When someone leaves your organization, the standard procedure is to revoke their access immediately. Lock the email account, preserve it for legal holds or knowledge transfer, and move on. It's clean, secure, and protects company assets.
Except when it violates the General Data Protection Regulation.
The Risks of Non-Compliance
The Italian Supervisory Authority recently fined a company 40,000 EUR for following this common practice. They locked a former employee out of his company email account after dismissal, continued receiving messages on his behalf, and forwarded them to another employee's account. This unlawful practice continued for about two months, exceeding the company's own 30-day internal limit.
The problem with the conventional approach is that it treats the employee's inbox as purely company property. Under the General Data Protection Regulation, that inbox contains the employee's personal data. Denying access and forwarding messages without consent violates Articles 15 (Right of Access) and 6 (Lawful Basis for Processing).
The Italian case highlights a deeper issue. The company had internal rules acknowledging a 30-day transition period but still failed to comply. Why? Because your offboarding checklist probably doesn't include "grant departing employee access to review and retrieve their inbox contents" as a step. It should.
Evidence of Non-Compliance
The Italian Supervisory Authority's decision was based on several failures:
The company denied the former employee access to his email account after termination. He submitted a formal request under the General Data Protection Regulation asking them to disable the account, forward any interim messages to his personal address, and activate an automatic reply with his new contact information. The company ignored the request entirely.
Meanwhile, they continued receiving emails addressed to him and forwarding them to another employee's account without his knowledge or consent. This went on for two months, violating their own internal 30-day policy.
The Authority considered the type and duration of violations, the company's failure to respond to a Data Subject Access Request, and the lack of any legitimate interest justifying the processing. The fine reflected not just the privacy breach, but the procedural contempt: when someone exercises their rights under the General Data Protection Regulation, you respond.
This isn't an edge case. Article 15 gives individuals the right to obtain confirmation of whether you're processing their personal data and to access that data. Article 17 grants the right to erasure under certain conditions. Your termination process must accommodate these rights, even when the relationship ends badly.
Steps to Ensure Compliance
First, revise your offboarding procedures to include a mandatory General Data Protection Regulation compliance step. Before you lock any departing employee out of their email account, you must:
- Provide them a reasonable window (the Italian case suggests 30 days as a defensible standard) to access and download their inbox contents. This includes emails they sent, received, or were copied on that contain their personal data.
- Respond to any Data Subject Access Requests within the 72-hour notification requirement window, even if the employee is no longer on payroll. The General Data Protection Regulation doesn't care about employment status.
- Document your legal basis for retaining the account after termination. If you're preserving it for litigation or regulatory compliance, that's Article 6(1)(f), legitimate interests. But you still must inform the individual and honor their access rights where they don't conflict with that basis.
- If you forward emails from a terminated employee's account to another employee, you're creating a new processing activity. You need consent or another lawful basis. "It's convenient" isn't one.
Second, separate personal data from business records in your retention policies. The contract documents, project files, and client communications the employee created may belong to you. The emails containing their health information, union correspondence, or personal messages to colleagues do not. You can't treat the entire mailbox as a monolithic asset.
Third, train your HR and IT teams on the distinction between access revocation (a security control) and data access rights (a legal obligation). These aren't the same thing. You can revoke system access while still providing a mechanism for the individual to retrieve their personal data. Export the mailbox to a PST file and provide it securely. Set up a temporary read-only web access session. Use a third-party data portability tool. The method doesn't matter; the outcome does.
Fourth, if your internal policies promise a specific timeframe or procedure for post-termination data access, follow them. The Italian company's own 30-day rule became evidence against them when they violated it. Your policies create expectations that supervisory authorities will enforce.
When Immediate Access Revocation is Appropriate
Immediate access revocation still makes sense for security. You should disable login credentials, revoke VPN access, and deactivate multi-factor authentication tokens the moment employment ends. No one disputes that.
Preserving evidence is also valid. If you're facing litigation, regulatory investigation, or internal misconduct review, you have legitimate grounds to retain the email account intact. Article 6(1)(f) and Article 9(2)(f) provide for processing necessary for legal claims. Just document it, inform the individual, and don't use that preservation as an excuse to deny all access.
Forwarding urgent business emails that arrive after termination is acceptable, but only those directly related to active projects or client needs, and only until you've properly transitioned those responsibilities. Blanket forwarding of everything is lazy and unlawful.
The real lesson from the Italian case isn't that you should give former employees permanent email access. It's that your termination procedures must account for their data rights under the General Data Protection Regulation. You can protect company assets and comply with data protection law simultaneously. You just have to plan for both.
Your offboarding checklist probably has 47 steps covering badge return, laptop wiping, and benefits continuation. Add one more: "Provide mechanism for departing employee to access and retrieve personal data from company systems within 30 days." It'll cost you far less than 40,000 EUR.





