In Newsletter No. 542, dated 29 January 2026, the Data Protection Authority reported on a recent decision concerning access to an employee’s email address. In particular, the Authority stated that the content of an employee’s emails and related attachments, as well as the contact details in such communications, fall within the concept of correspondence and are therefore protected by the right to confidentiality; consequently, access to such correspondence by the employer following dismissal may constitute a breach of the right to privacy.

In the specific case of the aforementioned ruling (No. 754, of 18 December 2025), the complainant reported having received a disciplinary notice from his employer, following which he was denied access to his company email account.

Following his subsequent dismissal, the complainant requested “the deactivation of the email account, the forwarding of any correspondence received in the meantime, and the activation of an automatic reply system to third parties containing the personal email address to which any communications should be sent”.

According to the complainant’s account, the Company failed to comply with these requests, prompting him to refer the matter to the Data Protection Authority to safeguard his rights.

During the investigation carried out by the Data Protection Authority, it emerged that the company had not only continued to receive emails addressed to the employee at his work email address, but had also forwarded these emails to another company email account (which, according to the company, was “to ensure business continuity”) and that the account was only closed permanently two months later.

According to the Data Protection Authority, the company’s conduct contravenes the General Data Protection Regulation (GDPR).

On the one hand, the prolonged practice of redirecting emails to another address resulted in the access and retention of personal emails as well, thereby breaching privacy legislation and constituting “the processing of personal data […] which is contrary to the principles of lawfulness, data minimisation and storage limitation”.

From another perspective, the Data Protection Authority observes that “The content of email messages, as well as the external data of communications and attached files, concern forms of correspondence protected by guarantees of confidentiality that are also constitutionally safeguarded, the rationale for which lies in protecting the essential core of human dignity and the full development of the personality within social structures”.

In light of the improper handling of data as noted above, the employer has been ordered to “comply with the data subject’s requests” and to pay an administrative fine of €40,000.

This case serves as yet another reminder of the importance of adopting clear and specific policies regarding the use of corporate email, with particular regard to the period immediately following the termination of employment.