Investigative Journalism
Unclessify — Journal of Investigation and Declassification, Founded by Graziano Costantino
Unclessify — Journal of Investigation and Declassification, Founded by Graziano Costantino
Corporate Tracking Architecture: Long-Term Geolocation and Biometric Surveillance in Field Operations
Acquired Record: garanteprivacy.it

Corporate Tracking Architecture: Long-Term Geolocation and Biometric Surveillance in Field Operations

garanteprivacy.itItalia2026public
#privacy-lavoro#dati-biometrici#geolocalizzazione#garante-privacy#gdpr

Verified Primary Investigative Source: garanteprivacy.it — Italia

Share:

Editorial Transparency & Fair Use Notice

Investigative dossier curated and structured by the Unclessify editorial team based on official disclosures, court filings and declassified records published by garanteprivacy.it. Historical context, analytical synthesis, and editorial commentary are provided by Unclessify under Public Interest, Freedom of the Press, and Fair Use principles.

Read Full Editorial Policy & Source Transparency →

Official Records & Declassified Dossier

Public Interest and Executive Summary

The boundary between operational fleet coordination and intrusive workplace surveillance represents one of the most critical legal battlegrounds in modern labor relations. When technological tools deployed for dispatching field technicians simultaneously capture granular geolocation records and access credentials, regulatory frameworks require strict proportionality, explicit legal grounds, and absolute transparency.

A formal regulatory enforcement proceeding concluded on June 1, 2023, established that an enterprise maintained continuous mobile application telemetry capturing geolocation records dating back to 2014, while operating a biometric fingerprint security mechanism without appropriate legal baselines. This case underscores the systemic vulnerability of enterprise monitoring architectures that accumulate historical data without automated deletion routines.

The enforcement findings reveal that technical capability frequently outpaces compliance governance in corporate environments, exposing field personnel to persistent digital tracking. As biometric identification and continuous device telemetry become standard hardware features, establishing clear legal boundaries remains vital for protecting individual civil liberties in the workplace.

Historical and Regulatory Context

The expansion of digital workforce management tools over the past decade fundamentally altered enterprise logistics across Europe. Beginning in the early 2010s, enterprises transitioned from manual dispatch logs and radio communications to centralized mobile applications capable of logging device coordinates, technical job allocations, and system statuses in real time.

Technological implementations often outlasted the legal regimes under which they were initially conceived. As mobile applications deployed around 2012 expanded their capabilities to record device locations in 2014, European data protection standards underwent a historic transformation with the adoption and enforcement of the General Data Protection Regulation (GDPR), which entered into direct application in May 2018.

Under previous frameworks, including national provisions such as the Italian Data Protection Code (Legislative Decree 196/2003), specialized provisions governed remote employee oversight. In particular, Article 114 of the Code established strict barriers against covert employee monitoring, reinforcing protections originally defined under labor statutes against automated surveillance.

The technical architecture of modern smartphones facilitated unprecedented data accumulation. Rather than processing location events ephemerally to confirm service execution, enterprise databases systematically archived raw timestamps and geographic coordinates for years, creating longitudinal dossiers on employee movements without clear retention boundaries.

Simultaneously, enterprise access control systems integrated biometric sensors, particularly optical and capacitive fingerprint scanners. On November 12, 2014, the national supervisory authority issued a general prescriptive measure establishing specific guidelines for biometric data processing, defining narrow exemptions where preliminary administrative verification was not mandatory.

Despite these clear regulatory guidelines, corporate facilities frequently deployed commercial biometric hardware directly integrated with alarm and intrusion detection systems. From September 2019 through late October 2021, biometric authentication mechanisms operated without fulfilling statutory transparency requirements, treating sensitive biometric templates as routine security credentials.

Institutional and Corporate Entities

The administrative proceeding involved the national supervisory authority for personal data protection, acting under statutory enforcement powers to audit, inspect, and sanction unlawful data processing operations across Italian jurisdiction.

The regulatory authority operates under public law mandates to uphold fundamental rights under the Charter of Fundamental Rights of the European Union (Charter of Fundamental Rights), with specific oversight concerning workplace privacy, sensitive data categories, and algorithmic monitoring mechanisms.

The responding enterprise, operating field technical teams and operational facilities, submitted defensive documentation on July 12, 2021, and December 23, 2021. The submissions sought to clarify the operational necessity of mobile dispatch systems and the physical security architecture safeguarding enterprise premises.

The formal inquiry also engaged legal frameworks governing administrative declarations, explicitly governed by Article 168 of the Data Protection Code. This statutory provision establishes severe penal consequences for any party submitting false documentation or misleading statements to supervisory authorities during official inquiries.

Critical Evidence Analysis

Mobile Telemetry and Geolocation Persistence

Forensic inspection of the enterprise infrastructure identified the earliest functional record of the technician mobile application in 2012, with the earliest persistent geographic coordinate record dating to 2014. Source code extracts verified that the application contained dedicated functions specifically programmed to query, capture, and transmit device location coordinates alongside unique technician identifiers.

The primary compliance failure did not lie solely in real-time dispatching, but in the systematic retention of historical positioning records. The data repository contained detailed geographic coordinates, timestamps, and technician IDs spanning years, violating the core principle of data minimization established under Article 5(1)(c) of the GDPR.

“Sono state acquisite evidenze circa il primo record di funzionamento dell’app, risalente all’anno 2012, il primo record di acquisizione della posizione geografica, risalente all’anno 2014, stralcio del codice sorgente dell’app relativo alle funzioni di rilevazione della posizione geografica e identificativo dei tecnici interessati.”

The regulatory authority examined whether a valid legal basis existed under Article 6 or Article 88 of the Regulation. While the formal notice of violation issued on November 29, 2021, initially alleged a breach of Article 6, the final determination archived that specific count following technical clarifications, focusing enforcement instead on systemic transparency and proportionality deficits under Articles 5(1)(a) and 13.

Biometric Authentication and Security Systems

The investigation uncovered an uncertified biometric fingerprint mechanism integrated into the corporate alarm system, operational from September 2019 until October 29, 2021. The enterprise argued that the system adhered to the general prescriptive guidelines of November 12, 2014, claiming exemption from prior authorization requirements.

However, under Article 9(1) of the GDPR, biometric data processed for uniquely identifying natural persons constitutes a special category of data subject to an outright prohibition, unless a specific statutory exemption under Article 9(2) applies. In the employment context, Article 9(2)(b) requires explicit authorization under European Union or Member State law, supplemented by appropriate safeguards for fundamental rights.

“Il predetto sistema è stato in funzione dal settembre 2019 fino al 29 ottobre 2021, data in cui è stato fatto installare un sistema alternativo (‘sistema tag’) che non tratta dati biometrici ed è stato ‘cancellato il database di riferimento per attivazione/disattivazione impianto’.”

In the Italian legal order, Article 2-septies of the Code implements Article 9(4) of the GDPR, mandating compliance with specific security measures and administrative safeguards issued by the supervisory authority. The investigation determined that the enterprise failed to provide workers with adequate, transparent notices pursuant to Articles 12 and 13 prior to capturing biometric characteristics.

Remediation and Structural Deficiencies

On October 29, 2021, facing regulatory scrutiny, the enterprise decommissioned the biometric scanner and deployed a contactless tag-based identification system. Defensive filings submitted on December 23, 2021, confirmed the total deletion of the underlying biometric database used for alarm activation and deactivation.

The documented facts reveal a recurring structural vulnerability in enterprise IT governance: privacy compliance measures are frequently retrofitted only after administrative intervention, rather than implemented by design and by default. The multi-year retention of GPS records and the deployment of biometric access controls demonstrate how operational convenience often overrides data protection baselines.

Transparency and Legal Foundation

This investigative analysis is constructed from the official enforcement decision issued by the Italian Data Protection Authority on June 1, 2023, indexed under register document number 9913830.

Public disclosure and dissemination of this regulatory decision are governed by Article 5 of Italian Law No. 633/1941, which excludes official acts of State and public administrative bodies from copyright restrictions, placing them in the public domain.

The complete official decision, outlining procedural stages, defensive arguments, and statutory penalties, is publicly verifiable through the official institutional repository at garanteprivacy.it.

What this piece rests on

The text was checked against the facts listed below, extracted from the act above. It does not yet carry corroboration from independent sources.

The 20 facts verified in the text
  1. Sono state acquisite evidenze circa "il primo record di funzionamento dell'app, risalente all'anno 2012, il primo record di acquisizione della posizione geografica, risalente all'anno 2014, stralcio del codice sorgente dell'app relativo alle funzioni di rilevazione della posizione geografica e identificativo dei tecnici interessati".
  2. In data 12 luglio 2021 la Società ha inviato un'ulteriore integrazione documentale. 2.
  3. In data 29 novembre 2021, l'Ufficio ha effettuato, ai sensi dell'art. 166, comma 5, del Codice, la notificazione alla Società delle presunte violazioni del Regolamento riscontrate, con riferimento agli artt. 114 del Codice, 5, par. 1, lett. a), c), 6, 9, 13 e 88 del Regolamento.
  4. Circostanza, quest'ultima, a cui è stato posto rimedio" (v. nota cit., p. 13, 14); - in merito al sistema di rilevazione delle impronte digitali "il Garante - con Provvedimento generale prescrittivo in tema di biometria del 12.11.2014 - ha fornito delle Linee Guida, con riferimento al corretto utilizzo delle c.d. tecniche biometriche […].
  5. Le Linee Guida contemplano anche talune ipotesi di esonero da tale obbligo di verifica preliminare da parte del Garante" (v. nota cit., p. 16); - "in particolare, in tema di impronte digitali, il Provvedimento del Garante del 12.11.2014 di cui sopra, non richiede al datore di lavoro di ottenere il previo consenso, da parte dei lavoratori, per l'installazione di alcune tecnologie biometriche.
  6. Il riferimento è al "sistema di tag" installato in data 29.10.2021 che, nelle previsioni del Titolare del trattamento - e sempre subordinando le proprie valutazioni ai rilievi che il Garante vorrà svolgere al riguardo - dovrebbe andare a sostituire il rilevamento di impronte digitali associato al sistema di allarme […].
  7. In proposito si evidenzia che, salvo che il fatto non costituisca più grave reato, chiunque, in un procedimento dinanzi al Garante, dichiara o attesta falsamente notizie o circostanze o produce atti o documenti falsi ne risponde ai sensi dell'art. 168 del Codice "Falsità nelle dichiarazioni al Garante e interruzione dell'esecuzione dei compiti o dell'esercizio dei poteri del Garante". 3.1.
  8. Il predetto sistema è stato in funzione dal settembre 2019 fino al 29 ottobre 2021, data in cui è stato fatto installare un sistema alternativo ("sistema tag") che non tratta dati biometrici ed è stato "cancellato il database di riferimento per attivazione/disattivazione impianto" (all. 4, 5 scritti difensivi 23.12.2021).
  9. Affinché, quindi, il trattamento dei dati biometrici, in ambito lavorativo, sia consentito, la fattispecie deve innanzitutto rientrare nelle ipotesi in cui il trattamento sia "necessario per assolvere gli obblighi ed esercitare i diritti specifici del titolare del trattamento o dell'interessato in materia di diritto del lavoro [e della sicurezza sociale e protezione sociale]" (v. pure art. 88, par. 1, Regolamento).
  10. Tra l'altro, si precisa che il trattamento dei dati biometrici è consentito solo "nella misura in cui sia autorizzato dal diritto dell'Unione o degli Stati membri […] in presenza di garanzie appropriate per i diritti fondamentali e gli interessi dell'interessato" (art. 9, par. 2, lett. b), e cons. nn. 51-53 del Regolamento).
  11. Il quadro normativo vigente prevede, inoltre, che il trattamento di dati biometrici, per poter essere lecitamente posto in essere, avvenga nel rispetto di "ulteriori condizioni, comprese limitazioni" (cfr. art. 9, par. 4, del Regolamento).
  12. A tale disposizione è stata data attuazione, nell'ordinamento nazionale, con l'art. 2-septies (Misure di garanzia per il trattamento dei dati genetici, biometrici e relativi alla salute) del Codice.
  13. La norma prevede che è lecito il trattamento di tali categorie di dati al ricorrere di una delle condizioni di cui all'art. 9, par. 2, del Regolamento "ed in conformità alle misure di garanzia disposte dal Garante", in relazione a ciascuna categoria dei dati.
  14. Il datore di lavoro, titolare del trattamento, è, in ogni caso, tenuto a rispettare i principi di "liceità, correttezza e trasparenza", "limitazione delle finalità", "minimizzazione" nonché "integrità e riservatezza" dei dati e "responsabilizzazione" (art. 5 del Regolamento).
  15. I dati devono, inoltre, essere "trattati in maniera da garantire un'adeguata sicurezza" degli stessi, "compresa la protezione, mediante misure tecniche e organizzative adeguate, da trattamenti non autorizzati o illeciti e dalla perdita, dalla distruzione o dal danno accidentali" (art. 5, par. 1, lett. f), e art. 32 del Regolamento).
  16. Inoltre, sempre in merito al trattamento dei dati biometrici, è stato accertato che la Società non ha fornito un'idonea informativa agli interessati ai sensi dell'art. 13 del Regolamento.
  17. Come chiarito dall'art. 12 del Regolamento "il titolare del trattamento adotta misure appropriate per fornire all'interessato tutte le informazioni di cui agli articoli 13 e 14 […] in forma concisa, trasparente, intelligibile e facilmente accessibile […].
  18. La Società, per i motivi suesposti, ha pertanto violato gli artt. 5, par. 1, lett. a), 9, par. 2, lett. b) del Regolamento e dell'art. 13 del Regolamento dalla data di installazione e messa in funzione del sistema di allarme mediante trattamento dei dati biometrici, fino alla sua disinstallazione e sostituzione nel 29 ottobre 2021.
  19. Alla luce dei chiarimenti forniti, non si ritiene invece sussistente la violazione dell'art. 6 del Regolamento, contenuta nella notifica di violazione del 29 novembre 2021, che deve intendersi pertanto archiviata. 3.2.
  20. Oltre al dato relativo alla posizione geografica, risultano essere stati raccolti anche il dato relativo all'ora e alla data della rilevazione della posizione stessa, tra l'altro anche dati relativi a periodi molto risalenti nel tempo (2014).
Click to switch theme:

Comments (0)