DATA ON SOCIAL NETWORKS AND DISCIPLINARY PROCEDURES: THE LIMITS SET BY THE DATA PROTECTION AUTHORITY
With provision no. 288 of 21 May 2025, the Italian Data Protection Authority (Garante della Privacy) ruled on digital monitoring of workers, in particular on the use by employers of employees’ data which have been obtained through social networks and private chats on messaging platforms in order to base on such data disciplinary proceedings leading to dismissal.
According to the Authority, after ascertaining the private nature of the conversations and comments – which are published in digital contexts with limited access – the company must refrain from using them, as it must comply with the principles set out in privacy legislation:
- principle of lawfulness, i.e. respect for the secrecy and confidentiality of private correspondence protected by the constitution (irrespective of whether the data was found directly by the employer or provided by third parties);
- principle of purpose limitation, i.e. data must be collected for specific, explicit and legitimate purposes, as well as processed in a manner consistent with those purposes (in particular, personal data on social networks, or otherwise accessible online, cannot be used freely and for any purpose, simply because they are visible to a certain number of people);
- principle of minimization, i.e. data must be adequate, relevant and limited to what is strictly necessary (for example, the data collected must not relate to exchanges of opinion that took place outside the context of the employment relationship and are not relevant for the purposes of professional assessment).


