A report from the inside
The decision of 28 May 2026 begins with a report from someone at work who realises they are being followed. The complainant argues that the data was collected without the conditions of legitimacy laid down in Article 4 of Law No 300 of 20 May 1970, and without the necessary information about the installation of the systems.
That law is the Italian Workers’ Statute, and Article 4 is the provision that has governed remote monitoring by employers in Italy for more than half a century. Naming it immediately shifts the question from data protection to labour law: two disciplines that intertwine here, and that the decision holds together to the end.
The controller is invited to submit written defences or documents, or to request a hearing before the Authority, under Article 166(6) and (7) of the Code and Article 18(1) of Law No 689 of 24 November 1981. This is the ordinary sanctioning procedure with its safeguards: first the allegation, then the hearing.
What was being collected
The object of the monitoring is the company fleet, and with it the people who drive it. The decision refers expressly to the «processing of data relating to the geolocation of the personnel using company vehicles»: the wording is precise, and separates the technical datum from its consequence. To locate a vehicle is to locate whoever is driving it.
During the proceedings the authority provides further material, including evidence that a data protection impact assessment under Article 35 of the Regulation was carried out with regard to vehicle geolocation. But the moment at which that assessment was made is decisive, and on this point the decision does not bend: the processing «was also carried out in the absence of a prior data protection impact assessment».
The word holding the entire finding together is prior. An impact assessment is not a formality that can be recovered after the fact, once the Authority knocks: it exists to decide whether and how to activate a risky processing operation, and an assessment made after activation has nothing left to assess.
The referral that turns the Statute into a condition of lawfulness
The legally densest passage is the one explaining why a law from 1970 still governs digital surveillance in 2026.
The Italian data protection Code, «confirming the framework predating the amendments introduced by Legislative Decree No 101 of 10 August 2018, makes express reference to national sectoral provisions protecting the dignity of persons in the workplace, with particular regard to possible monitoring by the employer».
And here is the consequence: «by virtue of that referral, and having regard to Article 88(2) of the Regulation, compliance with Articles 4 and 8 of Law No 300 of 20 May 1970, and with Article 10 of Legislative Decree No 297/2003 (where the conditions apply), constitutes a condition of lawfulness of the processing».
This is not a courtesy nod towards labour law. It means that where the Statute’s procedures have not been followed — the union agreement or administrative authorisation, adequate information to workers — the processing is unlawful also from a data protection standpoint, irrespective of any other consideration. The labour-law breach becomes a breach of the European Regulation.
The prohibition on reuse
From that referral flows a rule with very wide practical effects, stated by the decision without hedging: the legal framework «therefore allows the controller (the employer) to use, in the context of further processing for the purposes of managing the employment relationship, only the information originally collected in compliance with the conditions and limits laid down in Article 4 of Law 300 of 1970».
This is the principle that stops surveillance from expanding on its own. Data gathered for a legitimate purpose — vehicle security, fleet logistics — does not thereby become available for assessing a person, reconstructing their movements or grounding a disciplinary measure. And if it was gathered outside the conditions of the Statute, it cannot be used at all.
A framework that comes from far away and from close by
The decision does not rule in isolation: it rests on a chain of precedent worth reading, because it shows how settled the subject has become.
There is the Council of Europe, with its Recommendation of 1 April 2015, CM/Rec(2015)5, and in particular principle 16. There is the Italian Court of Cassation, with judgment No 18302 of 19 September 2016, which upheld a Garante decision of 21 July 2011, No 308. And there is the Court of Justice of the European Union, with case C-65/23 of 19 December 2024.
Domestically, the Garante cites its own decisions of 13 March 2025, No 135, and 10 July 2025, No 410. These are recent: the field is moving, and the Authority is building its position one line at a time.
The provisions infringed
The final list of infringements is unusually long, and each entry describes a different facet of the same problem.
The Garante declares, under Article 57(1)(f) of the Regulation, the unlawfulness of the processing carried out by the authority for infringement of Article 5(1)(a), (b) and (c), and Articles 6, 25, 35 and 88 of the Regulation, as well as Articles 113 and 114 of the Code.
Article 5 gathers the principles: lawfulness and fairness, purpose limitation, minimisation. Article 6 concerns the legal basis — the question whether the processing could be done at all. Article 25 is data protection by design, which requires thinking about safeguards before building the system rather than after. Article 35 is the missing impact assessment. Article 88 is the provision opening the door to national employment law. Articles 113 and 114 of the Code are those invoking the Workers’ Statute.
Read together they say one thing: the system was switched on without first asking the questions that must be asked first.
The penalty, and who pays it
Having regard to Article 83(3) of the Regulation, the infringement attracts the administrative fine provided for in Article 83(5), and its amount is set with due regard to the elements listed in Article 83(2). The Garante also cites the European Data Protection Board’s «Guidelines 4/2022 on the calculation of administrative fines under the GDPR» of 24 May 2023, at point 60.
The addressee is a public body: the order is directed to Azienda Tutela della Salute per la Liguria, in the person of its legal representative pro tempore, with registered office at Piazza Della Vittoria 15, 16121 Genoa, tax code 02421770997. The sum is 6,000 euro.
The decision adds an option provided for by Article 166(8) of the Code: the offender may settle the matter by paying, within thirty days, an amount equal to half the fine imposed. Failing that, the injunction requires payment of the 6,000 euro within thirty days of notification, failing which enforcement measures follow.
That halving mechanism is worth pausing on. It is a settlement device common to Italian administrative penalties, and it trades a lower payment for the end of the dispute: whoever pays the reduced amount closes the matter rather than contesting it. In a case turning on principle rather than on the size of the sum, the option quietly reveals what the penalty is really for. It is not the money that carries the message.
What remains
As with every injunction order, the Garante directs publication on its website under Article 166(7) of the Code and Article 16(1) of the Garante’s Regulation No 1/2019, and finds that the conditions of Article 17 of that same Regulation are met.
Six thousand euro, halvable to three thousand, is a figure a regional health authority absorbs without a tremor. But the penalty is not the substance of the decision: the substance is the finding that a public employer tracked its own staff without first establishing that it could, and that an impact assessment produced during the proceedings does not cure what had to be decided before the system was switched on.
It is a principle that touches every company fleet in the country, and the fact that a public administration is the one that got it wrong makes it more instructive, not less.

