
Italian Data Protection Authority Fines Piaggio €460,000 for Unlawful Employee Data Processing
regulations_and_complianceprivacy_and_personal_dataaccountabilitybackupprivacy_codepersonal_dataNIS_2_directiveDPOtrainingprivacy_authorityGDPRguideNISNIS_2privacyEU
The Italian Data Protection Authority (Garante per la protezione dei dati personali) imposed a €460,000 fine on Piaggio for unlawfully accessing and processing employee data via corporate email systems. The sanction also included a ban on further use of the illegally collected data. The case establishes new legal boundaries for workplace monitoring under GDPR and national privacy regulations. No specific technical details, dates, or CVE IDs were provided in the notice. The ruling serves as a precedent for other organizations regarding employee privacy and data processing limits.