The Spanish authority fines the Mancomunidad 1,000 euros for unauthorized disclosure of health data on WhatsApp
The unauthorized disclosure of a resident's health data in a condominium instant messaging group led the Spanish authority to sanction the homeowners' association, despite the perceived low severity of the incident and the corrective measures taken.
Facts and context
The Spanish Data Protection Agency (AEPD) today published a sanction decision against the homeowners' association MANCOMUNIDAD RESIDENCIAL A.A.A. (including the imposition of a 1,000 € fine) for breaches related to the unauthorized disclosure of health data on an instant messaging platform.
The case originated from a complaint by a resident following the disclosure, in a WhatsApp group of co-owners, of a document revealing her chemical sensitivity to justify the cessation of a phytosanitary treatment.
Grounds for the decision
Obligation of integrity and confidentiality (Article 5(1)(f) of the GDPR): The authority considered that the disclosure by the president of the association of a document containing health data to a group of co-owners on WhatsApp, without the consent of the data subject, constituted unauthorized access and disclosure. By failing to ensure the protection of this information against such disclosure, the association breached its obligation to ensure the confidentiality of personal data, thereby incurring its liability.
Prohibition of processing special categories of data (Article 9 of the GDPR): The information relating to the complainant's "chemical sensitivity" was classified as health data, the processing of which is generally prohibited. The authority noted that the consent given by the resident to inform only the president and the gardener could in no way be interpreted as explicit consent for disclosure to all co-owners. As no other derogatory condition of Article 9 was met, the disclosure constituted unlawful processing of sensitive data.
Authority's decision
Consequently, the authority imposed a fine of 1,000 € on the homeowners' association MANCOMUNIDAD RESIDENCIAL A.A.A., divided into 500 € for each breach. The authority took into account, as mitigating factors, the measures taken by the association to delete the messages and strengthen its internal protocols following the complaint.
Lessons learned
This decision confirms / specifies / recalls that:
Consent given to inform a limited number of people for a specific purpose does not constitute a valid legal basis for wider disclosure of the same data.
The use of informal communication tools, such as instant messaging groups, for communications related to condominium management engages the responsibility of the association as data controller, even if the group has no "official" status.
The communication of health data, even for a purportedly informative purpose for other residents, constitutes processing of special categories of data subject to the strict conditions of Article 9 of the GDPR.
The prompt implementation of corrective measures after discovering a breach, such as deleting the disclosed data and strengthening internal protocols, is a mitigating factor taken into account when determining the amount of the sanction.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire