TL;DR for the DPO
Italy's DPA (decision no. 311 of 29 April 2026) found unlawful the use of loyalty-card programme data to support an employee's dismissal. The data had been collected for one purpose (running the customer loyalty programme) and reused for an entirely different, incompatible purpose (disciplinary/dismissal), breaching the purpose-limitation principle (Art. 5(1)(b) GDPR).
The three points that matter
- Purpose limitation (Art. 5(1)(b)): data collected for the loyalty programme cannot be 'recycled' to monitor or sanction employees. The original purpose binds later use.
- Employee monitoring has its own rules: pulling from a customer database to build a disciplinary case bypasses the required safeguards (necessity, proportionality, Art. 4 of the Workers' Statute). It is not an allowed shortcut.
- Evidence gathered in breach of privacy is weak and backfires: beyond the fine, a dismissal based on that data becomes challengeable.
What to do now, in practice
For every client running loyalty programmes, CRM or newsletters: 1) clearly define the purposes in the notice and the record of processing; 2) separate access - those handling marketing and customer data must not be able to use it for HR or disciplinary purposes; 3) train anyone with database access on the ban on reuse for other purposes. The generator's notices (clients, newsletter, staff) already keep these purposes distinct.
Why it matters for your clients
It is a common, cross-sector mistake: the company 'already has the data' and uses it for whatever it needs at that moment. The decision is a reminder that the purpose stated at collection time is a boundary, not a suggestion. For a DPO it is the chance to check purpose separation and database access governance with clients, before an authority or a labour court raises the question.
Official source:Italian Data Protection Authority - decision no. 311 of 29 April 2026Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free