Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
GPS in Company Cars: What 120K Fine Teaches About Employee Monitoringgeneral
5 min readFor Compliance Officers

GPS in Company Cars: What 120K Fine Teaches About Employee Monitoring

The Compliance Lesson

The Italian Supervisory Authority fined a company 120,000 EUR for installing satellite tracking devices in five company cars without proper legal authorization under Italian labor law. These devices monitored employees' driving times, mileage, fuel consumption, and driving style during both work and private trips, assigning rating scores for performance evaluation.

This enforcement action highlights three compliance failures: inadequate legal basis under local labor regulations, unclear data controller relationships in multinational structures, and unauthorized cross-border access to monitoring data. The Italian SA's decision shows how workplace monitoring technologies trigger obligations under both data protection law and employment regulations.

The issue wasn't the technology itself, as satellite tracking for fleet management is common. The violations occurred because the company deployed the system without worker consultation required by Italian labor law, without transparent documentation of processing purposes, and without controlling who could access the monitoring data across the corporate group.

Key Findings

Labor law compliance is essential. The Italian workers' Charter requires specific safeguards before employers can monitor workers electronically. The company installed tracking at the request of its Swiss parent company but failed to establish the legal authorization required in Italy. Your data protection impact assessment can't replace labor law requirements. You need both.

This creates a sequencing problem for multinational deployments. A monitoring system approved by headquarters may violate local employment regulations even when it meets General Data Protection Regulation technical requirements. You can't roll out employee monitoring globally based on a single legal assessment.

Transparency issues at the controller level. The company provided workers with a privacy notice listing multiple affiliated companies, including entities outside the EU. The notice failed to specify which entity qualified as data controller, which as processor, and what purposes each entity pursued. Workers couldn't identify who made decisions about their monitoring data.

This matters because Article 13 of the General Data Protection Regulation requires you to identify the controller and describe specific processing purposes. Listing your entire corporate family tree without role definitions doesn't satisfy transparency obligations. Workers must know who controls decisions about their data and why each entity processes it.

Unauthorized cross-border access. Staff from other group companies accessed the tracking data without documented authorization. The company hadn't established processor agreements or access controls limiting who could view employee monitoring information.

When you grant access to monitoring data across corporate entities, each accessing party needs a defined legal role. If they process data on your behalf, you need processor agreements under Article 28. If they determine purposes and means, they become joint controllers under Article 26. Informal access arrangements create liability.

Immediate suspension reduced the penalty. The Italian SA considered the company's prompt suspension of tracking after the complaint was filed. Despite the violations, the fine remained at 120,000 EUR rather than escalating to higher penalty tiers. The SA also noted the limited number of affected employees (five).

This signals that enforcement authorities weigh your response timeline when calculating penalties. Continuing processing after a complaint or inspection increases financial exposure. Your incident response procedures should include immediate suspension protocols for challenged monitoring activities.

What This Means for Your Team

You can't deploy employee monitoring tools based solely on headquarters approval or vendor assurances. Each jurisdiction where you operate requires separate legal analysis covering both data protection and labor law. The General Data Protection Regulation establishes a floor, not a ceiling. Member states add employment-specific restrictions.

Your privacy notices must identify specific controllers and purposes. If your Swiss parent company determines monitoring parameters, it acts as controller. If your Italian subsidiary implements those decisions, it may be a joint controller. If a third-party platform processes the data, it's a processor. Workers need this clarity to exercise their rights under Articles 15-22.

Cross-border data flows within your corporate group require documented authorization. You can't assume that entities under common ownership can freely access employee monitoring data. Each transfer needs a legal mechanism: processor agreements, controller agreements, or Standard Contractual Clauses depending on the relationship and location.

Monitoring systems that score or evaluate workers trigger heightened scrutiny. The Italian SA specifically ordered deletion of driving behavior scores. When your monitoring feeds into performance ratings or automated decision-making, you activate Article 22 protections and must document how you prevent discriminatory outcomes.

Action Items by Priority

Conduct jurisdiction-specific legal assessments before any monitoring deployment. Don't rely on group-wide policies. Engage local employment counsel in each country where you operate to identify labor law restrictions on electronic monitoring. Document these requirements in your deployment checklist. Budget 4-6 weeks for legal review in new jurisdictions.

Map your controller-processor relationships for existing monitoring systems. List every entity that accesses employee monitoring data. Determine whether each entity processes on your behalf (processor) or makes independent decisions (controller). Document these relationships in written agreements that specify processing purposes, data categories, and security obligations. If you can't clearly define an entity's role, suspend their access until you establish proper authorization.

Revise privacy notices to specify controller identity and processing purposes. Replace generic corporate family references with named controllers and their specific purposes. If your parent company analyzes aggregated fleet data for cost optimization, state that. If your local entity monitors compliance with vehicle policies, state that separately. Test your notice by asking whether an employee could identify who to contact about each processing purpose.

Implement suspension protocols for challenged monitoring activities. Create a decision tree that your legal and HR teams can execute within 48 hours of receiving a complaint or regulatory inquiry. Define who has authority to suspend processing, how to preserve evidence, and what communication goes to affected workers. The Italian SA credited immediate suspension when calculating the penalty.

Separate work-period monitoring from private-use tracking. If you allow personal use of company vehicles, your monitoring system must technically or procedurally distinguish work trips from private trips. Consider systems that workers can deactivate during off-duty periods, or implement processing rules that automatically exclude non-work hours from scoring algorithms. Continuous monitoring during private use requires substantially stronger legal justification.

Topics:general
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like