A narrow ruling, not a ban on workplace investigations
On June 18, 2026, Italy's data protection authority, the Garante per la protezione dei dati personali, fined Vespa maker Piaggio & C. Spa €460,000 for how it handled employee email during two internal misconduct investigations. The decision, published as provvedimento 10272529, followed complaints from two former employees whose mailboxes Piaggio had searched after their departure. Investigators pulled 112 emails combined — 94 from one employee, 18 from the other — some dating back roughly two years before the company's suspicions of wrongdoing had even formed, according to the Garante's account confirmed in its own July newsletter.
Steelmanning the company's position
Piaggio's underlying instinct was not unreasonable. Employers have a legitimate interest in investigating suspected misconduct — theft, leaks, breach of fiduciary duty — and corporate email is often the clearest evidentiary trail available. Notably, Italy's labor courts upheld the dismissals that followed, finding the underlying conduct proven on the same email evidence the Garante later ruled had been unlawfully collected, a split outcome documented by GamingTechLaw's analysis of the case. That divergence is the crux of the story: a labor judge can find the evidence reliable enough to end an employment relationship while a privacy regulator simultaneously finds the process that produced it unlawful. Both can be right, because they are answering different questions — was the conduct real, versus was the surveillance proportionate.
Where Piaggio actually went wrong
The Garante's fine did not rest on the fact that Piaggio investigated its employees. It rested on three specific, bounded failures. First, retention: Piaggio backed up employee mailboxes for the full duration of employment and kept them for up to five years after termination — a period the company itself reduced to three months only after the Garante intervened — while access logs sat on the system for six months. Second, retroactivity: emails were pulled from long before any suspicion existed, meaning the company was not investigating a specific, dated concern but mining an indefinite archive after the fact. Third, transparency and rights: Piaggio gave employees inadequate notice of the legal basis and retention periods for mailbox data, and it ignored former employees' requests to confirm their accounts had been deactivated. The decision cites GDPR Articles 5(1)(a), (b), (c) and (e) on lawfulness and data minimization, Article 6 on legal basis, Articles 12(3), 13 and 17 on transparency and erasure, and Article 88 — the provision that lets member states set employment-specific safeguards — alongside Article 114 of Italy's own Privacy Code and Article 4 of the 1970 Workers' Statute, which requires heightened protection for remote-monitoring tools used on staff.
Proportionate, and a useful data point for compliance design
Compare the number to the Garante's own recent enforcement record. In 2021 it fined Deliveroo Italy €2.5 million and Foodinho €2.6 million for opaque, large-scale algorithmic monitoring of thousands of gig workers — systemic practices affecting an entire workforce's daily operations. Piaggio's fine, by contrast, addresses a single HR investigation involving two former employees and a retention policy that was overbroad but not deployed as a surveillance dragnet. The roughly five-to-six-times smaller penalty reflects that distinction reasonably well, and it should reassure companies that the Garante is not treating every misconduct investigation as a GDPR violation on par with algorithmic mass monitoring.
The compliance lesson is cheap to implement
What this ruling actually demands of employers is not expensive. A written email retention policy with a defined, short post-termination window; a documented date on which suspicion of misconduct arose, so that any email review can be shown to start from that point rather than reaching backward indefinitely; and a timely response process for departing employees' data requests. None of that requires new technology or meaningfully slows down legitimate investigations — it requires paperwork discipline that most competent HR and legal departments already have templates for. Article 88's opening clause exists precisely so that member states can calibrate employment-data rules to local labor law, and Italy's Workers' Statute layer adds a genuine compliance wrinkle for multinationals used to a GDPR baseline elsewhere in the bloc — but that friction is modest next to the alternative of an indefinite, unbounded email archive sitting on every departed employee.
The bottom line
Regulators get criticized, often fairly, when enforcement actions read as a blanket tax on ordinary business activity. This one does not. The Garante left Piaggio free to investigate misconduct, use email evidence, and win in labor court on that evidence — it fined the company for keeping years of every employee's mailbox on ice indefinitely and reaching into it retroactively without a defined trigger. That is a proportionate reading of GDPR's minimization principle, and one other EU employers can comply with cheaply by simply writing down what they are already supposed to be doing.