The case, explained
Privacy Authority: illegal use of system logs for employee monitoring
6 min read · Updated September 2026 · Editorial oversight: Avv. Federico Papa
The recent ruling of June has solidified an impassable boundary for employers: data collected for IT security cannot be transformed into productivity monitoring tools. According to reports in the national press, particularly specialized outlets like Il Sole 24 Ore and Agenda Digitale, the Privacy Authority has sanctioned the systematic use of access logs for disciplinary disputes, defining this practice as a violation of the guarantees provided by the Workers' Statute. The case arises from the need to balance cybersecurity requirements with the privacy rights of workers. While other profiles of this complex subject, such as the usability of data in criminal proceedings, are covered in dedicated articles of this column, here we will focus on administrative and labor law limits. Through the twin case of our Gaio Sventura, we will see how reckless management of IT systems can lead to heavy sanctions and the nullity of corporate measures.

In brief
The article analyzes the recent Privacy Authority ruling banning the use of system logs for disciplinary purposes without a union agreement. It explores the relationship between Art. 4 of the Workers' Statute and the GDPR, highlighting the incompatibility between security purposes and performance monitoring. Through a didactic reconstruction, it illustrates the consequences of illegal use of IT data and operational lessons for the correct management of corporate systems.
The fact
According to reports from outlets such as Il Sole 24 Ore and Agenda Digitale, the Privacy Authority concluded an investigation into a technology company that used system logs (server logins, connection times, and application usage) to minutely monitor its employees' activities. The proceedings, reaching the stage of a final administrative sanctioning order, established that data collected for declared IT security purposes were actually stored for excessive periods and cross-referenced to evaluate individual worker performance.
The company defended itself by arguing that the collection was necessary to protect corporate assets and constituted so-called defensive controls. However, the Authority noted the lack of a union agreement procedure and adequate information notice, declaring the processing unlawful. The case raised the issue of the so-called change of purpose: a company cannot surreptitiously use a technical security measure for disciplinary purposes, evading the protections of the Workers' Statute.

The rules in play
The core of the issue lies in Article 4 of Law 300/1970 (Workers' Statute).
- Paragraph 1 establishes that tools allowing remote monitoring can only be used for organizational, security, or asset protection needs, subject to a union agreement or authorization from the Labor Inspectorate.
- Paragraph 2 exempts tools necessary for performing the work from this procedure, but case law interprets this derogation restrictively, excluding massive system logs.
- Paragraph 3 conditions the usability of data on compliance with the GDPR and the delivery of a clear information notice. Other central rules are Articles 5 and 13 of EU Regulation 2016/679, which impose the principle of purpose limitation: data collected for security cannot be used for anything else without a suitable legal basis.
What case law says
The established orientation of the courts of legitimacy has clarified that logs generated by a server do not in themselves constitute the work tool, but represent a mode of indirect monitoring. The judges established that if the IT system allows constant, analytical, and preventive monitoring, the company must activate the union co-determination procedure, under penalty of the data being unusable for disciplinary purposes.
Furthermore, case law has limited so-called defensive controls. These are permitted without a prior union agreement only if activated ex post, i.e., after a well-founded and specific suspicion of a serious offense committed by the employee has arisen. Conversely, dragnet technological monitoring of ordinary productivity is not allowed, as the employer's right to protect company assets cannot override the dignity and privacy of the worker within the digital perimeter.
- Try edit.legal AI
Analysis drafted and verified with edit.legal
To verify the provisions cited in this article, we used edit.legal. Test our legal AI on official sources and apply it to your own matters.
What it teaches professionals
- Clearly distinguish between technical log collection for incident response purposes and using them for evaluating work performance.
- Always implement a DPIA (Data Protection Impact Assessment) before activating IT monitoring systems that could potentially intercept employee activity.
- Remember that the privacy information notice under Art. 13 GDPR must be granular: a generic mention of security is not sufficient to cover disciplinary uses of logs.
- Constantly verify retention periods for IT data, reducing them to the minimum necessary for the declared technical purpose.
References: Articolo 4 Legge 300/1970Articolo 5 Regolamento UE 2016/679 (GDPR)Articolo 13 Regolamento UE 2016/679 (GDPR)Articolo 114 D.Lgs. 196/2003
Related cases

Frequently asked questions
Can the employer check web history if the PC is company-owned?
Only if provided for by a clear policy, for lawful purposes (e.g., security), and in compliance with Art. 4 of the Workers' Statute; massive and indiscriminate monitoring is generally prohibited.
What do I risk if I use logs without a union agreement?
The main risk is the inadmissibility of evidence in court, the annulment of dismissals, and heavy fines from the Privacy Authority.
Are there logs that do not require union agreements?
Yes, those strictly necessary for the tool to function and allow performance, but the line is thin and must be evaluated case-by-case with a legal expert.
Verified legal research and drafting with edit.legal
Legal research and drafting with citations checked against official databases. edit.legal is free to try, no credit card.
Try edit.legal for free