Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • E-mail Would Get Updated Privacy Protections Under Bicameral Bill
    • Commerce IG Finds Flaws in NIST’s Management of Cyber Vulnerability Database
    • Commerce’s Commitment to Connected Car Ban Questioned Following Volvo Deal
    • Governor Signs Connecticut Bill to Implement New Privacy Protections
    • Luxembourg DPA: Tourist Accommodation Operators May Not Copy ID Documents
    • New York Assembly Committee Advances Proposed Data Protection Act
    • Organizations Should Prioritize Privacy in Chatbot Use, Belgian Regulator Says
    • Privacy Safeguards Required for AI-Powered Employee Stress Monitoring, Garante Says
    • Singapore Cyber Agency Warns of Agentic AI Risks
    • The Week in State Privacy and Cybersecurity Legislation—May 25-29, 2026
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, Privacy Safeguards Required for AI-Powered Employee Stress Monitoring, Garante Says, (Jun 1, 2026)

    By Tony Foley

    Garante, the Italian data protection authority, issued a warning last week to a startup that developed a plug-in for companies to monitor employee stress in the workplace to put privacy safeguards in place to prevent access to information related to ...

    By Tony Foley

    Garante, the Italian data protection authority, issued a warning last week to a startup that developed a plug-in for companies to monitor employee stress in the workplace to put privacy safeguards in place to prevent access to information related to employee well-being.

    The plug-in, which uses AI (artificial intelligence) technology, was developed by Myndoor Srl for use on corporate messaging platforms Slack and Microsoft Teams and provides semantic analysis of chats to detect the psychological stress levels of workers who voluntarily choose to use it to receive personalized suggestions. In a May 28 press release, Garante said it initiated an investigation and found that Myndoor should be treated as a data controller. The agency also determined that employers purchasing the Myndoor service could not access the content of the analyzed communications or the individual results processed by the plug-in.

    In its warning, Garante pointed out the particularly sensitive nature of the data processed and the possibility that employers could be provided with aggregate reports on employee stress levels. It urged the startup to adopt, from the product design stage, adequate measures to prevent any risk of access, either direct or indirect, to information related to workers’ emotional states. In fact, the agency said, employers may not legitimately acquire and process such information under relevant privacy and data protection law like the European Union’s General Data Protection Regulation (GDPR), the Italian Worker’s Statute, or the EU AI Act, the last of which expressly prohibits the use of AI systems designed to deduce or analyze people’s emotions in the workplace.

    Garante also highlighted the risks associated with the use of technologies based on linguistic models and semantic analysis, which it said could produce results that were not always transparent, explainable, or verifiable, potentially resulting in discrimination or damage to workers’ rights.

    News: InternationalLegislation LitigationEnforcement DataPrivacy GDPR AINews

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use