An Italian company has been fined 50,000 Euros by the Italian Data Protection Authority for installing GPS systems in its vehicles, thus illicitly monitoring around 50 employees during their working hours. The Authority intervened after an ex-employee lodged a complaint.
During inspections carried out in conjunction with the Finance Guard’s Privacy Protection Unit, it transpired that the GPS system was continuously tracking location data, speed, mileage, and the vehicles’ statuses (whether they were on or off), contravening data privacy laws and deviating from the guidelines outlined in the authorisation granted by the Regional Labor Inspectorate.
Specifically, severe shortcomings were noted in the information provided to the workers. This included failure to indicate the specific methods by which the data was processed and lack of information concerning the direct identifiability of the drivers of geolocated vehicles. These processing methods were also contrary to the specific safeguarding measures indicated in the authorisation granted by the Labor Inspectorate. This permission had stipulated anonymization of the data collected and the adoption of technological solutions capable of limiting the collection of unnecessary or excessive personal data.
Additionally, the collected data was stored for over 5 months, violating the principles of data minimisation and storage limitation established by the EU Regulation.
Considering the numerous and severe breaches, in addition to the fine, the Authority has ordered the company to provide appropriate information to its employees and to adjust the processing performed through the GPS system according to the guarantees prescribed in the authorisation granted by the Regional Labor Inspectorate.

