All news
Enforcement June 15, 2026 4 min

Loyalty-card data used to fire an employee: Italy's DPA says no. A lesson on purpose limitation

Data collected for the loyalty programme cannot be recycled to build a dismissal. A simple but very common case on Art. 5 GDPR

TL;DR for the DPO

Italy's DPA (decision no. 311 of 29 April 2026) found unlawful the use of loyalty-card programme data to support an employee's dismissal. The data had been collected for one purpose (running the customer loyalty programme) and reused for an entirely different, incompatible purpose (disciplinary/dismissal), breaching the purpose-limitation principle (Art. 5(1)(b) GDPR).

The three points that matter

  • Purpose limitation (Art. 5(1)(b)): data collected for the loyalty programme cannot be 'recycled' to monitor or sanction employees. The original purpose binds later use.
  • Employee monitoring has its own rules: pulling from a customer database to build a disciplinary case bypasses the required safeguards (necessity, proportionality, Art. 4 of the Workers' Statute). It is not an allowed shortcut.
  • Evidence gathered in breach of privacy is weak and backfires: beyond the fine, a dismissal based on that data becomes challengeable.

What to do now, in practice

For every client running loyalty programmes, CRM or newsletters: 1) clearly define the purposes in the notice and the record of processing; 2) separate access - those handling marketing and customer data must not be able to use it for HR or disciplinary purposes; 3) train anyone with database access on the ban on reuse for other purposes. The generator's notices (clients, newsletter, staff) already keep these purposes distinct.

Why it matters for your clients

It is a common, cross-sector mistake: the company 'already has the data' and uses it for whatever it needs at that moment. The decision is a reminder that the purpose stated at collection time is a boundary, not a suggestion. For a DPO it is the chance to check purpose separation and database access governance with clients, before an authority or a labour court raises the question.

Official source:Italian Data Protection Authority - decision no. 311 of 29 April 2026

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
26complaints, and no fine

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.

Aug 26, 2026New 6 min
Enforcement
825 mln €the second-largest fine ever

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

It is the second-largest fine ever imposed under the GDPR, behind only Meta's 1.2 billion. It is not about a data transfer or a security breach: it is about Article 22, the rule on automated decisions that almost nobody documents because it looks like a big-platform problem. It is in fact about anyone who lets software decide something that weighs on a person's life.

Aug 24, 2026New 5 min
Enforcement
64 mln złagainst 14 the year before

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

For years Poland was treated as a low-enforcement market. That assumption no longer holds: in twelve months the total went from fourteen to over sixty-four million zloty, and the three largest fines in the country's history all carry the same year. If you look after a client with a branch, a supplier or a service centre in Poland, the risk calculation has changed.

Aug 24, 2026New 4 min