AEPD (Spain) - EXP202310848
| AEPD - EXP202310848 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 4(1) GDPR Article 4(2) GDPR Article 4(7) GDPR Article 5(1)(a) GDPR Article 6(1) GDPR |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | 15.04.2025 |
| Decided: | 01.05.2025 |
| Published: | 01.05.2025 |
| Fine: | 42,000 |
| Parties: | n/a |
| National Case Number/Name: | EXP202310848 |
| European Case Law Identifier: | n/a |
| Appeal: | Not appealed |
| Original Language(s): | Spanish |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | Arran |
The DPA fined an employer €42,000 for unlawfully adding a former employee’s personal mobile number to a WhatsApp group for employees after the employee explicitly opposed to use her private phone number for work-related communication.
English Summary
Facts
The data subject, a former employee of the controller, was required to perform work-related communications using her personal mobile phone. The data subject asked for a corporate device to perform the work-related communications, but the controller never provided it to her.
On 11 May 2023, the data subject sent an email to management explicitly stating that she would stop using her personal phone for work matters at the start of her upcoming vacation. She also announced her intention to leave all company WhatsApp groups by 12 May 2023, the end of her last working day before the leave started. Despite this clear refusal, on 5 June 2023 (while she was on leave and using her personal phone), the controller added the data subject’s personal number to a company WhatsApp group without prior notice or consent, through a store manager that knew her personal number. The data subject was removed from the group on 28 June 2023, the same day she was dismissed from the company.
The controller argued that the WhatsApp group was composed only of internal employees, and the data processed (names and numbers) was minimal.
On 10 July 2023, the data subject filed a complaint with the DPA, alleging unlawful processing of her personal data for the use of her private mobile number for work communications without consent.
The controller later acknowledged the need to revise its internal practices and, as of 1 September 2023, prohibited the use of personal phones for corporate WhatsApp groups unless a company device was active.
The complaint was initially rejected (on 29 September 2023,) but later reopened on 16 April 2024.
Holding
First, the DPA found a violation of Article 6(1) GDPR. The DPA held that the controller had unlawfully processed the data subject’s personal mobile number by adding it to a WhatsApp workgroup without a valid legal basis. No consent was obtained under Article (6)(1) GDPR, and the controller failed to demonstrate that the processing was necessary for the performance of a contract or justified under any other legal ground. The data subject had clearly refused to continue using her private number for work communications in an email dated 11 May 2023, and yet the controller added her to the WhatsApp group on 5 June 2023. The DPA concluded that this action constituted unlawful processing of personal data.
Second, the DPA rejected the controller’s arguments about implied consent and operational necessity. The DPA emphasised that “operational convenience” does not override the requirement for lawful processing. The DPA highlighted that the controller admitted that some employees were using personal devices due to unavailability of corporate devices, and that this practice had been prohibited only from 1 September 2023 onward, well after the incident.
Third, the DPA reminded the controller of its duty under Article 5(2) GDPR (accountability) and Article 24 GDPR to implement appropriate measures and maintain records demonstrating that processing is lawful. In this case, the controller could not prove that the data subject had consented or that any other lawful basis existed. The failure to adopt proper safeguards and policies for using personal devices in messaging groups further aggravated the situation.
Several aggravating were to be found in this case:
- The explicit prior withdrawal of consent by the data subject;
- The continued use of the personal number despite this;
- The availability of corporate alternatives (ICON devices) that were not provided.
And as mitigating factors, the DPA took into account:
- The controller’s later implementation of an internal policy prohibiting personal phone use;
- The cooperation with the DPA during the proceedings;
- The controller’s voluntary payment and recognition of responsibility.
The fine was initially set at €70,000 but pursuant to Law 39/2015, a Spanish law concerning administrative proceedings, the DPA informed the controller that it may make a voluntary payment of the proposed fine and waive their right to appeal. This action reduces the imposed fine by 20%. The fine can be reduced by a further 20% if the controller acknowledges its liability. The controller opted for both and reduced the fine by 40%, paying the reduced sanction amount of €42,000. The controller ultimately recognized responsibility and paid the fine voluntarily on 1 May 2025.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.
1 / 2 File No.: EXP202314247 RESOLUTION ON APPEAL FOR RECONVERSION Having examined the appeal for reconsideration filed by IBERDROLA CLIENTES, S.A.U. (hereinafter, the appellant) against the resolution issued by the President of the Spanish Data Protection Agency...




