The Spanish authority fines an individual 200 euros for unauthorized disclosure of personal data

The Spanish authority sanctions an individual for disclosing personal data of their tenant, related to an alleged debt, to unauthorized third parties by sending it via email to their workplace, violating the confidentiality principle.

Facts and context

The Spanish Data Protection Authority (AEPD) has today published a sanction decision against an individual (including the imposition of a 200 € fine) for breaches related to the unauthorized disclosure of personal data.

The case originated from a complaint filed by a person whose personal data, related to an alleged rental debt, was communicated by their landlord to their employer and colleagues.

Reasons for the decision

  • Obligation to ensure data confidentiality (Article 5(1)(f) of the GDPR): The authority found that the data controller, in the context of a rental dispute, sent an email to the complainant's workplace. This message contained personal data, details about an alleged debt, and accusations of delinquent behavior. By disclosing this information to unauthorized third parties (the complainant's employer and colleagues), the data controller failed to ensure data confidentiality, violating the principle that requires protecting data against any unauthorized or unlawful processing.

Authority's decision

Consequently, the authority imposed a fine of 200 € on A.A.A. The data controller benefited from a 20% reduction by making a voluntary payment, reducing the final amount to 160 €.

Lessons learned

This decision confirms / specifies / recalls that:

  • The disclosure of personal data related to a civil dispute, such as unpaid rent, to unrelated third parties like the person's employer constitutes a violation of the confidentiality principle.
  • The processing of personal data within the framework of a contract (for example, a lease) does not authorize their communication to third parties to exert pressure or harm the reputation of the data subject.
  • The obligations of the GDPR, notably respecting confidentiality, also apply to natural persons acting as data controllers, including within private contractual relationships such as rental agreements.
  • The communication of information accusing a person of delinquent behavior, even to a limited circle of recipients, is considered a serious breach of data confidentiality.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire