Data Processing in the Workplace: Analysis of the Past Year – Part 1

At the beginning of the “first implementation” of data protection rules, it was not uncommon to hear the company representative of the day claim: “our company does not process personal data.” As if a business made up of people and resources could truly operate without managing information concerning its own human capital.

In reality, the processing of personal data in the workplace—meaning the processing of employees’ data—concerns organizations of every kind, both public and private: from the pre-employment phase to the management of the employment relationship, from occupational safety to information protection measures, up to and beyond the termination of employment.

Introduction

This series of Editorial features has been dedicated to data processing in the workplace for at least two strategic reasons.

  1. Proper management of employee data is the building block on which a company’s culture of respect is founded: it is the humus that makes the obligations of fairness and good faith in the performance and execution of the employment contract (Articles 1175 and 1375 of the Italian Civil Code) credible, enforceable, and lasting—together with the duties of diligence (Article 2104 c.c.) and, above all, loyalty (Article 2105 c.c.) on the part of the employee. In other words, without data processing that is lawful, transparent, proportionate, and secure, those duties—which define the employer/employee relationship—risk remaining mere statements of principle, lacking practical grounding.
  2. Experience shows that where employee data is well governed, the company itself is well governed: clear processes, traceable responsibilities, proper data minimization and retention, understandable privacy notices, appropriate legal bases, and effective security measures. It is often observed that a solid HR privacy perimeter coincides with a strong overall level of compliance—from data protection to cybersecurity, from internal controls to supplier management.

The goal of this series is therefore to offer a detailed analysis of data processing in the employment context, examining the most relevant decisions of the Italian Data Protection Authority (Garante) issued over the past year and drawing from them practical criteria, dos and don’ts, and actionable takeaways applicable to one’s own organizational setting.

Upcoming articles will address unlawful processing of health or sensitive data, processing through technological devices, online disclosure of employee data, and the code of conduct for employment agencies.

Condividi

Post Recenti

Workshop – Come realizzare una FRIA

Beyond the Algorithm: Safeguarding the Human in the Age of Artificial Intelligence

Energy Telemarketing: Law 49/2026 Changes the Rules of the Game – 2