Checking emails is a breach of privacy, but the dismissal is valid
The Court of Pisa has ruled that the evidence gathered remains admissible in court
The positions adopted by the Data Protection Authority regarding the management and monitoring of the email account assigned to employees for the purposes of their work are beginning to meet with some resistance from labour courts.
The ruling of the Court of Pisa
In a ruling dated 13 June, the Court of Pisa held that the dismissal for just cause of an employee whose misconduct had been established through checks (which were targeted and carried out following the emergence of a well-founded suspicion) was lawful of the messages contained in the company email account assigned to him.
The Court rightly considered irrelevant, for the purposes of assessing the lawfulness of the dismissal, the decision of the Data Protection Authority which, in the meantime, had initiated – following a complaint by the employee – sanction proceedings based on alleged unlawful practices in the way access logs to the email system and the messages themselves were stored, consisting, amongst other things, of a breach of Article 4 of the Workers’ Statute due to the lack of a trade union agreement or administrative authorisation.
The Court states, in fact, that ‘a distinction must be drawn between the unlawfulness of the system of mass data retention – which concerns the IT infrastructure and constitutes an administrative offence – and the admissibility of the evidence in the present proceedings’.
With specific reference, then, to the alleged breach of the Workers’ Statute, the judgement, citing the case-law of the Court of Cassation on this point, notes that ‘ex post defensive checks aimed at ascertaining unlawful conduct by an employee that has already taken place and is detrimental to the company’s assets fall outside the scope of Article 4 of the Workers’ Statute’. The retention of email logs and content without trade union or administrative authorisation for a period deemed (by the Data Protection Authority) to be excessive—even if it constitutes a breach of Article 4—does not therefore prevent the employer from carrying out (targeted and limited) checks on such data, provided there is a well-founded suspicion of unlawful conduct on the part of the employee.

