IZA OBRAS Y PROMOCIONES, S.A.

€50,000

Non-compliance with general data processing principles

Date de décision

14 décembre 2021

Autorité

Spanish Data Protection Authority (aepd)

ES

Secteur

Employment

Pays

ES

Droit

GDPR

Statut

FINAL

Description

The Spanish DPA has fined IZA OBRAS Y PROMOCIONES, S.A. EUR 50,000. An employee had filed a complaint with the DPA against the company, alleging that the controller had unauthorizedly disclosed his personal data to another company from which it had received a construction order. The data subject was working as a construction manager on the project, but was absent from work for a period of time due to illness. The controller therefore informed its client and additionally disclosed the data subject's email address and certain health information. The DPA determined that the disclosure of this data would not have been necessary and that the controller had therefore violated the principle of data minimization.

Citations légales

Art. 5 (1)

Questions et violations

Non-compliance with general data processing principles

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.