The Spanish authority fines SOCIETAT MUNICIPAL D'APARCAMENTS I PROJECTES 40,000 euros for GDPR non-compliance related to the ZELLO application

The Spanish data protection authority sanctioned a municipal company for failing to meet its obligations of fairness and transparency by installing an application on its employees' devices capable of recording their conversations without clear and complete prior information about its features and associated risks.

Facts and context

The Spanish data protection authority (AEPD) issued a sanction decision against the Municipal Parking and Projects Company, S.A. (SMAP), including a fine of €40,000, for breaches of the principles of fairness and transparency in the use of an application installed on its employees' professional devices.

The case originated from a complaint filed by union sections, denouncing the recording of employees' conversations via an application installed on their work devices without their consent.

Grounds for the decision

  • Obligation of fairness and transparency (Article 5(1)(a) of the GDPR): The authority found that the company had installed an application named "ZELLO" on 92 professional devices of its agents, officially to test an emergency alert system. However, this application also allowed the recording of conversations, a feature that was activated at least once, capturing an exchange while an employee was on break. The authority judged that the company did not process the data fairly and transparently, as employees were not adequately and fully informed about the existence of this recording feature, the conditions of its activation, the persons having access to it, and the potential risks to their rights and freedoms, especially during a testing phase. According to recital 60 of the GDPR, the principles of fair and transparent processing require that the data subject be informed of the existence of the processing operation and its purposes. Merely informing orally about the installation of an application in a testing phase, without detailing all its features and inherent risks, was deemed insufficient to meet this obligation.

Authority's decision

Consequently, the authority imposed a fine of €40,000 on the Municipal Parking and Projects Company, S.A.

Lessons learned

This decision reminds that:

  • The transparency obligation is strengthened when deploying new technologies in a testing phase; employees must be informed not only of the main purpose but also of all features, even ancillary ones, and the specific risks related to an unfinished version.
  • The recording of personal data, even if not followed by listening and files are deleted, constitutes a processing operation subject to the GDPR principles.
  • The adoption of corrective measures after discovering an incident, such as uninstalling an application, constitutes a mitigating circumstance but does not exempt the data controller from responsibility for the initial violation of data protection principles.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire