Garante per la protezione dei dati personali (Italy) - 9888206

From GDPRhub
Garante per la protezione dei dati personali - 9888206
Authority: Garante per la protezione dei dati personali (Italy)
Jurisdiction: Italy
Relevant Law: Article 4 GDPR
Article 5(1)(a) GDPR
Article 5(1)(c) GDPR
Article 6(1)(a) GDPR
Article 6(1)(c) GDPR
Article 12(1) GDPR
Article 13 GDPR
Article 28 GDPR
Article 28(3) GDPR
Article 88 GDPR
Type: Complaint
Outcome: Upheld
Started: 31.12.2020
Decided: 23.03.2023
Published:
Fine: 40000 EUR
Parties: La Risorsa Umana s.r.l.
Form App
National Case Number/Name: 9888206
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Italian
Original Source: Garante per la protezione dei dati personali (in IT)
Initial Contributor: ligialagev

The controller was fined €40,000 for ilegally controlling the professional e-mail of its employee in violation of Articles 5(1)(a) and (c), 13 and 28 GDPR.

English Summary

Facts

The data subject worked as a labour consultant for the controller and for its subsidiary under two parallel professional engagement contracts running from 3 June 2019 to 2 June 2020. The controller assigned him an individualised email account with an extension that linked to the controller's contact details

On 31 December 2020, the data subject filed a complaint with the DPA. They claimed that the company director was monitoring his email correspondence on a daily basis from her own account, and that several shared accounts (such as admin@, somministrazione@ and sicurquality@) were also visible to management. They attached numerous emails showing the director regularly stepping into ongoing threads to issue instructions and comment on the work of staff and external collaborators, keeping all original recipients in copy. They also stated that no written information had ever been provided about this monitoring.

The controller replied that the data subject had never been its employee. It argued that the shared accounts existed for operational reasons, that the information had been given "verbally", and that the director was authorised to act for both companies.

During the investigation, the DPA also found that, on 10 July 2018, the controller and Form-App had designated each other as data processors using identical and generic deeds, which did not specify the processing operations entrusted nor contain concrete instructions. A similar reciprocal designation already existed since November 2017.

Holding

The DPA noted that the controller had not provided the data subject with any written information about the systematic visibility of email exchanges by management, neither for the individualised account assigned to him nor for the shared accounts through which his correspondence transited. The privacy notices and internal codes produced by the controller either post-dated the facts of the complaint or contained no reference whatsoever to email management. The DPA also held that providing information "verbally", as claimed by the controller, did not satisfy Article 12(1) GDPR, which requires information to be given in writing and only allows oral information at the data subject's request. Therefore, the DPA found a violation of Article 13 GDPR. Since the duty to inform employees is, in the employment context, a direct expression of the principle of fairness, the DPA also found a violation of Article 5(1)(a) GDPR.

The DPA then assessed the director's systematic access to non-individualised accounts and, through them, to communications originating from individualised accounts of staff and external collaborators (including those of the subsidiary, with extension form-app.it). It found that this access went beyond what was necessary to coordinate the company's activities, since it was also used to comment on and evaluate the conduct of individual employees in front of their colleagues, in some cases using language that affected their professional dignity. Coordination and managerial instructions could have been issued through individualised channels that would not have exposed third parties' communications. Therefore, the DPA found that the processing was not adequate, relevant or limited to what was necessary, in violation of Article 5(1)(c) GDPR.

As to the reciprocal designations between the controller and Form-App, the DPA pointed out that the appointment of a data processor under Article 28 GDPR is not a merely formal step: the underlying legal act must identify the subject matter and duration of the processing, its nature and purposes, the type of personal data and the categories of data subjects, and must include specific instructions from the controller. Since the deeds in question only contained a generic and reciprocal formula and did not specify which processing operations were actually entrusted, the DPA found a violation of Article 28 GDPR. Finally, the DPA archived the contested violation of Article 6 GDPR concerning the director's access to communications from form-app.it accounts, accepting that the director acted as legal representative of both companies and was therefore authorised to process data on behalf of both.

On these grounds, the DPA fined the controller €40,000 for the violations of Articles 5(1)(a), 5(1)(c), 13 and 28 GDPR, taking into account, among other elements, the negligent conduct of the controller, the cooperation provided during the proceedings and the absence of prior relevant violations.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details.

[web doc. no. 9888206]

Measure of March 23, 2023

Register of Measures
No. 93 of March 23, 2023

THE ITALIAN DATA PROTECTION AUTHORITY

IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia and Guido Scorza, Members, and Councillor Fabio Mattei, Secretary General;

HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter, the "Regulation");

HAVING SEEN the Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 (Legislative Decree No. 196 of June 30, 2003, as amended by Legislative Decree No. 101 of August 10, 2018, hereinafter the "Code");

HAVING SEEN the complaint filed pursuant to Article 77 of the Regulation by Dr. XX against La Risorsa Umana.it s.r.l.;

HAVING EXAMINED the documentation in the file;

HAVING SEEN the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Guarantor No. 1/2000;

REPORTER: Professor Pasquale Stanzione;

WHEREAS

1. The complaint against the company and the investigation.

In a complaint dated December 31, 2020, settled on May 25, 2021, Dr. XX alleged violations of the Regulation by La Risorsa Umana.it s.r.l. (hereinafter, the Company), with reference to the processing of personal data carried out through the XX email account, assigned to the complainant as part of his employment relationship with the Company.

More specifically, the complaint alleged that the correspondence exchanged by the complainant through the aforementioned account, in the performance of his duties, was "monitored daily by the director [...]" through her individualized account, and extensive documentation in this regard was attached.

This was in the absence of any information provided to the Company's employees/collaborators regarding management's visibility of email exchanges (between Company personnel, between the latter and the employees and collaborators of the subsidiary Form-App s.r.l., as well as with external collaborators and consultants), which also occurred using shared company accounts. These processing operations were therefore carried out by the Company in violation of Article 13 of the Regulation and the "principles of necessity, relevance, and non-excessiveness, which do not allow for extensive and prolonged checks."

The Company, in its response to the Office's request for information, in a letter dated October 28, 2021, stated that:

a. "The complainant has never been an employee or collaborator of the undersigned company. The only contract actually signed by [the complainant] is the one stipulated with the company Form-App s.r.l., a wholly-owned subsidiary of La Risorsa Umana.it s.r.l." (note 28/10/2021, pp. 1-2);

b. The Company "has full ownership of the data processed by the various company offices, through email accounts" (note cited, p. 2);

c. "There are no situations where Management controls emails, and Management, on the other hand, has the right to access email communications from shared accounts and used by multiple users" (note cited, p. 2);

d. The Company "has mapped its processing operations, identified and authorized the individuals who can access the various processing operations" (note cited, p. 3);
e. "Since Form-App s.r.l. is the external data controller for La Risorsa Umana s.r.l., it could also process the undersigned's data" (note cited, p. 3);

f. "The owner of the data processed by the account [assigned to the complainant] is La Risorsa Umana s.r.l." (cited note, p. 4);

g. the complainant "performed services for both companies." A notice and a Code of Conduct were provided regarding the processing performed under the relevant contracts; the document relating to the "I.OP.26 procedure, currently under review [...], which explains the management of privacy obligations, including those related to the use of email, was also provided" (cited note, p. 4);

h. "There are many company accounts that are not personal, but are linked to specific operational sectors or offices and are therefore visible to multiple people for greater operational functionality" (cited note, p. 4);

i. "The admin@larisorsaumana.it account is visible to system administrators and management." “The Amministrazione@larisorsaumana.it account is shared and viewed by the HR department, external employment consultants […], and […] by company management”; “The sicurquality@larisorsaumana.it account is used not only by management, but also by those responsible for the ISO900 quality and safety system, and the head of the prevention and protection service” (note cited, p. 5);

j. “Internal personnel […] are designated as authorized to process data […]. External personnel […] are designated as external data processors” (note cited, p. 5);

k. “Form APP srl is part of the La Risorsa Umana.it srl group […], but each has different operational purposes and different, yet interconnected, types of activities”; “The two companies also operate from the same operational headquarters, therefore sharing physical premises, and use many management functions, including those related to the possibility that some employees may work for one company or for activities that are also useful to the other company in the group […]. As happened to [the complainant]” (note cited, p. 6);

l. “To address this operational need […] the appointment of an external data controller was contractually and formally established between the two companies. The documents formalizing the mutual appointment of external data controllers are attached” (note cited, p. 6).

In counterarguments dated January 17, 2022, the complainant argued that:

a. It is not true that "I did not perform any collaboration activities with the aforementioned company, otherwise the presence of documentation proving my role [...] would be inexplicable, nor would the reason why I was activated by Human Resources" (note 17/1/2022, p. 1);

b. the Company "does not explain why [...], through the address [XX], it could access and control all email communications in which it was not named, intervening in a blatant manner and with communications that were sometimes inappropriate for the type of role and function performed" (note cited, p. 2).

In a subsequent note dated June 14, 2022, sent in response to a request for further information made by the Office (dated May 26, 2022), the Company stated that:

a. A "LIST OF PERSONS AUTHORIZED TO PROCESS DATA with the Authorization Profile" has been prepared (note 14/6/2022, p. 3);

b. "for the purpose of optimal management of company work activities [...] many company operating sectors use shared email accounts" (note cited, p. 3);

c. "in order to improve understanding of shared accounts and the breakdown of authorization profiles, we have prepared [...] an organizational chart indicating the shared accounts used by Operating Unit" (note cited, p. 3).

2. Initiation of the procedure for the adoption of corrective measures and the company's submissions.

On September 1, 2022, the Office notified the Company, pursuant to Article 166, paragraph 5, of the Code, of the alleged violations of the Regulation found, with reference to Articles 5, paragraph 1, letter b). a) and c), 6, 13, and 28 of the Regulation.

In its defense briefs, submitted on September 28, 2022, the Company stated that:

a. "All documentation, including that no longer in force because it was replaced in the meantime," relating to the "complete management of the privacy system" is attached (note dated September 28, 2022, p. 2);

b. the complainant "was provided with a company email address solely for personal requests and operational convenience" (note cited, p. 3);

c. "The information was provided verbally, postponing the formalities to a later date, which unfortunately did not happen [...] due to sheer forgetfulness" (note cited, p. 3);

d. "All operators [...] are aware of the fact that, as highlighted in the Quality Manual, and as in any work instruction, Management must always be kept informed" (note cited, p. 3);

e. "Staff are trained and informed about communication flows, and the Company has preferred to prioritize operational practices, and everyone is fully aware of the process" (note cited, p. 3);

f. "The processing and operational management of communications sees email as the only tool available for intra-company communications, given that there are offices and locations scattered across the country and it is not always possible to hold in-person meetings"; "[Management's] intervention immediately informed all interested parties of Management's decisions, without the need for further email exchanges, thus avoiding overlaps and saving time for the operators involved" (note cited, p. 4);

g. In any case, the Company has currently taken steps "to better highlight the communication flow and the types of relationships between Management and offices and employees for important decisions or more confidential discussions" (note cited, p. 4);

h. "It is believed that the management of Form-App srl and LaRisorsaUmana.it srl, identified as the same natural person as [director], is justified and authorized to process data in the name and on behalf of the two companies and, in this specific case, to also communicate with operational personnel with an email address with the extension form-app.it" (note cited, pp. 4-5);

i. Regarding the relationship between the Company and Form-App srl, from November 15, 2017, "documentation was present that highlighted the operational needs between the companies and indicated the processing activities related to these activities"; as required by Legislative Decree 196/2003 in force at the time, "the appointment of an external data controller between the two companies was formalized, again in the form of an addendum to the contract" (note cited, p. 5);

j. "Subsequent to May 25, 2018 [...] new contracts were formalized in the form of addendums [...] and, at the same time, after verifying the structure of the two companies [...] it seemed logical and appropriate to re-formalize the appointment of external Data Processors between the two companies with a view to a possible future contextualization of joint data ownership for certain types of processing"; given that both companies "have similar quality systems and are [...] managed by the same control group, no specific instructions for mutual data processing had been formalized" (note cited, p. 6);

k. Among the measures adopted during the proceedings, it is noted that "the consistency of the emails shared with the individual operating sectors was verified by deleting emails no longer used and checking email access permissions based on internal data processing authorizations"; A "Code of Conduct for the Management of Email and the Internet" has also been drawn up, which also includes information on shared emails and the characteristics related to the possibility of multiple users accessing communications for work-related reasons (cited note, p. 7);

1. Finally, the Company has provided all the information required by Article 83, paragraph 2 of the Regulation.

During the hearing, held on November 9, 2022, the Company further stated that:

a. "The company deeply regrets the allegations raised by the Guarantor, especially considering that this is the first allegation of violations relating to the regulations governing the processing of personal data";

b. "Any violations believed to have been committed by the company were never committed (not even at the group level) to gain an unfair advantage. If any violations occurred, they concerned the internal architecture relating to the use of company email";

c. "In this regard, the company submitted, with its defense briefs of September 28, 2022, Annex 17, which contains the company regulations for the use of company email and the internet. These regulations also incorporate elements already present in documents previously prepared by the company and made available to employees via the company server";

d. Form-App is a sole-shareholder limited liability company, LaRisorsaUmana.it. The relationship between the two companies is governed by a service agreement. [The Company's director] is the manager of both companies.

3. Outcome of the investigation and the procedure for the adoption of corrective measures and sanctions.

3.1. Outcome of the investigation.

Following the examination of the statements made to the Authority during the proceedings, as well as the documentation acquired, it appears that the Company, as data controller, has carried out certain processing operations, relating to the complainant, that do not comply with the regulations on personal data protection.

In this regard, it is noted that, unless the act constitutes a more serious crime, anyone who, in proceedings before the Data Protection Authority, falsely declares or certifies information or circumstances, or produces false documents or records, is liable pursuant to Article 1323 of the Italian Data Protection Code. 168 of the Code "False declarations to the Guarantor and interruption of the performance of the Guarantor's duties or powers."

On the merits, it emerged that the Company assigned the complainant an individualized email account (XX) as part of an employment relationship (see the professional assignment pursuant to art. 2222 of the Italian Civil Code signed by the parties on April 23, 2019, effective June 3, 2019, a copy of which was provided by the complainant in a note dated January 17, 2022).

The professional assignment continued until June 2, 2020 (see the termination of the professional assignment dated February 27, 2020, effective June 2, 2020, a copy of which was provided by the complainant in a note dated January 17, 2022).

On the same date, a professional assignment was also signed between the complainant and Form-App s.r.l., effective as of the same date (June 3, 2019). Termination of this contract also took effect on June 2, 2020.

As part of his work as an employment consultant, the complainant engaged in correspondence through his company account with other employees and collaborators of the Company who used individualized or non-individualized accounts with the extension larisorsaumana.it. Electronic correspondence also occurred with other users using email addresses with the different extension form-app.it and with third parties (clients and consultants).

In numerous cases, documented in the documents, the Company's director also intervened during the correspondence, using her own individual account (XX), providing guidance and commenting on the complainant's previous emails (including criticizing the complainant's and other employees' actions, including the use of less than commendable language: see copies of the numerous emails attached to the complaint).

This resulted in the Company (represented by the director, who acts as supervisor and representative) processing the complainant's personal data contained in the electronic correspondence exchanged via the company account.

During the investigation, it also emerged that, on July 10, 2018, the Company designated Form-App s.r.l. (a wholly-owned subsidiary of LaRisorsaUmana.it) as data controller "limited to the scope of the task entrusted to you and with reference to the personal data you may become aware of in the performance of your activities and those that will be entrusted to you in the future."

This document does not specifically indicate the processing operations entrusted to FormApp srl, nor does it contain instructions on how to carry out the processing.

Furthermore, it emerged that, on the same date, Form-App s.r.l. also designated LaRisorsaUmana.it as data controller using the same formula, which likewise does not identify the operations entrusted to the data controller ("limited to the scope of the task entrusted to you and with reference to the personal data you may become aware of in the performance of your activities and those that will be entrusted to you in the future": see Appendices 14 and 15, Company memo dated October 28, 2021).

Attached to the defense briefs is a copy of the service provision agreement, signed on November 15, 2017, between the Company and Form-App s.r.l., under which the parent company undertakes to provide services in relation to: accounting and administrative services; financial management services; use of the IT platform and multifunctional photocopiers; telephone switchboard services; and continuous use of vehicles upon specific request (see Annex 1, briefs dated September 28, 2022; Annex 3 includes a copy of the addendum dated June 30, 2018, containing the assignment of additional services).

A copy of two deeds of "appointment of the data controller, pursuant to and for the purposes of Article 29 of Legislative Decree No. 196 of June 30, 2003," dated November 15, 2017, issued by the Company to Form-App s.r.l. and by the latter to the Company, respectively, is also attached. Both deeds concern the "management of electronic processing systems" (see Annex 2, briefs dated September 28, 2022).

3.2. Violation of Articles 5, paragraph 1, letter a), and 13 of the Regulation.

Upon review of the preliminary investigation findings, it appears, first and foremost, that the Company did not inform the complainant of its ability to perform the described processing. Nor, more generally, was any information provided regarding the use of the individualized email account or the management of non-individualized accounts with the extension larisorsaumana.it, all of which are visible to Company Management, as evidenced by the extensive correspondence attached to the complaint, including those in addition to those expressly indicated by the Company in its response note of October 28, 2021 (see in particular: pesaro@larisorsaumana.it; commercialepesaro@larisorsaumana.it; somministrapesaro@larisorsaumana.it, as well as accounts with extensions attributable to a separate company, such as commerciale@form-app.it and pugliaformazione@form-app.it).

Indeed, it emerged that the "Notice for the Processing of Supplier Personal Data" template provided by the Company, version October 2021, which in any case occurred after the events that are the subject of the complaint, contains no reference to this matter (Annex 2, company note dated October 28, 2021).

Similarly, nothing is included in the notice provided by Form App "Notice pursuant to the Personal Data Processing Code," also in the October 2021 version, which occurs after the events that are the subject of the complaint (the reference to this notice would not be relevant in this case, given that the data controller of the data processed through the account assigned to the complainant, with the extension larisorsaumana.it, is the Company in question, as also maintained by the latter; see Annex 2A, company note dated October 28, 2021).

The Code of Ethics and Conduct, approved on May 8, 2020, and therefore also subsequent to the events that are the subject of the complaint, does not provide any guidance regarding the management of email accounts (see Annex 3, Company memo dated October 28, 2021). The Operating Instruction - Procedure for the Correct Application of GDPR 679-2016 - I.Op 26 (see Annex 4, Company memo dated October 28, 2021), which is also subsequent to the events that are the subject of the complaint, given that it was first issued on August 31, 2021, also contains no reference to the proper management of email accounts.

The information documents attached to the defense briefs, dated prior to the events that are the subject of the complaint (Operating Procedure for the Management of Privacy Compliance, May 25, 2018; Security Policy Document, February 14, 2017; Operating Instructions for the Correct Application of GDPR 679-2016, July 2018, see defense briefs, Annexes 10, 12, and 16), do not contain any information in this regard.

Nor can the provision of the information "verbally," as claimed by the Company in the defense briefs (see note dated September 28, 2022), be considered compliant with current legislation, given that, pursuant to Article 12, paragraph 1, of the Regulation, "the information shall be provided in writing or by other means, including, where appropriate, electronic means," and information may be provided orally only upon the request of the interested party.

In any case, it is noted that, during the proceedings, the Company prepared a "Corporate Regulation for the Use of Email and the Internet," dated July 2022. Form-App s.r.l. has also prepared similar regulations, which include several signed acknowledgements dated September 2022.

With regard to the content of these documents, the Company is invited, pursuant to Article 57, paragraph 1, letter d) of the Regulation, to take into account the provisions of the Authority regarding the processing of data relating to employees' email and web browsing, including with regard to the application of the regulations on remote monitoring and the prohibition on surveys of opinions referred to in Articles 114 and 113 of the Code (in relation to Article 88 of the Regulation), most recently with the provisions of December 1, 2022, No. 409 (web doc. no. 9833530), 13 May 2021, no. 190 (web doc. no. 9669974) and 15 April 2021, no. 137 (web doc. no. 9670738).

It is therefore established that the Company failed to inform the complainant of company management's systematic visibility of emails exchanged with non-individualized accounts (although in some cases associated with individual employees, e.g., 'Dott.ssa […] - La Risorsa Umana.it' <sicurquality@larisorsaumana.it>) and, through these, of correspondence exchanged, including using individualized accounts, between colleagues, with the Company's clients, and with employees and collaborators working on behalf of the subsidiary Form-App s.r.l.

The information regarding the account visibility regime by company management should also have been provided, especially given that access to the electronic correspondence exchanges not only allowed for coordination of activities (as stated by the Company), but also for providing guidance on conduct and assessments of the complainant's and other employees and collaborators' performance.

The employer must clearly and adequately inform its employees and collaborators, in any case, which methods of using the tools provided are deemed appropriate and whether, to what extent, and by what methods controls are carried out. These controls must, however, comply with the principles of lawfulness, proportionality, and graduality (see the Italian Data Protection Authority's Guidelines for E-mail and the Internet, Provision 1/3/2007, No. 13, in Official Journal No. 58 of 10/3/2007, web doc. No. 1387522).

The Company's conduct described above therefore violated Article 13 of the Italian Data Protection Code. 13 of the Regulation, which provides that the data controller is obliged to inform data subjects about the specific processing method implemented, specifically by making communications visible through the company account and non-individualized accounts (including those referring to a separate data controller, as in the case of email addresses with the extension form-app.it: see in particular the emails dated 15/10/2019, 10:36 a.m., and 3/12/2019, 8:53 a.m., sent by the Company's director).

In this regard, it should be noted that, in the context of an employment relationship, the obligation to inform the employee is an expression of the general principle of fair processing (Article 5, paragraph 1, letter a) of the Regulation).

3.3. Violation of Article 5, paragraph 1, letter c) of the Regulation.

Under the legislation governing the protection of personal data in the context of employment relationships, regardless of the nature of the relationship, the data controller/employer may lawfully process personal data, as a general rule, only if the processing is necessary for the management of the employment relationship or if it is necessary to fulfill specific obligations or tasks imposed by the applicable sector regulations (Article 6, paragraph 1, letters a) and c) of the Regulation, with reference to so-called "common" data; Article 88 of the Regulation).

The data controller is, in any case, required to comply with data protection principles, in particular the principles of lawfulness, fairness, and transparency (Article 5, paragraph 1, letter a) of the Regulation) and data minimization, according to which the data processed are adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed (Article 5, paragraph 1, letter c) of the Regulation).

In particular, data processing carried out using information technology within the employment context must comply with the fundamental rights and freedoms, as well as the dignity of the data subject, especially if the processing involves communications via email accounts, given the specific protections that the law attaches to different forms of communication (see Recommendation CM/Rec (2015)5 of the Committee of Ministers to Member States on the processing of personal data in the employment context, especially points 3 and 14).

In this case, it emerged that the company management, through the systematic inspection (and consequent apprehension of the content) of non-individualized accounts, even when used by individual employees or collaborators of the Company (as can be seen from the very name of the accounts present in the documents, such as 'Dott.ssa […] - La Risorsa Umana.it' <sicurquality@larisorsaumana.it> or 'Dott.ssa […] – Form App <commerciale@form-app.it>'), and consequently of the communications also carried out through individualized accounts (such as the one assigned to the complainant) by its own employees and collaborators – but also, in at least two cases documented in the documents, by collaborators of the subsidiary Form App s.r.l. – By reconstructing the "chain" of messages sent, he provided information, requested clarification, and expressed comments and assessments (often critical) on the actions of employees and collaborators, leaving and/or copying all interlocutors of the original communication (in some cases including others), so that all participants in the conversation were aware of its content.

It is noted that the Company, in its decision to issue a warning to management for the behavior, as revealed by the emails at issue in this proceeding, deemed "inappropriate" and "reprehensible" (see defense briefs, pages 4 and 7).

Without prejudice to the need to ensure the continuity of adequate communication flows within the company (see defense briefs and Annexes 13 and 14), the methods adopted by the Company in managing the emails subject to the complaint do not comply with the aforementioned principle of minimization and proportionality, with respect to the objectives pursued. This is also true given that the objectives specifically pursued go beyond the need to ensure coordination of activities, resulting in systematic intervention on the work of individual employees and collaborators, which is also disclosed to other colleagues/collaborators, in some cases using expressions that are detrimental to the dignity, including professional dignity, of the recipients, thus interfering in the private and professional spheres of collaborators and employees.

The coordination of activities and, even more so, the making of decisions that fall within the remit of company management and the related communication to recipients may well be carried out in an individualized manner that does not infringe the confidentiality of collaborators and employees.

The processing therefore occurred in violation of Article 5, paragraph 1, of the Italian Legislative Decree. 1, letter c) of the Regulation.

3.4. Violation of Article 28 of the Regulation.

Finally, it emerged that the Company designated its subsidiary Form-App s.r.l. as data processor, based on, according to the information provided, an "operational need" related to the use of "many management functions" by employees and collaborators of the respective companies. At the same time, Form App s.r.l., in turn, designated the Company as data processor.

This designation appears to have been made as early as November 2017, through the signing of two mirrored deeds of mutual appointment by the Company and Form-App s.r.l. as data processors, with the same purpose (the "management of electronic processing systems," see Annex 2, briefs dated September 28, 2022).

On the same date (November 15, 2017), a service agreement was signed between the Company and Form-App srl, under which the parent company undertakes to provide the subsidiary with a variety of services, the scope of which was subsequently expanded (dated June 30, 2018: see Annexes 1 and 3, briefs dated September 28, 2022).

Both the mutual appointment as data processors for the same purpose (November 15, 2017) and the subsequent mutual designation as data processors (July 10, 2018), through documents—also drafted and signed on the same date—which, however, were generic and purely formal, do not comply with the provisions of the personal data protection regulations, given that the specific processing operations that the data controller entrusts to the data processor are not identified, nor are specific instructions given.

Given that this configuration contradicts the assignment by Form-App s.r.l. of specific services to the parent company (with a contract dated November 15, 2017, as seen above), given the latter's greater management capacity and availability of resources, it should be noted that, at present, pursuant to Article 28, paragraph 3 of the Regulation, the designation by the controller of a data processor chosen on the basis of the "sufficient guarantees" the processor can provide, in relation to the performance of specific processing operations for which the controller alone determines the purposes and means, including security measures, does not constitute a mere formality.

In fact, the legal document underlying the designation must identify "the subject-matter and duration of the processing, the nature and purposes of the processing, the type of personal data and the categories of data subjects," in order to effectively comply with the provisions of the Regulation, including with regard to the need to protect the rights and freedoms of data subjects (see recital 81 of the Regulation).

Responsibility for compliance with personal data protection regulations must be clearly assigned to the separate entities performing processing operations.

The mutual designation of the two companies in the terms emerging from the investigation—and consequently the processing operations performed on the basis of the two documents—is therefore not compliant with the provisions of Article 28 of the Regulation.

In this regard, the fact that personal data processing actually occurred pursuant to the aforementioned agreements is evident both from the Company's statements (use of management functions by employees of the respective companies) and from the fact that management also had visibility of accounts with the extension form-app.it, as noted above (see emails dated 15/10/2019, 10:36 a.m. and 3/12/2019, 8:53 a.m., sent by management, in the file).

The processing operations carried out by the Company pursuant to the aforementioned mutual designation agreements, for the reasons stated above, are therefore in violation of Article 28 of the Regulation.

Finally, with regard to the alleged violation of Article 28 of the Regulation, 6 of the Regulation, carried out in relation to the possibility for the Company's management to learn the content of communications made using accounts with the extension form-app.it, i.e., attributable to a separate company (Form-App s.r.l.), and the resulting processing of personal data of employees and collaborators using the related accounts, having acknowledged the Company's statements in its defense briefs ("the Management of Form-App srl and La RisorsaUmana.it srl, identified as the same natural person [...], is justified and authorized to process the data in the name and on behalf of the two companies and, in this specific case, to also communicate with operational personnel with email addresses with the extension form-app.it") and having considered the attached documentation (Annex 1, Minutes of the meeting chaired by the Sole Director of Form-App srl, dated 15/11/2017, containing the company organizational chart where the company's representative appears to be representing the company and acting as company manager), it is deemed appropriate to dismiss the relevant dispute.

4. Conclusions: Declaration of unlawful processing. Corrective measures pursuant to Article 58, paragraph 2, of the Regulation.

For the above reasons, the Authority believes that the statements, documentation, and reconstructions provided by the data controller during the investigation do not address the concerns notified by the Office in the initiation of the proceedings and are therefore unsuitable for dismissing this proceeding. Furthermore, none of the cases provided for by Article 11 of the Garante Regulation No. 1/2019 apply.

The processing of personal data carried out by the Company, and specifically data processed via company email and processing carried out on the basis of mutual designations as data processors, is unlawful, in the terms set out above, in relation to Articles 5, paragraph 1, letters a) and c), 13, and 28 of the Regulation.

The violation established in the terms set out in the reasons cannot be considered "minor," taking into account the nature and severity of the violation, the degree of responsibility, and the manner in which the supervisory authority became aware of the violation (see recital 148 of the Regulation).

Therefore, given the corrective powers granted by Article 58, paragraph 2 of the Regulation, an administrative pecuniary sanction is imposed pursuant to Article 83 of the Regulation, commensurate with the circumstances of the specific case (Article 58, paragraph 2, letter i) of the Regulation).

5. Adoption of an injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letter i), and Article 83 of the Regulation; Article 166, paragraph 7, of the Code).

As a result of the proceedings, it appears that La Risorsa Umana.it s.r.l. violated Articles 5, paragraph 1, letters a) and c), 13, and 28 of the Regulation. Violations of the aforementioned provisions are subject to the application of the administrative pecuniary sanction provided for in Article 83, paragraph 4, letters a) and b) of the Regulation, through the issuance of an injunction (Article 18, Law No. 689 of November 24, 1981).

We believe it is appropriate to apply Article 83, paragraph 3 of the Regulation, which provides that "If, for the same or linked processing operations, a controller […] infringes several provisions of this Regulation, intentionally or negligently, the total amount of the administrative pecuniary sanction shall not exceed the amount specified for the gravest infringement." The total amount of the sanction is calculated so as not to exceed the maximum sanction provided for in the same Article 83, paragraph 5.

With reference to the elements listed in Article 83, paragraph 3, of the Regulation, the following applies: 83, paragraph 2 of the Regulation, for the purposes of applying the administrative fine and its quantification, taking into account that the fine must "in any case be effective, proportionate and dissuasive" (Article 83, paragraph 1 of the Regulation), it is noted that, in this case, the following circumstances were considered:

a) in relation to the nature and severity of the violation, the nature of the violation was considered relevant, as it concerned the general principles of processing (in particular the principles of fairness and data minimization), the disclosure obligation, and the provision on the data processor (Article 83, paragraph 1, letter a) of the Regulation);

b) with regard to the degree of responsibility of the controller, the negligent conduct of the Company, which failed to comply with data protection regulations in the context of the employment relationship with its employees, was taken into consideration (Article 83, paragraph 1, letter b) of the Regulation);

c) regarding the level of cooperation with the Supervisory Authority, it was considered that the Company cooperated with the Garante during the proceedings (Article 83, paragraph 1, letter f) of the Regulation);

d) regarding the intentional or negligent nature of the violation, it was considered that the Company, through its conduct, intended to monitor the communications of employees and collaborators (Article 83, paragraph 1, letter b) of the Regulation);

e) in favor of the Company, the absence of previous violations regarding the protection of personal data was also taken into account (Article 83, paragraph 1, letters a), e), and g) of the Regulation).

Furthermore, it is believed that, given the aforementioned principles of effectiveness, proportionality, and dissuasiveness, which the Authority must adhere to in determining the amount of the fine (Article 83, paragraph 1, of the Regulation), the following are of primary importance in this case: the financial situation of the offender, determined based on the Company's revenues in the ordinary financial statements for 2021.

In light of the above elements and the assessments made, it is deemed appropriate, in this case, to impose an administrative fine of €40,000 (forty thousand) against La Risorsa Umana.it s.r.l.

In this context, it is also considered, given the nature of the violations identified, which concerned the general principles of processing (in particular the principles of fairness and data minimization), the disclosure obligation and the provisions governing the data processor, which, pursuant to Article 83, paragraph 1, of the Regulation, are relevant. 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Italian Data Protection Authority Regulation No. 1/2019, this provision should be published on the Italian Data Protection Authority's website.

It is also believed that the conditions set forth in Article 17 of Regulation No. 1/2019 are met.

NOW WITHOUT PREJUDICE, THE ITALIAN DATA PROTECTION AUTHORITY

deems the processing carried out by La Risorsa Umana.it s.r.l., represented by its legal representative, with registered office at Via Carlo Marx, 95, Modena (MO), VAT No. 01971890353, pursuant to Article 143 of the Code, is unlawful due to the violation of Articles 5, paragraph 1, letters a) and c), 13, and 28 of the Regulation;

RESOLVES

to dismiss the complaint filed against La Risorsa Umana.it s.r.l., represented by its legal representative, with a deed dated September 1, 2022, limited to the violation of Article 6 of the Regulations;

ORDERS

pursuant to Article 58, paragraph 2, letter i) of the Regulations, La Risorsa Umana.it s.r.l. to pay the sum of €40,000 (forty thousand) as an administrative fine for the violations indicated in this order;

THEREFORE ORDERS

the same Company to pay the aforementioned sum of €40,000 (forty thousand), according to the procedures indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the resulting enforcement actions pursuant to Article 27 of Law No. 689/1981. Please note that the offender retains the right to settle the dispute by paying—in accordance with the procedures indicated in the attachment—an amount equal to half the fine imposed, within the deadline set out in Article 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, for filing an appeal as indicated below (Article 166, paragraph 8, of the Code);

ORDERS

the publication of this provision on the website of the Guarantor pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Guarantor Regulation No. 1/20129, and believes that the conditions set out in Article 17 of Regulation No. 1/2019 are met.

Pursuant to Article 78 of the Regulation, as well as Articles 152 of the Code and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be lodged with the ordinary judicial authority, with an appeal filed with the ordinary court of the place identified in the same Article 10, within thirty days from the date of notification of the provision itself, or sixty days if the appellant resides abroad.

Rome, March 23, 2023

THE PRESIDENT
Stanzione

THE REPORTER
Stanzione

THE SECRETARY GENERAL
Mattei

[web doc. no. 9888206]

Provision of March 23, 2023

Register of Provisions
no. 93 of March 23, 2023

THE AUTHORITY FOR THE PROTECTION OF PERSONAL DATA

During today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia and Guido Scorza, attorney, members, and Fabio Mattei, general secretary;

HAVING SEEN Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter, the "Regulation");

HAVING SEEN the Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 (Legislative Decree No. 196 of 30 June 2003, as amended by Legislative Decree No. 101 of 10 August 2018, hereinafter the "Code");

HAVING SEEN the complaint filed pursuant to Article 77 of the Regulation by Dr. XX against La Risorsa Umana.it s.r.l.;

HAVING EXAMINED the documentation in the file;

HAVING SEEN the observations made by the Secretary General pursuant to Article 15 of the Guarantor's Regulation No. 1/2000;

REPORTER: Professor Pasquale Stanzione;

WHEREAS

1. The complaint against the company and the investigation.

In a complaint dated December 31, 2020, settled on May 25, 2021, Dr. XX alleged violations of the Regulation by La Risorsa Umana.it s.r.l. (hereinafter, the Company), with reference to the processing of personal data carried out through the XX email account, assigned to the complainant as part of his employment relationship with the Company.

More specifically, the complaint alleged that the correspondence exchanged by the complainant through the aforementioned account, in the performance of his duties, was "monitored daily by the director [...]" through her individualized account, and extensive documentation in this regard was attached.

This was in the absence of any information provided to the Company's employees/collaborators regarding management's visibility of email exchanges (between Company personnel, between the latter and the employees and collaborators of the subsidiary Form-App s.r.l., as well as with external collaborators and consultants), which also occurred using shared company accounts. These processing operations were therefore carried out by the Company in violation of Article 13 of the Regulation and the "principles of necessity, relevance, and non-excessiveness, which do not allow for extensive and prolonged checks."

The Company, in its response to the Office's request for information, in a letter dated October 28, 2021, stated that:

a. "The complainant has never been an employee or collaborator of the undersigned company. The only contract actually signed by [the complainant] is the one stipulated with the company Form-App s.r.l., a wholly-owned subsidiary of La Risorsa Umana.it s.r.l." (note 28/10/2021, pp. 1-2);

b. The Company "has full ownership of the data processed by the various company offices, through email accounts" (note cited, p. 2);

c. "There are no situations where Management controls emails, and Management, on the other hand, has the right to access email communications from shared accounts and used by multiple users" (note cited, p. 2);

d. The Company "has mapped its processing operations, identified and authorized the individuals who can access the various processing operations" (note cited, p. 3);
e. "Since Form-App s.r.l. is the external data controller for La Risorsa Umana s.r.l., it could also process the undersigned's data" (note cited, p. 3);

f. "The owner of the data processed by the account [assigned to the complainant] is La Risorsa Umana s.r.l." (cited note, p. 4);

g. the complainant "performed services for both companies." A notice and a Code of Conduct were provided regarding the processing performed under the relevant contracts; the document relating to the "I.OP.26 procedure, currently under review [...], which explains the management of privacy obligations, including those related to the use of email, was also provided" (cited note, p. 4);

h. "There are many company accounts that are not personal, but are linked to specific operational sectors or offices and are therefore visible to multiple people for greater operational functionality" (cited note, p. 4);

i. "The admin@larisorsaumana.it account is visible to system administrators and management." “The Amministrazione@larisorsaumana.it account is shared and viewed by the HR department, external employment consultants […], and […] by company management”; “The sicurquality@larisorsaumana.it account is used not only by management, but also by those responsible for the ISO900 quality and safety system, and the head of the prevention and protection service” (note cited, p. 5);

j. “Internal personnel […] are designated as authorized to process data […]. External personnel […] are designated as external data processors” (note cited, p. 5);

k. “Form APP srl is part of the La Risorsa Umana.it srl group […], but each has different operational purposes and different, yet interconnected, types of activities”; “The two companies also operate from the same operational headquarters, therefore sharing physical premises, and use many management functions, including those related to the possibility that some employees may work for one company or for activities that are also useful to the other company in the group […]. As happened to [the complainant]” (note cited, p. 6);

l. “To address this operational need […] the appointment of an external data controller was contractually and formally established between the two companies. The documents formalizing the mutual appointment of external data controllers are attached” (note cited, p. 6).

In counterarguments dated January 17, 2022, the complainant argued that:

a. It is not true that "I did not perform any collaboration activities with the aforementioned company, otherwise the presence of documentation proving my role [...] would be inexplicable, nor would the reason why I was activated by Human Resources" (note 17/1/2022, p. 1);

b. the Company "does not explain why [...], through the address [XX], it could access and control all email communications in which it was not named, intervening in a blatant manner and with communications that were sometimes inappropriate for the type of role and function performed" (note cited, p. 2).

In a subsequent note dated June 14, 2022, sent in response to a request for further information made by the Office (dated May 26, 2022), the Company stated that:

a. A "LIST OF PERSONS AUTHORIZED TO PROCESS DATA with the Authorization Profile" has been prepared (note 14/6/2022, p. 3);

b. "for the purpose of optimal management of company work activities [...] many company operating sectors use shared email accounts" (note cited, p. 3);

c. "in order to improve understanding of shared accounts and the breakdown of authorization profiles, we have prepared [...] an organizational chart indicating the shared accounts used by Operating Unit" (note cited, p. 3).

2. Initiation of the procedure for the adoption of corrective measures and the company's submissions.

On September 1, 2022, the Office notified the Company, pursuant to Article 166, paragraph 5, of the Code, of the alleged violations of the Regulation found, with reference to Articles 5, paragraph 1, letter b). a) and c), 6, 13, and 28 of the Regulation.

In its defense briefs, submitted on September 28, 2022, the Company stated that:

a. "All documentation, including that no longer in force because it was replaced in the meantime," relating to the "complete management of the privacy system" is attached (note dated September 28, 2022, p. 2);

b. the complainant "was provided with a company email address solely for personal requests and operational convenience" (note cited, p. 3);

c. "The information was provided verbally, postponing the formalities to a later date, which unfortunately did not happen [...] due to sheer forgetfulness" (note cited, p. 3);

d. "All operators [...] are aware of the fact that, as highlighted in the Quality Manual, and as in any work instruction, Management must always be kept informed" (note cited, p. 3);

e. "Staff are trained and informed about communication flows, and the Company has preferred to prioritize operational practices, and everyone is fully aware of the process" (note cited, p. 3);

f. "The processing and operational management of communications sees email as the only tool available for intra-company communications, given that there are offices and locations scattered across the country and it is not always possible to hold in-person meetings"; "[Management's] intervention immediately informed all interested parties of Management's decisions, without the need for further email exchanges, thus avoiding overlaps and saving time for the operators involved" (note cited, p. 4);

g. In any case, the Company has currently taken steps "to better highlight the communication flow and the types of relationships between Management and offices and employees for important decisions or more confidential discussions" (note cited, p. 4);

h. "It is believed that the management of Form-App srl and LaRisorsaUmana.it srl, identified as the same natural person as [director], is justified and authorized to process data in the name and on behalf of the two companies and, in this specific case, to also communicate with operational personnel with an email address with the extension form-app.it" (note cited, pp. 4-5);

i. Regarding the relationship between the Company and Form-App srl, from November 15, 2017, "documentation was present that highlighted the operational needs between the companies and indicated the processing activities related to these activities"; as required by Legislative Decree 196/2003 in force at the time, "the appointment of an external data controller between the two companies was formalized, again in the form of an addendum to the contract" (note cited, p. 5);

j. "Subsequent to May 25, 2018 [...] new contracts were formalized in the form of addendums [...] and, at the same time, after verifying the structure of the two companies [...] it seemed logical and appropriate to re-formalize the appointment of external Data Processors between the two companies with a view to a possible future contextualization of joint data ownership for certain types of processing"; given that both companies "have similar quality systems and are [...] managed by the same control group, no specific instructions for mutual data processing had been formalized" (note cited, p. 6);

k. Among the measures adopted during the proceedings, it is noted that "the consistency of the emails shared with the individual operating sectors was verified by deleting emails no longer used and checking email access permissions based on internal data processing authorizations"; A "Code of Conduct for the Management of Email and the Internet" has also been drawn up, which also includes information on shared emails and the characteristics related to the possibility of multiple users accessing communications for work-related reasons (cited note, p. 7);

1. Finally, the Company has provided all the information required by Article 83, paragraph 2 of the Regulation.

During the hearing, held on November 9, 2022, the Company further stated that:

a. "The company deeply regrets the allegations raised by the Guarantor, especially considering that this is the first allegation of violations relating to the regulations governing the processing of personal data";

b. "Any violations believed to have been committed by the company were never committed (not even at the group level) to gain an unfair advantage. If any violations occurred, they concerned the internal architecture relating to the use of company email";

c. "In this regard, the company submitted, with its defense briefs of September 28, 2022, Annex 17, which contains the company regulations for the use of company email and the internet. These regulations also incorporate elements already present in documents previously prepared by the company and made available to employees via the company server";

d. Form-App is a sole-shareholder limited liability company, LaRisorsaUmana.it. The relationship between the two companies is governed by a service agreement. [The Company's director] is the manager of both companies.

3. Outcome of the investigation and the procedure for the adoption of corrective measures and sanctions.

3.1. Outcome of the investigation.

Following the examination of the statements made to the Authority during the proceedings, as well as the documentation acquired, it appears that the Company, as data controller, has carried out certain processing operations, relating to the complainant, that do not comply with the regulations on personal data protection.

In this regard, it is noted that, unless the act constitutes a more serious crime, anyone who, in proceedings before the Data Protection Authority, falsely declares or certifies information or circumstances, or produces false documents or records, is liable pursuant to Article 1323 of the Italian Data Protection Code. 168 of the Code "False declarations to the Guarantor and interruption of the performance of the Guarantor's duties or powers."

On the merits, it emerged that the Company assigned the complainant an individualized email account (XX) as part of an employment relationship (see the professional assignment pursuant to art. 2222 of the Italian Civil Code signed by the parties on April 23, 2019, effective June 3, 2019, a copy of which was provided by the complainant in a note dated January 17, 2022).

The professional assignment continued until June 2, 2020 (see the termination of the professional assignment dated February 27, 2020, effective June 2, 2020, a copy of which was provided by the complainant in a note dated January 17, 2022).

On the same date, a professional assignment was also signed between the complainant and Form-App s.r.l., effective as of the same date (June 3, 2019). Termination of this contract also took effect on June 2, 2020.

As part of his work as an employment consultant, the complainant engaged in correspondence through his company account with other employees and collaborators of the Company who used individualized or non-individualized accounts with the extension larisorsaumana.it. Electronic correspondence also occurred with other users using email addresses with the different extension form-app.it and with third parties (clients and consultants).

In numerous cases, documented in the documents, the Company's director also intervened during the correspondence, using her own individual account (XX), providing guidance and commenting on the complainant's previous emails (including criticizing the complainant's and other employees' actions, including the use of less than commendable language: see copies of the numerous emails attached to the complaint).

This resulted in the Company (represented by the director, who acts as supervisor and representative) processing the complainant's personal data contained in the electronic correspondence exchanged via the company account.

During the investigation, it also emerged that, on July 10, 2018, the Company designated Form-App s.r.l. (a wholly-owned subsidiary of LaRisorsaUmana.it) as data controller "limited to the scope of the task entrusted to you and with reference to the personal data you may become aware of in the performance of your activities and those that will be entrusted to you in the future."

This document does not specifically indicate the processing operations entrusted to FormApp srl, nor does it contain instructions on how to carry out the processing.

Furthermore, it emerged that, on the same date, Form-App s.r.l. also designated LaRisorsaUmana.it as data controller using the same formula, which likewise does not identify the operations entrusted to the data controller ("limited to the scope of the task entrusted to you and with reference to the personal data you may become aware of in the performance of your activities and those that will be entrusted to you in the future": see Appendices 14 and 15, Company memo dated October 28, 2021).

Attached to the defense briefs is a copy of the service provision agreement, signed on November 15, 2017, between the Company and Form-App s.r.l., under which the parent company undertakes to provide services in relation to: accounting and administrative services; financial management services; use of the IT platform and multifunctional photocopiers; telephone switchboard services; and continuous use of vehicles upon specific request (see Annex 1, briefs dated September 28, 2022; Annex 3 includes a copy of the addendum dated June 30, 2018, containing the assignment of additional services).

A copy of two deeds of "appointment of the data controller, pursuant to and for the purposes of Article 29 of Legislative Decree No. 196 of June 30, 2003," dated November 15, 2017, issued by the Company to Form-App s.r.l. and by the latter to the Company, respectively, is also attached. Both deeds concern the "management of electronic processing systems" (see Annex 2, briefs dated September 28, 2022).

3.2. Violation of Articles 5, paragraph 1, letter a), and 13 of the Regulation.

Upon review of the preliminary investigation findings, it appears, first and foremost, that the Company did not inform the complainant of its ability to perform the described processing. Nor, more generally, was any information provided regarding the use of the individualized email account or the management of non-individualized accounts with the extension larisorsaumana.it, all of which are visible to Company Management, as evidenced by the extensive correspondence attached to the complaint, including those in addition to those expressly indicated by the Company in its response note of October 28, 2021 (see in particular: pesaro@larisorsaumana.it; commercialepesaro@larisorsaumana.it; somministrapesaro@larisorsaumana.it, as well as accounts with extensions attributable to a separate company, such as commerciale@form-app.it and pugliaformazione@form-app.it).

Indeed, it emerged that the "Notice for the Processing of Supplier Personal Data" template provided by the Company, version October 2021, which in any case occurred after the events that are the subject of the complaint, contains no reference to this matter (Annex 2, company note dated October 28, 2021).

Similarly, nothing is included in the notice provided by Form App "Notice pursuant to the Personal Data Processing Code," also in the October 2021 version, which occurs after the events that are the subject of the complaint (the reference to this notice would not be relevant in this case, given that the data controller of the data processed through the account assigned to the complainant, with the extension larisorsaumana.it, is the Company in question, as also maintained by the latter; see Annex 2A, company note dated October 28, 2021).

The Code of Ethics and Conduct, approved on May 8, 2020, and therefore also subsequent to the events that are the subject of the complaint, does not provide any guidance regarding the management of email accounts (see Annex 3, Company memo dated October 28, 2021). The Operating Instruction - Procedure for the Correct Application of GDPR 679-2016 - I.Op 26 (see Annex 4, Company memo dated October 28, 2021), which is also subsequent to the events that are the subject of the complaint, given that it was first issued on August 31, 2021, also contains no reference to the proper management of email accounts.

The information documents attached to the defense briefs, dated prior to the events that are the subject of the complaint (Operating Procedure for the Management of Privacy Compliance, May 25, 2018; Security Policy Document, February 14, 2017; Operating Instructions for the Correct Application of GDPR 679-2016, July 2018, see defense briefs, Annexes 10, 12, and 16), do not contain any information in this regard.

Nor can the provision of the information "verbally," as claimed by the Company in the defense briefs (see note dated September 28, 2022), be considered compliant with current legislation, given that, pursuant to Article 12, paragraph 1, of the Regulation, "the information shall be provided in writing or by other means, including, where appropriate, electronic means," and information may be provided orally only upon the request of the interested party.

In any case, it is noted that, during the proceedings, the Company prepared a "Corporate Regulation for the Use of Email and the Internet," dated July 2022. Form-App s.r.l. has also prepared similar regulations, which include several signed acknowledgements dated September 2022.

With regard to the content of these documents, the Company is invited, pursuant to Article 57, paragraph 1, letter d) of the Regulation, to take into account the provisions of the Authority regarding the processing of data relating to employees' email and web browsing, including with regard to the application of the regulations on remote monitoring and the prohibition on surveys of opinions referred to in Articles 114 and 113 of the Code (in relation to Article 88 of the Regulation), most recently with the provisions of December 1, 2022, No. 409 (web doc. no. 9833530), 13 May 2021, no. 190 (web doc. no. 9669974) and 15 April 2021, no. 137 (web doc. no. 9670738).

It is therefore established that the Company failed to inform the complainant of company management's systematic visibility of emails exchanged with non-individualized accounts (although in some cases associated with individual employees, e.g., 'Dott.ssa […] - La Risorsa Umana.it' <sicurquality@larisorsaumana.it>) and, through these, of correspondence exchanged, including using individualized accounts, between colleagues, with the Company's clients, and with employees and collaborators working on behalf of the subsidiary Form-App s.r.l.

The information regarding the account visibility regime by company management should also have been provided, especially given that access to the electronic correspondence exchanges not only allowed for coordination of activities (as stated by the Company), but also for providing guidance on conduct and assessments of the complainant's and other employees and collaborators' performance.

The employer must clearly and adequately inform its employees and collaborators, in any case, which methods of using the tools provided are deemed appropriate and whether, to what extent, and by what methods controls are carried out. These controls must, however, comply with the principles of lawfulness, proportionality, and graduality (see the Italian Data Protection Authority's Guidelines for E-mail and the Internet, Provision 1/3/2007, No. 13, in Official Journal No. 58 of 10/3/2007, web doc. No. 1387522).

The Company's conduct described above therefore violated Article 13 of the Italian Data Protection Code. 13 of the Regulation, which provides that the data controller is obliged to inform data subjects about the specific processing method implemented, specifically by making communications visible through the company account and non-individualized accounts (including those referring to a separate data controller, as in the case of email addresses with the extension form-app.it: see in particular the emails dated 15/10/2019, 10:36 a.m., and 3/12/2019, 8:53 a.m., sent by the Company's director).

In this regard, it should be noted that, in the context of an employment relationship, the obligation to inform the employee is an expression of the general principle of fair processing (Article 5, paragraph 1, letter a) of the Regulation).

3.3. Violation of Article 5, paragraph 1, letter c) of the Regulation.

Under the legislation governing the protection of personal data in the context of employment relationships, regardless of the nature of the relationship, the data controller/employer may lawfully process personal data, as a general rule, only if the processing is necessary for the management of the employment relationship or if it is necessary to fulfill specific obligations or tasks imposed by the applicable sector regulations (Article 6, paragraph 1, letters a) and c) of the Regulation, with reference to so-called "common" data; Article 88 of the Regulation).

The data controller is, in any case, required to comply with data protection principles, in particular the principles of lawfulness, fairness, and transparency (Article 5, paragraph 1, letter a) of the Regulation) and data minimization, according to which the data processed are adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed (Article 5, paragraph 1, letter c) of the Regulation).

In particular, data processing carried out using information technology within the employment context must comply with the fundamental rights and freedoms, as well as the dignity of the data subject, especially if the processing involves communications via email accounts, given the specific protections that the law attaches to different forms of communication (see Recommendation CM/Rec (2015)5 of the Committee of Ministers to Member States on the processing of personal data in the employment context, especially points 3 and 14).

In this case, it emerged that the company management, through the systematic inspection (and consequent apprehension of the content) of non-individualized accounts, even when used by individual employees or collaborators of the Company (as can be seen from the very name of the accounts present in the documents, such as 'Dott.ssa […] - La Risorsa Umana.it' <sicurquality@larisorsaumana.it> or 'Dott.ssa […] – Form App <commerciale@form-app.it>'), and consequently of the communications also carried out through individualized accounts (such as the one assigned to the complainant) by its own employees and collaborators – but also, in at least two cases documented in the documents, by collaborators of the subsidiary Form App s.r.l. – By reconstructing the "chain" of messages sent, he provided information, requested clarification, and expressed comments and assessments (often critical) on the actions of employees and collaborators, leaving and/or copying all interlocutors of the original communication (in some cases including others), so that all participants in the conversation were aware of its content.

It is noted that the Company, in its decision to issue a warning to management for the behavior, as revealed by the emails at issue in this proceeding, deemed "inappropriate" and "reprehensible" (see defense briefs, pages 4 and 7).

Without prejudice to the need to ensure the continuity of adequate communication flows within the company (see defense briefs and Annexes 13 and 14), the methods adopted by the Company in managing the emails subject to the complaint do not comply with the aforementioned principle of minimization and proportionality, with respect to the objectives pursued. This is also true given that the objectives specifically pursued go beyond the need to ensure coordination of activities, resulting in systematic intervention on the work of individual employees and collaborators, which is also disclosed to other colleagues/collaborators, in some cases using expressions that are detrimental to the dignity, including professional dignity, of the recipients, thus interfering in the private and professional spheres of collaborators and employees.

The coordination of activities and, even more so, the making of decisions that fall within the remit of company management and the related communication to recipients may well be carried out in an individualized manner that does not infringe the confidentiality of collaborators and employees.

The processing therefore occurred in violation of Article 5, paragraph 1, of the Italian Legislative Decree. 1, letter c) of the Regulation.

3.4. Violation of Article 28 of the Regulation.

Finally, it emerged that the Company designated its subsidiary Form-App s.r.l. as data processor, based on, according to the information provided, an "operational need" related to the use of "many management functions" by employees and collaborators of the respective companies. At the same time, Form App s.r.l., in turn, designated the Company as data processor.

This designation appears to have been made as early as November 2017, through the signing of two mirrored deeds of mutual appointment by the Company and Form-App s.r.l. as data processors, with the same purpose (the "management of electronic processing systems," see Annex 2, briefs dated September 28, 2022).

On the same date (November 15, 2017), a service agreement was signed between the Company and Form-App srl, under which the parent company undertakes to provide the subsidiary with a variety of services, the scope of which was subsequently expanded (dated June 30, 2018: see Annexes 1 and 3, briefs dated September 28, 2022).

Both the mutual appointment as data processors for the same purpose (November 15, 2017) and the subsequent mutual designation as data processors (July 10, 2018), through documents—also drafted and signed on the same date—which, however, were generic and purely formal, do not comply with the provisions of the personal data protection regulations, given that the specific processing operations that the data controller entrusts to the data processor are not identified, nor are specific instructions given.

Given that this configuration contradicts the assignment by Form-App s.r.l. of specific services to the parent company (with a contract dated November 15, 2017, as seen above), given the latter's greater management capacity and availability of resources, it should be noted that, at present, pursuant to Article 28, paragraph 3 of the Regulation, the designation by the controller of a data processor chosen on the basis of the "sufficient guarantees" the processor can provide, in relation to the performance of specific processing operations for which the controller alone determines the purposes and means, including security measures, does not constitute a mere formality.

In fact, the legal document underlying the designation must identify "the subject-matter and duration of the processing, the nature and purposes of the processing, the type of personal data and the categories of data subjects," in order to effectively comply with the provisions of the Regulation, including with regard to the need to protect the rights and freedoms of data subjects (see recital 81 of the Regulation).

Responsibility for compliance with personal data protection regulations must be clearly assigned to the separate entities performing processing operations.

The mutual designation of the two companies in the terms emerging from the investigation—and consequently the processing operations performed on the basis of the two documents—is therefore not compliant with the provisions of Article 28 of the Regulation.

In this regard, the fact that personal data processing actually occurred pursuant to the aforementioned agreements is evident both from the Company's statements (use of management functions by employees of the respective companies) and from the fact that management also had visibility of accounts with the extension form-app.it, as noted above (see emails dated 15/10/2019, 10:36 a.m. and 3/12/2019, 8:53 a.m., sent by management, in the file).

The processing operations carried out by the Company pursuant to the aforementioned mutual designation agreements, for the reasons stated above, are therefore in violation of Article 28 of the Regulation.

Finally, with regard to the alleged violation of Article 28 of the Regulation, 6 of the Regulation, carried out in relation to the possibility for the Company's management to learn the content of communications made using accounts with the extension form-app.it, i.e., attributable to a separate company (Form-App s.r.l.), and the resulting processing of personal data of employees and collaborators using the related accounts, having acknowledged the Company's statements in its defense briefs ("the Management of Form-App srl and La RisorsaUmana.it srl, identified as the same natural person [...], is justified and authorized to process the data in the name and on behalf of the two companies and, in this specific case, to also communicate with operational personnel with email addresses with the extension form-app.it") and having considered the attached documentation (Annex 1, Minutes of the meeting chaired by the Sole Director of Form-App srl, dated 15/11/2017, containing the company organizational chart where the company's representative appears to be representing the company and acting as company manager), it is deemed appropriate to dismiss the relevant dispute.

4. Conclusions: Declaration of unlawful processing. Corrective measures pursuant to Article 58, paragraph 2, of the Regulation.

For the above reasons, the Authority believes that the statements, documentation, and reconstructions provided by the data controller during the investigation do not address the concerns notified by the Office in the initiation of the proceedings and are therefore unsuitable for dismissing this proceeding. Furthermore, none of the cases provided for by Article 11 of the Garante Regulation No. 1/2019 apply.

The processing of personal data carried out by the Company, and specifically data processed via company email and processing carried out on the basis of mutual designations as data processors, is unlawful, in the terms set out above, in relation to Articles 5, paragraph 1, letters a) and c), 13, and 28 of the Regulation.

The violation established in the terms set out in the reasons cannot be considered "minor," taking into account the nature and severity of the violation, the degree of responsibility, and the manner in which the supervisory authority became aware of the violation (see recital 148 of the Regulation).

Therefore, given the corrective powers granted by Article 58, paragraph 2 of the Regulation, an administrative pecuniary sanction is imposed pursuant to Article 83 of the Regulation, commensurate with the circumstances of the specific case (Article 58, paragraph 2, letter i) of the Regulation).

5. Adoption of an injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letter i), and Article 83 of the Regulation; Article 166, paragraph 7, of the Code).

As a result of the proceedings, it appears that La Risorsa Umana.it s.r.l. violated Articles 5, paragraph 1, letters a) and c), 13, and 28 of the Regulation. Violations of the aforementioned provisions are subject to the application of the administrative pecuniary sanction provided for in Article 83, paragraph 4, letters a) and b) of the Regulation, through the issuance of an injunction (Article 18, Law No. 689 of November 24, 1981).

We believe it is appropriate to apply Article 83, paragraph 3 of the Regulation, which provides that "If, for the same or linked processing operations, a controller […] infringes several provisions of this Regulation, intentionally or negligently, the total amount of the administrative pecuniary sanction shall not exceed the amount specified for the gravest infringement." The total amount of the sanction is calculated so as not to exceed the maximum sanction provided for in the same Article 83, paragraph 5.

With reference to the elements listed in Article 83, paragraph 3, of the Regulation, the following applies: 83, paragraph 2 of the Regulation, for the purposes of applying the administrative fine and its quantification, taking into account that the fine must "in any case be effective, proportionate and dissuasive" (Article 83, paragraph 1 of the Regulation), it is noted that, in this case, the following circumstances were considered:

a) in relation to the nature and severity of the violation, the nature of the violation was considered relevant, as it concerned the general principles of processing (in particular the principles of fairness and data minimization), the disclosure obligation, and the provision on the data processor (Article 83, paragraph 1, letter a) of the Regulation);

b) with regard to the degree of responsibility of the controller, the negligent conduct of the Company, which failed to comply with data protection regulations in the context of the employment relationship with its employees, was taken into consideration (Article 83, paragraph 1, letter b) of the Regulation);

c) regarding the level of cooperation with the Supervisory Authority, it was considered that the Company cooperated with the Garante during the proceedings (Article 83, paragraph 1, letter f) of the Regulation);

d) regarding the intentional or negligent nature of the violation, it was considered that the Company, through its conduct, intended to monitor the communications of employees and collaborators (Article 83, paragraph 1, letter b) of the Regulation);

e) in favor of the Company, the absence of previous violations regarding the protection of personal data was also taken into account (Article 83, paragraph 1, letters a), e), and g) of the Regulation).

Furthermore, it is believed that, given the aforementioned principles of effectiveness, proportionality, and dissuasiveness, which the Authority must adhere to in determining the amount of the fine (Article 83, paragraph 1, of the Regulation), the following are of primary importance in this case: the financial situation of the offender, determined based on the Company's revenues in the ordinary financial statements for 2021.

In light of the above elements and the assessments made, it is deemed appropriate, in this case, to impose an administrative fine of €40,000 (forty thousand) against La Risorsa Umana.it s.r.l.

In this context, it is also considered, given the nature of the violations identified, which concerned the general principles of processing (in particular the principles of fairness and data minimization), the disclosure obligation and the provisions governing the data processor, which, pursuant to Article 83, paragraph 1, of the Regulation, are relevant. 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Italian Data Protection Authority Regulation No. 1/2019, this provision should be published on the Italian Data Protection Authority's website.

It is also believed that the conditions set forth in Article 17 of Regulation No. 1/2019 are met.

NOW WITHOUT PREJUDICE, THE ITALIAN DATA PROTECTION AUTHORITY

deems the processing carried out by La Risorsa Umana.it s.r.l., represented by its legal representative, with registered office at Via Carlo Marx, 95, Modena (MO), VAT No. 01971890353, pursuant to Article 143 of the Code, is unlawful due to the violation of Articles 5, paragraph 1, letters a) and c), 13, and 28 of the Regulation;

RESOLVES

to dismiss the complaint filed against La Risorsa Umana.it s.r.l., represented by its legal representative, with a deed dated September 1, 2022, limited to the violation of Article 6 of the Regulations;

ORDERS

pursuant to Article 58, paragraph 2, letter i) of the Regulations, La Risorsa Umana.it s.r.l. to pay the sum of €40,000 (forty thousand) as an administrative fine for the violations indicated in this order;

THEREFORE ORDERS

the same Company to pay the aforementioned sum of €40,000 (forty thousand), according to the procedures indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the resulting enforcement actions pursuant to Article 27 of Law No. 689/1981. Please note that the offender retains the right to settle the dispute by paying—in accordance with the procedures indicated in the attachment—an amount equal to half the fine imposed, within the deadline set out in Article 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, for filing an appeal as indicated below (Article 166, paragraph 8, of the Code);

ORDERS

the publication of this provision on the website of the Guarantor pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Guarantor Regulation No. 1/20129, and believes that the conditions set out in Article 17 of Regulation No. 1/2019 are met.

Pursuant to Article 78 of the Regulation, as well as Articles 152 of the Code and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be lodged with the ordinary judicial authority, with an appeal filed with the ordinary court of the place identified in the same Article 10, within thirty days from the date of notification of the provision itself, or sixty days if the appellant resides abroad.

Rome, March 23, 2023

THE PRESIDENT
Stanzione

THE REPORTER
Stanzione

THE SECRETARY GENERAL
Mattei