Investigative Journalism
Unclessify — Journal of Investigation and Declassification, Founded by Graziano Costantino
Unclessify — Journal of Investigation and Declassification, Founded by Graziano Costantino
Workplace Surveillance and Unauthorized Camera Deployment: The Hanako Case
Acquired Record: garanteprivacy.it

Workplace Surveillance and Unauthorized Camera Deployment: The Hanako Case

garanteprivacy.itItalia2024public
#videosorveglianza#privacy#lavoro#sicurezza-dati#statuto-dei-lavoratori

Verified Primary Investigative Source: garanteprivacy.it — Italia

Share:

Editorial Transparency & Fair Use Notice

Investigative dossier curated and structured by the Unclessify editorial team based on official disclosures, court filings and declassified records published by garanteprivacy.it. Historical context, analytical synthesis, and editorial commentary are provided by Unclessify under Public Interest, Freedom of the Press, and Fair Use principles.

Read Full Editorial Policy & Source Transparency →

Official Records & Declassified Dossier

Public Interest and the Realities of Remote Surveillance

The boundary between commercial property security and covert employee surveillance is increasingly contested in the service sector. When hospitality venues deploy network-connected closed-circuit television systems capable of remote smartphone streaming, the constitutional and statutory rights of workers are directly placed under digital oversight. Regulatory scrutiny reveals that even small-scale installations trigger comprehensive data protection obligations that employers cannot circumvent through ex-post regularizations.

On August 15, 2024, an on-site operational check conducted at the catering premises of Hanako s.r.l. in Padua unmasked an active five-camera surveillance network operating without the mandatory statutory agreements or labor inspectorate clearances. The case encapsulates a systemic compliance deficit across the service economy, where digital equipment is deployed prior to securing statutory authorization. This regulatory intervention establishes that real-time visual streaming without local recording remains fully actionable under European and national privacy jurisprudence.

By dissecting the enforcement trajectory initiated by financial police investigators and concluded by regulatory injunction, this dossier examines the structural intersection between labor protection law and international privacy governance. The findings demonstrate that technological convenience cannot supersede explicit statutory safeguards designed to prevent the digital subordination of workers in everyday commercial environments.

Historical Context and Statutory Intersections

Italian labor jurisprudence has maintained strict protections against unilateral worker monitoring since the enactment of Law No. 300 of May 20, 1970, commonly known as the Workers’ Statute. Under Article 4 of this foundational statute, audiovisual installations and other technical instruments capable of remotely monitoring workers’ activities may only be installed following collective agreements with internal union representations or, failing that, explicit prior authorization from the competent territorial labor inspectorate.

The integration of the General Data Protection Regulation (EU) 2016/679 into Italian national law preserved these specific protections through Article 88 of the Regulation, which explicitly allows Member States to maintain or introduce more specific rules safeguarding employment rights. Italian legislators operationalized this mechanism through Article 114 of the national Privacy Code (Legislative Decree No. 196/2003), establishing that any processing of personal data in violation of Article 4 of Law No. 300/1970 constitutes an unlawful processing activity subject to both administrative and criminal sanctions under Article 171 of the Code.

The operational chronology began during a public holiday inspection on August 15, 2024, when officers from the Guardia di Finanza of Padua entered the restaurant operated by Hanako s.r.l. The inspecting officers identified five operational cameras: four monitoring external perimeter zones and one positioned internally, directly covering areas where employees performed their daily duties. At the moment of the inspection, the company lacked any union agreement or administrative authorization from the competent labor authority.

Following the inspection, Hanako s.r.l. sought to regularize its legal standing by obtaining authorization No. 40218 from the Territorial Labor Inspectorate of Padua-Rovigo on October 31, 2024. However, the transmission of the formal operational report by the Guardia di Finanza’s Rome-based Privacy and Technological Fraud Unit on February 25, 2025, consolidated the regulatory evidence base. The documentation established that the system had operated unlawfully during the period preceding the administrative clearance.

Institutional Actors and Corporate Entities

The regulatory procedure involves a distinct network of specialized public authorities, judicial bodies, and private commercial entities operating within the European regulatory matrix:

  • Hanako s.r.l.: A private commercial entity operating in the catering sector in Padua, Italy, designated as the data controller responsible for the operational surveillance installation.
  • Guardia di Finanza: The Italian militarized economic and financial police authority, acting through its local unit in Padua for field inspections and its specialized Privacy and Technological Fraud Unit (Nucleo privacy e frodi tecnologiche) in Rome for technical protocol transmissions.
  • Garante per la protezione dei dati personali: The national supervisory authority for data protection in Italy, empowered under GDPR Article 58 to exercise corrective and sanctioning powers against non-compliant entities.
  • Pasquale Stanzione: President of the Italian Data Protection Authority, signatory to the formal injunction order issued under collegiate authority.
  • Ginevra Cerrina Feroni: Vice President and designated Relator within the regulatory proceeding, responsible for the legal evaluation of the evidentiary record.
  • Ispettorato del Lavoro di Padova-Rovigo: The territorial public agency empowered to grant statutory administrative authorizations for workplace surveillance equipment under Statuto dei Lavoratori.

Critical Analysis of the Evidence

The central evidentiary finding in this case rests upon the operational state of the monitoring hardware during the August 2024 inspection. The regulatory findings established that five cameras were actively processing personal visual data while employees were stationed within the capture fields. The defense that data was not stored on physical hard drives, but merely streamed live to a mobile device, was dismissed as legally inconsequential under established precedent.

“The use of video surveillance systems constitutes processing of personal data under Article 4(1)(2) of the Regulation—even in cases where there is only collection of personal data and remote viewing via smartphone without recording, as declared in the case at issue.”

This statutory determination aligns directly with Italian Supreme Court case law (Cass. September 2, 2015, No. 17740), reinforcing that real-time surveillance represents an active processing operation. Transmitting a live stream over digital networks subjects workers to potential continuous oversight, thereby fulfilling all criteria of personal data processing under European law, regardless of whether a permanent digital archive is generated.

A second critical failure identified in the investigation concerns transparency and informative obligations under Article 13 of the GDPR. Hanako s.r.l. failed to display mandatory preliminary signage informing data subjects—both workers and patrons—of the monitoring system, the identity of the controller, and the specific purposes of the processing. The regulatory framework requires clear, multi-layered visual information, which may be paired with standard icons under Article 12(7) of the Regulation to ensure immediate intelligibility.

“Such information may be provided in combination with an icon to provide, in an easily visible, intelligible, and clearly legible manner, a meaningful overview of the intended processing.”

The evidence also demonstrates a total failure to document technical and organizational security measures under Article 32 of the GDPR. Transmitting unencrypted or inadequately managed remote video feeds to consumer smartphones creates structural vulnerabilities, exposing visual workplace data to unauthorized access and interception. The data controller failed to prove the existence of internal access controls, user credential auditing, or secure transmission protocols.

Crucially, the subsequent issuance of authorization No. 40218 by the Labor Inspectorate on October 31, 2024, did not cure the retroactive unlawfulness of the system. The Garante established that statutory protections under Article 4 of Law No. 300/1970 must precede system activation. Operating surveillance infrastructure prior to official authorization constitutes a complete statutory infraction that cannot be mitigated by post-factum administrative filings.

Evaluating the proportionality, dissuasiveness, and effectiveness criteria mandated by Article 83(1) of the GDPR, the Authority levied a pecuniary administrative sanction of €2,000.00 against Hanako s.r.l. for cumulative breaches of Articles 5(1)(a), 5(1)(f), 13, and 32 of the Regulation, in conjunction with Article 114 of the Italian Privacy Code.

Transparency, Legal Basis, and Institutional Traceability

The foundational documentation governing this investigation is rooted in official Italian administrative proceedings published in the public registry of the national supervisory authority. In accordance with Italian Law No. 633 of April 22, 1941, Article 5, official texts of the State and public administration acts are not subject to copyright restrictions and reside in the public domain, ensuring full civic and journalistic scrutiny.

The authoritative instrument underlying this dossier is the formal Injunction Order (Ordinanza Ingiunzione) issued on March 12, 2026, cataloged under Document Card No. 10240451 by the Garante per la protezione dei dati personali. The instrument carries the institutional signatures of President Pasquale Stanzione, Relator Ginevra Cerrina Feroni, and Vice Secretary General Filippi. Judicial appeal against the ruling is preserved under GDPR Article 78, Article 152 of the Privacy Code, and Article 10 of Legislative Decree No. 150/2011, open within thirty days before the ordinary judicial authorities.

Primary document reference: Provvedimento del 12 marzo 2026 [10240451] - Garante per la protezione dei dati personali.

What this piece rests on

The text was checked against the facts listed below, extracted from the act above. It does not yet carry corroboration from independent sources.

The 19 facts verified in the text
  1. Con nota pervenuta il 25.2.2025, la Guardia di Finanza di Roma – Nucleo privacy e frodi tecnologiche ha trasmesso al Garante il verbale delle operazioni compiute da parte della Guardia di Finanza di Padova in relazione all’attività di ristorazione esercitata da Hanako s.r.l. (di seguito la “Società”).
  2. Durante tali verifiche, svoltesi il 15.8.2024, è stata accertata la presenza di un impianto di videosorveglianza (composto da 4 telecamere esterne ed una interna) nonché la presenza di lavoratori nelle aree interessate dalle riprese.
  3. All’esito delle verifiche, è stata trasmessa all’Autorità copia della comunicazione ricevuta dall’Ispettorato del lavoro di Padova-Rovigo con la quale è stata trasmessa l’autorizzazione n. 40218 all’installazione di un sistema di videosorveglianza presso la società, a far data dal 31 ottobre 2024 (data successiva al giorno delle verifiche). 1.2.
  4. Nelle stesse linee guida si prevede inoltre che “tali informazioni possono essere fornite in combinazione con un’icona per dare, in modo ben visibile, intelligibile e chiaramente leggibile, un quadro d’insieme del trattamento previsto (articolo 12, paragrafo 7, del RGPD).
  5. L’utilizzo di sistemi di videosorveglianza determina, inoltre, un trattamento di dati personali ai sensi dell’art. 4, par. 1, n. 2, del Regolamento – anche nel caso in cui vi sia solo raccolta di dati personali e visualizzazione da remoto degli stessi mediante smartphone senza registrazione, come dichiarato nel caso di specie (in tal senso, v. anche Cass. 2 settembre 2015, n. 17740).
  6. Tale trattamento deve pertanto deve essere effettuato nel rispetto della disciplina di protezione dei dati personali e, per quanto qui di diretto rilievo, dei principi contenuti nell’art. 5, par. 1, lett. a) del Regolamento, in particolare del principio di liceità, il quale si declina nel dovere di osservare quanto prescritto dall’art. 4, legge 20 maggio 1970, n. 300 in base all’art. 114 del Codice.
  7. Coerentemente con tale impostazione, l’art. 88 del Regolamento ha fatto salve le norme nazionali di maggior tutela (“norme più specifiche”) volte ad assicurare la protezione dei diritti e delle libertà con riguardo al trattamento dei dati personali dei lavoratori.
  8. Al riguardo, come è noto, il legislatore nazionale ha approvato, quale disposizione più specifica, l’art. 114 del Codice che tra le condizioni di liceità del trattamento ha stabilito l’osservanza di quanto prescritto dall’art. 4, legge 20 maggio 1970, n. 300.
  9. La violazione dell’art. 88 del Regolamento è soggetta, ricorrendone i requisiti, all’applicazione di una sanzione amministrativa pecuniaria ai sensi dell’art. 83, par. 5, lett. d) del Regolamento.
  10. La violazione di tale disposizione è penalmente sanzionata (v. art. 171 del Codice).
  11. Si rappresenta infine che per il trattamento dei dati personali, ivi compreso quello effettuato mediante l’utilizzo di sistemi di videosorveglianza, vanno rispettate misure tecniche e organizzative previste dall’art. 32 del Regolamento al fine di garantire la sicurezza del trattamento e l’accesso ai dati ai soli soggetti autorizzati. 3.
  12. Tale condotta si pone in contrasto con quanto stabilito dall’art. 13 del Regolamento, in base al quale il titolare del trattamento è tenuto a fornire all’interessato tutte le informazioni relative alle caratteristiche essenziali del trattamento, nonché del principio generale di trasparenza del trattamento di cui all’art. 5, par. 1, lett. a) del medesimo Regolamento. 3.2.
  13. Alla luce di quanto rappresentato e dei termini complessivi della vicenda in esame, si ritiene pertanto di adottare un’ordinanza ingiunzione ai sensi dell’art. 58, par. 2, lett. i) del Regolamento per l’applicazione di una sanzione amministrativa pecuniaria in ordine alla violazione delle disposizioni sopra richiamate al punto 4.1. 4.5.
  14. In ragione dei suddetti elementi, valutati nel loro complesso, e ai principi di effettività, proporzionalità e dissuasività previsti dall’art. 83, par. 1, del Regolamento, si ritiene di determinare l’ammontare della sanzione pecuniaria nella misura di euro 2.000,00 (duemila) per la violazione degli artt. 5, par. 1, lett. a) e f), 13, 32 del Regolamento e 114 del Codice.
  15. TUTTO CIÒ PREMESSO, IL GARANTE dichiara, ai sensi degli artt. 57, par. 1, lett. f) e 83 del Regolamento, l’illiceità del descritto trattamento effettuato dal titolare del trattamento individuato in premessa (al punto 1) con violazione degli artt. 5, par. 1, lett. a) e f), 13 e 32 del Regolamento nonché 114 del Codice e 4, l. n. 300/1970;
  16. ORDINA al titolare del trattamento di pagare la somma di euro 2.000,00 (duemila) a titolo di sanzione amministrativa pecuniaria per la violazione indicata in motivazione;
  17. INGIUNGE al medesimo titolare del trattamento: ai sensi degli artt. 58, par. 2, lett. i), del Regolamento, di pagare la somma di euro 2.000,00 (duemila), secondo le modalità indicate in allegato, entro 30 giorni dalla notifica del presente provvedimento, pena l’adozione dei conseguenti atti esecutivi a norma dell’art. 27 della legge n. 689/1981.
  18. Ai sensi dell’art. 78 del Regolamento, degli artt. 152 del Codice e 10, d.lgs. 1° settembre 2011, n. 150, avverso il presente provvedimento è possibile proporre ricorso dinanzi all’autorità giudiziaria ordinaria, a pena di inammissibilità, entro trenta giorni dalla data di comunicazione del provvedimento stesso ovvero entro sessanta giorni se il ricorrente risiede all’estero.
  19. Roma, 12 marzo 2026 IL PRESIDENTE Stanzione IL RELATORE Cerrina Feroni IL VICE SEGRETARIO GENERALE Filippi Scheda Doc-Web 10240451 Data 12/03/26 Argomenti Misure di sicurezza Videosorveglianza Informativa Lavoro privato Tipologie Ordinanza ingiunzione o revoca Vedi anche (1) NEWSLETTER del 29 luglio 2026 - Dal Garante privacy sanzione di 460mila a Piaggio & C.
Click to switch theme:

Comments (0)