Garante per la protezione dei dati personali (Italy) - 342/2026

From GDPRhub
Garante per la protezione dei dati personali - Case number: 342/2026

Internal number: 10255494

Authority: Garante per la protezione dei dati personali (Italy)
Jurisdiction: Italy
Relevant Law: Article 5 GDPR
Article 6 GDPR
Article 9 GDPR
Article 24 GDPR
Article 25 GDPR
Article 88(2) GDPR
Article 5(1)(f) of Regulation 2024/1689
Art. 113 of the Code
Type: Investigation
Outcome: Violation Found
Started: 03.06.2025
Decided: 14.05.2026
Published:
Fine: n/a
Parties: Myndoor S.r.l.
National Case Number/Name: Case number: 342/2026

Internal number: 10255494

European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Italian
Original Source: GPDP (in IT)
Initial Contributor: ap

The DPA investigated a workplace consulting company providing sentiment analyses of messages exchanged by employees in order to assess their stress level and prepare a respective report to their employer. The DPA issued a warning, stating its concern that, in the future, data subjects could unlawfully be identified by the reports.

English Summary

Facts

Myndoor S.r.l. (the controller) is a workplace consulting company. The controller offers a plug-in system that carries out sentiment analysis of messages exchanged by employees (data subjects) that activated the plug-in. The system used AI to analyse the content of messages sent between data subjects in order to assess their stress levels, and generated a report on a weekly basis.

The DPA initiated an ex-officio investigation following press reports on the controller. During its investigations, the controller stated that it currently only provided the service to one company, and that the report was only compiled if a minimum number of data subjects used it. In addition, the controller argued that the report covered the entire workforce of a company to prevent employees from being identified. Finally, the controller argued that the system only processed information provided by the data subject (such as names and contact information), and that sensitive and usage data was anonymised.

Holding

The DPA first clarified that the company providing the system acted as a controller in relation to the data subjects, and not the employers who purchased the system. According to the DPA, employers are technically prohibited from accessing the data processed by the controller to provide the service, and would in any case lack the valid legal basis to do so under the GDPR. While employers can receive reports of the data subjects’ stress levels, the DPA concluded that the employer in question did not have sufficient information to identify the data subjects involved.[1]

The DPA also emphasised that the controller has the obligation to comply with the GDPR from the design phase (Article 25 GDPR). In addition, the controller must comply with national provisions that prohibit employers from collecting data that is irrelevant to work activities (Article 113 of the Code). If this provision is not complied with, the processing is not lawful under Article 88(2) GDPR.

The DPA also noted that the controller must also comply with Article 5(1)(f) of the AI Act, which expressly prohibits the use of AI systems to infer the emotions of a data subject in the workplace. The DPA highlighted that AI systems can generate further inferences in relation to the data originally processed that may not be understandable or verifiable. Therefore, aspects such as model reliability, quality of the data, transparency and explainability are essential conditions to prevent processing activities that are invasive and non-compliant with the GDPR. It is also essential that companies take a prudent approach when adopting AI systems.

The DPA did not find a violation of the GDPR, as the controller did not transfer the data to employers, and the company that received the report was unable to identify specific data subjects. However, the DPA issued a warning, as it could not rule out that the processing activities were likely to infringe the GDPR in the future. The DPA was concerned of the possibility that companies and entities could, in the future, identify data subjects from the reports provided by the controller. This would result in a violation of Articles 5, 6, 9, 24, 25 and 88 GDPR, and Article 113 of the Code. Therefore, the DPA ordered the controller to implement measures to prevent it from disclosing data from data subjects to their employers in any way, even indirectly.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details.

SEE ALSO Press release of May 28, 2026

[web doc. no. 10255494]

Measure of May 14, 2026

Register of Measures
No. 342 of May 14, 2026

THE ITALIAN DATA PROTECTION AUTHORITY

IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General;

HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter "Regulation");

CONSIDERING Legislative Decree No. 30 June 2003, 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code");

CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Data Protection Authority, approved with Resolution No. 98 of 4 April 2019, published in the Official Journal No. 106 of 8 May 2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Data Protection Authority Regulation No. 1/2019");

Having regard to the documentation in the file;

Having regard to the observations made by the Secretary General pursuant to Article 15 of Regulation No. 1/2000 of the Italian Data Protection Authority on the organization and functioning of the Office of the Italian Data Protection Authority, web doc. No. 1098801;

Rapporteur: Professor Ginevra Cerrina Feroni;

WHEREAS

1. Introduction.

In light of certain press reports, the Authority has initiated specific inspections of Myndoor S.r.l. (hereinafter also referred to as "Myndoor" or the "Company"), pursuant to Article 58, paragraph 1, of the Regulation and Articles 157 and 158 of the Code, in relation to the processing carried out using the plug-in system developed by the same Company, which involves the use of sentiment analysis of messages exchanged by individuals who decide to use it in carrying out their their work activities in the context of Slack and Teams chats (see the minutes of the operations carried out on June 3 and 4, 2025).

In this regard, it should be noted first of all that these inspections were initiated on the assumption that, based on what was learned from the aforementioned press reports, the Myndoor plug-in system was in use by numerous public administration entities – including, in particular, XX – with the consequence that, therefore, they would have carried out such processing of personal data relating to their employees, acting as employers and data controllers.

Regarding this circumstance, with declarations also made pursuant to Article 168 of the Code as part of the preliminary investigation, the Company nevertheless stated that "XX [...] has not purchased, at present, [...] the [aforementioned] plugins for company chats" (see the minutes of June 3, 2025).

This provision therefore concerns only the processing that, in Generally, in the current configuration of the Myndoor system, processing of personal data of individuals who choose to use it could be carried out by entities and companies that, having purchased this service, would act within this framework as employers of the aforementioned individuals and data controllers of their personal data.

2. Investigative activity.

During the aforementioned inspections, elements emerged regarding the application's functioning and details on the commercial solutions adopted by the Company, and, in particular, as relevant to the purposes of this provision:

- regarding the "service provided to companies (currently only one) when they also request the sending of a specific report containing aggregate data relating to the work-related stress levels of their employees [...], the report is then generated on a weekly basis only if at least 10 workers have simultaneously activated the plugin." In these cases, the Company interfaces with a contact person for the client-employer" (see minutes of June 4, 2025); "this report, exclusively with reference to Teams, concerns the entire client's workforce and not a more limited organizational context (e.g., department, branch) in order to prevent the worker from being identified" (see minutes of June 3, 2025);

- in any case, the Company has "never matched the worker's name with the data contained in its database" (see minutes of June 4, 2025).

Subsequently, with a note dated July 2, 2025, the Company provided specific information to resolve the reservations raised during the aforementioned inspections, making available to the Authority the information provided to data subjects pursuant to Article 13 of the Regulation (see Annexes 1 and 2 of the aforementioned note of July 2, 2025), in which stated that:

- "The data controller is: Myndoor S.r.l. […]";

- The data processed through the Myndoor system consists of:

- "Processing data": "The Application uses an artificial intelligence model to analyze the textual content of messages sent by the Data Subject within Slack. This data is processed to evaluate user stress parameters." The analysis data, being information provided entirely and at the user's discretion, may include: - Common data: such as, for example, name and surname, email address, telephone number, place and date of birth, and residence. - Special categories of data, pursuant to Article 9 of EU Regulation No. 679/2016. Such data is analyzed anonymously or pseudonymized and is not retained by the Application. Once the analysis has been performed and the response has been processed, the data is deleted;

- "usage data": "anonymous data regarding the use of the Application, such as the number of messages analyzed and the stress assessments generated";

- "processing data is used for preventive medicine, diagnosis, and care purposes. In particular, the data will be used to evaluate stress parameters aimed at identifying the Data Subject's general levels of well-being or stress." The aforementioned stress parameters will be identified by analyzing the text content entered by the data subject into Slack [or Teams] as part of their daily work activities;

- "in the event that the Service is activated by a company to which the data subject belongs, a further purpose of the data processing will be to provide the company with a report containing the results of the analysis performed, which will only include the aggregate data resulting from such analysis [...]."

Subsequently, in a note dated December 24, 2025, the Company, providing further information and clarifications necessary for the definition of the preliminary investigation, highlighted, in particular, that:

- "following appropriate and definitive assessments, [...] the Company has decided to act as Data Controller of the data of service users"; this also "regardless of the marketing method or the relationship with the client/contractor company";

- "the companies and entities that have purchased the service to make it available to their employees do not have access to the data subjects' personal data, which is processed directly and solely by Myndoor S.r.l. as the data controller; "The sole purpose of the service in question is to provide users/data subjects with a tool that can support their mental well-being by identifying potential stressors and providing appropriate suggestions. For this reason, as the service has no additional purposes, access to the data by companies or entities purchasing the service is categorically excluded."

- "Following the recent optimization of the technological infrastructure, the current system architecture no longer requires the acquisition of personal data by Myndoor for the provision of the Service. The plugin is activated exclusively using a unique identifier (ID) which, in line with data minimization principles, does not allow the data subject's identity to be traced, thus ensuring the provider's anonymity in providing services.

- "The report with the results of the analysis performed, which only includes aggregated data resulting from this analysis, was made available to a single company [...] and Myndoor S.r.l. did not request or spontaneously disclose personal data directly attributable to individuals to the purchasing companies."

- "No further communication or transmission of aggregated reports [...] occurred outside of the aforementioned case." Furthermore, "due to the decrease in the active user base at the aforementioned company [...], the system automatically blocked the generation of new reports and access to historical views. This technical security measure ensures that data cannot be extracted, even indirectly, in contexts where the small sample size could compromise the anonymity of data subjects.

- "The processing model adopted by Myndoor is structured to ensure that the only output accessible to the customer (Data Controller) is an exclusively statistical-aggregated report, resulting from the analysis of previously pseudonymized data. To mitigate the risk of single-out (isolation) and guarantee the confidentiality of data subjects, the following technical and organizational measures have been implemented:

- Minimum Statistical Population Threshold: Report generation is subject to a minimum sample of at least 10 active users on a weekly basis. This measure ensures a sufficient level of aggregation to prevent re-identification by inference; should the user base fall below this threshold, the system immediately disables the generation of new reports and suspends access to the consultation page.

- View-only access: The report is available exclusively through the Myndoor platform, within your secure company account. There are no automatic data streams or raw data downloads, nor are there any identifiers or codes that could allow results to be associated with specific individuals.

- Absence of semi-aggregated data: The analysis procedure excludes the provision of microdata or semi-aggregated data, limiting the customer's visibility to the final statistical data produced by the algorithm.

3. Processing of personal data using the Myndoor plug-in.

The investigation revealed, in particular, that the Myndoor plug-in can be purchased by organizations and companies to allow individuals who choose to use it while performing their work activities to assess their level of psychological stress based on an analysis of the semantics used in messages exchanged within Slack and Teams chats.

In providing this service to the aforementioned individuals, the Company, taking into account the purposes pursued and the means used, collects and processes the relevant personal data in the context of a dialogue that exists solely between the Company itself and the data subjects who have expressly chosen to use the aforementioned service. Therefore, the Company operates in relation to their data as the data controller. (Articles 4, no. 7, and 24 of the Regulation), as also indicated in the information provided to data subjects in the documents (Article 13 of the Regulation).

The Myndoor plug-in system, being a service purchased by the employer for the benefit of its personnel who wish to use it, is therefore configured as an application made available to employees and other personnel working in various capacities within the organization. These are the only individuals who, in practice, can choose whether or not to use it for their own personal needs. The employer is technically prevented from accessing the data necessary for the Company to provide the service to the data subjects only (both data relating to the content of messages exchanged in chats and data relating to the system's processing and the emotional sphere of the people using the service).

This follows an approach that, in this respect, is similar to what, in practice, occurs when employers and companies enter into service contracts for the provision of benefits and services. for employees (e.g., health insurance contracts, access to psychological support services for workers, agreements with commercial establishments and other suppliers of goods and services). In this scenario, from a data protection perspective, regardless of the civil law nature of the underlying contracts (e.g., contracts for the benefit of third parties, Article 1411 of the Italian Civil Code), no data processing deriving from the provision of the same service is carried out by employers, nor, moreover, could it be carried out, lacking suitable lawfulness requirements for the processing in question by the employer (e.g., regarding the type of healthcare services for which the employee requests reimbursement from the insurance company; the type of goods and services purchased from affiliated entities; access or otherwise to psychological support services).

In this context, it should be noted, however, that, as also specified in the information provided to data subjects (Article 13 of the Regulation), the entities and companies that have purchased the service may request the Company to provide them with a report containing a An aggregate report on the level of psychological stress calculated by the Myndoor system for employees who used it, provided that there were more than ten of them.

In light of the Company's statements in the documents, this report was made available, in a single case, to a single company. However, that company did not appear to have requested or, in any case, did not have further references or details that would have allowed it to actually identify the individuals who, within its company, had used the Myndoor system and to whom the aggregate analysis contained in the report referred.

4. The regulatory framework for the protection of personal data and the protection of workers' dignity.

Under the regulatory framework for the protection of personal data, the data controller has "general responsibility" for the processing performed, being required to implement appropriate technical and organizational measures to ensure, and be able to demonstrate, that the processing is performed in compliance with the legislation on personal data protection. Reviewing and updating such measures when necessary, taking into account the nature, scope, context, and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons (see Article 24 of the Regulation; see also Recital 74 of the Regulation).

From this perspective, with particular regard to the "development, design, selection, and use of applications, services, and products based on the processing of personal data or processing personal data to perform their functions," it is stipulated that "producers of products, services, and applications should be encouraged to take into account the right to data protection when developing and designing such products, services, and applications" (see Recital 78 of the Regulation).

It is therefore noted that, in the case of services and applications that require the processing of personal data, such as the Myndoor system, compliance with data protection regulations must be ensured, starting from the relevant design phase, including with regard to the correct implementation of the fundamental processing decisions, such as, in particular, the definition of roles in the processing plan. of personal data, if necessary also by implementing specific measures to prevent the risk of data being made available to unauthorized third parties (in this case, the employer who purchased the service for employees).

In light of the above, it should be remembered that, in general, with reference to processing carried out in the workplace, employers must, among other things, comply with national regulations, which "include appropriate and specific measures to safeguard the human dignity, legitimate interests and fundamental rights of data subjects, in particular with regard to transparency of processing [...] and workplace monitoring systems" (Articles 6, paragraph 2, and 88, paragraph 2, of the Regulation).

On this point, it is particularly noted that Article 113 of the Code ("Data collection and relevance"), confirming the framework prior to the amendments introduced by Legislative Decree No. 101 of 10 August 2018, expressly refers to the relevant national provisions that protect the dignity of individuals in the workplace and prohibit employers from collecting data that is not relevant to their work (Articles 8 of Law No. 300 of 20 May 1970 and 10 of Legislative Decree No. 297/2003, violation of which is also punishable by law; see Article 171 of the Code). Compliance with these provisions, as a result of this reference and taking into account Article 88, paragraph 2, of the Regulation, constitutes a condition for the lawfulness of processing.

Within the regulatory framework outlined above, information regarding employees' emotional well-being, and therefore their state of psychological well-being or stress, constitutes information falling within the scope of Article 113 of the Code, and employers are therefore barred from accessing it.

Similarly, the pursuit of the stated purpose of "preventive medicine, diagnosis, and assistance" (see information provided to data subjects) must be considered This is radically precluded from the employer, not only because of the aforementioned provisions prohibiting the acquisition of information not relevant to the work activity and the traditional prohibition on employers from independently undertaking health assessments on employees (see Article 5 of Law No. 300 of 20 May 1970), but also given the fact that the aforementioned purpose has a public nature which, within the framework of the regulations on health and safety in the workplace, constitutes, in the workplace context, the expression of a competence proper to the competent physician alone (see Legislative Decree No. 81/2008; see also, more generally, Article 5 of Law No. 300 of 20 May 1970).

This is also in compliance with the traditional division of responsibilities and separation of roles between the competent physician and the employer, which is the main element of the guarantee of the rules that, in regulating their duties and functions, establish limits, conditions, and prerequisites. for the processing of data within this specific context (see, for similar considerations, Guidance Document of May 14, 2021, "The role of the 'competent doctor' in matters of workplace safety, also with reference to the emergency context," web doc. no. 958536).

This also takes into account, from another but related perspective, the need to ensure the compliance of the marketed product with the separate regulatory framework on artificial intelligence and, in particular, the prohibition set forth in Article 5, paragraph 1, letter f), of Regulation (EU) 2024/1689 of June 13, 2024, the so-called "Artificial Intelligence Regulation" (which expressly prohibits "the placing on the market, putting into service for this specific purpose, or use of AI systems to infer the emotions of a natural person in the workplace [...]"). In this context, also in light of data protection principles and more specific national provisions and Greater protection of the dignity of individuals in their work and professional context (Articles 88 of the Regulation and 113 of the Code), this principle requires and confirms that the use of such systems must not involve making information about their employees, inferred through artificial intelligence systems, available to employers. It follows that, even in application of the data protection principles "by design" and "by default" (Article 25 of the Regulation), assessments must be made regarding the deactivation of functions that have no legal basis, are incompatible with the purposes of the processing, or, as in this case, could likely conflict with specific sector-specific provisions established by national and supranational law.

More generally, it is important to emphasize that the use of artificial intelligence systems requires considering the substantial implications of these technologies' ability to generate additional inferences, sometimes not immediately predictable or controllable, with respect to the data originally processed. This inferential capacity—a hallmark of machine learning models and, in particular, systems based on semantic analysis and linguistic models—requires a particularly cautious approach, especially in cases where the results derive from correlation and classification processes characterized by limited interpretability, which make the algorithm's logical decision-making process not immediately understandable or verifiable.

From this perspective, the reliability of the models, the quality and representativeness of the data, as well as the transparency and explainability of their operating logic are not merely technical aspects but represent essential conditions for preventing invasive and non-compliant forms of data processing. The absence of such guarantees creates the risk of relying on algorithmic outputs, generated through statistical patterns and predictive models. If not adequately verified, this can lead to potential distorting effects, amplification of biases, and margins of error that are not always easily detectable, particularly where the system is opaque or has limited explainability. Moreover, in certain sensitive processing contexts involving vulnerable data subjects, this can lead to detrimental effects and discrimination, with sometimes irreparable consequences for the individual's identity and dignity.

It follows that the adoption of such technologies requires a prudent and informed approach, based on a concrete assessment of the implications of their use, the robustness of the models, the quality of the training data, and the verifiability of the outputs. This approach must always ensure adequate information guarantees and effective human oversight, capable of intervening and influencing the decision-making process, thus mitigating the risks associated with automated decision-making.

Furthermore, the aforementioned Regulation (EU) 2024/1689 of 13 June 2024 expressly requires that high-risk AI systems be characterized by an adequate level of transparency, through specific information and instructions for use, including with regard to the characteristics, capabilities, and performance limits of the systems in question, including "the intended purpose," "the level of accuracy that can be expected, including robustness and cybersecurity metrics," "risks to health and safety or to fundamental rights," as well as "the capabilities and technical characteristics of the high-risk AI system related to the provision of relevant information to explain its output" (Article 13 of Regulation (EU) 2024/1689 of 13 June 2024).

5. Concluding remarks.

In light of the foregoing, regardless of any assessment of the scientific reliability of the data produced by the Myndoor system and made available to users, we acknowledge the Company's approach, which excludes any form of data processing performed through the Myndoor system by the entities and companies that have purchased the service and that act as employers of the individuals who will choose whether or not to use it.

Considering the above, and noting that, in the sole case in which the Company declared it had made the aforementioned aggregate report available to one of its clients, it emerged that the client did not have sufficient additional information to allow it to specifically re-identify the data subjects, it must be concluded that, based on the current state of the case, there is no evidence that such processing was actually carried out by the entities and companies that purchased the service for the benefit of their employees, since Myndoor did not actually disclose to them the personal data of the individuals who used it individually.

Therefore, even taking into account that, in any case, the legislation on personal data protection applies when the processing of personal data has actually taken place (see Article 2 of the Regulation), the Company does not incur any specific liability in this regard.

6. Adoption of a warning pursuant to Article 58, paragraph 2, letter a), of the Regulation and Article 154, paragraph 1, letter f), of the Code.

Given that the Garante, pursuant to Article 58, paragraph 2, letter a), of the Regulation, has the power to issue warnings to the data controller or processor that the planned processing is likely to violate the provisions of the Regulation and, in this context, pursuant to Article 154, paragraph 1, letter f), 1, letter f), of the Code, is required to ensure the protection of the fundamental rights and freedoms of individuals by appropriately implementing the Regulation and the Code, the following is highlighted.

Based on a comprehensive assessment of the preliminary investigation documents, considering the sensitivity of the data processed and the relevant context, and given, in particular, the impossibility of completely ruling out the possibility that, in the future, entities and companies requesting the aforementioned aggregate report may be able to trace the identity of their employees who have chosen to use the service individually, it is noted, for the aspects within its jurisdiction, that the documents reveal the risk that the transmission of the aforementioned report by Myndoor to entities and companies that request it could likely result in a violation of the regulatory framework regarding the protection of personal data and the dignity of workers (see, in particular, Articles 5, 6, 9, 24, 25, and 88 of the Regulation and Articles 2-ter and 113 of the Code). This is particularly true given the specific characteristics of individual employer organizations (for example, in terms of size or the number and characteristics of the personnel employed).

Therefore, given the conditions set forth in Article 58, paragraph 2, letter a), of the Regulation, it is deemed necessary that, in the relevant context, the Company ensures the adoption of measures and precautions aimed at preventing any form of disclosure, including through the aforementioned report, of the data of individuals who decide to use the Myndoor plug-in to the entities and companies that are their respective employers, in order to prevent them from gaining any knowledge, even indirectly, of the information processed through the system in question.

NOW CONSIDERING ALL THE ABOVE, THE GUARANTOR

- pursuant to Article 58, paragraph 2, letter a), of the Regulation and Article 154, paragraph 1, letter c), of the GDPR. f) of the Code, warns Myndoor S.r.l., with registered office at Via Aldo Moro 5/3 - 20088 Rosate (MI) – VAT No. 12097060961, that, under the terms described above, the envisaged processing may likely violate the regulatory framework regarding the protection of personal data and the dignity of workers (see, in particular, Articles 5, 6, 9, 24, 25, and 88 of the Regulation and Articles 2-ter and 113 of the Code);

- Pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Guarantor Regulation No. 1/2019, orders the publication of this provision on the Authority's website.

Pursuant to Articles 78 of the Regulation, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad.

Rome, May 14, 2026

THE PRESIDENT
Stanzione

THE REPORTER
Cerrina Feroni

THE SECRETARY GENERAL
Montuori

SEE ALSO Press release of May 28, 2026

[web doc. no. 10255494]

Provision of May 14, 2026

Register of Provisions
no. 342 of May 14, 2026

THE AUTHORITY FOR THE PROTECTION OF PERSONAL DATA

During today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, member, and Dr. Luigi Montuori, Secretary General;

SEEN Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter "Regulation");

SEEN Legislative Decree no. 196 of 30 June 2003 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code");

CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Data Protection Authority, approved with Resolution No. 98 of 4 April 2019, published in the Official Journal No. 106 of 8 May 2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Data Protection Authority Regulation No. 1/2019");

Having seen the documents in the file;

Having seen the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Guarantor No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801;

Rapporteur: Professor Ginevra Cerrina Feroni;

WHEREAS

1. Introduction.

In light of certain press reports, the Authority has initiated specific inspections of Myndoor S.r.l. (hereinafter also referred to as "Myndoor" or the "Company"), pursuant to Article 58, paragraph 1, of the Regulation and Articles 157 and 158 of the Code, in relation to the processing carried out using the plug-in system developed by the same Company. This system uses sentiment analysis of messages exchanged by individuals who choose to use it in the course of their work within Slack and Teams chats (see the minutes of the operations carried out on June 3 and 4, 2025).

In this regard, it should be noted first that these inspections were initiated on the assumption that, based on what was learned from the aforementioned press reports, the Myndoor plug-in system was in use by numerous public administration entities—including, in particular, XX—with the consequence that they would have carried out such processing of personal data relating to their employees, acting as employers and data controllers.

Regarding this circumstance, with declarations also made pursuant to Article 168 of the Code as part of the preliminary investigation, the Company nevertheless stated that "XX [...] has not purchased, at present, [...] the [aforesaid] plugins for company chats" (see minutes of June 3, 2025).

This provision therefore concerns only the processing that, in general, under the current configuration of the Myndoor system, could be carried out, with respect to the data of individuals who decide to use it, by entities and companies that, having purchased this service, would act within this framework as employers of the aforementioned individuals and as data controllers of their personal data.

2. The preliminary investigation.

During the aforementioned inspections, information emerged regarding the application's functionality and details on the commercial solutions adopted by the Company, and in particular, as relevant to this provision:

- regarding the "service provided to companies (currently only one) when they also request the sending of a specific report containing aggregate data on their employees' work-related stress levels [...], the report is then generated weekly only if at least 10 workers have simultaneously activated the plugin. In these cases, the Company liaises with a contact person for the client-employer" (see minutes of June 4, 2025); "this report, exclusively with regard to Teams, concerns the client's entire workforce and not a more restricted organizational context (e.g., department, branch) in order to avoid identifying the worker" (see minutes of June 3, 2025);

- In any case, the Company "never matched the worker's name with the data contained in its database" (see minutes of June 4, 2025).

Subsequently, in a note dated July 2, 2025, the Company provided specific information to resolve the reservations raised during the aforementioned inspections, making available to the Authority the information provided to data subjects pursuant to Article 13 of the Regulation (see Annexes 1 and 2 of the aforementioned note of July 2, 2025), which stated that:

- "The data controller is: Myndoor S.r.l. […]";

- The data processed through the Myndoor system consists of:

- "Processing data": "The Application uses an artificial intelligence model to analyze the textual content of messages sent by the Data Subject within Slack. This data is processed to evaluate user stress parameters. Since the analysis data is information provided entirely and at the user's discretion, it may include: - Common data: such as, for example, name and surname, email, telephone number, place and date of birth, and residence. - Special categories of data, pursuant to Article 9 of EU Regulation No. 679/2016. Such data is analyzed anonymously or pseudonymized and is not retained by the Application. Once the analysis has been performed and the response has been processed, the data is deleted."

- "usage data": "anonymous data regarding the use of the Application, such as the number of messages analyzed and stress assessments generated";

- "processing data is used for preventive medicine, diagnosis, and care purposes. Specifically, the data will be used to evaluate stress parameters aimed at identifying the Data Subject's general levels of well-being or stress. These stress parameters will be identified by analyzing the text content entered by the Data Subject into Slack [or Teams] as part of their daily work activities";

- "in the event that the Service is activated by a company to which the Data Subject belongs, an additional purpose of data processing will be to provide that company with a report containing the results of the analysis performed, which will only include the aggregated data resulting from such analysis [...]".

Subsequently, in a note dated December 24, 2025, the Company, providing further information and clarifications necessary to define the preliminary investigation framework, highlighted, in particular, that:

- "following appropriate and definitive assessments, [...] the Company has decided to act as Data Controller for the data of service users"; this also "regardless of the marketing method or the relationship with the client/contractor company";

- "the companies and entities that have purchased the service to make it available to their employees do not have access to the personal data of the data subjects, which are processed directly and solely by Myndoor S.r.l. as the data controller"; The sole purpose of this service is to provide users/interested parties with a tool that can support their mental well-being by identifying potential stressors and providing appropriate suggestions. For this reason, since the service has no additional purposes, access to the data by companies or entities purchasing the service is categorically excluded.

Following recent optimization of the technological infrastructure, the current system architecture no longer requires the acquisition of personal data by Myndoor for the provision of the Service. The plugin is activated exclusively using a unique identifier (ID) that, in line with data minimization principles, does not allow the data subject's identity to be traced, thus ensuring the provision of services anonymously for the provider.

- "The report containing the results of the analysis performed, which only included aggregate data resulting from that analysis, was made available to a single company […] and Myndoor S.r.l. did not request or spontaneously disclose personal data directly attributable to individuals to the purchasing companies";

- "No further communication or transmission of aggregate reports […] occurred outside of the aforementioned case"; furthermore, "following the reduction in the active user base at the aforementioned company […], the system automatically blocked the generation of new reports and access to historical views. This technical security measure ensures that data cannot be extracted, even indirectly, in contexts where the small sample size could compromise the anonymity of the data subjects";

- "The processing model adopted by Myndoor is structured to ensure that the only output accessible to the customer (Data Controller) is a report of an exclusively statistical and aggregate nature, resulting from the analysis of previously pseudonymized data. To mitigate the risk of single-out (isolation) and guarantee the confidentiality of data subjects, the following technical and organizational measures have been implemented:

- Minimum Statistical Population Threshold: Report generation is subject to the presence of a minimum sample of at least 10 active users on a weekly basis. This measure ensures a level of aggregation sufficient to prevent re-identification by inference; should the user base fall below this threshold, the system immediately disables the generation of new reports and suspends access to the consultation page.

- View-only access: The report is made available exclusively via the Myndoor Platform, within the protected company account. There are no automatic transmission flows or downloads of raw data, nor is there any inclusion of identifiers or codes that may allow the results to be associated with individual users.

- Absence of semi-aggregated data: The analysis procedure excludes the provision of microdata or semi-aggregated data, limiting the client's visibility to the final statistical data produced by the algorithm.

3. Processing of personal data using the Myndoor plug-in.

The investigation revealed, in particular, that the Myndoor plug-in can be purchased by organizations and companies to allow individuals who choose to use it while performing their work activities to assess their level of psychological stress based on an analysis of the semantics used in messages exchanged within Slack and Teams chats.

In providing this service to the aforementioned individuals, the Company, taking into account the purposes pursued and the means actually employed, collects and processes the relevant personal data in the context of a dialogue that exists solely between the Company itself and the data subjects who have expressly chosen to use the aforementioned service. Therefore, the Company operates in relation to the data of the latter as data controller (Articles 4, No. 7, and 24 of the Regulation), as also indicated in the information provided to data subjects in the records (Article 13 of the Regulation).

The Myndoor plug-in system, being a service purchased by the employer for the benefit of its staff who wish to use it, is therefore an application made available to employees and other personnel working in various capacities within the organization. These are the only individuals who can choose whether or not to use it for their own personal needs. The employer is technically prevented from accessing the data necessary for the Company to provide the service to the interested parties only (both data relating to the content of messages exchanged in chats and data relating to the system's processing and the emotional state of the people using the service).

This follows an approach that, from this perspective, is similar to what, in practice, occurs when employers and entities enter into service contracts for the provision of benefits and services to employees (for example, health insurance contracts, access to psychological support services for workers, agreements with commercial establishments and other suppliers of goods and services). In this scenario, from a data protection perspective, regardless of the civil law nature of the underlying contracts (for example, contracts for the benefit of third parties, Article 1411 of the Italian Civil Code), no data processing deriving from the provision of the same service is carried out by employers, nor, moreover, could it be carried out, lacking appropriate lawfulness requirements for the processing in question by the employer (for example, regarding the type of healthcare services for which the employee requests reimbursement from the insurance company; the type of goods and services purchased from affiliated entities; access to psychological support services).

In this context, it should be noted, however, that, as also specified in the information provided to data subjects (Article 13 of the Regulation), entities and companies that have purchased the service may request the Company to provide them with a report containing an aggregated summary of the level of psychological stress calculated by the Myndoor system for employees who have used it, provided that there are more than ten of them.

In light of the Company's statements in the documents, such a report was made available, in a single case, to a single company. However, that company does not appear to have requested, or in any case did not have, further references or details that would have allowed it to actually identify the individuals who, within their company, had used the Myndoor system and to whom the aggregate analysis contained in the report referred.

4. The regulatory framework for the protection of personal data and the protection of workers' dignity.

Under the personal data protection regulatory framework, the data controller has "general responsibility" for the processing carried out, being required to implement appropriate technical and organizational measures to ensure, and to be able to demonstrate, that processing is performed in accordance with the personal data protection legislation, reviewing and updating those measures when necessary, taking into account the nature, scope, context, and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons (see Article 24 of the Regulation; see also Recital 74 of the Regulation).

From this perspective, with particular regard to the "development, design, selection, and use of applications, services, and products that rely on the processing of personal data or that process personal data to perform their functions," it is stipulated that "producers of products, services, and applications should be encouraged to take into account the right to data protection when developing and designing such products, services, and applications" (see Recital 78 of the Regulation).

It is therefore noted that, for services and applications that require the processing of personal data, such as the Myndoor system, compliance with data protection regulations must be ensured from the design stage, including through the correct implementation of fundamental processing decisions, particularly the definition of roles in the processing of personal data, and, where appropriate, by implementing specific measures to prevent the risk of data being made available to unauthorized third parties (in this case, the employer who purchased the service for employees).

In light of the above, it should be remembered that, in general, with regard to processing carried out in the workplace, employers must, among other things, comply with national regulations, which "include suitable and specific measures to safeguard the human dignity, legitimate interests and fundamental rights of data subjects, in particular with regard to transparency of processing [...] and workplace monitoring systems" (Articles 6(2) and 88(2) of the Regulation). On this point, it is particularly noted that Article 113 of the Code ("Data Collection and Relevance"), confirming the framework prior to the amendments introduced by Legislative Decree No. 101 of August 10, 2018, expressly refers to the relevant national provisions that protect the dignity of individuals in the workplace and prohibit employers from collecting data that is not relevant to their work activities (Articles 8 of Law No. 300 of May 20, 1970, and Article 10 of Legislative Decree No. 297/2003, violation of which is also punishable by law; see Article 171 of the Code). Compliance with these provisions, as a result of this reference and taking into account Article 88, paragraph 2, of the Regulation, constitutes a condition for the lawfulness of the processing.

Within the regulatory framework outlined above, information regarding employees' emotional well-being, and therefore their state of psychological well-being or stress, constitutes information falling within the scope of Article 113 of the Code, and employers are therefore barred from accessing such information.

Similarly, the pursuit of the stated purpose of "preventive medicine, diagnosis, and care" (see information provided to interested parties) must be considered radically precluded for the employer, not only because of the aforementioned provisions prohibiting the acquisition of information not relevant to work-related activities and the traditional prohibition on employers from independently undertaking health assessments of employees (see Article 5 of Law No. 300 of May 20, 1970), but also given the same circumstance that the aforementioned purpose has a public nature which, within the framework of the regulations on health and safety in the workplace, constitutes, in the workplace context, the expression of a competence proper to the competent physician alone (see Legislative Decree No. 81/2008; see also, more generally, Article 5 of Law No. 300 of May 20, 1970).

This is also in compliance with the traditional division of responsibilities and separation of roles between the occupational physician and the employer, which is the main element of the safeguards of the regulations that, in regulating their duties and functions, establish limits, conditions, and prerequisites for data processing within this specific context (see, for similar considerations, Guidance Document of May 14, 2021, "The role of the occupational physician in matters of safety in the workplace, also with reference to the emergency context," web doc. no. 958536).

This also takes into account, from another but related perspective, the need to ensure compliance of the marketed product with the separate regulatory framework on artificial intelligence and, in particular, the prohibition set forth in Article 5, paragraph 1, letter f), of Regulation (EU) 2024/1689 of June 13, 2024, the so-called "Artificial Intelligence Regulation." "Artificial Intelligence Regulation" (which expressly prohibits "the placing on the market, putting into service for that specific purpose, or use of AI systems to infer the emotions of a natural person in the workplace [...]"). Within this framework, also in light of data protection principles and more specific national provisions that protect the dignity of individuals in their work and professional context (Articles 88 of the Regulation and 113 of the Code), this principle requires and confirms that the use of such systems must not involve making information, inferred through AI systems, about their employees available to employers. It follows that, even in application of the data protection principles "by design" and "by default" (Article 25 of the Regulation), assessments must be made regarding the deactivation of functions that have no legal basis, are incompatible with the purposes of the processing, or, as in this case, could likely conflict with specific sector-specific provisions established by national and supranational law.

More generally, it is important to emphasize that the use of artificial intelligence systems requires considering the substantial implications of these technologies' ability to generate additional inferences, sometimes not immediately predictable or controllable, with respect to the data originally processed. This inferential capacity—specific to machine learning models and, in particular, systems based on semantic analysis and linguistic models—requires a particularly cautious approach, especially in cases where the results derive from correlation and classification processes characterized by limited interpretability, which make the algorithm's logical decision-making process not immediately understandable or verifiable.

From this perspective, the reliability of models, the quality and representativeness of data, and the transparency and explainability of operating logic are not merely technical aspects but represent essential conditions for preventing invasive and non-compliant forms of processing. The absence of such guarantees creates the risk of reliance on algorithmic outputs, generated through statistical patterns and predictive models. If not adequately verified, this can lead to potential distorting effects, amplification of bias, and margins of error that are not always easily detectable, particularly where the system is opaque or has limited explainability. Moreover, in certain sensitive processing contexts involving vulnerable data subjects, this can lead to detrimental effects and discrimination, with sometimes irreparable consequences for the identity and dignity of the individual.

It follows that the adoption of these technologies requires a prudent and informed approach, based on a concrete assessment of the implications of their use, the robustness of the models, the quality of the training data, and the verifiability of the outputs. This approach must always ensure adequate information guarantees and effective human control, capable of intervening and influencing the decision-making process, thus mitigating the risks associated with automated decision-making.

Furthermore, the aforementioned Regulation (EU) 2024/1689 of 13 June 2024 expressly requires that high-risk AI systems be characterized by an adequate level of transparency, through specific information and instructions for use, including with regard to the characteristics, capabilities, and performance limits of the systems in question, including "the intended purpose," "the level of accuracy that can be expected, including robustness and cybersecurity metrics," "risks to health and safety or to fundamental rights," as well as "the capabilities and technical characteristics of the high-risk AI system related to the provision of relevant information to explain its output" (Article 13 of Regulation (EU) 2024/1689 of 13 June 2024).

5. Concluding remarks.

In light of the foregoing, regardless of any assessment of the scientific reliability of the data produced by the Myndoor system and made available to users, we acknowledge the Company's approach, which excludes any form of data processing performed through the Myndoor system by the entities and companies that have purchased the service and that act as employers of the individuals who will choose whether or not to use it.

Considering the above, and noting that, in the sole case in which the Company declared it had made the aforementioned aggregate report available to one of its clients, it emerged that the client did not have sufficient additional information to allow it to specifically re-identify the data subjects, it must be concluded that, based on the current state of the case, there is no evidence that such processing was actually carried out by the entities and companies that purchased the service for the benefit of their employees, since Myndoor did not actually disclose to them the personal data of the individuals who used it individually.

Therefore, even taking into account that, in any case, the legislation on personal data protection applies when the processing of personal data has actually taken place (see Article 2 of the Regulation), the Company does not incur any specific liability in this regard.

6. Adoption of a warning pursuant to Article 58, paragraph 2, letter a), of the Regulation and Article 154, paragraph 1, letter f), of the Code.

Given that the Garante, pursuant to Article 58, paragraph 2, letter a), of the Regulation, has the power to issue warnings to the data controller or processor that the planned processing is likely to violate the provisions of the Regulation and, in this context, pursuant to Article 154, paragraph 1, letter f), 1, letter f), of the Code, is required to ensure the protection of the fundamental rights and freedoms of individuals by appropriately implementing the Regulation and the Code, the following is highlighted.

Based on a comprehensive assessment of the preliminary investigation documents, considering the sensitivity of the data processed and the relevant context, and given, in particular, the impossibility of completely ruling out the possibility that, in the future, entities and companies requesting the aforementioned aggregate report may be able to trace the identity of their employees who have chosen to use the service individually, it is noted, for the aspects within its jurisdiction, that the documents reveal the risk that the transmission of the aforementioned report by Myndoor to entities and companies that request it could likely result in a violation of the regulatory framework regarding the protection of personal data and the dignity of workers (see, in particular, Articles 5, 6, 9, 24, 25, and 88 of the Regulation and Articles 2-ter and 113 of the Code). This is particularly true given the specific characteristics of individual employer organizations (for example, in terms of size or the number and characteristics of the personnel employed).

Therefore, given the conditions set forth in Article 58, paragraph 2, letter a), of the Regulation, it is deemed necessary that, in the relevant context, the Company ensures the adoption of measures and precautions aimed at preventing any form of disclosure, including through the aforementioned report, of the data of individuals who decide to use the Myndoor plug-in to the entities and companies that are their respective employers, in order to prevent them from gaining any knowledge, even indirectly, of the information processed through the system in question.

NOW CONSIDERING ALL THE ABOVE, THE GUARANTOR

- pursuant to Article 58, paragraph 2, letter a), of the Regulation and Article 154, paragraph 1, letter c), of the GDPR. f) of the Code, warns Myndoor S.r.l., with registered office at Via Aldo Moro 5/3 - 20088 Rosate (MI) – VAT No. 12097060961, that, under the terms described above, the envisaged processing may likely violate the regulatory framework regarding the protection of personal data and the dignity of workers (see, in particular, Articles 5, 6, 9, 24, 25, and 88 of the Regulation and Articles 2-ter and 113 of the Code);

- Pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Guarantor Regulation No. 1/2019, orders the publication of this provision on the Authority's website.

Pursuant to Articles 78 of the Regulation, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be filed before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad.

Rome, May 14, 2026

THE PRESIDENT
Stanzione

THE REPORTER
Cerrina Feroni

THE SECRETARY GENERAL
Montuori
  1. The DPA compared this to employers entering into a contract for the provision of benefits and services to employees (such as health insurance or access to psychological counselling services).