USB Lavoro Privato Puglia – €50,000 Fine (Italy, 2025)

€50,000Garante per la protezione dei dati personali10 July 2025Italy
final
ePrivacy
Fine

USB Lavoro Privato Puglia, a workers' union, challenged an automotive company for conducting interviews that collected sensitive health information from employees without proper consent. The data protection authority found this practice violated privacy laws. This case serves as a reminder for companies to ensure they have a valid legal basis before collecting personal information.

What happened

The automotive company conducted 'return to work interviews' that collected health data from employees without a valid legal basis.

Who was affected

Employees of the automotive company who were subjected to these interviews after returning from leave.

What the authority found

The authority determined that the company violated GDPR by not having a valid legal basis for processing sensitive health data during the interviews.

Why this matters

This case highlights the need for businesses to review their data collection practices, especially when dealing with sensitive information, to avoid legal issues.

GDPR Articles Cited

AI-verified

Art. 6(GDPR)
Art. 9(GDPR)
Art. 13(GDPR)
Art. 5(1)(a) GDPR
Art. 5(1)(c) GDPR
Art. 5(1)(e) GDPR
Art. 88(GDPR)
View original scraped data
Art. 5(1)(c) GDPR
Art. 5(1)(e) GDPR
Art. 5(1)(a) GDPR
Art. 6(GDPR)
Art. 9(GDPR)
Art. 13(GDPR)
Art. 88(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Article 113 d. lgs. 196/2003

Entities Involved

USB Lavoro Privato Puglia
Magna PT S.p.a.
Source verified 4 April 2026
articles corrected
national law identified
Full Legal Summary
Detailed

An automotive company (Magna PT S.p.A., the data controller) asked its employees (the data subjects) to undergo “return to work interviews” (“RTWI”) upon returning after leave. Interviews were carried out by the direct superior of the data subjects. The purpose of the interview was to support data subjects in their return to their workplace and gather information on possible shortcomings of the working environment in order to later address them. The questions included, among others, whether the employee's leave was caused by their work, whether their health condition got worse in time, and whether their doctor prescribed specific accomodations or limitations. The controller claimed that participation in the interview was voluntary. Answers given in the interview were manually transcribed in a form and forwarded to HR. HR would then assess the modules and consider possible action to address any issues, along with the data subjects’ superior or the company doctor. Forms were stored for a maximum of ten years. In practice, the controller periodically reviewed the forms and destroyed the ones it did not consider relevant anymore. At the time of the investigation, no form had been stored for longer than 1 year. In 2021 a workers’ union (USB Lavoro Privato Puglia) challenged the lawfulness of this practice by filing a complaint with the DPA. The DPA investigated the complaint two years later. The DPA held that the controller violated Articles 5(1)(c)(e), 6, 9, 13 and 88 GDPR as well as Article 113 of the Italian privacy code. The DPA issued a €50,000 fine and ordered the erasure of the subjects’ data. = The controller stated that the processing relied on the legal basis of consent. In this regard, the controller observed that while consent cannot generally be freely given by employees, EDPB and WP29 Guidelines leave some room for consent when the employee's refusal has no negative consequences for the employee. The controller argued that this was precisely the case of

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for USB Lavoro Privato Puglia in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

10 July 2025

Authority

Garante per la protezione dei dati personali

Fine Amount

€50,000

GDPRhub ID

gdprhub-9438

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. USB Lavoro Privato Puglia - Italy (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: