With decision No. 165 of 2026, the Italian Data Protection Authority sanctioned ITAS Mutua for GDPR violation in the management of corporate email accounts of former employees. The case touches on an operational topic every DPO faces: what to do with corporate email after employment has ended.
Violations identified
- Undocumented and unjustified access to former employee's emails
- Data retention for a period disproportionate to the purposes
- Lack of a formalized internal procedure for post-termination management
- Absence of adequate notice to the employee at hiring time
An outdated view
The employer's temptation to consider everything happening on their servers as 'their property' is a residue of a proprietary vision that GDPR and European case law have definitively overcome.
Best practices to implement
- Specific notice at hiring indicating times and methods of email management after termination
- Formalized procedure for immediate mailbox deactivation (within 24-48 hours)
- Automatic reply for max 30-60 days indicating the alternative contact
- Limited and encrypted backup, retained max 12 months unless ongoing litigation
- Access to content only with documented authorization and for specific purposes
In DPO Workspace
Among the sector templates there is a 'Post-termination employee email management' procedure that the DPO can apply to the client as an initial placeholder to customize.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free