Thomas International Systems, S.A.

€40,000

Insufficient legal basis for data processing

Päätöspäivä

16. tammikuuta 2023

Viranomainen

Spanish Data Protection Authority (aepd)

ES

Ala

Finance, Insurance and Consulting

Maa

ES

Laki

GDPR

Tila

FINAL

Kuvaus

The Spanish DPA has imposed a fine on Thomas International Systems, S.A.. Thomas International performs psychological tests on behalf of other companies. Thomas International had conducted such a test on behalf of the company Agroxarxa, S.L.. A participant of such a test had filed a complaint against the controller because they had to provide sensitive personal data (ethnicity, disability). However, Agroxarxa had indicated that the test did not request and process such sensitive data. During its investigation, the DPA found that Thomas International had nevertheless processed sensitive personal data without the consent of the data subject or the processing being necessary for the fulfillment of the contractually agreed purpose between Agroxarxa and Thomas International. The DPA considered this to be a violation of Art. 9 GDPR. The original fine of EUR 50,000 was reduced to EUR 40,000 due to voluntary payment.

Oikeudelliset viittaukset

Art. 9

Asiat ja rikkomukset

Insufficient legal basis for data processing

Pysy ajan tasalla yksityisyyden suojan valvonnasta

Kunnioitamme yksityisyyttäsi. Yksi sähköpostiviesti kuukaudessa, ei roskapostia, peruuta tilaus milloin tahansa.