Our Expert in Italy
No results available
Workplace monitoring in Italy is entering its most scrutinised period yet, as the phased rollout of the EU Artificial Intelligence Act (AI Act) collides with an already demanding data protection regime supervised by the Garante per la protezione dei dati personali (the Italian Data Protection Authority). For HR managers, in-house counsel, compliance officers and small and medium-sized enterprises (SMEs), 2026 brings a convergence of obligations covering closed-circuit television (CCTV), biometric systems and AI-driven surveillance tools. The baseline established by the EU General Data Protection Regulation (GDPR) has not changed, but the practical expectations around transparency, proportionality and documentation have intensified.
This guide sets out what the law requires, how the Garante approaches enforcement, and the concrete steps employers should take now to stay compliant.
Quick answer: Practical compliance guidance for employers in Italy who use CCTV, biometric or AI monitoring, what the GDPR, the Garante and the EU AI Act require, and the immediate steps to comply.
Three developments make this a pivotal year. First, the EU AI Act is being applied in staged phases, bringing many workplace monitoring and profiling tools within a formal risk-based framework for the first time. Second, the Garante continues to scrutinise employer surveillance practices, with data protection impact assessments (DPIAs), notices and lawful bases repeatedly tested in enforcement. Third, the growing use of AI in human resources, from productivity analytics to automated screening, has expanded the surface area of processing that employers must justify and document.
The core message for employers is that workplace monitoring in Italy is lawful only where it is transparent, necessary, proportionate and properly documented. Where AI or biometric data is involved, the compliance burden rises sharply. The sections below map the legal framework, then work through CCTV, biometrics, AI tools, DPIAs and how to respond if the Garante opens an inquiry.
The starting point for any workplace surveillance under GDPR in Italy is the set of core principles in Article 5 of the GDPR: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Every monitoring measure must be built on these principles from the outset, not retrofitted afterwards.
Employers must also identify a valid lawful basis under Article 6. In the employment context, consent is rarely reliable because of the inherent imbalance of power between employer and employee, a position consistently reflected in European Data Protection Board (EDPB) guidance on processing employees’ data. Legitimate interest or compliance with a legal obligation are usually more defensible bases, provided the necessity and proportionality of the measure can be demonstrated.
Where processing is likely to result in a high risk to individuals, Article 35 requires a DPIA before processing begins. Systematic monitoring of a workplace on a large scale, biometric identification and AI profiling all typically meet that threshold.
Italian law supplements the GDPR through Legislative Decree 196/2003 (the Personal Data Protection Code), as amended by Legislative Decree 101/2018, which adapted domestic data protection rules to the Regulation. In addition, Article 4 of the Workers’ Statute (Law No. 300/1970), as amended, specifically constrains remote monitoring of workers and generally requires either a collective agreement with employee representatives or authorisation from the competent labour authority (Ispettorato Nazionale del Lavoro) before installing equipment capable of remote monitoring. Official Italian legislative instruments are published in the Gazzetta Ufficiale. The Garante supervises compliance, issues guidance and imposes corrective measures and administrative fines. Its published decisions on workplace monitoring are the most reliable indicator of how abstract principles translate into practical expectations for employers.
CCTV is the most established form of workplace monitoring in Italy, and also one of the most frequently challenged. It is permitted only in limited circumstances and remains subject to strict transparency, proportionality and purpose limitations.
Video surveillance may be justified to protect people and property, prevent theft or ensure workplace safety. It cannot lawfully be deployed for the primary purpose of monitoring the productivity or general conduct of employees. Under Article 4 of the Workers’ Statute, installing equipment from which remote monitoring of workers may result generally requires a prior agreement with union representatives or, failing that, authorisation from the Ispettorato Nazionale del Lavoro. Cameras are prohibited in areas dedicated to employee privacy, such as restrooms, changing rooms and rest areas. Coverage of workstations should be avoided or minimised, and the system should be scoped to the specific risk it addresses.
Employees and visitors must be clearly informed before entering a monitored area. Signage should indicate that CCTV is in operation, identify the controller, state the purpose and point to where fuller information can be found. A layered privacy notice, a short on-site sign linked to a detailed internal policy, helps satisfy the transparency requirement under Article 5 and the information obligations of the GDPR.
A brief sample sign might read: “This area is monitored by CCTV operated by [Company Name] for security purposes. For details of how your data is processed and your rights, see [policy reference/contact].” This is a sample only and must be tailored to the specific installation and legal basis.
Data minimisation applies directly to camera placement. Employers should select the least intrusive configuration capable of meeting the stated purpose: fixed rather than roaming cameras, entrances and stock areas rather than desks, and disabled audio recording unless a specific and justified need exists. Where a less intrusive alternative achieves the same objective, the more intrusive option is unlikely to be considered proportionate.
Footage must be retained only for as long as necessary and for a period stated in advance in the privacy notice. Short retention windows are expected unless a specific incident justifies preservation. Employers must also be able to respond to data subject access requests, which means logging who can view footage, applying access controls and being able to locate and produce recordings relating to a specific individual where required.
Practical CCTV checklist:
Biometric processing in the workplace attracts some of the highest levels of scrutiny in employee monitoring in Italy. Under Article 9 of the GDPR, biometric data processed for the purpose of uniquely identifying a person is a special category of data, which is prohibited unless a specific exception applies. This transforms the risk profile of fingerprint, facial recognition and similar systems.
Because consent is generally unsuitable in the employment relationship, employers cannot usually rely on it as the primary route to lawful biometric processing. An Article 9 exception must be identified, and even then the processing must satisfy the necessity and proportionality tests. The Garante has historically treated biometric time-and-attendance or access systems with caution, expecting employers to demonstrate that no less intrusive alternative would achieve the same aim.
Where biometric processing is justified, robust safeguards under Article 32 are essential. These typically include storing biometric templates rather than raw images, encryption, strict access controls, on-device or tokenised storage where feasible, and defined deletion routines once the identification purpose ends. Documentation of these measures forms part of the DPIA and the accountability record.
Before deploying any biometric system, an employer should run a structured proportionality assessment: identify the objective, list less intrusive options (badges, PINs, key cards), assess whether they meet the need, and record why biometrics are necessary if they are chosen. Practical pre-deployment steps include running a limited trial, consulting the Data Protection Officer (DPO) where one is appointed, and engaging works councils, trade unions or workers’ representatives. Early consultation reduces legal risk and is viewed favourably by the Garante.
The most significant shift for workplace monitoring in Italy in 2026 is the layering of the EU AI Act (Regulation (EU) 2024/1689) on top of the GDPR. AI monitoring of employees, productivity analytics, behavioural profiling, automated evaluation and emotion or attention tracking, now engages a second, parallel regime alongside data protection law. The European Commission’s European approach to AI sets out the risk-based structure and the obligations attaching to high-risk systems.
The AI Act adopts a tiered model. Certain AI systems used in employment contexts, for example those intended to be used for recruitment, or to evaluate workers or make decisions affecting their working conditions, are classified as high-risk, triggering the most demanding obligations. Employers deploying such systems should assess classification carefully, because misclassification carries substantial regulatory exposure. Some AI practices, such as certain forms of emotion recognition in the workplace, are among the prohibited practices under the AI Act, subject to limited exceptions.
High-risk AI systems carry documentation and logging obligations. Employers deploying them should retain records demonstrating the intended purpose, the information and instructions for use provided by the provider, risk-management and human-oversight measures, and event logs that allow the system’s operation to be traced over time. These records complement, and should be cross-referenced with, the DPIA required under the GDPR, avoiding duplication while ensuring both regimes are satisfied.
Human oversight is a central obligation for high-risk AI. No consequential decision about a worker should be taken solely on the basis of automated processing without meaningful human involvement, a requirement that also reflects Article 22 of the GDPR on automated individual decision-making. Employers should design a review layer in which a qualified person can understand, question and override the system’s outputs, and should train reviewers so that oversight is substantive rather than a rubber stamp.
AI procurement checklist for employers and vendors:
A DPIA is the central compliance document for most workplace monitoring in Italy. Under Article 35, it is required whenever processing is likely to result in a high risk to individuals, which covers systematic monitoring, large-scale CCTV, biometric identification and AI profiling. The DPIA must be completed before processing begins and kept under review.
A compliant DPIA should contain:
Illustrative risk and mitigation entries:
Where the DPIA indicates a high residual risk that cannot be mitigated, the employer must consult the Garante before proceeding, as required by Article 36. The Garante and the EDPB publish guidance on DPIA best practice that should inform the methodology used, and the Garante maintains a published list of processing operations that require a DPIA.
If the Garante opens an inquiry into your workplace monitoring, a calm, documented and prompt response is essential. The quality of an employer’s existing records, DPIAs, notices, contracts and logs, often determines the outcome.
Immediate steps:
A short initial acknowledgement might state that the company has received the request, has appointed a coordinating contact and DPO, is preserving relevant documentation, and will provide a full response by the stated deadline. This is a sample framework and should be adapted to the specific inquiry.
Sanctions can include orders to stop or modify processing, corrective measures and administrative fines. Under the GDPR, the most serious breaches can attract fines of up to €20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher. Demonstrating good-faith accountability, a completed DPIA, employee consultation and prompt remediation, materially improves an employer’s position.
| Feature / Monitoring type | CCTV / Video | Biometric (fingerprint/face) | AI-powered monitoring / profiling |
|---|---|---|---|
| Typical lawful basis | Legitimate interest or legal obligation; heavy transparency and minimisation required; Workers’ Statute Art. 4 procedure may apply | Requires an Article 9 exception; identification purpose treated as special category | Often high-risk under the AI Act; requires DPIA, transparency and human oversight |
| DPIA usually required? | Often yes (systematic, large-scale) | Almost always yes | Very likely yes (AI Act and GDPR overlap) |
| Consent required? | Not usually recommended (imbalance risk) | Problematic; employee consent often invalid | Rarely suitable; use lawful basis plus AI Act safeguards |
| Retention limits | Proportionate and stated; delete when no longer needed | Minimise storage; delete after identification need ends | Depends on purpose; oversight logs often required |
| Garante scrutiny | High, location, notice and purpose tested | Very high, biometric processing flagged | Very high in 2026 due to AI Act; vendor and documentation focus |
Workplace monitoring in Italy in 2026 rewards employers who plan, document and consult, and penalises those who deploy first and justify later. The GDPR baseline of transparency, proportionality and minimisation remains, but the AI Act and active Garante enforcement raise the stakes for biometric and AI tools in particular.
This content is for informational purposes only and does not constitute legal advice. Given the pace of change in workplace monitoring in Italy, employers should confirm their specific obligations with qualified counsel before deploying or continuing any monitoring programme. For jurisdiction-specific support, see Data protection lawyers, Italy.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Susanna Greggio at GTA Studio Legale, a member of the Global Law Experts network.
posted 36 seconds ago
posted 4 minutes ago
posted 7 minutes ago
posted 9 minutes ago
posted 11 minutes ago
posted 15 minutes ago
posted 19 minutes ago
posted 24 minutes ago
posted 26 minutes ago
posted 27 minutes ago
posted 32 minutes ago
posted 35 minutes ago
No results available
Find the right Legal Expert for your business
Send welcome message