https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00368/2021&feed=atom&action=historyAEPD (Spain) - PS/00368/2021 - Revision history2024-03-28T16:46:37ZRevision history for this page on the wikiMediaWiki 1.39.6https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00368/2021&diff=29597&oldid=prevCarmen.villarroel at 14:25, 24 November 20222022-11-24T14:25:34Z<p></p>
<table style="background-color: #fff; color: #202122;" data-mw="interface">
<col class="diff-marker" />
<col class="diff-content" />
<col class="diff-marker" />
<col class="diff-content" />
<tr class="diff-title" lang="en">
<td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">← Older revision</td>
<td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">Revision as of 14:25, 24 November 2022</td>
</tr><tr><td colspan="2" class="diff-lineno" id="mw-diff-left-l49">Line 49:</td>
<td colspan="2" class="diff-lineno">Line 49:</td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|Appeal_To_Link=</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|Appeal_To_Link=</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>|Initial_Contributor=Carmen Villarroel</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>|Initial_Contributor=<ins style="font-weight: bold; text-decoration: none;">[https://gdprhub.eu/index.php?title=User:Carmen.villarroel </ins>Carmen Villarroel<ins style="font-weight: bold; text-decoration: none;">]</ins></div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|}}</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|}}</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
</table>Carmen.villarroelhttps://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00368/2021&diff=24974&oldid=prev122.15.156.141: /* Holding */2022-03-25T10:34:46Z<p><span dir="auto"><span class="autocomment">Holding</span></span></p>
<table style="background-color: #fff; color: #202122;" data-mw="interface">
<col class="diff-marker" />
<col class="diff-content" />
<col class="diff-marker" />
<col class="diff-content" />
<tr class="diff-title" lang="en">
<td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">← Older revision</td>
<td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">Revision as of 10:34, 25 March 2022</td>
</tr><tr><td colspan="2" class="diff-lineno" id="mw-diff-left-l68">Line 68:</td>
<td colspan="2" class="diff-lineno">Line 68:</td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>On the other hand, the AEPD established that the RFEF did have a valid legal basis for the processing of personal data in this case, since Article 18 of the [https://www.boe.es/buscar/act.php?id=BOE-A-2015-10566 Spanish Act for the Regulation of the Public Sector] (''Ley 40/2015, de 1 de octubre, de Régimen Jurídico del Sector Público - LRJSP'') allows public bodies to record their meetings and to store them in order to keep a literal transcript of the minutes. However, the AEPD noted that having a valid legal basis does not excuse the controller from properly informing the data subjects with the requirements included under [[Article 13 GDPR]]. According to the AEPD, stating that the recording would take place in order to keep a transcript of the meeting, did not amount to providing adequate information under this provision, including basic information regarding the legal basis and the purposes of the processing.</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>On the other hand, the AEPD established that the RFEF did have a valid legal basis for the processing of personal data in this case, since Article 18 of the [https://www.boe.es/buscar/act.php?id=BOE-A-2015-10566 Spanish Act for the Regulation of the Public Sector] (''Ley 40/2015, de 1 de octubre, de Régimen Jurídico del Sector Público - LRJSP'') allows public bodies to record their meetings and to store them in order to keep a literal transcript of the minutes. However, the AEPD noted that having a valid legal basis does not excuse the controller from properly informing the data subjects with the requirements included under [[Article 13 GDPR]]. According to the AEPD, stating that the recording would take place in order to keep a transcript of the meeting, did not amount to providing adequate information under this provision, including basic information regarding the legal basis and the purposes of the processing.</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>In relation to public bodies' transparency obligations related to keeping a record of their meetings' minutes and disclosing them, the AEPD observed that this obligation only includes a written record of certain aspects, not a recording of the meeting itself. Therefore, although these obligations would allow RFEF to record the meeting, as well as to provide access to the written minutes, it would not allow it to share the actual recording. The AEPD highlighted Recital 50 GDPR, which states that ''"the processing of personal data for purposes other than those for which the personal data were initially collected should be allowed only where the processing is compatible with the purposes for which the personal data were initially collected."'' For the subsequent processing which occurred when sharing the video with the broadcasters, the RFEF relied on freedom of information and expression, considering that it had the legitimacy to refute a press released by the AFE which was not factual, and to substantiate this refutation by providing a recording of what was exactly said during the meeting. However, the AEPD held these rights could have been exercised by sharing the written record of the meeting, and not the actual recording. The AEPD also noted that the recording contained comments of a personal and private nature, and that therefore the RFEF should have only shared the minimum amount of data necessary to achieve that purpose, according to the data <del style="font-weight: bold; text-decoration: none;">minimisation </del>principle. Consequently, the AEPD held that the RFEF had violated [[Article 6 GDPR|Article 6(1) GDPR]], processing personal data without a valid legal basis by sharing the recording instead of a transcript limited to the relevant details.</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>In relation to public bodies' transparency obligations related to keeping a record of their meetings' minutes and disclosing them, the AEPD observed that this obligation only includes a written record of certain aspects, not a recording of the meeting itself. Therefore, although these obligations would allow RFEF to record the meeting, as well as to provide access to the written minutes, it would not allow it to share the actual recording. The AEPD highlighted Recital 50 GDPR, which states that ''"the processing of personal data for purposes other than those for which the personal data were initially collected should be allowed only where the processing is compatible with the purposes for which the personal data were initially collected."'' For the subsequent processing which occurred when sharing the video with the broadcasters, the RFEF relied on freedom of information and expression, considering that it had the legitimacy to refute a press released by the AFE which was not factual, and to substantiate this refutation by providing a recording of what was exactly said during the meeting. However, the AEPD held these rights could have been exercised by sharing the written record of the meeting, and not the actual recording. The AEPD also noted that the recording contained comments of a personal and private nature, and that therefore the RFEF should have only shared the minimum amount of data necessary to achieve that purpose, according to the data <ins style="font-weight: bold; text-decoration: none;">minimization </ins>principle. Consequently, the AEPD held that the RFEF had violated [[Article 6 GDPR|Article 6(1) GDPR]], processing personal data without a valid legal basis by sharing the recording instead of a transcript limited to the relevant details.</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Based on these considerations, the AEPD fined the RFEF a total of €200,000 ( €100,000 for the violating [[Article 13 GDPR]], and €100,000 for the violating [[Article 6 GDPR|Article 6(1) GDPR]]).</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Based on these considerations, the AEPD fined the RFEF a total of €200,000 ( €100,000 for the violating [[Article 13 GDPR]], and €100,000 for the violating [[Article 6 GDPR|Article 6(1) GDPR]]).</div></td></tr>
</table>122.15.156.141https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00368/2021&diff=23714&oldid=prevCarmen.villarroel: /* Holding */2022-02-24T12:05:04Z<p><span dir="auto"><span class="autocomment">Holding</span></span></p>
<table style="background-color: #fff; color: #202122;" data-mw="interface">
<col class="diff-marker" />
<col class="diff-content" />
<col class="diff-marker" />
<col class="diff-content" />
<tr class="diff-title" lang="en">
<td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">← Older revision</td>
<td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">Revision as of 12:05, 24 February 2022</td>
</tr><tr><td colspan="2" class="diff-lineno" id="mw-diff-left-l57">Line 57:</td>
<td colspan="2" class="diff-lineno">Line 57:</td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>=== Facts ===</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>=== Facts ===</div></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Representatives of the Spanish Football Federation (RFEF), the Association of Spanish Footballers (AFE), and the Professional Football League (LNFP) held a meeting via Zoom on April 2020 to follow-up on the COVID-19 pandemic situation, and its impact on the national football landscape. According to the AFE and the LNFP, the <del style="font-weight: bold; text-decoration: none;">REEF </del>shared the recording of this meeting with two radio broadcasters (Cadena Ser, COPE) without the participant's knowledge or consent, who eventually found out when the recordings were broadcasted a few days later. As a result, both the AFE and the LNFP filed several complaints against the <del style="font-weight: bold; text-decoration: none;">REEF </del>with the Spanish DPA (AEPD). According to the claimants, the participants were not informed about the fact that the meeting was being recorded, and they did not receive the required information under [[Article 13 GDPR]].</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Representatives of the Spanish Football Federation (RFEF), the Association of Spanish Footballers (AFE), and the Professional Football League (LNFP) held a meeting via Zoom on April 2020 to follow-up on the COVID-19 pandemic situation, and its impact on the national football landscape. According to the AFE and the LNFP, the <ins style="font-weight: bold; text-decoration: none;">RFEF </ins>shared the recording of this meeting with two radio broadcasters (Cadena Ser, COPE) without the participant's knowledge or consent, who eventually found out when the recordings were broadcasted a few days later. As a result, both the AFE and the LNFP filed several complaints against the <ins style="font-weight: bold; text-decoration: none;">RFEF </ins>with the Spanish DPA (AEPD). According to the claimants, the participants were not informed about the fact that the meeting was being recorded, and they did not receive the required information under [[Article 13 GDPR]].</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>The RFEF alleged that during a prior in-person meeting, all the participants had agreed to record that meeting. The <del style="font-weight: bold; text-decoration: none;">REEF </del>claimed that in the subsequent second meeting held on Zoom, all the participants were informed that the meeting was being recorded because there was an indicative red circle sign next to the word "recording" on the screen. Additionally, the <del style="font-weight: bold; text-decoration: none;">REEF </del>stated that the meeting was recorded in order to obtain a literal transcript (the minutes), and to publish a press release according to its transparency requirements. The <del style="font-weight: bold; text-decoration: none;">REEF </del>also alleged that it had only shared the recording to refute a false statement made by the AFE related to that meeting.</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>The RFEF alleged that during a prior in-person meeting, all the participants had agreed to record that meeting. The <ins style="font-weight: bold; text-decoration: none;">RFEF </ins>claimed that in the subsequent second meeting held on Zoom, all the participants were informed that the meeting was being recorded because there was an indicative red circle sign next to the word "recording" on the screen. Additionally, the <ins style="font-weight: bold; text-decoration: none;">RFEF </ins>stated that the meeting was recorded in order to obtain a literal transcript (the minutes), and to publish a press release according to its transparency requirements. The <ins style="font-weight: bold; text-decoration: none;">RFEF </ins>also alleged that it had only shared the recording to refute a false statement made by the AFE related to that meeting.</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Lastly, the <del style="font-weight: bold; text-decoration: none;">REEF </del>provided a document (drafted after the second meeting) that was shared with participants for setting up future meetings, which contained a data protection clause stating that participants consented to the recording of the meeting, and that this recording was carried out by the <del style="font-weight: bold; text-decoration: none;">REEF </del>for public interest purposes. </div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Lastly, the <ins style="font-weight: bold; text-decoration: none;">RFEF </ins>provided a document (drafted after the second meeting) that was shared with participants for setting up future meetings, which contained a data protection clause stating that participants consented to the recording of the meeting, and that this recording was carried out by the <ins style="font-weight: bold; text-decoration: none;">RFEF </ins>for public interest purposes. </div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>=== Holding ===</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>=== Holding ===</div></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>With regard to the information obligation from [[Article 13 GDPR|Article 13 GDPR]], the AEPD considered different issues. First, that the <del style="font-weight: bold; text-decoration: none;">REEF </del>could not prove that the participants had been informed that the second meeting was being recorded, since it was only at the beginning of the first meeting where <del style="font-weight: bold; text-decoration: none;">REEF</del>'s representative warned the participants that the meeting was being recorded. However, the AEPD noted that no more information was given, and the fact that future meetings would also be recorded was not mentioned. Additionally, the AEPD observed that this <del style="font-weight: bold; text-decoration: none;">communciation </del>would have been insufficient since some participants in the second meeting had not attended the first one. Therefore, the AEPD held that the <del style="font-weight: bold; text-decoration: none;">REEF </del>could not prove that the participants in the meeting had been informed about the processing of personal data as required by [[Article 13 GDPR]]. Furthermore, the AEPD, highlighted that the <del style="font-weight: bold; text-decoration: none;">REEF </del>did not provide the information required by [[Article 13 GDPR#3|Article 13(3) GDPR]] about further processing of the data, which in this case was related to sharing the recording with two radio broadcasters. Therefore, the AEPD held that the <del style="font-weight: bold; text-decoration: none;">REEF </del>had breached [[Article 13 GDPR]].</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>With regard to the information obligation from [[Article 13 GDPR|Article 13 GDPR]], the AEPD considered different issues. First, that the <ins style="font-weight: bold; text-decoration: none;">RFEF </ins>could not prove that the participants had been informed that the second meeting was being recorded, since it was only at the beginning of the first meeting where <ins style="font-weight: bold; text-decoration: none;">RFEF</ins>'s representative warned the participants that the meeting was being recorded. However, the AEPD noted that no more information was given, and the fact that future meetings would also be recorded was not mentioned. Additionally, the AEPD observed that this <ins style="font-weight: bold; text-decoration: none;">communication </ins>would have been insufficient since some participants in the second meeting had not attended the first one. Therefore, the AEPD held that the <ins style="font-weight: bold; text-decoration: none;">RFEF </ins>could not prove that the participants in the meeting had been informed about the processing of personal data as required by [[Article 13 GDPR]]. Furthermore, the AEPD, highlighted that the <ins style="font-weight: bold; text-decoration: none;">RFEF </ins>did not provide the information required by [[Article 13 GDPR#3|Article 13(3) GDPR]] about further processing of the data, which in this case was related to sharing the recording with two radio broadcasters. Therefore, the AEPD held that the <ins style="font-weight: bold; text-decoration: none;">RFEF </ins>had breached [[Article 13 GDPR]].</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>On the other hand, the AEPD established that the <del style="font-weight: bold; text-decoration: none;">REEF </del>did have a valid legal basis for the processing of personal data in this case, since Article 18 of the [https://www.boe.es/buscar/act.php?id=BOE-A-2015-10566 Spanish Act for the Regulation of the Public Sector] (''Ley 40/2015, de 1 de octubre, de Régimen Jurídico del Sector Público - LRJSP'') allows public bodies to record their meetings and to store them in order to keep a literal transcript of the minutes. However, the AEPD noted that having a valid legal basis does not excuse the controller from properly informing the data subjects with the requirements included under [[Article 13 GDPR]]. According to the AEPD, stating that the recording would take place in order to keep a transcript of the meeting, did not amount to providing adequate information under this provision, <del style="font-weight: bold; text-decoration: none;">inlcuding </del>basic information regarding the legal basis and the purposes of the processing.</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>On the other hand, the AEPD established that the <ins style="font-weight: bold; text-decoration: none;">RFEF </ins>did have a valid legal basis for the processing of personal data in this case, since Article 18 of the [https://www.boe.es/buscar/act.php?id=BOE-A-2015-10566 Spanish Act for the Regulation of the Public Sector] (''Ley 40/2015, de 1 de octubre, de Régimen Jurídico del Sector Público - LRJSP'') allows public bodies to record their meetings and to store them in order to keep a literal transcript of the minutes. However, the AEPD noted that having a valid legal basis does not excuse the controller from properly informing the data subjects with the requirements included under [[Article 13 GDPR]]. According to the AEPD, stating that the recording would take place in order to keep a transcript of the meeting, did not amount to providing adequate information under this provision, <ins style="font-weight: bold; text-decoration: none;">including </ins>basic information regarding the legal basis and the purposes of the processing.</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>In relation to public bodies' transparency obligations related to keeping a record of their meetings' minutes and disclosing them, the AEPD observed that this obligation only includes a written record of certain aspects, not a recording of the meeting itself. Therefore, although these obligations would allow <del style="font-weight: bold; text-decoration: none;">REEF </del>to record the meeting, as well as to provide access to the written minutes, it would not allow it to share the actual recording. The AEPD highlighted Recital 50 GDPR, which states that ''"the processing of personal data for purposes other than those for which the personal data were initially collected should be allowed only where the processing is compatible with the purposes for which the personal data were initially collected."'' For the subsequent processing which occurred when sharing the video with the broadcasters, the <del style="font-weight: bold; text-decoration: none;">REEF </del>relied on freedom of information and expression, considering that it had the legitimacy to refute a press released by the AFE which was not factual, and to substantiate this refutation by providing a recording of what was exactly said during the meeting. However, the AEPD held these rights could have been <del style="font-weight: bold; text-decoration: none;">excercised </del>by sharing the written record of the meeting, and not the actual recording. The AEPD also noted that the recording contained comments of a personal and private nature, and that therefore the <del style="font-weight: bold; text-decoration: none;">REEF </del>should have only shared the minimum amount of data necessary to achieve that purpose, according to the data minimisation principle. Consequently, the AEPD held that the <del style="font-weight: bold; text-decoration: none;">REEF </del>had violated [[Article 6 GDPR|Article 6(1) GDPR]], processing personal data without a valid legal basis by sharing the recording instead of a transcript limited to the relevant details.</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>In relation to public bodies' transparency obligations related to keeping a record of their meetings' minutes and disclosing them, the AEPD observed that this obligation only includes a written record of certain aspects, not a recording of the meeting itself. Therefore, although these obligations would allow <ins style="font-weight: bold; text-decoration: none;">RFEF </ins>to record the meeting, as well as to provide access to the written minutes, it would not allow it to share the actual recording. The AEPD highlighted Recital 50 GDPR, which states that ''"the processing of personal data for purposes other than those for which the personal data were initially collected should be allowed only where the processing is compatible with the purposes for which the personal data were initially collected."'' For the subsequent processing which occurred when sharing the video with the broadcasters, the <ins style="font-weight: bold; text-decoration: none;">RFEF </ins>relied on freedom of information and expression, considering that it had the legitimacy to refute a press released by the AFE which was not factual, and to substantiate this refutation by providing a recording of what was exactly said during the meeting. However, the AEPD held these rights could have been <ins style="font-weight: bold; text-decoration: none;">exercised </ins>by sharing the written record of the meeting, and not the actual recording. The AEPD also noted that the recording contained comments of a personal and private nature, and that therefore the <ins style="font-weight: bold; text-decoration: none;">RFEF </ins>should have only shared the minimum amount of data necessary to achieve that purpose, according to the data minimisation principle. Consequently, the AEPD held that the <ins style="font-weight: bold; text-decoration: none;">RFEF </ins>had violated [[Article 6 GDPR|Article 6(1) GDPR]], processing personal data without a valid legal basis by sharing the recording instead of a transcript limited to the relevant details.</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Based on these considerations, the AEPD fined the <del style="font-weight: bold; text-decoration: none;">REEF </del>a total of €200,000 ( €100,000 for the violating [[Article 13 GDPR]], and €100,000 for the violating [[Article 6 GDPR|Article 6(1) GDPR]]).</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Based on these considerations, the AEPD fined the <ins style="font-weight: bold; text-decoration: none;">RFEF </ins>a total of €200,000 ( €100,000 for the violating [[Article 13 GDPR]], and €100,000 for the violating [[Article 6 GDPR|Article 6(1) GDPR]]).</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Comment ==</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Comment ==</div></td></tr>
</table>Carmen.villarroelhttps://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00368/2021&diff=23604&oldid=prevCms: Just minor changes in wording and phrasing. Great summary as usual!2022-02-22T17:56:42Z<p>Just minor changes in wording and phrasing. Great summary as usual!</p>
<table style="background-color: #fff; color: #202122;" data-mw="interface">
<col class="diff-marker" />
<col class="diff-content" />
<col class="diff-marker" />
<col class="diff-content" />
<tr class="diff-title" lang="en">
<td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">← Older revision</td>
<td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">Revision as of 17:56, 22 February 2022</td>
</tr><tr><td colspan="2" class="diff-lineno" id="mw-diff-left-l52">Line 52:</td>
<td colspan="2" class="diff-lineno">Line 52:</td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|}}</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|}}</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>The Spanish DPA fined the Spanish Football Federation €200,000 for sharing the recording of a meeting <del style="font-weight: bold; text-decoration: none;">between representatives of different bodies </del>without <del style="font-weight: bold; text-decoration: none;">their </del>knowledge or consent and for not <del style="font-weight: bold; text-decoration: none;">properly informing </del>the <del style="font-weight: bold; text-decoration: none;">participants of the processing of their personal data as </del>required by [[Article 13 GDPR|Article 13 GDPR]].</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>The Spanish DPA fined the Spanish Football Federation €200,000 for sharing the recording of a meeting <ins style="font-weight: bold; text-decoration: none;">held on Zoom </ins>without <ins style="font-weight: bold; text-decoration: none;">the </ins>knowledge or consent <ins style="font-weight: bold; text-decoration: none;">of the participants representing other entities in the meeting, </ins>and for not <ins style="font-weight: bold; text-decoration: none;">providing them with </ins>the <ins style="font-weight: bold; text-decoration: none;">necessary information </ins>required by [[Article 13 GDPR|Article 13 GDPR]].</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== English Summary ==</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== English Summary ==</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>=== Facts ===</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>=== Facts ===</div></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Representatives of the Spanish Football Federation (RFEF), the Association of Spanish Footballers (AFE), and the Professional Football League (LNFP) held a meeting via Zoom on April 2020 to follow-up <del style="font-weight: bold; text-decoration: none;">of </del>the COVID-19 pandemic situation and its impact on the national football landscape.</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Representatives of the Spanish Football Federation (RFEF), the Association of Spanish Footballers (AFE), and the Professional Football League (LNFP) held a meeting via Zoom on April 2020 to follow-up <ins style="font-weight: bold; text-decoration: none;">on </ins>the COVID-19 pandemic situation<ins style="font-weight: bold; text-decoration: none;">, </ins>and its impact on the national football landscape<ins style="font-weight: bold; text-decoration: none;">. According to the AFE and the LNFP, the REEF shared the recording of this meeting with two radio broadcasters (Cadena Ser, COPE) without the participant's knowledge or consent, who eventually found out when the recordings were broadcasted a few days later. As a result, both the AFE and the LNFP filed several complaints against the REEF with the Spanish DPA (AEPD). According to the claimants, the participants were not informed about the fact that the meeting was being recorded, and they did not receive the required information under [[Article 13 GDPR]]</ins>.</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><del style="font-weight: bold; text-decoration: none;">According </del>to the <del style="font-weight: bold; text-decoration: none;">Association of Spanish Footballers and </del>the <del style="font-weight: bold; text-decoration: none;">Professional Football League</del>, the <del style="font-weight: bold; text-decoration: none;">Spanish Football Federation shared </del>the <del style="font-weight: bold; text-decoration: none;">recording of such </del>meeting <del style="font-weight: bold; text-decoration: none;">with two radio broadcasters </del>(<del style="font-weight: bold; text-decoration: none;">Cadena Ser</del>, <del style="font-weight: bold; text-decoration: none;">COPE) without the knowledge </del>and <del style="font-weight: bold; text-decoration: none;">consent of the participants, who discovered </del>it <del style="font-weight: bold; text-decoration: none;">when </del>the <del style="font-weight: bold; text-decoration: none;">recordings were broadcasted </del>a <del style="font-weight: bold; text-decoration: none;">few days later</del>.</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div><ins style="font-weight: bold; text-decoration: none;">The RFEF alleged that during a prior in-person meeting, all the participants had agreed </ins>to <ins style="font-weight: bold; text-decoration: none;">record that meeting. The REEF claimed that in </ins>the <ins style="font-weight: bold; text-decoration: none;">subsequent second meeting held on Zoom, all the participants were informed that the meeting was being recorded because there was an indicative red circle sign next to the word "recording" on </ins>the <ins style="font-weight: bold; text-decoration: none;">screen. Additionally</ins>, the <ins style="font-weight: bold; text-decoration: none;">REEF stated that </ins>the meeting <ins style="font-weight: bold; text-decoration: none;">was recorded in order to obtain a literal transcript </ins>(<ins style="font-weight: bold; text-decoration: none;">the minutes)</ins>, and <ins style="font-weight: bold; text-decoration: none;">to publish a press release according to its transparency requirements. The REEF also alleged that </ins>it <ins style="font-weight: bold; text-decoration: none;">had only shared </ins>the <ins style="font-weight: bold; text-decoration: none;">recording to refute </ins>a <ins style="font-weight: bold; text-decoration: none;">false statement made by the AFE related to that meeting</ins>.</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><del style="font-weight: bold; text-decoration: none;">Therefore</del>, <del style="font-weight: bold; text-decoration: none;">both </del>the <del style="font-weight: bold; text-decoration: none;">AFE and the LNFP filed several complaints with the Spanish DPA (AEPD). According to the claimants, the participants were not informed about the fact that the meeting was being recorded, and did not receive the mandatory information from [[Article 13 GDPR|Article 13 GDPR]].</del></div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div><ins style="font-weight: bold; text-decoration: none;">Lastly</ins>, the <ins style="font-weight: bold; text-decoration: none;">REEF </ins>provided a document (drafted after the second meeting) that <ins style="font-weight: bold; text-decoration: none;">was </ins>shared <ins style="font-weight: bold; text-decoration: none;">with participants for </ins>setting <ins style="font-weight: bold; text-decoration: none;">up future meetings, which </ins>contained a data protection clause <ins style="font-weight: bold; text-decoration: none;">stating </ins>that participants consented to the recording <ins style="font-weight: bold; text-decoration: none;">of the meeting, </ins>and that <ins style="font-weight: bold; text-decoration: none;">this recording was carried out by </ins>the <ins style="font-weight: bold; text-decoration: none;">REEF for </ins>public interest <ins style="font-weight: bold; text-decoration: none;">purposes</ins>. </div></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div> </div></td><td colspan="2" class="diff-side-added"></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><del style="font-weight: bold; text-decoration: none;">The RFEF (the controller) alleged that during the first meeting they held (Zoom meeting at issue was the second one - the first one was on-site) all the participants had agreed to record the meetings, and that during the Zoom meeting there was a red round sign that indicated the participants that the meeting was also being recorded, and that therefore all the participants were informed about this facts. The controller also alleged that the they had shared the recording of the meeting to refute a false statement made by the AFE.</del></div></td><td colspan="2" class="diff-side-added"></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div> </div></td><td colspan="2" class="diff-side-added"></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><del style="font-weight: bold; text-decoration: none;">According to the controller, the meeting was recorded in order to obtain a literal record of the meeting (the minutes), and so a press release could be published due to transparency requirements. The controller also </del>provided a document (drafted after the second meeting) that <del style="font-weight: bold; text-decoration: none;">had </del>shared <del style="font-weight: bold; text-decoration: none;">when </del>setting <del style="font-weight: bold; text-decoration: none;">the meeting that </del>contained a data protection clause that <del style="font-weight: bold; text-decoration: none;">stated that the </del>participants consented to the recording and that the <del style="font-weight: bold; text-decoration: none;">controller had a </del>public interest <del style="font-weight: bold; text-decoration: none;">to record the meetings</del>.</div></td><td colspan="2" class="diff-side-added"></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>=== Holding ===</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>=== Holding ===</div></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>With regard to the information obligation from [[Article 13 GDPR|Article 13 GDPR]], the AEPD considered different issues. First, that the <del style="font-weight: bold; text-decoration: none;">controller </del>could not prove that the participants had been informed that the meeting was being recorded<del style="font-weight: bold; text-decoration: none;">. It </del>was only at the beginning of the first meeting where <del style="font-weight: bold; text-decoration: none;">the </del>representative <del style="font-weight: bold; text-decoration: none;">of the controller </del>warned the participants that the meeting was being recorded, <del style="font-weight: bold; text-decoration: none;">in order to document everything </del>that <del style="font-weight: bold; text-decoration: none;">was said in the meeting. Yet, </del>no more information was given, and the fact that future meetings would also be recorded was not mentioned. Additionally, <del style="font-weight: bold; text-decoration: none;">there were </del>participants in the second meeting <del style="font-weight: bold; text-decoration: none;">that </del>had not attended the first <del style="font-weight: bold; text-decoration: none;">meeting; and during the second meeting participants were not informed about the recording</del>.</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>With regard to the information obligation from [[Article 13 GDPR|Article 13 GDPR]], the AEPD considered different issues. First, that the <ins style="font-weight: bold; text-decoration: none;">REEF </ins>could not prove that the participants had been informed that the <ins style="font-weight: bold; text-decoration: none;">second </ins>meeting was being recorded<ins style="font-weight: bold; text-decoration: none;">, since it </ins>was only at the beginning of the first meeting where <ins style="font-weight: bold; text-decoration: none;">REEF's </ins>representative warned the participants that the meeting was being recorded<ins style="font-weight: bold; text-decoration: none;">. However</ins>, <ins style="font-weight: bold; text-decoration: none;">the AEPD noted </ins>that no more information was given, and the fact that future meetings would also be recorded was not mentioned. Additionally, <ins style="font-weight: bold; text-decoration: none;">the AEPD observed that this communciation would have been insufficient since some </ins>participants in the second meeting had not attended the first <ins style="font-weight: bold; text-decoration: none;">one</ins>. Therefore, the <ins style="font-weight: bold; text-decoration: none;">AEPD held that the REEF </ins>could not prove that the participants in the meeting had been informed about the processing of personal data as required by [[Article 13 GDPR]]. <ins style="font-weight: bold; text-decoration: none;">Furthermore</ins>, the <ins style="font-weight: bold; text-decoration: none;">AEPD</ins>, <ins style="font-weight: bold; text-decoration: none;">highlighted that </ins>the <ins style="font-weight: bold; text-decoration: none;">REEF </ins>did not provide the information required by [[Article 13 GDPR#3|Article 13(3) GDPR]] about further processing of the data<ins style="font-weight: bold; text-decoration: none;">, which </ins>in this case <ins style="font-weight: bold; text-decoration: none;">was related to </ins>sharing the recording with two radio broadcasters. Therefore, the AEPD <ins style="font-weight: bold; text-decoration: none;">held </ins>that the <ins style="font-weight: bold; text-decoration: none;">REEF </ins>had breached [[Article 13 GDPR]].</div></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div> </div></td><td colspan="2" class="diff-side-added"></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Therefore, the <del style="font-weight: bold; text-decoration: none;">controller did not and </del>could not prove that the participants in the meeting had been informed about the processing of personal data as required by [[<del style="font-weight: bold; text-decoration: none;">Article 13 GDPR|</del>Article 13 GDPR]]. <del style="font-weight: bold; text-decoration: none;">And</del>, <del style="font-weight: bold; text-decoration: none;">as highlighted by </del>the <del style="font-weight: bold; text-decoration: none;">DPA</del>, the <del style="font-weight: bold; text-decoration: none;">controller </del>did not provide <del style="font-weight: bold; text-decoration: none;">either </del>the information required by [[Article 13 GDPR#3|Article 13(3) GDPR]] about further processing of the data <del style="font-weight: bold; text-decoration: none;">(</del>in this case<del style="font-weight: bold; text-decoration: none;">, </del>sharing the recording with two radio broadcasters<del style="font-weight: bold; text-decoration: none;">)</del>. Therefore, the AEPD <del style="font-weight: bold; text-decoration: none;">concluded </del>that the <del style="font-weight: bold; text-decoration: none;">controller </del>had breached [[Article 13 GDPR]]<del style="font-weight: bold; text-decoration: none;">.</del></div></td><td colspan="2" class="diff-side-added"></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div> </div></td><td colspan="2" class="diff-side-added"></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><del style="font-weight: bold; text-decoration: none;">On the other hand, the AEPD concluded that the controller had a valid legal basis for the processing of personal data in the first place, since Article 18 of the [https://www.boe.es/buscar/act.php?id=BOE-A-2015-10566 Spanish Act for the Regulation of the Public Sector] (LRJSP) allows public bodies to record their meetings and to store them in order to keep a literal record of the minutes.</del></div></td><td colspan="2" class="diff-side-added"></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div> </div></td><td colspan="2" class="diff-side-added"></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><del style="font-weight: bold; text-decoration: none;">However, having a valid legal basis does not prevent the controller from properly informing the data subjects about all the mandatory points included in [[Article 13 GDPR|Article 13 GDPR]]. According to the AEPD, saying 'we are recording the meeting so we can keep record of everything that will be said' at the beginning of the meeting does not amount to providing the mandatory information, and it cannot be considered to be providing basic information about the legal basis and the purposes of the processing</del>.</div></td><td colspan="2" class="diff-side-added"></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><del style="font-weight: bold; text-decoration: none;">Regarding </del>the <del style="font-weight: bold; text-decoration: none;">transparency obligations </del>of public bodies <del style="font-weight: bold; text-decoration: none;">with respect </del>to the minutes <del style="font-weight: bold; text-decoration: none;">of their meetings</del>, the AEPD noted that the <del style="font-weight: bold; text-decoration: none;">obligation </del>to <del style="font-weight: bold; text-decoration: none;">disclose </del>the <del style="font-weight: bold; text-decoration: none;">minutes does not include </del>the recording <del style="font-weight: bold; text-decoration: none;">itself but </del>a <del style="font-weight: bold; text-decoration: none;">written record </del>of <del style="font-weight: bold; text-decoration: none;">certain aspects. Therefore, while this allows to record </del>the meeting <del style="font-weight: bold; text-decoration: none;">and to provide access to the written minutes</del>, <del style="font-weight: bold; text-decoration: none;">it does </del>not <del style="font-weight: bold; text-decoration: none;">allow </del>to <del style="font-weight: bold; text-decoration: none;">share </del>the <del style="font-weight: bold; text-decoration: none;">actual recording </del>of <del style="font-weight: bold; text-decoration: none;">it</del>.</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div><ins style="font-weight: bold; text-decoration: none;">On </ins>the <ins style="font-weight: bold; text-decoration: none;">other hand, the AEPD established that the REEF did have a valid legal basis for the processing </ins>of <ins style="font-weight: bold; text-decoration: none;">personal data in this case, since Article 18 of the [https://www.boe.es/buscar/act.php?id=BOE-A-2015-10566 Spanish Act for the Regulation of the Public Sector] (''Ley 40/2015, de 1 de octubre, de Régimen Jurídico del Sector Público - LRJSP'') allows </ins>public bodies to <ins style="font-weight: bold; text-decoration: none;">record their meetings and to store them in order to keep a literal transcript of </ins>the minutes<ins style="font-weight: bold; text-decoration: none;">. However</ins>, the AEPD noted that <ins style="font-weight: bold; text-decoration: none;">having a valid legal basis does not excuse </ins>the <ins style="font-weight: bold; text-decoration: none;">controller from properly informing the data subjects with the requirements included under [[Article 13 GDPR]]. According </ins>to the <ins style="font-weight: bold; text-decoration: none;">AEPD, stating that </ins>the recording <ins style="font-weight: bold; text-decoration: none;">would take place in order to keep </ins>a <ins style="font-weight: bold; text-decoration: none;">transcript </ins>of the meeting, <ins style="font-weight: bold; text-decoration: none;">did </ins>not <ins style="font-weight: bold; text-decoration: none;">amount </ins>to <ins style="font-weight: bold; text-decoration: none;">providing adequate information under this provision, inlcuding basic information regarding the legal basis and </ins>the <ins style="font-weight: bold; text-decoration: none;">purposes </ins>of <ins style="font-weight: bold; text-decoration: none;">the processing</ins>.</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><del style="font-weight: bold; text-decoration: none;">With regard </del>to the <del style="font-weight: bold; text-decoration: none;">second and subsequent processing </del>of <del style="font-weight: bold; text-decoration: none;">data</del>, <del style="font-weight: bold; text-decoration: none;">in which </del>the <del style="font-weight: bold; text-decoration: none;">recording was shared with </del>the <del style="font-weight: bold; text-decoration: none;">radio broadcasters</del>, the AEPD highlighted Recital 50 GDPR, <del style="font-weight: bold; text-decoration: none;">that </del>states that "the processing of personal data for purposes other than those for which the personal data were initially collected should be allowed only where the processing is compatible with the purposes for which the personal data were initially collected"<del style="font-weight: bold; text-decoration: none;">. </del>For <del style="font-weight: bold; text-decoration: none;">this </del>subsequent processing, the <del style="font-weight: bold; text-decoration: none;">controller </del>relied on <del style="font-weight: bold; text-decoration: none;">the right to </del>freedom of information and <del style="font-weight: bold; text-decoration: none;">freedom of </del>expression, <del style="font-weight: bold; text-decoration: none;">since the controller considered </del>that it had the legitimacy to refute <del style="font-weight: bold; text-decoration: none;">the allegedly false </del>press released by the AFE and to substantiate <del style="font-weight: bold; text-decoration: none;">such </del>refutation by providing a <del style="font-weight: bold; text-decoration: none;">literal record and the </del>recording of what was exactly said during the meeting. However, the <del style="font-weight: bold; text-decoration: none;">authority reasoned that such right </del>could have been <del style="font-weight: bold; text-decoration: none;">vindicated just </del>by sharing the written record of the meeting, and not the actual recording. <del style="font-weight: bold; text-decoration: none;">In this regard, the </del>AEPD <del style="font-weight: bold; text-decoration: none;">remarked </del>that the recording <del style="font-weight: bold; text-decoration: none;">of the meeting also </del>contained comments of a personal and private nature<del style="font-weight: bold; text-decoration: none;">. Therefore</del>, <del style="font-weight: bold; text-decoration: none;">if needed, they </del>should have shared the minimum data necessary to achieve that purpose, according to the <del style="font-weight: bold; text-decoration: none;">minimization </del>principle. <del style="font-weight: bold; text-decoration: none;">Therefore, by sharing the recording of the meeting</del>, the AEPD <del style="font-weight: bold; text-decoration: none;">considered </del>that the <del style="font-weight: bold; text-decoration: none;">controller breached </del>[[Article 6 GDPR|Article 6(1) GDPR]], <del style="font-weight: bold; text-decoration: none;">for </del>processing personal data without a valid legal basis.</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div><ins style="font-weight: bold; text-decoration: none;">In relation to public bodies' transparency obligations related </ins>to <ins style="font-weight: bold; text-decoration: none;">keeping a record of their meetings' minutes and disclosing them, </ins>the <ins style="font-weight: bold; text-decoration: none;">AEPD observed that this obligation only includes a written record of certain aspects, not a recording </ins>of <ins style="font-weight: bold; text-decoration: none;">the meeting itself. Therefore</ins>, <ins style="font-weight: bold; text-decoration: none;">although these obligations would allow REEF to record </ins>the <ins style="font-weight: bold; text-decoration: none;">meeting, as well as to provide access to </ins>the <ins style="font-weight: bold; text-decoration: none;">written minutes</ins>, <ins style="font-weight: bold; text-decoration: none;">it would not allow it to share </ins>the <ins style="font-weight: bold; text-decoration: none;">actual recording. The </ins>AEPD highlighted Recital 50 GDPR, <ins style="font-weight: bold; text-decoration: none;">which </ins>states that <ins style="font-weight: bold; text-decoration: none;">''</ins>"the processing of personal data for purposes other than those for which the personal data were initially collected should be allowed only where the processing is compatible with the purposes for which the personal data were initially collected<ins style="font-weight: bold; text-decoration: none;">.</ins>"<ins style="font-weight: bold; text-decoration: none;">'' </ins>For <ins style="font-weight: bold; text-decoration: none;">the </ins>subsequent processing <ins style="font-weight: bold; text-decoration: none;">which occurred when sharing the video with the broadcasters</ins>, the <ins style="font-weight: bold; text-decoration: none;">REEF </ins>relied on freedom of information and expression, <ins style="font-weight: bold; text-decoration: none;">considering </ins>that it had the legitimacy to refute <ins style="font-weight: bold; text-decoration: none;">a </ins>press released by the AFE <ins style="font-weight: bold; text-decoration: none;">which was not factual, </ins>and to substantiate <ins style="font-weight: bold; text-decoration: none;">this </ins>refutation by providing a recording of what was exactly said during the meeting. However, the <ins style="font-weight: bold; text-decoration: none;">AEPD held these rights </ins>could have been <ins style="font-weight: bold; text-decoration: none;">excercised </ins>by sharing the written record of the meeting, and not the actual recording. <ins style="font-weight: bold; text-decoration: none;">The </ins>AEPD <ins style="font-weight: bold; text-decoration: none;">also noted </ins>that the recording contained comments of a personal and private nature, <ins style="font-weight: bold; text-decoration: none;">and that therefore the REEF </ins>should have <ins style="font-weight: bold; text-decoration: none;">only </ins>shared the minimum <ins style="font-weight: bold; text-decoration: none;">amount of </ins>data necessary to achieve that purpose, according to the <ins style="font-weight: bold; text-decoration: none;">data minimisation </ins>principle. <ins style="font-weight: bold; text-decoration: none;">Consequently</ins>, the AEPD <ins style="font-weight: bold; text-decoration: none;">held </ins>that the <ins style="font-weight: bold; text-decoration: none;">REEF had violated </ins>[[Article 6 GDPR|Article 6(1) GDPR]], processing personal data without a valid legal basis <ins style="font-weight: bold; text-decoration: none;">by sharing the recording instead of a transcript limited to the relevant details</ins>.</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><del style="font-weight: bold; text-decoration: none;">For </del>the <del style="font-weight: bold; text-decoration: none;">violation </del>of [[Article 13 GDPR]], <del style="font-weight: bold; text-decoration: none;">the AEPD fined the controller </del>€100,000<del style="font-weight: bold; text-decoration: none;">. For </del>the <del style="font-weight: bold; text-decoration: none;">violation of </del>[[Article 6 GDPR|Article 6(1) GDPR]]<del style="font-weight: bold; text-decoration: none;">, the AEPD fined the controller another €100,000</del>.</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div><ins style="font-weight: bold; text-decoration: none;">Based on these considerations, the AEPD fined </ins>the <ins style="font-weight: bold; text-decoration: none;">REEF a total </ins>of <ins style="font-weight: bold; text-decoration: none;">€200,000 ( €100,000 for the violating </ins>[[Article 13 GDPR]], <ins style="font-weight: bold; text-decoration: none;">and </ins>€100,000 <ins style="font-weight: bold; text-decoration: none;">for </ins>the <ins style="font-weight: bold; text-decoration: none;">violating </ins>[[Article 6 GDPR|Article 6(1) GDPR]]<ins style="font-weight: bold; text-decoration: none;">)</ins>.</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Comment ==</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Comment ==</div></td></tr>
<!-- diff cache key gdprwiki:diff::1.12:old-23464:rev-23604 -->
</table>Cmshttps://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00368/2021&diff=23464&oldid=prevCarmen.villarroel at 00:25, 19 February 20222022-02-19T00:25:45Z<p></p>
<table style="background-color: #fff; color: #202122;" data-mw="interface">
<col class="diff-marker" />
<col class="diff-content" />
<col class="diff-marker" />
<col class="diff-content" />
<tr class="diff-title" lang="en">
<td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">← Older revision</td>
<td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">Revision as of 00:25, 19 February 2022</td>
</tr><tr><td colspan="2" class="diff-lineno" id="mw-diff-left-l52">Line 52:</td>
<td colspan="2" class="diff-lineno">Line 52:</td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|}}</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|}}</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>The Spanish DPA fined the Spanish Football Federation €200,000 for sharing the recording of a meeting between representatives of different bodies without their knowledge <del style="font-weight: bold; text-decoration: none;">and </del>consent and for not properly informing the participants of the processing of their personal data as required by [[Article 13 GDPR|Article 13 GDPR]].</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>The Spanish DPA fined the Spanish Football Federation €200,000 for sharing the recording of a meeting between representatives of different bodies without their knowledge <ins style="font-weight: bold; text-decoration: none;">or </ins>consent and for not properly informing the participants of the processing of their personal data as required by [[Article 13 GDPR|Article 13 GDPR]].</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== English Summary ==</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== English Summary ==</div></td></tr>
</table>Carmen.villarroelhttps://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00368/2021&diff=23463&oldid=prevCarmen.villarroel: /* Holding */2022-02-19T00:25:14Z<p><span dir="auto"><span class="autocomment">Holding</span></span></p>
<table style="background-color: #fff; color: #202122;" data-mw="interface">
<col class="diff-marker" />
<col class="diff-content" />
<col class="diff-marker" />
<col class="diff-content" />
<tr class="diff-title" lang="en">
<td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">← Older revision</td>
<td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">Revision as of 00:25, 19 February 2022</td>
</tr><tr><td colspan="2" class="diff-lineno" id="mw-diff-left-l68">Line 68:</td>
<td colspan="2" class="diff-lineno">Line 68:</td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>=== Holding ===</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>=== Holding ===</div></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>With regard to the information obligation from [[Article 13 GDPR|Article 13 GDPR]], the AEPD considered <del style="font-weight: bold; text-decoration: none;">the following</del>. First, that the controller could not prove that the participants had been informed that the meeting was being recorded. <del style="font-weight: bold; text-decoration: none;">Only </del>at the beginning of the first meeting <del style="font-weight: bold; text-decoration: none;">did </del>the representative of the controller <del style="font-weight: bold; text-decoration: none;">warn </del>the participants that the meeting was being recorded <del style="font-weight: bold; text-decoration: none;">so </del>everything that was said in the meeting <del style="font-weight: bold; text-decoration: none;">could be documented</del>. <del style="font-weight: bold; text-decoration: none;">However</del>, no more information was given, and the fact that future meetings would also be recorded was not mentioned. Additionally, there were participants in the second meeting that had not attended the first meeting; and during the second meeting participants were not informed about the recording.</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>With regard to the information obligation from [[Article 13 GDPR|Article 13 GDPR]], the AEPD considered <ins style="font-weight: bold; text-decoration: none;">different issues</ins>. First, that the controller could not prove that the participants had been informed that the meeting was being recorded. <ins style="font-weight: bold; text-decoration: none;">It was only </ins>at the beginning of the first meeting <ins style="font-weight: bold; text-decoration: none;">where </ins>the representative of the controller <ins style="font-weight: bold; text-decoration: none;">warned </ins>the participants that the meeting was being recorded<ins style="font-weight: bold; text-decoration: none;">, in order to document </ins>everything that was said in the meeting. <ins style="font-weight: bold; text-decoration: none;">Yet</ins>, no more information was given, and the fact that future meetings would also be recorded was not mentioned. Additionally, there were participants in the second meeting that had not attended the first meeting; and during the second meeting participants were not informed about the recording.</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Therefore, the controller did not and could not prove that the participants in the meeting had been informed about the processing of personal data as required by [[Article 13 GDPR|Article 13 GDPR]]. And, as highlighted by the DPA, the controller did not provide the information required by [[Article 13 GDPR#3|Article 13(3) GDPR]] about further processing of the data (in this case, sharing <del style="font-weight: bold; text-decoration: none;">it </del>with radio broadcasters).</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Therefore, the controller did not and could not prove that the participants in the meeting had been informed about the processing of personal data as required by [[Article 13 GDPR|Article 13 GDPR]]. And, as highlighted by the DPA, the controller did not provide <ins style="font-weight: bold; text-decoration: none;">either </ins>the information required by [[Article 13 GDPR#3|Article 13(3) GDPR]] about further processing of the data (in this case, sharing <ins style="font-weight: bold; text-decoration: none;">the recording </ins>with <ins style="font-weight: bold; text-decoration: none;">two </ins>radio broadcasters)<ins style="font-weight: bold; text-decoration: none;">. Therefore, the AEPD concluded that the controller had breached [[Article 13 GDPR]]</ins>.</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><del style="font-weight: bold; text-decoration: none;">The </del>AEPD concluded that the controller had a valid legal basis for the processing of personal data in the first place, since Article 18 of the [https://www.boe.es/buscar/act.php?id=BOE-A-2015-10566 Spanish Act for the Regulation of the Public Sector] (LRJSP) allows public bodies to record their meetings and to store them in order to keep a literal record of the minutes.</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div><ins style="font-weight: bold; text-decoration: none;">On the other hand, the </ins>AEPD concluded that the controller had a valid legal basis for the processing of personal data in the first place, since Article 18 of the [https://www.boe.es/buscar/act.php?id=BOE-A-2015-10566 Spanish Act for the Regulation of the Public Sector] (LRJSP) allows public bodies to record their meetings and to store them in order to keep a literal record of the minutes.</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>However, having a valid legal basis does not prevent the controller from properly informing the data subjects about all the mandatory points included in [[Article 13 GDPR|Article 13 GDPR]]. According to the AEPD, saying 'we are recording the meeting so we can keep record of everything that will be said' at the beginning of the meeting does not amount to providing the mandatory information, and it cannot be considered to <del style="font-weight: bold; text-decoration: none;">provide </del>basic information about the legal basis and the purposes of the processing.</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>However, having a valid legal basis does not prevent the controller from properly informing the data subjects about all the mandatory points included in [[Article 13 GDPR|Article 13 GDPR]]. According to the AEPD, saying 'we are recording the meeting so we can keep record of everything that will be said' at the beginning of the meeting does not amount to providing the mandatory information, and it cannot be considered to <ins style="font-weight: bold; text-decoration: none;">be providing </ins>basic information about the legal basis and the purposes of the processing.</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><del style="font-weight: bold; text-decoration: none;">With regard to </del>the <del style="font-weight: bold; text-decoration: none;">second processing </del>of <del style="font-weight: bold; text-decoration: none;">data, in which the recording was shared </del>with the <del style="font-weight: bold; text-decoration: none;">radio broadcasters</del>, the AEPD <del style="font-weight: bold; text-decoration: none;">highlighted Recital 50 GDPR, </del>that <del style="font-weight: bold; text-decoration: none;">states that "</del>the <del style="font-weight: bold; text-decoration: none;">processing of personal data for purposes other than those for which </del>the <del style="font-weight: bold; text-decoration: none;">personal data were initially collected should be allowed only where </del>the <del style="font-weight: bold; text-decoration: none;">processing is compatible with the purposes for which the personal data were initially collected"</del>. <del style="font-weight: bold; text-decoration: none;">For </del>this <del style="font-weight: bold; text-decoration: none;">subsequent processing, </del>the <del style="font-weight: bold; text-decoration: none;">controller relied on the right of freedom of information </del>and <del style="font-weight: bold; text-decoration: none;">freedom of expression, since they considered that the had the legitimacy </del>to <del style="font-weight: bold; text-decoration: none;">refute the allegedly false press release by the AFE and </del>to <del style="font-weight: bold; text-decoration: none;">substantiate such refutation by providing a record of what was exactly said during </del>the <del style="font-weight: bold; text-decoration: none;">meeting. In this regard</del>, the <del style="font-weight: bold; text-decoration: none;">AEPD noted that the </del>recording of <del style="font-weight: bold; text-decoration: none;">the meeting also contained comments of a personal and private nature</del>.</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div><ins style="font-weight: bold; text-decoration: none;">Regarding </ins>the <ins style="font-weight: bold; text-decoration: none;">transparency obligations </ins>of <ins style="font-weight: bold; text-decoration: none;">public bodies </ins>with <ins style="font-weight: bold; text-decoration: none;">respect to </ins>the <ins style="font-weight: bold; text-decoration: none;">minutes of their meetings</ins>, the AEPD <ins style="font-weight: bold; text-decoration: none;">noted </ins>that the <ins style="font-weight: bold; text-decoration: none;">obligation to disclose </ins>the <ins style="font-weight: bold; text-decoration: none;">minutes does not include </ins>the <ins style="font-weight: bold; text-decoration: none;">recording itself but a written record of certain aspects</ins>. <ins style="font-weight: bold; text-decoration: none;">Therefore, while </ins>this <ins style="font-weight: bold; text-decoration: none;">allows to record </ins>the <ins style="font-weight: bold; text-decoration: none;">meeting </ins>and to <ins style="font-weight: bold; text-decoration: none;">provide access </ins>to the <ins style="font-weight: bold; text-decoration: none;">written minutes</ins>, <ins style="font-weight: bold; text-decoration: none;">it does not allow to share </ins>the <ins style="font-weight: bold; text-decoration: none;">actual </ins>recording of <ins style="font-weight: bold; text-decoration: none;">it</ins>.</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><del style="font-weight: bold; text-decoration: none;">Regarding </del>the <del style="font-weight: bold; text-decoration: none;">transparency obligations </del>of <del style="font-weight: bold; text-decoration: none;">public bodies </del>with <del style="font-weight: bold; text-decoration: none;">respect </del>to the <del style="font-weight: bold; text-decoration: none;">minutes </del>of <del style="font-weight: bold; text-decoration: none;">their meetings</del>, the AEPD <del style="font-weight: bold; text-decoration: none;">noted </del>that the <del style="font-weight: bold; text-decoration: none;">obligation </del>to <del style="font-weight: bold; text-decoration: none;">disclose </del>the <del style="font-weight: bold; text-decoration: none;">minutes does not include </del>the recording <del style="font-weight: bold; text-decoration: none;">itself but </del>a <del style="font-weight: bold; text-decoration: none;">written record of certain aspects</del>.</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div><ins style="font-weight: bold; text-decoration: none;">With regard to the second and subsequent processing of data, in which the recording was shared with the radio broadcasters, </ins>the <ins style="font-weight: bold; text-decoration: none;">AEPD highlighted Recital 50 GDPR, that states that "the processing </ins>of <ins style="font-weight: bold; text-decoration: none;">personal data for purposes other than those for which the personal data were initially collected should be allowed only where the processing is compatible </ins>with <ins style="font-weight: bold; text-decoration: none;">the purposes for which the personal data were initially collected". For this subsequent processing, the controller relied on the right to freedom of information and freedom of expression, since the controller considered that it had the legitimacy </ins>to <ins style="font-weight: bold; text-decoration: none;">refute </ins>the <ins style="font-weight: bold; text-decoration: none;">allegedly false press released by the AFE and to substantiate such refutation by providing a literal record and the recording </ins>of <ins style="font-weight: bold; text-decoration: none;">what was exactly said during the meeting. However, the authority reasoned that such right could have been vindicated just by sharing the written record of the meeting, and not the actual recording. In this regard</ins>, the AEPD <ins style="font-weight: bold; text-decoration: none;">remarked </ins>that the <ins style="font-weight: bold; text-decoration: none;">recording of the meeting also contained comments of a personal and private nature. Therefore, if needed, they should have shared the minimum data necessary to achieve that purpose, according </ins>to the <ins style="font-weight: bold; text-decoration: none;">minimization principle. Therefore, by sharing </ins>the recording <ins style="font-weight: bold; text-decoration: none;">of the meeting, the AEPD considered that the controller breached [[Article 6 GDPR|Article 6(1) GDPR]], for processing personal data without </ins>a <ins style="font-weight: bold; text-decoration: none;">valid legal basis</ins>.</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div> </div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div><ins style="font-weight: bold; text-decoration: none;">For the violation of [[Article 13 GDPR]], the AEPD fined the controller €100,000. For the violation of [[Article 6 GDPR|Article 6</ins>(<ins style="font-weight: bold; text-decoration: none;">1</ins>) <ins style="font-weight: bold; text-decoration: none;">GDPR]], the AEPD fined the controller another €100,000.</ins></div></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div> </div></td><td colspan="2" class="diff-side-added"></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>(<del style="font-weight: bold; text-decoration: none;">IN PROGRESS</del>)</div></td><td colspan="2" class="diff-side-added"></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Comment ==</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Comment ==</div></td></tr>
<!-- diff cache key gdprwiki:diff::1.12:old-23460:rev-23463 -->
</table>Carmen.villarroelhttps://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00368/2021&diff=23460&oldid=prevCarmen.villarroel: /* Holding */2022-02-18T14:06:52Z<p><span dir="auto"><span class="autocomment">Holding</span></span></p>
<table style="background-color: #fff; color: #202122;" data-mw="interface">
<col class="diff-marker" />
<col class="diff-content" />
<col class="diff-marker" />
<col class="diff-content" />
<tr class="diff-title" lang="en">
<td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">← Older revision</td>
<td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">Revision as of 14:06, 18 February 2022</td>
</tr><tr><td colspan="2" class="diff-lineno" id="mw-diff-left-l19">Line 19:</td>
<td colspan="2" class="diff-lineno">Line 19:</td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|Date_Started=</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|Date_Started=</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|Date_Decided=</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|Date_Decided=</div></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>|Date_Published=</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>|Date_Published=<ins style="font-weight: bold; text-decoration: none;">16/02/2022</ins></div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|Year=</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|Year=</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|Fine=200000</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|Fine=200000</div></td></tr>
<tr><td colspan="2" class="diff-lineno" id="mw-diff-left-l50">Line 50:</td>
<td colspan="2" class="diff-lineno">Line 50:</td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|Initial_Contributor=Carmen Villarroel</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>|Initial_Contributor=Carmen Villarroel</div></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>|</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>|}}</div></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>}}</div></td><td colspan="2" class="diff-side-added"></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>The Spanish DPA fined the Spanish Football Federation €200,000 for sharing the recording of a meeting between representatives of different bodies without their knowledge and consent and for not properly informing the participants of the processing of their personal data as required by [[Article 13 GDPR|Article 13 GDPR]].</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>The Spanish DPA fined the Spanish Football Federation €200,000 for sharing the recording of a meeting between representatives of different bodies without their knowledge and consent and for not properly informing the participants of the processing of their personal data as required by [[Article 13 GDPR|Article 13 GDPR]].</div></td></tr>
<tr><td colspan="2" class="diff-lineno" id="mw-diff-left-l73">Line 73:</td>
<td colspan="2" class="diff-lineno">Line 72:</td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Therefore, the controller did not and could not prove that the participants in the meeting had been informed about the processing of personal data as required by [[Article 13 GDPR|Article 13 GDPR]]. And, as highlighted by the DPA, the controller did not provide the information required by [[Article 13 GDPR#3|Article 13(3) GDPR]] about further processing of the data (in this case, sharing it with radio broadcasters).</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Therefore, the controller did not and could not prove that the participants in the meeting had been informed about the processing of personal data as required by [[Article 13 GDPR|Article 13 GDPR]]. And, as highlighted by the DPA, the controller did not provide the information required by [[Article 13 GDPR#3|Article 13(3) GDPR]] about further processing of the data (in this case, sharing it with radio broadcasters).</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker" data-marker="−"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>The AEPD concluded that the controller had a valid legal basis for the processing of personal data in the first place, since Article 18 of the <del style="font-weight: bold; text-decoration: none;">Spanish Act for the Regulation of the Public Sector (LRJSP) </del>https://www.boe.es/buscar/act.php?id=BOE-A-2015-10566 allows public bodies to record their meetings and to store them in order to keep a literal record of the minutes.</div></td><td class="diff-marker" data-marker="+"></td><td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>The AEPD concluded that the controller had a valid legal basis for the processing of personal data in the first place, since Article 18 of the <ins style="font-weight: bold; text-decoration: none;">[</ins>https://www.boe.es/buscar/act.php?id=BOE-A-2015-10566 <ins style="font-weight: bold; text-decoration: none;">Spanish Act for the Regulation of the Public Sector] (LRJSP) </ins>allows public bodies to record their meetings and to store them in order to keep a literal record of the minutes.</div></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br/></td></tr>
<tr><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>However, having a valid legal basis does not prevent the controller from properly informing the data subjects about all the mandatory points included in [[Article 13 GDPR|Article 13 GDPR]]. According to the AEPD, saying 'we are recording the meeting so we can keep record of everything that will be said' at the beginning of the meeting does not amount to providing the mandatory information, and it cannot be considered to provide basic information about the legal basis and the purposes of the processing.</div></td><td class="diff-marker"></td><td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>However, having a valid legal basis does not prevent the controller from properly informing the data subjects about all the mandatory points included in [[Article 13 GDPR|Article 13 GDPR]]. According to the AEPD, saying 'we are recording the meeting so we can keep record of everything that will be said' at the beginning of the meeting does not amount to providing the mandatory information, and it cannot be considered to provide basic information about the legal basis and the purposes of the processing.</div></td></tr>
</table>Carmen.villarroelhttps://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00368/2021&diff=23458&oldid=prevCarmen.villarroel: Created page with "{{DPAdecisionBOX |Jurisdiction=Spain |DPA-BG-Color=background-color:#ffffff; |DPAlogo=LogoES.jpg |DPA_Abbrevation=AEPD (Spain) |DPA_With_Country=AEPD (Spain) |Case_Number_Na..."2022-02-18T13:51:14Z<p>Created page with "{{DPAdecisionBOX |Jurisdiction=Spain |DPA-BG-Color=background-color:#ffffff; |DPAlogo=LogoES.jpg |DPA_Abbrevation=AEPD (Spain) |DPA_With_Country=AEPD (Spain) |Case_Number_Na..."</p>
<a href="https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00368/2021&diff=23458">Show changes</a>Carmen.villarroel