Justice

It is permissible to track the location of remote workers in accordance with agreed criteria

According to the Court of Cassation, ‘proportionality’ between the use of technology and the protection of privacy is of fundamental importance

 alex.pin - stock.adobe.com

4' min read

Translated by AI
Versione italiana

4' min read

Translated by AI
Versione italiana

The geolocation of workers, particularly when it intersects with remote working, is one of the most sensitive areas in the relationship between the organisational needs of a company or public body and the protection of privacy. The judgement of the Court of Cosenza of 1 July 2026, which quashed injunction order 135/2025 of the Data Protection Authority, addresses precisely this balance and does so with a clear message: a technological tool cannot be judged solely on the basis of what it could theoretically do, but must be assessed according to the way in which it is actually used.

The story

The case stems from an appeal lodged by an organisation employer, which was fined 50,000 euros by the Data Protection Authority in relation to its use of the Time Relax system, employed to record employees’ attendance whilst working remotely. An employee, whose individual contract specified three possible locations for carrying out her work, had been subject to checks which revealed that she had been present at locations not compatible with those declared. This led to disciplinary proceedings, which were subsequently suspended, a complaint to the Data Protection Authority and also a criminal complaint, which was later dismissed.

Loading...

According to the Data Protection Authority, the system would have allowed for constant and indiscriminate monitoring of the employee, in breach of the GDPR, the Privacy Code and the provisions of the Workers’ Statute on remote monitoring. The Court, however, interprets the tool’s operation differently. According to the judicial findings, Time Relax did not continuously track the employee’s movements, but recorded geographical coordinates, location, date and time only at the moment of clocking in. Furthermore, spot checks were carried out in accordance with a defined procedure: direct call, on-call period, request for double clocking in, and consent to geolocation. The system did not record any further data, did not operate outside working hours, and had been approved by the trade unions, as well as being included in the 2024–2026 Integrated Activity and Organisation Plan (PIAO).

The key legal issue concerns Article 4 of the Workers’ Statute. The provision distinguishes between tools for recording access and attendance and those that may enable remote monitoring, which are permitted where specific needs exist and subject to trade union agreement or administrative authorisation. The Court classifies Time Relax as an attendance recording system, whilst acknowledging that the geolocation component nevertheless requires enhanced safeguards. In this specific case, however, those safeguards had been put in place: there was a trade union agreement, information provided to employees, and technical limitations and specific organisational purposes had been established.

It is from this approach that the most significant criticism levelled at the Data Protection Authority’s decision stems. The Authority had argued that the flexible nature of agile working would be difficult to reconcile with the monitoring of working hours and the locations where work is carried out. The judge observes, however, that the Data Protection Authority cannot take the place of the employer in choosing the organisational model, provided that it is lawful, transparent and proportionate. The Authority’s role is to verify the correctness of data processing, not to determine the best way to organise remote working.

The position of case law

The decision forms part of a line of case law that focuses on the practical operation of the instrument.

The Court of Cassation has repeatedly made it clear that not every technology that can also be used for monitoring is, by that fact alone, unlawful: it is necessary to assess the purposes, operating procedures, safeguards put in place and the information provided to the employee. Enhanced time-recording systems, for example, are not prohibited in themselves; they become problematic when used for continuous, covert or disproportionate monitoring. The key word is ‘proportionality’ in their use.

The same approach is also evident at European level. In France, the CNIL and case law permit the geolocation of workers provided there are legitimate purposes, prior notification and proportionality in the processing. In Germany, continuous, covert or disproportionate tracking is considered particularly problematic, whilst targeted, transparent monitoring that is necessary to meet specific organisational needs may be permitted. The European Court of Human Rights, starting with Bărbulescu v. Romania, has furthermore framed the monitoring of workers as a matter of balancing employers’ powers against the right to private life, emphasising prior information, the scope of monitoring, the degree of intrusion, legitimate grounds for monitoring and procedural safeguards.

This is the most significant aspect of the judgement. If a technology is penalised solely on the basis of its potential, regardless of the limits within which it is configured and used, there is a risk of creating a dangerous regulatory uncertainty, by allowing supervisory authorities broad discretion, contrary to the liberal principles of the rule of law. Any digital tool, in fact, can theoretically be used in an intrusive manner. However, data protection law should not transform every technical possibility into a presumption of unlawfulness.

Governance

In terms of governance, anyone intending to use remote time-recording systems or tools that involve a form of location tracking must carry out an impact assessment where necessary, provide clear information, secure trade union agreements or authorisations where required, draw up detailed internal policies, set technical limits on data collection, defined retention periods and periodic checks on the actual use of the tool. However, the Data Protection Authority cannot become the company’s Chief Operating Officer.

Loading...

The ‘Lampi di Governance’ column is edited by Alessandro De Nicola

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti