A €15,000 Fine Imposed on DIMAGAZA, S.L. by the Spanish Authority for Personal Data Published on a Notice Board

The Spanish data protection authority sanctioned a company for failing to physically secure a notice board on which sensitive personal data of employees had been published, considering this omission a violation of the obligation to implement appropriate technical and organizational measures.

Facts and Context

The Spanish data protection authority (AEPD) today published a sanction decision against DIMAGAZA, S.L. including the imposition of a €15,000 fine for breaches related to the security of a physical notice board.

The case originated from a complaint filed by an individual on May 13, 2023, concerning the publication, on the company’s notice board, of the nominative list of employees affected by a collective dismissal, including data such as name, identity document number, social security number, and date of birth.

Grounds for the Decision

  • Obligation to secure processing (Article 32 of the GDPR): The authority found that the minutes of the collective dismissal agreement and its annex, containing personal data of numerous employees, had been posted on a simple cork board without any physical protection such as a glass case or locking system. The company, as the controller for making this notice board available in accordance with the Spanish Workers’ Statute, was required to ensure a level of security appropriate to the risk. The AEPD considered that the absence of technical and organizational measures to prevent unauthorized access, alteration, or removal of the documents by anyone with access to the premises constituted serious negligence. Although the company argued that the board was located in a restricted access area (port premises, second floor), it failed to prove that access was exclusively reserved for employees or that the board itself was secured, thus failing its protection obligation.

Authority’s Decision

Consequently, the authority imposed a €15,000 fine on DIMAGAZA, S.L.

Lessons Learned

This decision reminds that:

  • Data processing security also applies to physical media, and a simple cork notice board is not considered an appropriate technical measure for displaying personal data, especially if sensitive.
  • The company providing a notice board to employee representatives is considered the controller for the means provided and must ensure its security, regardless of the responsibility of those who publish content on it.
  • The location of a processing medium in a generally restricted access area is a relevant but insufficient measure if the medium itself is not protected against unauthorized access by persons authorized to enter that area.
  • Human error by an employee or staff representative publishing data does not exempt the controller from its own obligation to implement preventive measures to secure processing media.
  • It is incumbent on the controller to document and be able to demonstrate the implementation of security measures; the inability to provide evidence, even due to premises closure, can weaken its defense.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire