[codicts-css-switcher id=”346″]

Global Law Experts Logo
workplace monitoring in italy

Workplace Monitoring in Italy (2026): CCTV, Biometrics, AI Tools and What Employers Must Do Under the Garante & GDPR

By Global Law Experts
– posted 1 hour ago

Workplace monitoring in Italy is entering its most scrutinised period yet, as the phased rollout of the EU Artificial Intelligence Act (AI Act) collides with an already demanding data protection regime supervised by the Garante per la protezione dei dati personali (the Italian Data Protection Authority). For HR managers, in-house counsel, compliance officers and small and medium-sized enterprises (SMEs), 2026 brings a convergence of obligations covering closed-circuit television (CCTV), biometric systems and AI-driven surveillance tools. The baseline established by the EU General Data Protection Regulation (GDPR) has not changed, but the practical expectations around transparency, proportionality and documentation have intensified.

This guide sets out what the law requires, how the Garante approaches enforcement, and the concrete steps employers should take now to stay compliant.

Quick answer: Practical compliance guidance for employers in Italy who use CCTV, biometric or AI monitoring, what the GDPR, the Garante and the EU AI Act require, and the immediate steps to comply.

Why 2026 matters for workplace monitoring in Italy

Three developments make this a pivotal year. First, the EU AI Act is being applied in staged phases, bringing many workplace monitoring and profiling tools within a formal risk-based framework for the first time. Second, the Garante continues to scrutinise employer surveillance practices, with data protection impact assessments (DPIAs), notices and lawful bases repeatedly tested in enforcement. Third, the growing use of AI in human resources, from productivity analytics to automated screening, has expanded the surface area of processing that employers must justify and document.

The core message for employers is that workplace monitoring in Italy is lawful only where it is transparent, necessary, proportionate and properly documented. Where AI or biometric data is involved, the compliance burden rises sharply. The sections below map the legal framework, then work through CCTV, biometrics, AI tools, DPIAs and how to respond if the Garante opens an inquiry.

Legal framework, GDPR, Italian law and the Garante

The starting point for any workplace surveillance under GDPR in Italy is the set of core principles in Article 5 of the GDPR: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Every monitoring measure must be built on these principles from the outset, not retrofitted afterwards.

Employers must also identify a valid lawful basis under Article 6. In the employment context, consent is rarely reliable because of the inherent imbalance of power between employer and employee, a position consistently reflected in European Data Protection Board (EDPB) guidance on processing employees’ data. Legitimate interest or compliance with a legal obligation are usually more defensible bases, provided the necessity and proportionality of the measure can be demonstrated.

Where processing is likely to result in a high risk to individuals, Article 35 requires a DPIA before processing begins. Systematic monitoring of a workplace on a large scale, biometric identification and AI profiling all typically meet that threshold.

Italian law supplements the GDPR through Legislative Decree 196/2003 (the Personal Data Protection Code), as amended by Legislative Decree 101/2018, which adapted domestic data protection rules to the Regulation. In addition, Article 4 of the Workers’ Statute (Law No. 300/1970), as amended, specifically constrains remote monitoring of workers and generally requires either a collective agreement with employee representatives or authorisation from the competent labour authority (Ispettorato Nazionale del Lavoro) before installing equipment capable of remote monitoring. Official Italian legislative instruments are published in the Gazzetta Ufficiale. The Garante supervises compliance, issues guidance and imposes corrective measures and administrative fines. Its published decisions on workplace monitoring are the most reliable indicator of how abstract principles translate into practical expectations for employers.

CCTV and video surveillance: legality, limits and practical steps

CCTV is the most established form of workplace monitoring in Italy, and also one of the most frequently challenged. It is permitted only in limited circumstances and remains subject to strict transparency, proportionality and purpose limitations.

When CCTV is permitted

Video surveillance may be justified to protect people and property, prevent theft or ensure workplace safety. It cannot lawfully be deployed for the primary purpose of monitoring the productivity or general conduct of employees. Under Article 4 of the Workers’ Statute, installing equipment from which remote monitoring of workers may result generally requires a prior agreement with union representatives or, failing that, authorisation from the Ispettorato Nazionale del Lavoro. Cameras are prohibited in areas dedicated to employee privacy, such as restrooms, changing rooms and rest areas. Coverage of workstations should be avoided or minimised, and the system should be scoped to the specific risk it addresses.

Transparency and notice requirements

Employees and visitors must be clearly informed before entering a monitored area. Signage should indicate that CCTV is in operation, identify the controller, state the purpose and point to where fuller information can be found. A layered privacy notice, a short on-site sign linked to a detailed internal policy, helps satisfy the transparency requirement under Article 5 and the information obligations of the GDPR.

A brief sample sign might read: “This area is monitored by CCTV operated by [Company Name] for security purposes. For details of how your data is processed and your rights, see [policy reference/contact].” This is a sample only and must be tailored to the specific installation and legal basis.

Minimal intrusiveness and location considerations

Data minimisation applies directly to camera placement. Employers should select the least intrusive configuration capable of meeting the stated purpose: fixed rather than roaming cameras, entrances and stock areas rather than desks, and disabled audio recording unless a specific and justified need exists. Where a less intrusive alternative achieves the same objective, the more intrusive option is unlikely to be considered proportionate.

Retention limits and access requests

Footage must be retained only for as long as necessary and for a period stated in advance in the privacy notice. Short retention windows are expected unless a specific incident justifies preservation. Employers must also be able to respond to data subject access requests, which means logging who can view footage, applying access controls and being able to locate and produce recordings relating to a specific individual where required.

Practical CCTV checklist:

  • Purpose. Document the specific security or safety purpose before installation.
  • DPIA. Conduct a DPIA for systematic or large-scale monitoring.
  • Placement. Exclude private areas and minimise coverage of workstations.
  • Notice. Install clear signage and publish a detailed internal policy.
  • Retention. Fix and enforce a short, stated retention period.
  • Access. Restrict and log access to footage.
  • Consultation. Secure a union agreement or labour-authority authorisation where required under Article 4 of the Workers’ Statute.

Biometric data and AI monitoring, lawful bases and consent

Biometric processing in the workplace attracts some of the highest levels of scrutiny in employee monitoring in Italy. Under Article 9 of the GDPR, biometric data processed for the purpose of uniquely identifying a person is a special category of data, which is prohibited unless a specific exception applies. This transforms the risk profile of fingerprint, facial recognition and similar systems.

When biometric systems are allowed

Because consent is generally unsuitable in the employment relationship, employers cannot usually rely on it as the primary route to lawful biometric processing. An Article 9 exception must be identified, and even then the processing must satisfy the necessity and proportionality tests. The Garante has historically treated biometric time-and-attendance or access systems with caution, expecting employers to demonstrate that no less intrusive alternative would achieve the same aim.

Technical and organisational safeguards

Where biometric processing is justified, robust safeguards under Article 32 are essential. These typically include storing biometric templates rather than raw images, encryption, strict access controls, on-device or tokenised storage where feasible, and defined deletion routines once the identification purpose ends. Documentation of these measures forms part of the DPIA and the accountability record.

Alternatives and proportionality tests

Before deploying any biometric system, an employer should run a structured proportionality assessment: identify the objective, list less intrusive options (badges, PINs, key cards), assess whether they meet the need, and record why biometrics are necessary if they are chosen. Practical pre-deployment steps include running a limited trial, consulting the Data Protection Officer (DPO) where one is appointed, and engaging works councils, trade unions or workers’ representatives. Early consultation reduces legal risk and is viewed favourably by the Garante.

AI-powered employee monitoring in 2026: EU AI Act obligations and GDPR overlap

The most significant shift for workplace monitoring in Italy in 2026 is the layering of the EU AI Act (Regulation (EU) 2024/1689) on top of the GDPR. AI monitoring of employees, productivity analytics, behavioural profiling, automated evaluation and emotion or attention tracking, now engages a second, parallel regime alongside data protection law. The European Commission’s European approach to AI sets out the risk-based structure and the obligations attaching to high-risk systems.

When an AI system used for monitoring is high-risk

The AI Act adopts a tiered model. Certain AI systems used in employment contexts, for example those intended to be used for recruitment, or to evaluate workers or make decisions affecting their working conditions, are classified as high-risk, triggering the most demanding obligations. Employers deploying such systems should assess classification carefully, because misclassification carries substantial regulatory exposure. Some AI practices, such as certain forms of emotion recognition in the workplace, are among the prohibited practices under the AI Act, subject to limited exceptions.

Record-keeping and documentation

High-risk AI systems carry documentation and logging obligations. Employers deploying them should retain records demonstrating the intended purpose, the information and instructions for use provided by the provider, risk-management and human-oversight measures, and event logs that allow the system’s operation to be traced over time. These records complement, and should be cross-referenced with, the DPIA required under the GDPR, avoiding duplication while ensuring both regimes are satisfied.

Mitigation measures and human review

Human oversight is a central obligation for high-risk AI. No consequential decision about a worker should be taken solely on the basis of automated processing without meaningful human involvement, a requirement that also reflects Article 22 of the GDPR on automated individual decision-making. Employers should design a review layer in which a qualified person can understand, question and override the system’s outputs, and should train reviewers so that oversight is substantive rather than a rubber stamp.

AI procurement checklist for employers and vendors:

  1. Classify. Assess whether the tool is high-risk (or prohibited) under the AI Act before purchase.
  2. Assess. Complete a DPIA covering the AI processing and its GDPR risks.
  3. Contract. Require vendor assurances on training data, bias testing, logging and conformity documentation.
  4. Transparency. Inform employees clearly about the AI system, its purpose and its logic.
  5. Oversight. Build and staff a human review process for all consequential outputs.
  6. Audit. Retain the right to audit the vendor and to receive updated documentation.
  7. Exit. Include data return and deletion obligations on termination.

DPIAs for workplace monitoring, when required and a practical checklist

A DPIA is the central compliance document for most workplace monitoring in Italy. Under Article 35, it is required whenever processing is likely to result in a high risk to individuals, which covers systematic monitoring, large-scale CCTV, biometric identification and AI profiling. The DPIA must be completed before processing begins and kept under review.

A compliant DPIA should contain:

  • Description. A systematic description of the processing, its purposes and the categories of data.
  • Necessity and proportionality. An assessment of why the measure is needed and why less intrusive alternatives were rejected.
  • Risks. Identification of risks to the rights and freedoms of employees.
  • Mitigations. Technical and organisational measures to reduce those risks.
  • Consultation. The outcome of consultation with the DPO and, where relevant, employee representatives.

Illustrative risk and mitigation entries:

  • CCTV. Risk: excessive coverage of workstations. Mitigation: reposition cameras to entrances and reduce field of view; short retention period.
  • Biometrics. Risk: exposure of special-category data. Mitigation: store templates only, encrypt, restrict access, define deletion routine.
  • AI monitoring. Risk: opaque or biased automated evaluation. Mitigation: human review of outputs, vendor bias testing, transparent employee notice.

Where the DPIA indicates a high residual risk that cannot be mitigated, the employer must consult the Garante before proceeding, as required by Article 36. The Garante and the EDPB publish guidance on DPIA best practice that should inform the methodology used, and the Garante maintains a published list of processing operations that require a DPIA.

Responding to a Garante inquiry into workplace monitoring, immediate steps and templates

If the Garante opens an inquiry into your workplace monitoring, a calm, documented and prompt response is essential. The quality of an employer’s existing records, DPIAs, notices, contracts and logs, often determines the outcome.

Immediate steps:

  1. Designate a lead. Appoint a single point of contact to coordinate the response.
  2. Preserve documentation. Secure DPIAs, privacy notices, vendor contracts, technical logs and consultation records.
  3. Notify the DPO. Involve the DPO immediately where one is appointed.
  4. Respond on time. Meet any deadlines set by the Garante and request extensions in writing if genuinely required.
  5. Engage counsel. Instruct experienced data protection counsel early.
  6. Propose remediation. Where gaps exist, present a credible remedial plan rather than defending the indefensible.

A short initial acknowledgement might state that the company has received the request, has appointed a coordinating contact and DPO, is preserving relevant documentation, and will provide a full response by the stated deadline. This is a sample framework and should be adapted to the specific inquiry.

Sanctions can include orders to stop or modify processing, corrective measures and administrative fines. Under the GDPR, the most serious breaches can attract fines of up to €20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher. Demonstrating good-faith accountability, a completed DPIA, employee consultation and prompt remediation, materially improves an employer’s position.

Comparison table: CCTV vs biometric vs AI monitoring under the GDPR and Garante lens

Feature / Monitoring type CCTV / Video Biometric (fingerprint/face) AI-powered monitoring / profiling
Typical lawful basis Legitimate interest or legal obligation; heavy transparency and minimisation required; Workers’ Statute Art. 4 procedure may apply Requires an Article 9 exception; identification purpose treated as special category Often high-risk under the AI Act; requires DPIA, transparency and human oversight
DPIA usually required? Often yes (systematic, large-scale) Almost always yes Very likely yes (AI Act and GDPR overlap)
Consent required? Not usually recommended (imbalance risk) Problematic; employee consent often invalid Rarely suitable; use lawful basis plus AI Act safeguards
Retention limits Proportionate and stated; delete when no longer needed Minimise storage; delete after identification need ends Depends on purpose; oversight logs often required
Garante scrutiny High, location, notice and purpose tested Very high, biometric processing flagged Very high in 2026 due to AI Act; vendor and documentation focus

Conclusion: key takeaways and a six-step employer checklist

Workplace monitoring in Italy in 2026 rewards employers who plan, document and consult, and penalises those who deploy first and justify later. The GDPR baseline of transparency, proportionality and minimisation remains, but the AI Act and active Garante enforcement raise the stakes for biometric and AI tools in particular.

  1. Justify. Document a specific, legitimate purpose for every monitoring measure.
  2. Assess. Complete a DPIA before deploying CCTV, biometrics or AI monitoring.
  3. Choose the right basis. Avoid relying on employee consent; use legitimate interest or legal obligation with a proportionality analysis.
  4. Be transparent. Provide clear notices and a detailed internal policy.
  5. Consult. Involve the DPO and employee representatives early, and follow the Workers’ Statute procedure where applicable.
  6. Govern AI. Classify AI tools, secure vendor assurances and build meaningful human oversight.

This content is for informational purposes only and does not constitute legal advice. Given the pace of change in workplace monitoring in Italy, employers should confirm their specific obligations with qualified counsel before deploying or continuing any monitoring programme. For jurisdiction-specific support, see Data protection lawyers, Italy.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Susanna Greggio at GTA Studio Legale, a member of the Global Law Experts network.

Sources

  1. Garante per la protezione dei dati personali (Italian Data Protection Authority)
  2. EU General Data Protection Regulation (GDPR), consolidated text
  3. European Commission, European approach to AI (AI Act policy)
  4. European Data Protection Board (EDPB)
  5. Gazzetta Ufficiale (Official Journal of the Italian Republic)

FAQs

Can employers legally use CCTV and other surveillance at the workplace in Italy?
Yes, but only in limited circumstances. CCTV is subject to GDPR transparency, proportionality and purpose limitations, with strong restrictions on private areas such as restrooms and changing rooms. Where equipment could allow remote monitoring of workers, Article 4 of the Workers’ Statute generally requires a union agreement or authorisation from the labour authority. Employers should also conduct a DPIA, provide clear signage and maintain an internal policy explaining the purpose, retention period and employee rights.
Consent is generally unsuitable in the employment context because of the power imbalance between employer and employee. Employers should rely on other lawful bases, such as legitimate interest or a legal obligation, and apply strong safeguards. Biometric data used for identification is a special category under Article 9 and attracts additional scrutiny and technical measures.
A DPIA is required under Article 35 whenever processing is likely to result in a high risk to individuals, which covers systematic monitoring, large-scale CCTV, biometric identification and AI profiling. It must describe the processing, assess necessity and proportionality, identify risks and mitigations, and record the outcome of consultation with the DPO and employee representatives. Where residual risk remains high, prior consultation with the Garante under Article 36 may be necessary.
Preserve all relevant documentation, DPIAs, contracts, notices and technical logs, appoint a compliance lead, notify the DPO, respond within any deadlines and engage experienced counsel. Where gaps exist, propose credible remedial measures. Good-faith accountability improves the outcome of any Garante inquiry into workplace monitoring in Italy.
Only to a limited and proportionate degree. Remote monitoring requires clear policies, technical limits and role-based monitoring confined to work-related systems, and the Workers’ Statute restrictions on remote monitoring continue to apply. Monitoring private devices should be avoided without an explicit contractual and legal basis, and blanket or covert surveillance of home workers is not permitted.
The Garante can order processing to stop or be modified and impose corrective measures. Administrative fines under the GDPR can reach up to €20 million or 4% of total worldwide annual turnover of the preceding financial year for the most serious breaches, alongside potential reputational and contractual consequences.
accounting requirements for srl italy
By Global Law Experts

posted 26 minutes ago

find family lawyer france
By Global Law Experts

posted 35 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Workplace Monitoring in Italy (2026): CCTV, Biometrics, AI Tools and What Employers Must Do Under the Garante & GDPR

Send welcome message

Custom Message