Work

Checking emails is a breach of privacy, but the dismissal is valid

The Court of Pisa has ruled that the evidence gathered remains admissible in court

fizkes - stock.adobe.com

3' min read

Translated by AI
Versione italiana

3' min read

Translated by AI
Versione italiana

The positions adopted by the Data Protection Authority regarding the management and monitoring of the email account assigned to employees for the purposes of their work are beginning to meet with some resistance from labour courts.

The ruling of the Court of Pisa

In a ruling dated 13 June, the Court of Pisa held that the dismissal for just cause of an employee whose misconduct had been established through checks (which were targeted and carried out following the emergence of a well-founded suspicion) was lawful of the messages contained in the company email account assigned to him.

Loading...

The Court rightly considered irrelevant, for the purposes of assessing the lawfulness of the dismissal, the decision of the Data Protection Authority which, in the meantime, had initiated – following a complaint by the employee – sanction proceedings based on alleged unlawful practices in the way access logs to the email system and the messages themselves were stored, consisting, amongst other things, of a breach of Article 4 of the Workers’ Statute due to the lack of a trade union agreement or administrative authorisation.

The Court states, in fact, that ‘a distinction must be drawn between the unlawfulness of the system of mass data retention – which concerns the IT infrastructure and constitutes an administrative offence – and the admissibility of the evidence in the present proceedings’.

With specific reference, then, to the alleged breach of the Workers’ Statute, the judgement, citing the case-law of the Court of Cassation on this point, notes that ‘ex post defensive checks aimed at ascertaining unlawful conduct by an employee that has already taken place and is detrimental to the company’s assets fall outside the scope of Article 4 of the Workers’ Statute’. The retention of email logs and content without trade union or administrative authorisation for a period deemed (by the Data Protection Authority) to be excessive—even if it constitutes a breach of Article 4—does not therefore prevent the employer from carrying out (targeted and limited) checks on such data, provided there is a well-founded suspicion of unlawful conduct on the part of the employee.

The judge from Pisa has taken a stance that seeks to apply a measure of common sense to the potentially devastating consequences of the radical positions recently expressed by the Data Protection Authority regarding corporate email.

Devices excluded from the authorisation process

However, the judgement contains a further interesting statement which fundamentally undermines the interpretation of Article 4 of the Workers’ Statute repeatedly adopted by the Data Protection Authority. The decision states that ‘company IT equipment – such as computers or company email – is excluded from the scope of the authorisation procedure referred to in paragraph 1, falling instead within the scope of paragraph 2. They can, in fact, be classified as genuine tools necessary for the performance of work’.

This interpretation of Article 4 is consistent with the intention of the 2015 legislator, who had intended to exempt from prior authorisation procedures all devices used within a company for work-related purposes, which is quite different from the restrictive interpretation of the concept of a work tool also adopted by the Data Protection Authority, which effectively ‘breaks down’ the work tool in order to subject certain stages (in this case, the retention of logs and email messages) to prior authorisation.

Of course, as the judgement points out, the lawfulness of monitoring work equipment (as well as any devices that enable remote monitoring of work activities) is subject to workers being informed in advance and compliance with data protection legislation.

A principle of transparency that stems from EU principles and is therefore shared by all European countries, none of which, however, provide for anachronistic forms of prior authorisation.

Copyright reserved ©

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti