PWC Business Solutions

€150,000

Insufficient legal basis for data processing

Ngày ra quyết định

30 tháng 7, 2019

Thẩm quyền

Hellenic Data Protection Authority (HDPA)

GR

Ngành

Employment

Quốc gia

GR

Luật

GDPR

Trạng thái

FINAL

Mô tả

The processing of employee personal data was based on consent. The HDPA found that consent as legal basis was inappropriate, as the processing of personal data was intended to carry out acts directly linked to the performance of employment contracts, compliance with a legal obligation to which the controller is subject and the smooth and effective operation of the company, as its legitimate interest. In addition, the company gave employees the false impression that it was processing their personal data under the legal basis of consent, while in reality it was processing their data under a different legal basis. This was in violation of the principle of transparency and thus in breach of the obligation to provide information under Articles 13(1)(c) and 14(1)(c) of the GDPR. Lastly, in violation of the accountability principle, the company failed to provide the HDPA with evidence that it had carried out a prior assessment of the appropriate legal bases for processing employee personal data

Trích dẫn pháp lý

Art. 5 (1)Art. 5 (2)Art. 6 (1)Art. 13 (1)Art. 14 (1)

Vấn đề & Vi phạm

Insufficient legal basis for data processing

Cập nhật thông tin về việc thực thi quy định bảo vệ dữ liệu cá nhân

Chúng tôi tôn trọng quyền riêng tư của bạn. Chỉ một email mỗi tháng, không spam, có thể hủy đăng ký bất cứ lúc nào.