The Spanish authority issues a warning to the Huelva La Luz basketball club for unlawful processing of personal data via a WhatsApp group

A sports club was warned by the Spanish authority for adding a person to an instant messaging group without their consent, the authority having found that the use of the group for organizational purposes made the club responsible for the processing, despite its denials.

Facts and context

The Spanish Data Protection Authority (AEPD) today published a decision issuing a warning against CLUB DEPORTIVO BALONCESTO HUELVA LA LUZ for breaches related to the lack of a legal basis for data processing.

The case originated from a complaint by a person added without their consent, on 5 May 2024, to an instant messaging group managed by club members, where they were exposed to other members and subjected to insulting comments.

Grounds for the decision

  • Lack of legal basis for processing (Article 6(1) of the GDPR): The authority found that the complainant had been added to the messaging group without their consent, exposing their name, phone number, and profile to the other 28 members. The club argued that it was not an official communication channel and that it was not responsible, as the group had been created autonomously by the players. However, the authority rejected this argument based on several factual elements: the group administrators included key club staff members (coach, assistant coach), and the exchanged messages concerned the organization of club activities (training schedules, medical examinations, requests for copies of identity documents). The authority therefore concluded that, despite its informal nature, the group was used for professional purposes, making the club the controller. In the absence of any other applicable legal basis, the processing of the complainant's data was unlawful.

Decision of the authority

Consequently, the authority issued a warning to CLUB DEPORTIVO BALONCESTO HUELVA LA LUZ.

Lessons learned

This decision reminds that:

  • The qualification as controller does not depend on the official designation of a communication channel, but on its actual use for professional purposes.
  • The use of instant messaging tools, even as "auxiliary" means, for internal communications engages the responsibility of the entity as controller of the data shared therein.
  • Adding a person to a discussion group, exposing their phone number and profile to other members, constitutes processing of personal data requiring a valid legal basis, such as prior consent.
  • The nature of the exchanged messages and the status of the administrators (e.g., supervisory staff members) are determining factors to establish the real purpose of a discussion group and attribute processing responsibility to the organization.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire