Every company has a drawer where it keeps things “just in case”. Piaggio, the Italian group behind the Vespa, kept one too: a backup of its employees’ email, retained for the entire employment relationship and up to five years after people had left, plus six months of access logs. This summer Italy’s data protection authority, the Garante, put a price on that drawer: a 460,000 euro fine, and a ban on using anything inside it.
The decision, dated 18 June 2026 and made public in August, reads like an anatomy of well-intentioned surveillance. During the employment relationship the company had accessed workers’ mailboxes, acquiring 112 emails in total. The information given to staff about why their mail was being stored, and on what legal basis, was found lacking. Employees who exercised their right to ask what data the company held about them got no answer. And the whole arrangement, the authority concluded, was capable of reconstructing a person’s working activity, which makes it remote monitoring, the thing Italian labour law only allows under strict guarantees that were nowhere to be found.
The instinct that built that system is universal, and that is what makes the case worth reading outside Italy. Nobody plans a surveillance programme: an administrator configures a generous backup, someone decides five years is safer than one, an office opens a mailbox “just for this one check”. Each step feels like diligence. The sum of the steps is a dossier on every employee, and the bill arrives all at once.
Could you say, right now, how long your company keeps each piece of employee data and why? In the free 14-day trial you can see what retention looks like when it is designed before, not after.
No credit card, running in 2 minutes.
Open your trialWorth underlining: the authority did not rule that backups are forbidden, or that an employer can never investigate a concrete suspicion. It ruled that any tool capable of monitoring workers’ activity has to live inside the guarantees labour law builds around it, in Italy that means article 4 of the Workers’ Statute with its union agreements and inspectorate authorisations, and everywhere in Europe it means telling people clearly what happens to their data and keeping it no longer than the stated purpose allows. Outside that fence, the most ordinary IT plumbing counts as unlawful surveillance, however innocent the intent of whoever set it up.
Keeping everything is not a safety net
The GDPR calls the principle storage limitation, and it applies from Lisbon to Helsinki: you keep personal data only as long as the purpose justifies, and every byte you hold is something you must explain, protect and produce on request. Seen through that lens, an ever-growing archive is not a reserve of prudence, it is liability compounding quietly in a server room. Piaggio stumbled on exactly that: subject access requests going unanswered while the backups grew.
There is a second confusion underneath, and we see it in small firms as often as in industrial groups: using tools built for communication as if they were tools for documentation. The mailbox, the chat history, the old threads become the improvised archive a business plans to defend itself with when a client or an employee disputes something. It is the worst of both worlds. As evidence it is weak, fragmentary and easy to challenge. As data processing it is enormous, because five years of email contain a person’s life, not their work.










