IZA OBRAS Y PROMOCIONES, S.A.

€50,000

Non-compliance with general data processing principles

Дата на решението

14 декември 2021 г.

Орган

Spanish Data Protection Authority (aepd)

ES

Сектор

Employment

Държава

ES

Право

GDPR

Статус

FINAL

Описание

The Spanish DPA has fined IZA OBRAS Y PROMOCIONES, S.A. EUR 50,000. An employee had filed a complaint with the DPA against the company, alleging that the controller had unauthorizedly disclosed his personal data to another company from which it had received a construction order. The data subject was working as a construction manager on the project, but was absent from work for a period of time due to illness. The controller therefore informed its client and additionally disclosed the data subject's email address and certain health information. The DPA determined that the disclosure of this data would not have been necessary and that the controller had therefore violated the principle of data minimization.

Правни цитати

Art. 5 (1)

Въпроси и нарушения

Non-compliance with general data processing principles

Бъдете информирани за прилагането на поверителността

Уважаваме поверителността ви. Един имейл на месец, без спам, отпишете се по всяко време.