Italy’s Data Protection Authority Draws a Line on AI-Based Emotional Monitoring at Work
Share this article

There’s an Italian start-up, Myndoor, that built a plug-in for Slack and Teams capable of reading employees’ emotional state by analysing the language used in their workplace chats. The idea started with good intentions: catch signs of stress early, offer support, improve wellbeing at work. Italy’s Data Protection Authority (Garante Privacy), in a ruling issued on 14 May, didn’t shut the project down – but it did shine a light that every company working with AI in HR should pay close attention to.
The Weak Spot: Aggregated Reports
In its base version, the system is already fairly cautious: employees opt in voluntarily, and the company can’t read individual messages or see individual results. The problem, according to the Authority, arises when this data feeds into aggregated stress-level reports for a team – generated only once at least ten users are active, and therefore theoretically anonymous. But “theoretically” is the key word: in a small office, or a department with few employees, tracing who’s struggling can become easier than it sounds.
A Principle That Goes Beyond This One Case
The ruling points to a clear principle, grounded in several regulatory sources at once – the GDPR, Italy’s Workers’ Statute, and now the EU AI Act: employers cannot collect or process information about employees’ emotional state or stress levels. The AI Act, specifically, explicitly bans AI systems designed to infer people’s emotions in the workplace. This isn’t a technical footnote – it’s a boundary meant to protect people’s psychological freedom within the employment relationship.
The Real Issue Is Algorithmic Explainability
There’s a second layer here, arguably even more relevant for anyone working in HR and organizational design. The Authority notes that AI systems built on language analysis don’t just collect data – they generate inferences, meaning conclusions about sensitive aspects of a person, often without a clear way to reconstruct how the algorithm reached them. This is where the most serious risks hide – evaluation errors, amplified bias, possible discrimination – which is why the Authority calls for transparency, data quality, and genuine (not just formal) human oversight over these processes.
What It Actually Means for Companies
The underlying message is easy to summarize, harder to put into practice: improving organizational wellbeing remains a legitimate goal, but it can’t turn into a form of surveillance, however well-intentioned. Any company evaluating AI tools for monitoring internal climate or productivity should ask itself a simple question from the design stage onward: does this system tell me how people work, or does it risk telling me how they feel? For the Authority, that distinction isn’t subtle – it’s exactly what separates a support tool from a control tool.