registry of the Italian Data Protection Authority (Provvedimento del 13 novembre 2024 [10074601]).

