Five-Year Retention of Employee Emails and Conditions for Access: The Garante's Decision

The Italian data protection authority Garante Per La Protezione Dei Dati Personali ("Garante") imposed an administrative fine of EUR 460,000 on Piaggio & C. S.p.A. by its decision dated June 18, 2026 and numbered 2026/476. The decision concerns the retention of corporate email accounts allocated to former employees for five years, the retrospective review of such correspondence for use in disciplinary proceedings, and the failure to respond to data subject requests.
Background of the Dispute
Two employees whose employment contracts were terminated for just cause at Piaggio in March 2023 requested confirmation twice from the employer that the corporate email accounts allocated to them had been deactivated. No response whatsoever was provided by the company within the one-month period set out in Article 12(3) of the GDPR.
The data subjects further alleged that the employer had accessed many emails and used them as evidence in the pending employment proceedings. The correspondence accessed amounted to at least 18 emails for one employee and 94 for the other, some dating back to April 2020 and including correspondence with personal accounts and with third parties.
In its defense, the data controller stated that, following internal reports in November 2022, a "defensive control" had been carried out in consultation with the data protection officer and limited by predetermined filters and keywords, and that employees' emails were retained throughout the employment relationship and for five years following its termination, while access logs were retained for six months.
Failure to Respond to Data Subject Requests
The Garante established that a corporate email address allocated to a specific employee, together with the correspondence passing through that account, constitutes personal data relating to that employee.
Accordingly, a request for confirmation that an email account has been deactivated must be characterized as a request for the cessation of the processing activities carried out until that moment, even where the data subject does not expressly state so. The legislation does not subject data subject requests to any formal requirement.
According to the Garante, while the existence of pending employment proceedings may justify restricting the exercise of a right, even in that scenario the controller remains obliged to provide the data subjects with a reasoned notification within the statutory period and to inform them of the available judicial and administrative remedies. Since no response whatsoever was provided in the case at hand, the Garante held that Article 12(3) had been infringed in connection with Article 17 of the GDPR.
The Retention Practice as the Source of Unlawfulness
The Garante stated that the actual source of the unlawfulness was the retention practice itself. The five-year retention period did not serve a purpose whose scope and limits had been determined in advance and did not rely on a valid legal basis. On this basis, the Garante found an infringement of the principles of purpose limitation, data minimization and storage limitation set out in subparagraphs (b), (c) and (e) of Article 5(1) of the GDPR.
The Garante further emphasized that the data contained in email correspondence falls within the scope of the confidentiality of communications protected under the constitution and that employees retain a reasonable expectation of privacy even in the workplace. It concluded that, even if email use is accepted as a working tool, the systematic collection and retention of email content and of the data connected to it results in the retrospective monitoring of employee activity, and that such monitoring, carried out without the legal and trade union safeguards afforded to employees under labor law, is unlawful.
In addition to the above, although the suspicion of unlawful conduct arose in November 2022, the review was found to cover correspondence dating back approximately two years. The Garante held that limiting the control through filters and keywords and carrying out a balancing test was not sufficient in itself, since the review relied on data that had been systematically collected and retained before any suspicion arose, and the unlawfulness could therefore not be cured.
The Sanction and the Principles Established by the Decision
Even where the employee's explicit consent exists, the application of a company policy permitting the email account of an employee whose contract has ended for any reason to be kept active for thirty days on vague "service needs" grounds and permitting incoming messages to be forwarded to other employees, was found to be unlawful.
The failure to set out the purposes and legal bases of data retention in the company's privacy notices was also considered a separate infringement of Article 5(1)(a) and Article 13 of the GDPR.
For these reasons, the Garante imposed an administrative fine of EUR 460,000 on account of keeping former employees' email accounts accessible for five years, reviewing the correspondence retrospectively, and breaching the principles governing retention periods.
The decision establishes two essential principles for controllers:
- A long-term email and log retention practice carried out on a "just in case" basis, without being limited by a specific purpose and legal basis, is unlawful.
- Requests that employees' email accounts no longer be used and that access be terminated must be treated as legitimate data subject requests without any formal requirement, and must be answered with reasons within the statutory period. The existence of pending litigation does not remove this obligation.
Assessment for Companies Operating Under the KVKK
Although the decision concerns the application of the GDPR, the principles on which it is based produce parallel results under the KVKK. The principles set out in Article 4 of the KVKK, namely that personal data must be relevant, limited and proportionate to the purposes for which they are processed and must be retained for the period stipulated in the relevant legislation or required for the purpose of processing, apply equally to the email accounts of former employees.
Within this scope, it is important for companies to review the following points as a priority:
- How long the email account of a former employee is kept active, and whether the closure and archiving steps are governed by a written procedure.
- Which specific legal obligation or interest the retention period envisaged for archived correspondence relies on, and whether that period is reflected in the Personal Data Retention and Destruction Policy and in periodic destruction processes.
- Whether a less intrusive method is feasible, such as sending an automatic notification to the sender indicating an alternative corporate contact address, instead of forwarding messages received at a former employee's email address to another employee.
- In which circumstances and through which approval mechanism correspondence may be reviewed, and whether the review is limited to data generated after the date on which the suspicion arose.
- Whether employee privacy notices clearly set out the purpose, legal basis, retention period and conditions applicable to the employer's review of the email account.
- Whether the retention period for access logs and the retention period for email content are determined separately.
Indeed, in its decision dated September 17, 2020 with individual application number 2016/13010, the Turkish Constitutional Court likewise held that the employer's review of corporate communication tools must satisfy the criteria of foreseeability, prior notification of the employee, limitation of the review to its purpose, and preference for the less intrusive method. Where an employer carries out a review of corporate email accounts contrary to the principles set out in the Constitutional Court's decision and uses the data so obtained against the employee, such conduct may not only give rise to serious administrative sanctions under the Personal Data Protection Law, but may also constitute offenses such as the violation of the confidentiality of communications under Article 132 of the Turkish Criminal Code or the violation of the privacy of private life under Article 134 of the Turkish Criminal Code. In this respect, the Piaggio decision may be said to align with the approach applied under Turkish law.
Conclusion
The Piaggio decision shifts the discussion on the review of employee emails from the moment of review to the moment of retention. The finding at the center of the decision is that, irrespective of how carefully the review was filtered, the retention of the data from the outset without being tied to a specific purpose constitutes unlawfulness.
Companies should therefore ask the following fundamental control question: On what legal basis, for what period and accessible to whom is the email account of a former employee currently being retained?
If there is no clear answer to this question based on a written procedure, the existing practice should be reassessed within the scope of the decision.
You can access the original text of the Decision here and its English summary here.
-
-
Notification!




