Myndoor S.r.l. – Violation Found (Italy, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Myndoor S.r.l. used AI to analyze employee messages without any mention of cookie or consent issues. This matters because it shows that companies must still be careful about how they handle personal information, even when using advanced technology. The case highlights the importance of following data protection rules when processing employee data.
What happened
Myndoor S.r.l. used AI for sentiment analysis of employee messages without addressing consent issues.
Who was affected
Employees whose messages were analyzed by Myndoor S.r.l.'s AI system were affected.
What the authority found
The authority found no specific violations but emphasized the need for compliance with data protection rules.
Why this matters
This case serves as a reminder for companies to ensure they are compliant with data protection regulations when using AI tools. It highlights the ongoing scrutiny of how personal data is handled in the workplace.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
Myndoor S.r.l. (the controller) is a workplace consulting company. The controller offers a plug-in system that carries out sentiment analysis of messages exchanged by employees (data subjects) that activated the plug-in. The system used AI to analyse the content of messages sent between data subjects in order to assess their stress levels, and generated a report on a weekly basis. The DPA initiated an ex-officio investigation following press reports on the controller. During its investigations, the controller stated that it currently only provided the service to one company, and that the report was only compiled if a minimum number of data subjects used it. In addition, the controller argued that the report covered the entire workforce of a company to prevent employees from being identified. Finally, the controller argued that the system only processed information provided by the data subject (such as names and contact information), and that sensitive and usage data was anonymised. The DPA first clarified that the company providing the system acted as a controller in relation to the data subjects, and not the employers who purchased the system. According to the DPA, employers are technically prohibited from accessing the data processed by the controller to provide the service, and would in any case lack the valid legal basis to do so under the GDPR. While employers can receive reports of the data subjects’ stress levels, the DPA concluded that the employer in question did not have sufficient information to identify the data subjects involved.The DPA compared this to employers entering into a contract for the provision of benefits and services to employees (such as health insurance or access to psychological counselling services). The DPA also emphasised that the controller has the obligation to comply with the GDPR from the design phase (Article 25 GDPR). In addition, the controller must comply with national provisions that prohibit employers from collecting dat
Outcome
Violation Found
The DPA found a violation but did not impose a fine.
Related Enforcement Actions (0)
No other enforcement actions found for Myndoor S.r.l. in IT
This is the only recorded action for this entity in this jurisdiction.
Details
Decision Date
14 May 2026
Authority
Garante per la protezione dei dati personali
GDPRhub ID
gdprhub-10036About this data
Cite as: Cookie Fines. Myndoor S.r.l. - Italy (2026). Retrieved from cookiefines.eu
Last updated: