The case, explained
Investigation into Fictitious Remote Work and Digital Monitoring: Log-ins as Evidence
8 min read · Updated September 2026 · Editorial oversight: Avv. Federico Papa
The hypothesis of investigations into fictitious remote work based on connection data brings to the fore the legitimacy of digital monitoring. The issue, which could involve consultancy firms, revolves around the possibility that employees work from locations other than those declared, allowing companies to unduly benefit from contribution relief intended for disadvantaged areas. This scenario brings to the fore the boundary between work tools and covert surveillance. Through an analysis of the applicable framework and a twin case featuring our recurring characters, this article examines how IT log-ins can evolve from technical data into key evidence in potential criminal proceedings. The article specifically focuses on the evidentiary weight of such data under the Workers' Statute, distinguishing this scenario from GPS tracking or external investigative checks.

In brief
The article analyzes the legal issues related to fictitious remote work, focusing on the admissibility of IT log-ins and IP addresses as evidence of potential fraud against the State. It examines the relationship between Art. 4 of the Workers' Statute and defensive checks, highlighting how data collected through work tools can be used in criminal proceedings to establish contribution offenses, provided that information transparency toward the employee is ensured.
The facts
The legal debate stems from the hypothesis that a consultancy firm might adopt operating models aimed at unduly benefiting from contribution relief. In this theoretical scenario, a company could formally certify that employees perform their duties remotely from geographic areas that guarantee tax or contribution breaks, whereas they would permanently work at other offices. The core of any potential evidentiary framework would lie in cross-referencing the contribution statements sent to INPS with IT traffic data. The analysis of IP addresses and connection metadata to corporate servers could reveal a systematic discrepancy between declared and actual geographic locations. Other aspects concerning privacy and the right to disconnect are addressed in dedicated articles.

The laws at play
The applicable legal framework rests on three fundamental pillars governing the intersection of corporate management and compliance:
- Art. 640-bis of the Italian Criminal Code (Aggravated fraud for obtaining public funds), which punishes anyone who, through deception or artifice, misleads a public body to obtain undue benefits, with penalties of up to seven years' imprisonment.
- Art. 4, paragraph 2, of Law no. 300/1970 (Workers' Statute), which provides that restrictions on remote monitoring do not apply to tools used by employees to perform their work, making log-in data theoretically accessible to the employer.
- Legislative Decree no. 231/2001, defining the administrative liability of entities, which imposes financial and disqualifying sanctions if fraud is committed in the company's interest or to its benefit without adequate organizational models to prevent it. The evidentiary effectiveness of these rules strictly depends on compliance with the information obligations under the Privacy Code, as the failure to notify employees regarding data usage may invalidate the admissibility of evidence.
Case law
Supreme Court case law has established that data extracted from work tools are fully admissible when aimed at detecting criminal offenses.
- Regarding defensive checks, the Supreme Court has clarified that an employer may monitor digital activity to protect corporate assets against criminal conduct, bypassing the procedural constraints of Art. 4 of the Workers' Statute when the check is conducted ex post and targeted at a specific offense.
- However, labor case law takes a stricter view: if the check is intended merely to verify compliance with working hours, it remains subject to trade union agreements or authorization from the Labor Inspectorate.
- Concerning contribution fraud, the prevailing view holds that falsely stating the workplace location in data submissions sent to INPS constitutes the offense, as it deprives the public body of the ability to verify eligibility for contribution relief. The principle of proportionality remains paramount, requiring IP data analysis to be strictly limited to what is necessary to prove fraudulent conduct, without degenerating into generalized surveillance of private life.
- Try edit.legal AI
Analysis drafted and verified with edit.legal
To verify the provisions cited in this article, we used edit.legal. Test our legal AI on official sources and apply it to your own matters.
What it teaches professionals
The analysis yields key operational lessons for managing corporate compliance:
- Promptly update the privacy notice, explicitly stating that log-in data may be processed for asset protection and contribution compliance checks.
- Enhance organizational models under Legislative Decree no. 231/2001 by establishing cross-checking procedures between declared locations for incentives and technical connection data.
- Strictly distinguish between performance monitoring (prohibited if covert) and defensive checks (permitted to detect unlawful conduct), ensuring proper documentation of the grounds justifying an internal investigation.
- Carefully assess the evidentiary package: in criminal proceedings, raw IP data alone may require supporting testimonial or documentary evidence regarding the employee's actual physical location.
Update and rectification note (17 September 2026)
The previous version of this article referred to an investigation by the Milan Financial Police, against a consulting company, with the assigned prosecutor named, mentioning notices of conclusion of investigations and preventive seizures. Following an editorial review, it emerged that these statements are not supported by any official documents or primary sources, and the named entity does not appear to exist in these terms. The text has therefore been corrected and anonymized, removing all unfounded attributions and transforming the discussion into a general legal analysis.
References: Art. 640-bis c.p.Art. 4 Legge 300/1970D.Lgs. 231/2001Legge 81/2017
Related cases

Frequently asked questions
Can the company use my IP address to fire me if I work from a location other than the one agreed upon?
In general, using IP data for disciplinary purposes requires that the employee was previously provided with adequate privacy notice. However, if the conduct constitutes a criminal offense or causes severe harm to corporate assets, the check may qualify as a defensive check and be deemed lawful; ultimate evaluation rests with the trial court.
What risks does an employee face if involved in their company's contribution fraud?
If the employee is aware of the false representations and actively contributes to the fraudulent scheme, they may be prosecuted as a co-perpetrator in aggravated fraud against the State, alongside facing employment disciplinary sanctions.
How long does the State have to challenge these IT log-in frauds?
The crime of aggravated fraud for obtaining public funds is subject to an ordinary statute of limitations of six years, which can extend to seven and a half years in the presence of interrupting acts, such as the notification of an official investigation notice or the conclusion of preliminary investigations.
Verified legal research and drafting with edit.legal
Legal research and drafting with citations checked against official databases. edit.legal is free to try, no credit card.
Try edit.legal for free