Lead: Public Interest and the Boundaries of Municipal Surveillance
The boundary between administrative asset protection and unlawful employee monitoring represents one of the most critical battlegrounds in European data protection law. When public sector entities deploy video surveillance across operational facilities without adhering to strict statutory labor safeguards, they undermine systemic constitutional protections established to safeguard human dignity in the workplace.
This case exposes the structural vulnerability of municipal data governance when local administrations bypass statutory labor negotiations, fail to conduct mandatory Data Protection Impact Assessments (DPIAs), and deploy flawed legal notices. The regulatory response establishes an unyielding precedent: operational necessity cannot override mandatory transparency or statutory employee protections.
Historical and Institutional Context
The regulatory architecture governing workplace monitoring in Italy is rooted in Article 4 of Law No. 300 of May 20, 1970 ([[Statuto dei lavoratori|Q3968662]]), historically enacted to prevent authoritarian surveillance and unilateral employer control. With the integration of European privacy standards under Regulation (EU) 2016/679 ([[General Data Protection Regulation|Q11723]]), national labor safeguards were directly incorporated through Article 88(2), which permits Member States to establish specific rules protecting workers’ dignity and transparency.
Over recent years, local public administrations have faced mounting pressure to secure public equipment and municipal depots against theft and damage. However, administrative attempts to separate asset security from workplace monitoring frequently run afoul of statutory protections, especially when municipal personnel access secured depots to retrieve and store official vehicles during everyday operational duties.
Municipal compliance failures often stem from a fundamental misapprehension regarding what constitutes a protected work environment under labor law. Local authorities have increasingly attempted to treat secondary facilities—such as storage warehouses, equipment garages, and logistics yards—as non-work environments simply because worker occupancy is episodic rather than permanent.
The supervisory intervention of the national data protection authority ([[Garante per la protezione dei dati personali|Q3758368]]) reflects a broader institutional campaign to eliminate unilateral electronic surveillance mechanisms in the public sector. The enforcement record demonstrates that intermittent physical presence does not diminish statutory labor rights nor excuse public controllers from conducting mandatory prior risk evaluations.
Actors Involved
The principal oversight entity in this proceeding is the Italian Data Protection Authority ([[Garante per la protezione dei dati personali|Q3758368]]), acting pursuant to its supervisory and corrective powers under GDPR Article 58 and Article 166 of the national Privacy Code. The supervisory authority functions as the statutory guarantor of individual data rights, enforcing compliance through formal inquiries, compliance audits, and pecuniary administrative sanctions.
The responding party is the municipal administration (the Municipality), acting in its legal capacity as the data controller responsible for the operational management of municipal infrastructure and the supervision of local public workers. The controller maintained administrative control over the municipal warehouse where the electronic monitoring apparatus was installed and operationalized.
The complainant is an individual affected worker who formally alerted the supervisory authority to the presence of unauthorized surveillance hardware within the municipal facility. This complaint triggered the formal regulatory investigation under Article 77 of the GDPR and national administrative inquiry procedures established by Law No. 689/1981.
Critical Analysis of Evidence
The evidentiary record established during the supervisory investigation centers on three primary compliance failures: the complete absence of prior statutory labor procedures, defective transparency declarations, and the failure to execute a mandatory Data Protection Impact Assessment under Article 35 of the GDPR.
The Workplace Classification Defense
In its formal defense submitted under Article 166 of the Privacy Code and Article 18(1) of Law 689/1981, the municipal administration attempted to justify the unannounced installation of video surveillance cameras by claiming the depot did not constitute an authentic place of employment. The Municipality formally asserted its position in the regulatory record:
“l’accesso al magazzino comunale, garantito agli operai incaricati dall’Ente avviene solo in casi di necessità per recuperare ovvero depositare i mezzi utili all’espletamento dell’attività che viene svolta sul territorio”
The supervisory authority categorically rejected this restrictive interpretation. Under Article 4 of Law 300/1970 and Article 88(2) of the GDPR, any operational location where employees execute assigned duties—including retrieving vehicles, loading tools, or depositing operational machinery—constitutes a workplace subject to statutory co-determination procedures, requiring prior agreement with trade union representatives or authorization from the territorial labor inspectorate.
The Transparency Deficit and Erroneous Legal Bases
The investigation uncovered systemic defects in the information notices provided to municipal staff under Articles 12, 13, and 14 of the GDPR. While the Municipality claimed to have distributed general privacy disclosures to its workforce, it acknowledged that the documentation omitted all references to video surveillance operations, arguing that employees were not direct subjects of the monitoring apparatus:
“non è stata redatta ai sensi dell’art. 4 comma 3 della l. 300/1970 in quanto i dipendenti non sono oggetto di trattamento relativo alla videosorveglianza”
This argument was found to be legally untenable. Statutory labor guarantees and data protection mandates require an explicit, accessible privacy notice detailing video surveillance parameters, camera angles, and data retention durations regardless of whether the employer intends to use footage for disciplinary or performance evaluation purposes under Article 4(3) of Law 300/1970.
Furthermore, internal municipal compliance documents erroneously cited Article 6(1)(e) and Article 9(2)(g) of the GDPR without establishing the necessary legal preconditions or articulating the systematic operational logic demanded by Article 35(7)(a) of the Regulation. The citation of special-category processing bases for general municipal surveillance demonstrated a pronounced failure of administrative accountability.
Absence of Prior Impact Assessment and Remedial Outcomes
The deployment of optical surveillance over workers without prior consultation or safeguards constituted a direct violation of Article 35 of the GDPR. A comprehensive Data Protection Impact Assessment is an indispensable prerequisite when introducing technologies capable of systematic remote employee oversight:
“Alla luce di tutte le considerazioni che precedono, deve concludersi che il Comune ha posto in essere un trattamento di dati personali dei lavoratori, mediante il sistema di videosorveglianza in questione, in assenza di una preliminare valutazione di impatto sulla protezione dei dati e, pertanto, in violazione dell’art. 35 del Regolamento.”
Following the formal initiation of enforcement proceedings, the Municipality deactivated the optical surveillance apparatus and ceased all associated personal data processing activities. Because the unlawful conduct had fully exhausted its operational effects, the Authority determined that supplementary corrective orders under Article 58(2) were unnecessary, proceeding instead with an administrative pecuniary sanction pursuant to Article 58(2)(i), Article 83, and Article 166(7) of the Privacy Code.
Transparency and Legal Framework
This investigative analysis is constructed directly from official administrative records issued by the national supervisory authority, specifically the formal injunction decision published under registry reference Provvedimento del 12 febbraio 2026 [10226611]. The primary source document is officially cataloged and maintained within the public institutional repository of the Italian Data Protection Authority at https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10226611.
Under Article 5 of Italian Law No. 633/1941, official texts of legislative, administrative, and judicial acts of the State and public administrations are exempt from copyright and remain strictly within the public domain. The publication of this analytical dossier serves the vital public interest in administrative transparency, regulatory accountability, and the preservation of fundamental employee data rights across public sector institutions.

