In Newsletter No. 542, dated 29 January 2026, the Data Protection Authority reported on a recent decision concerning access to an employee’s email address. In particular, the Authority stated that the content of an employee’s emails and related attachments, as well as the contact details in such communications, fall within the concept of correspondence and are therefore protected by the right to confidentiality; consequently, access to such content by the employer following dismissal may constitute a breach of the right to privacy.
In the specific case of the aforementioned decision (No. 754 of 18 December 2025), the complainant stated that he had received a disciplinary notice from his employer, following which he was denied access to his work email account.
Following his subsequent dismissal, the claimant requested “the deactivation of his email account, the forwarding of any correspondence received in the meantime, and the activation of an automatic reply system for third parties, stating the personal email address to which any communications should be sent”.
According to the complainant’s account, the company failed to act on the request, prompting the complainant to refer the matter to the Data Protection Authority to safeguard their rights.
During the investigation carried out by the Data Protection Authority, it emerged that the company had not only continued to receive emails addressed to the employee at his work email address, but had also forwarded those emails to another company email account (which, according to the company, was done “to ensure business continuity”) and that the account was only closed permanently two months later.
According to the Data Protection Authority, the company’s conduct is in breach of the General Data Protection Regulation (GDPR).
On the one hand, the prolonged practice of redirecting emails to another address has resulted in the access and retention of personal emails as well, thereby breaching data protection legislation and constituting “the processing of personal data […] which is contrary to the principles of lawfulness, data minimisation and storage limitation”.
From another perspective, the Data Protection Authority notes that “The content of email messages, as well as the metadata of communications and attached files, constitute forms of correspondence protected by guarantees of confidentiality that are enshrined in the Constitution, the rationale for which lies in safeguarding the essential core of human dignity and the full development of the individual within society”.
In view of the incorrect handling of data as noted above, the employer has been ordered to “comply with the data subject’s requests” and to pay an administrative fine of €40,000.
This case serves as yet another reminder of the importance of adopting clear and specific policies regarding the use of corporate email, with particular regard to the period immediately following the termination of employment.