All news
Italian DPA May 7, 2026 5 min

Corporate email post-termination: Italian DPA fines ITAS Mutua

Decision 165/2026: limited access and disproportionate retention

With decision No. 165 of 2026, the Italian Data Protection Authority sanctioned ITAS Mutua for GDPR violation in the management of corporate email accounts of former employees. The case touches on an operational topic every DPO faces: what to do with corporate email after employment has ended.

Violations identified

  • Undocumented and unjustified access to former employee's emails
  • Data retention for a period disproportionate to the purposes
  • Lack of a formalized internal procedure for post-termination management
  • Absence of adequate notice to the employee at hiring time

An outdated view

The employer's temptation to consider everything happening on their servers as 'their property' is a residue of a proprietary vision that GDPR and European case law have definitively overcome.

Best practices to implement

  • Specific notice at hiring indicating times and methods of email management after termination
  • Formalized procedure for immediate mailbox deactivation (within 24-48 hours)
  • Automatic reply for max 30-60 days indicating the alternative contact
  • Limited and encrypted backup, retained max 12 months unless ongoing litigation
  • Access to content only with documented authorization and for specific purposes

In DPO Workspace

Among the sector templates there is a 'Post-termination employee email management' procedure that the DPO can apply to the client as an initial placeholder to customize.

Official source:Right to access corporate email: Italian DPA 2026 decision (Altalex)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Italian DPA
12keuro

Misconfigured document register: 12,000 euro fine for the Metropolitan City of Sassari

Following a data breach notification and a complaint, the Italian data protection authority fined the Metropolitan City of Sassari for misconfiguring its electronic document register, making documents containing personal data accessible to staff who, given their role and duties, were not authorised to process them. The fine is 12,000 euro, but the principle applies to every public body and every company running a document management system: filing is not a neutral activity, and a default of total visibility breaches the principles of integrity and confidentiality.

Jul 29, 2026 6 min
Italian DPA
2/2genitori

Children's photos on social media: both parents must consent

In its 17 June 2026 newsletter the Italian DPA restated a principle that matters well beyond family disputes: publishing photos of minor children on social media requires the consent of BOTH parents. In case of disagreement, the child's protection prevails. For the DPO it is an operational criterion affecting schools, nurseries, sports clubs, parishes and companies publishing images of minors for promotional purposes.

Jul 15, 2026 3 min
Italian DPA
STOPcopie

Italian DPA to hoteliers: do not keep copies of guests' ID documents

In a notice addressed to the hospitality sector, the Italian DPA reiterated that hoteliers may not keep copies of guests' identity documents: the legal duty (Art. 109 of the Italian public-security code) is to identify the guest and transmit the data to the police via the Alloggiati Web portal - after that, document copies must be destroyed or deleted. A widespread habit becomes a concrete sanction risk.

Jul 14, 2026 3 min