[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fXVZmkt5UXi8SM-tfRgT26pfA3IfzXvVsNcxTvb385_M":3},{"article":4,"iocs":45},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"52978aa4-06df-4dd2-b359-7353e35f3c25","AEPD (Spain) - PS-00637-2025","aepd-spain-ps-00637-2025-d3c9bc","Created page with \"{{DPAdecisionBOX |Jurisdiction=Spain |DPA-BG-Color= |DPAlogo=LogoES.jpg |DPA_Abbrevation=AEPD |DPA_With_Country=AEPD (Spain) |Case_Number_Name=PS-00637-2025 |ECLI= |Original_Source_Name_1=AEPD |Original_Source_Link_1=https:\u002F\u002Fwww.aepd.es\u002Fdocumento\u002Fps-00637-2025.pdf |Original_Source_Language_1=Spanish |Original_Source_Language__Code_1=ES |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Language_2= |Original_Source_Language__Code_2= |Type=Complaint...\" New page {{DPAdecisionBOX |Jurisdiction=Spain |DPA-BG-Color= |DPAlogo=LogoES.jpg |DPA_Abbrevation=AEPD |DPA_With_Country=AEPD (Spain) |Case_Number_Name=PS-00637-2025 |ECLI= |Original_Source_Name_1=AEPD |Original_Source_Link_1=https:\u002F\u002Fwww.aepd.es\u002Fdocumento\u002Fps-00637-2025.pdf |Original_Source_Language_1=Spanish |Original_Source_Language__Code_1=ES |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Language_2= |Original_Source_Language__Code_2= |Type=Complaint |Outcome=Upheld |Date_Started= |Date_Decided=22.04.2025 |Date_Published=20.08.2026 |Year=2025 |Fine=4000.0 |Currency=EUR |GDPR_Article_1=Article 5(1)(c) GDPR |GDPR_Article_Link_1=Article 5 GDPR#1c |GDPR_Article_2= |GDPR_Article_Link_2= |GDPR_Article_3= |GDPR_Article_Link_3= |EU_Law_Name_1= |EU_Law_Link_1= |EU_Law_Name_2= |EU_Law_Link_2= |National_Law_Name_1= |National_Law_Link_1= |National_Law_Name_2= |National_Law_Link_2= |Party_Name_1=BODENSE ESTRUCTURAS Y CALDELERÍA, S.L. |Party_Link_1=https:\u002F\u002Fwww.bodense.es |Party_Name_2= |Party_Link_2= |Party_Name_3= |Party_Link_3= |Appeal_To_Body= |Appeal_To_Case_Number_Name= |Appeal_To_Status=Unknown |Appeal_To_Link= |Initial_Contributor=bms | }} The AEPD fined an employer €4,000 for continuously recording workplace audio through CCTV. The measure was disproportionate and violated the data minimisation principle under [[Article 5 GDPR|Article 5(1)(c) GDPR]]. == English Summary == === Facts === On 22 April 2025, a data subject lodged a complaint with the Spanish Data Protection Authority (AEPD) against BODENSE ESTRUCTURAS Y CALDELERÍA, S.L., the controller. The data subject claimed that the controller had installed cameras recording both images and audio in workplace areas and had relied on the recordings in disciplinary proceedings against them. The controller confirmed that its video surveillance system, installed in 2019, consisted of seven cameras and was capable of recording both images and sound. Recordings were stored for seven days and could be accessed by the controller's security manager. The controller stated that the system pursued both security and employee-monitoring purposes. The controller argued that audio recording was necessary because of a previous burglary and because of the data subject's alleged inappropriate behaviour towards colleagues and management. According to the controller, the audio recordings had been used to substantiate the disciplinary proceedings. === Holding === The DPA found that the continuous recording of workplace audio violated the data minimisation principle under [[Article 5 GDPR|Article 5(1)(c) GDPR]]. It considered audio recording particularly intrusive because it could capture private conversations and interfere with the workers' private sphere. The existence of information signs did not make such processing proportionate. The DPA rejected the controller's justification that audio recording was necessary for security and disciplinary purposes. In relation to the employee's conduct, the DPA considered that less intrusive evidence, such as statements from colleagues or supervisors, could have been used. Similarly, the previous burglary did not justify permanent audio recording, since video images alone could have been sufficient to establish the relevant facts. Therefore, the measure was neither necessary nor proportionate to the purposes pursued. The DPA also referred to Article 89(3) LOPDGDD, under which workplace audio recording is permitted only where risks to the security of installations, assets or persons arising from the activity carried out at the workplace make it necessary, and subject to proportionality and minimum-intervention requirements. The DPA considered that audio recording should be limited to exceptional situations rather than operate permanently. Consequently, the DPA imposed a €4,000 fine for infringement of [[Article 5 GDPR|Article 5(1)(c) GDPR]]. In addition, it ordered the controller, within one month after the decision became final and enforceable, to disable the audio functionality of the video-surveillance system, where applicable, and adapt its data protection policy accordingly. == Comment == ''Share your comments here!'' == Further Resources == ''Share blogs or news articles here!'' == English Machine Translation of the Decision == The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details. Case No.: EXP202506417 DECISION ON DISCIPLINARY PROCEEDINGS Regarding the proceedings conducted by the Spanish Data Protection Agency and based on the following BACKGROUND FIRST: On April 22, 2025, a complaint was filed with the Spanish Data Protection Agency regarding a possible violation attributable to the entity BODENSE ESTRUCTURAS Y CALDELERÍA, S.L., with Tax ID No. B91843060 (*hereinafter, BCE). The facts brought to the attention of this authority are as follows: The complainant alleges that the respondent company has installed cameras that record audio and movement in work areas without the consent of the employees, and that the footage has been used to justify the initiation of a disciplinary proceeding. Along with the complaint, the claimant submits a statement of defense in response to a CFR, which was served on him on ***DATE.1, notifying him of the initiation of a disciplinary proceeding leading to dismissal. In the SECOND complaint, the claimant points out that the disciplinary proceedings are based on a single piece of evidence: the installation of video surveillance cameras without having provided information or obtained his consent, thereby violating Article 89.1 of the LOPDGDD. SECOND: In accordance with Article 65.4 of Organic Law 3\u002F2018, dated December 5, on data protection and the Guarantee of Digital Rights (hereinafter hereinafter “LOPDGDD”), said complaint was forwarded to BCE so that it could analyze it and inform this Agency, within one month, of the actions taken to comply with the requirements set forth in the data protection regulations. The notification of the referral of the complaint, which was carried out in accordance with the rules established in Law 39\u002F2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), was issued on April 24, 2025, as evidenced by the acknowledgment of receipt on file. On May 23, 2025, this Agency received a written response indicating that the party against whom the complaint was filed states that it has a video surveillance system installed contracted through the enterprise ***ENTERPRISE.1 (a copy of the contract is provided). It was installed on March 4, 2019, in common areas (hallways, entrance, and management office). It records both video and audio. C\u002F Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 2\u002F10 The system consists of seven cameras; five of them are fixed and located in areas at risk of intrusion, and the other two cameras—one in the warehouse and the other in an office facing the street—both record 24 hours a day. There is no monitor; the images are viewed on the mobile phone of the security manager via a User name and password. The recordings are stored for 7 days in encrypted form on a server belonging to the security enterprise, and only the security manager of the defendant has access to them. The system’s operating manual, according to the defendant’s complaint, was communicated to all staff, as it was part of the office’s internal security procedures. The respondent states that there are informational signs regarding both video and audio recording next to the devices, which are accessible to all affected individuals. It provides photographs of the signs, but due to their size, it cannot be verified whether they actually also inform of the existence of audio recording and whether they comply with the requirements of Article 22.4 of the LOPDGDD. It provides photographs of the devices but does not provide images of the field of view of the cameras to verify whether, as the respondent claims, there are no cameras in restrooms, service areas, cafeterias, or employee break rooms. Regarding audio recording, the respondent asserts that it is necessary for two reasons: first, due to external risk, as they suffered a burglary in the year 2023 (they provide a copy of part of the police report); and second, because they had experienced problems with the complainant—now a former employee of the enterprise—who, for a time, engaged in abusive behavior, including insults, provocations, and humiliations in front of his coworkers and enterprise management; the audio was essential to prove these facts and serve as the basis for the disciplinary proceedings. The respondent states that the audio recordings have been used solely for the disciplinary proceedings and have not been disclosed to third parties. Finally, the respondent indicates that the purpose of processing the images captured by the cameras is twofold: to ensure safety and to monitor the employees’ work performance. The respondent has not provided images of the cameras’ field of view and has not demonstrated that it informed its employees of the purpose of the processing for workplace monitoring (as required by Article 89.1 of the LOPDGDD). THIRD: On July 22, 2025, in accordance with Article 65 of the LOPDGDD, the complaint was accepted for processing. FOURTH: On March 21, 2026, the Presidency of the Spanish Data Protection Data Protection agreed to initiate sanctioning proceedings against the respondent, for the alleged violation of Article 5.1.c) of the GDPR, as defined in Article 83.5.a) of the GDPR. C\u002F Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 3\u002F10 FIFTH: Following notification of the aforementioned decision to initiate proceedings in accordance with the rules established in Law 39\u002F2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), and following the expiration of the period granted for the submission of arguments, it has been confirmed that no arguments have been received from the respondent. Article 64.2.f) of the LPACAP—a provision of which the respondent was informed in the decision to initiate the proceedings—establishes that if no statements are submitted within the prescribed period regarding the content of the decision to initiate proceedings, and provided that the notice contains a specific determination regarding the liability attributed, it may be considered a proposed resolution. In the present case, the decision to initiate disciplinary proceedings set forth the facts on which the charge was based, the GDPR violation attributed to the respondent, and the penalty that could be imposed. Therefore, taking into account that the respondent has not submitted any arguments regarding the decision to initiate proceedings and in accordance with the provisions of Article 64.2.f) of the LPACAP, the aforementioned decision to initiate proceedings is considered, in this case, a proposed resolution. In light of all the proceedings, the Spanish Data Protection Agency in this proceeding considers the following to be established facts: ESTABLISHED FACTS First. The facts stem from the complaint dated 04\u002F22\u002F25, which alleges the “installation of cameras that record audio and movement” in the work areas without the consent of the employees. Second. BODENSE ESTRUCTURAS Y CALDELERÍA, S.L., with Tax ID No. B91843060, has been identified as the primary responsible party. Third. It has been established that devices are present in the workplace that affect common areas, without a justified cause explained or legally substantiated. Fourth. The system allows for the recording of , a fact confirmed by the defendant itself in a letter dated May 23, 25. The signs clearly indicate the recording of video and audio, the identity of the person responsible, and how to exercise the rights set forth in Article 15 and subsequent articles of the GDPR. Fifth. The system’s operational status and the processing of data for purposes beyond mere workplace monitoring have been substantiated, affecting conversations that may take place on the premises. C\u002F Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 4\u002F10 LEGAL GROUNDS I Jurisdiction In accordance with the powers granted by Article 58(2) of Regulation (EU) 2016\u002F679 (General Data Protection Regulation, hereinafter GDPR) grants to each supervisory authority, and in accordance with Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3\u002F2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter, LOPDGDD), the Presidency of the Spanish Data Protection Agency has jurisdiction to initiate and resolve this proceeding. II Procedure Likewise, Article 63.2 of the LOPDGDD provides that: “Proceedings handled by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016\u002F679, this Organic Law, the adopted to implement it, and, to the extent they do not contradict them, on a subsidiary basis, by the general rules on administrative proceedings.” In accordance with Article 64 of the LOPDGDD, and taking into account the nature of the alleged violation(s) committed, a penalty proceeding is initiated. The proceedings shall last for a maximum of twelve months from the date of the decision to initiate proceedings. Upon the expiration of that period, the proceedings shall lapse and, consequently, the case shall be closed, in accordance with the provisions of article 64 of the LOPDGDD. If you do not file any objections to this notice of initiation within the stipulated period, it may be considered a proposed resolution, as provided for in Article 64.2.f) of Law 39\u002F2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP). III Preliminary Issues Article 4.1) of the GDPR defines “personal data” as: “any information relating to an identified or identifiable natural person (‘the data subject’); an identifiable natural person shall be any person whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or several factors specific to that person’s physical, physiological, genetic, mental, economic, cultural, or social identity.” C\u002F Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 5\u002F10 Article 4(2) of the GDPR defines “processing” as: “any operation or set of operations performed on personal data or sets of personal data, whether by automated means or not, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.” Article 4(7) of the GDPR defines the “controller” or “data controller” as: “the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing; if Union law Union or of the Member States determines the purposes and means of the processing, the controller or the specific criteria for its designation may be established by Union or Member State law.” In turn, Article 4(8) of the GDPR defines the “processor” as the natural or legal person, public authority, agency, or other body that performs personal data processing on behalf of the controller. In the present case, in accordance with the provisions of Articles 4(1) and 4(2) of the GDPR, the processing of personal data has taken place, since the BCE carries out, among other processing activities, the collection of through the video surveillance system. BCE carries out this activity in its capacity as the controller, given that it is the entity that determines the purposes and means of such activity, pursuant to Article [4.7 \u002F 4.8] of the GDPR. IV In the present case, we will examine the complaint filed with this agency—which will be limited to its jurisdiction—regarding the collection of from the installed video surveillance system. Audio recording in a workplace context constitutes a clear intrusion on the right to privacy of all affected employees in a private and confidential sphere (e.g., the recording of conversations). The enterprise against which the complaint was filed does not deny the installation of the system, acknowledging in its initial statements the possibility of audio recording through the system installed by a specialized security company. This is set forth on page 3 of the Response Brief, where the information is presented as follows: The signs clearly indicate the recording of video and audio, the identity of the data controller, and how to exercise the rights under Article 15 and following of the GDPR. The presence of informational signs is considered insufficient for the measure adopted, which was initially disproportionate to the intended purpose: the protection of the enterprise and its facilities. C\u002F Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 6\u002F10 It justifies the collection of to preserve a “dignified, safe, and violence-free” work environment; however, this would only be justified in an case, which does not correspond to the attitude of the employee subject to disciplinary proceedings, nor does it justify a measure that is permanent in nature. The Constitutional Court (TC) defines a “disproportionate measure” as any restriction on fundamental rights that fails to strike a balance between the purposes pursued and the impact caused, thereby rendering it excessive. The (witness) statements of other coworkers or competent supervisors, which corroborate the described conduct, would suffice to justify a disciplinary dismissal, without the need for further documentation. Nor is the collection of justified in the case of a single incident of theft on the premises, since the mere viewing of the footage is considered valid admissible evidence to substantiate the facts and the alleged perpetrator thereof. The foregoing, which is fully substantiated, justifies, in the opinion of this Agency, that the measure is not proportionate to the intended purpose, as it would have been possible to establish the conduct of the dismissed employee through a means less harmful to the rights not not only the employee’s rights but also those of third parties who are affected by the measure imposed without the minimum legally established safeguards. The National Court (AN), in SAN 4102\u002F2025 of September 29, has made the following recital that a voice recording system is intrusive in nature and requires greater justification regarding its necessity, appropriateness, and proportionality, since the system may affect private conversations. The aforementioned court relies on the extensive case law of the Constitutional Court (Constitutional Court), which holds that an employer’s rights to surveillance and control cannot simply override fundamental rights, much less because of the existence of an employment contract that purports to include clauses—allegedly lawful—that legitimize the recording of conversations reserved for privacy; the principle of minimal intervention must prevail, with certain very strictly defined guarantees and requirements. The facts described above constitute a violation of Article 5.1(c) of the GDPR, without prejudice to the repercussions of this type of conduct in other areas of law (e.g., infringement of the right to personal privacy). Article 5.1(c) of the GDPR provides: Personal data shall be: (c) adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed (“data minimisation”); Article 89(2) of the LOPDGDD provides: “Under no circumstances shall the installation of audio recording or video surveillance systems in places intended for the rest or recreation of workers or public employees, such as locker rooms, restrooms, dining rooms, and similar areas.” (*boldface added by the AEPD). C\u002F Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 7\u002F10 The possibility of obtaining is limited to exceptional cases and on a temporary basis (e.g., a flagrant case of harassment, by way of example), and the collection and storage of private conversations, as these are reserved for the personal and intimate sphere, separate from work activities. This is set forth in Section 3 of Article 89 of the LOPDGDD. The use of systems similar to those referred to in the preceding sections for sound recording in the workplace shall be permitted only when there are significant risks to the safety of facilities, property, and persons arising from the activity carried out at the workplace, and provided that the principles of proportionality and minimal intervention are respected, as well as the safeguards provided for in the preceding paragraphs. The deletion of audio recordings stored by these recording systems shall be carried out in accordance with the provisions of Article 22, paragraph 3, of this law. Article 72(1) of the LOPDGDD (Organic Law 3\u002F2018, December 5), regarding the statute of limitations for very serious violations, states that “they shall be subject to a three-year statute of limitations,” and in particular the following: a) The processing of personal data in violation of the principles and safeguards established in Article 5 of Regulation (EU) 2016\u002F679 V Article 83(1) of the GDPR provides: “Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this article for infringements of this Regulation referred to in paragraphs 4, 5, and 6 is, in each individual case, effective, proportionate, and dissuasive.” Article 83(5) of the GDPR provides as follows: “Infringements of the following provisions shall be subject, in accordance with paragraph 2, to administrative fines not exceeding EUR 20,000,000 or, in the case of an enterprise, an amount not exceeding 4% of the total worldwide annual turnover in the preceding financial year, whichever is higher: a) The basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9 (…)”. When determining the penalty, the following factors are taken into account: - the nature, severity, and duration of the violation, taking into account the nature, scope, or purpose of the data processing operation in question, as well as as the number of data subjects affected and the extent of the damages that C\u002F Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 8\u002F10 they have suffered (Art. 83.5(a) GDPR); the impact of the measure is taken into account, although it is not possible to specify the number of individuals affected. - whether the infringement was intentional or due to negligence (Article 83.5(b) GDPR), as it involves a system lacking the necessary safeguards that affects an area reserved for the privacy of employees, given that it allows for the collection of (voice, which constitutes personal data). - the categories of data affected by the violation (Article 83(2)(g)), as the system is equipped with the capability to capture voice (personal data). Based on the foregoing, it is deemed appropriate to impose a fine of €4,000, (four thousand euros) for the violation of Art 5.1(c), for operating a video- Surveillance system that does not comply with current regulations and encroaches upon an area reserved for the privacy of employees, which falls within the lowest range for this type of violation and is commensurate with the severity of the facts presented. VI Corrective Measures The text of the decision sets forth the violations committed and the facts that gave rise to the breach of data protection regulations, from which it is clear what measures must be adopted, without prejudice to the fact that the specific procedures, mechanisms, or tools for implement them is up to the sanctioned party, since it is the controller who fully understands its organization and must decide, based on accountability and a risk-based approach, how to comply with the GDPR and the LOPDGDD. This decision sets forth the alleged violation committed and the facts that could give rise to this possible breach of data protection regulations, from which it is clear what measures must be taken, without prejudice that the specific types of procedures, mechanisms, or tools for implementing them are the responsibility of the party subject to the sanction, since it is the controller who fully understands their organization and must decide, based on accountability and a risk-based approach, how to comply with the GDPR and the LOPDGDD. However, in this case, notwithstanding the foregoing, in accordance with the evidence currently available at the time of the agreement to initiate sanctioning proceedings, the resolution to be adopted may require BCE to adopt the following measures within a maximum period of 1 MONTH from the date on which the final decision concluding this proceeding becomes enforceable: Uninstall, where applicable, the mode from the video surveillance system, notify this agency, and, at the same time, adapt the data protection policy to the required standard. C\u002F Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 9\u002F10 The imposition of this measure or these measures is compatible with the sanction consisting of an administrative fine, pursuant to the provisions of Art. 83(2) of the GDPR. Please be advised that failure to comply with any order to adopt measures imposed by this agency in the decision concluding this enforcement proceeding may be considered an administrative violation in accordance with the provisions of the GDPR, classified as a violation under Articles 83.5 and 83.6, and such conduct may lead to the initiation of further administrative sanction proceedings. Therefore, in accordance with applicable law and after evaluating the criteria for determining the severity of the sanctions, the existence of which has been established, the Presidency of the Spanish Data Protection Agency RESOLVES: FIRST: TO IMPOSE on BODENSE ESTRUCTURAS Y CALDELERÍA, S.L., with Tax ID No. B91843060, for a violation of Article 5.1.c) of the GDPR, classified as an infraction in Article 83.5.a) of the GDPR, a fine of €4,000 (four thousand euros). SECOND: TO ORDER BODENSE ESTRUCTURAS Y CALDELERÍA, S.L., with Tax ID No. B91843060, to provide proof, pursuant to Article 58.2.d) of the GDPR, within a maximum period of 1 MONTH from the date this decision becomes final and enforceable, that it has complied with the following measure: -Uninstall, if applicable, the mode from the video surveillance system, notify this agency, and simultaneously adapt the data protection policy to the required measure. THIRD PARTY: NOTIFY the entity BODENSE ESTRUCTURAS Y CALDERERÍA, S.L., of this decision. FOURTH: This decision shall become enforceable once the deadline for filing the optional appeal for reconsideration has expired (one month from the day following the notification of this decision) without the data subject having exercised this right. The party subject to the penalty is hereby notified that they must pay the imposed penalty once this decision becomes enforceable, in accordance with the provisions of Art. 98.1.b) of Law 39\u002F2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), within the voluntary payment period established in Art. 68 of the General Collection Regulation, approved by Royal Decree 939\u002F2005, dated July 29, in conjunction with Art. 62 of Law 58\u002F2003, dated December 17, by making a payment and indicating the taxpayer identification number (NIF) of the party subject to the penalty and the procedure number appearing at the top of this document, into the restricted account No. IBAN: ES00-0000-0000-0000-0000-0000 (BIC\u002FSWIFT Code: CAIXESBBXXX), opened in the name of the Spanish Data Protection Agency at the bank CAIXABANK, S.A. Otherwise, the amount will be collected through enforcement proceedings. Upon receipt of the notice and once it becomes enforceable, if the enforceability date falls between the 1st and 15th of each month, inclusive, the deadline for making the will be until the 20th of the following month or the next business day thereafter; and if it falls between the 16th and the last day of each month, inclusive, the payment deadline will be until the 5th of the second following month or the next business day thereafter. C\u002F Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 10\u002F10 In accordance with the provisions of Article 50 of the LOPDGDD, this Decision shall be made public. Publication shall take place once it has been notified to the data subjects. Against this resolution, which concludes the administrative proceedings pursuant to Article 48.6 of the LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, the data subjects may, at their discretion, file an appeal for reconsideration with the Presidency of the Spanish Data Protection Agency within one month counting from the day following notification of this resolution, or directly file a contentious-administrative appeal before the Contentious-Administrative Chamber of the National Court, in accordance with the provisions of Article 25 and paragraph 5 of the fourth additional provision of Law 29\u002F1998, of July 13, regulating the Contentious-Administrative Jurisdiction, within two months from the day following notification of this decision, as provided for in Article 46.1 of the aforementioned Law. Finally, it is noted that, in accordance with the provisions of Article 90.3(a) of the LPACAP, a final administrative decision may be provisionally suspended if the data subject expresses their intention to file a contentious-administrative appeal. If this is the case, the data subject must formally notify the Spanish Data Protection Agency of this fact by submitting a written notice to the Spanish Data Protection Agency through the Agency’s Electronic Registry [https:\u002F\u002Fsedeaepd.gob.es\u002Fsede-electronica- web\u002F], or through any of the other registries provided for in Art. 16.4 of the aforementioned Law 39\u002F2015, of October 1. The interested party must also provide the Agency with the documentation proving that the contentious-administrative appeal has been effectively filed. If the Agency is not notified of the filing of the contentious-administrative appeal within two months from the day following notification of this resolution, it will consider the provisional suspension to have ended. 938-090326 Lorenzo Cotino Hueso President of the Spanish Data Protection Agency C\u002F Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es","The Spanish Data Protection Authority (AEPD) has fined BODENSE ESTRUCTURAS Y CALDELERÍA, S.L. €4,000 for continuously recording workplace audio through CCTV. The AEPD ruled that this practice violated the data minimisation principle under Article 5(1)(c) of the GDPR, deeming it disproportionate and overly intrusive. The company was ordered to disable the audio recording functionality and update its data protection policies.","Spain's AEPD fines employer €4,000 for continuous workplace audio recording via CCTV.","Help AEPD (Spain) - PS-00637-2025: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 13:40, 26 August 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators281 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 13:40, 26 August 2026 AEPD - PS-00637-2025 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 5(1)(c) GDPR Type: Complaint Outcome: Upheld Started: Decided: 22.04.2025 Published: 20.08.2026 Fine: 4000.0 EUR Parties: BODENSE ESTRUCTURAS Y CALDELERÍA, S.L. National Case Number\u002FName: PS-00637-2025 European Case Law Identifier: n\u002Fa Appeal: Unknown Original Language(s): Spanish Original Source: AEPD (in ES) Initial Contributor: bms The AEPD fined an employer €4,000 for continuously recording workplace audio through CCTV. The measure was disproportionate and violated the data minimisation principle under Article 5(1)(c) GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts On 22 April 2025, a data subject lodged a complaint with the Spanish Data Protection Authority (AEPD) against BODENSE ESTRUCTURAS Y CALDELERÍA, S.L., the controller. The data subject claimed that the controller had installed cameras recording both images and audio in workplace areas and had relied on the recordings in disciplinary proceedings against them. The controller confirmed that its video surveillance system, installed in 2019, consisted of seven cameras and was capable of recording both images and sound. Recordings were stored for seven days and could be accessed by the controller's security manager. The controller stated that the system pursued both security and employee-monitoring purposes. The controller argued that audio recording was necessary because of a previous burglary and because of the data subject's alleged inappropriate behaviour towards colleagues and management. According to the controller, the audio recordings had been used to substantiate the disciplinary proceedings. Holding The DPA found that the continuous recording of workplace audio violated the data minimisation principle under Article 5(1)(c) GDPR. It considered audio recording particularly intrusive because it could capture private conversations and interfere with the workers' private sphere. The existence of information signs did not make such processing proportionate. The DPA rejected the controller's justification that audio recording was necessary for security and disciplinary purposes. In relation to the employee's conduct, the DPA considered that less intrusive evidence, such as statements from colleagues or supervisors, could have been used. Similarly, the previous burglary did not justify permanent audio recording, since video images alone could have been sufficient to establish the relevant facts. Therefore, the measure was neither necessary nor proportionate to the purposes pursued. The DPA also referred to Article 89(3) LOPDGDD, under which workplace audio recording is permitted only where risks to the security of installations, assets or persons arising from the activity carried out at the workplace make it necessary, and subject to proportionality and minimum-intervention requirements. The DPA considered that audio recording should be limited to exceptional situations rather than operate permanently. Consequently, the DPA imposed a €4,000 fine for infringement of Article 5(1)(c) GDPR. In addition, it ordered the controller, within one month after the decision became final and enforceable, to disable the audio functionality of the video-surveillance system, where applicable, and adapt its data protection policy accordingly. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details. Case No.: EXP202506417 DECISION ON DISCIPLINARY PROCEEDINGS Regarding the proceedings conducted by the Spanish Data Protection Agency and based on the following BACKGROUND FIRST: On April 22, 2025, a complaint was filed with the Spanish Data Protection Agency regarding a possible violation attributable to the entity BODENSE ESTRUCTURAS Y CALDELERÍA, S.L., with Tax ID No. B91843060 (*hereinafter, BCE). The facts brought to the attention of this authority are as follows: The complainant alleges that the respondent company has installed cameras that record audio and movement in work areas without the consent of the employees, and that the footage has been used to justify the initiation of a disciplinary proceeding. Along with the complaint, the claimant submits a statement of defense in response to a CFR, which was served on him on ***DATE.1, notifying him of the initiation of a disciplinary proceeding leading to dismissal. In the SECOND complaint, the claimant points out that the disciplinary proceedings are based on a single piece of evidence: the installation of video surveillance cameras without having provided information or obtained his consent, thereby violating Article 89.1 of the LOPDGDD. SECOND: In accordance with Article 65.4 of Organic Law 3\u002F2018, dated December 5, on data protection and the Guarantee of Digital Rights (hereinafter hereinafter “LOPDGDD”), said complaint was forwarded to BCE so that it could analyze it and inform this Agency, within one month, of the actions taken to comply with the requirements set forth in the data protection regulations. The notification of the referral of the complaint, which was carried out in accordance with the rules established in Law 39\u002F2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), was issued on April 24, 2025, as evidenced by the acknowledgment of receipt on file. On May 23, 2025, this Agency received a written response indicating that the party against whom the complaint was filed states that it has a video surveillance system installed contracted through the enterprise ***ENTERPRISE.1 (a copy of the contract is provided). It was installed on March 4, 2019, in common areas (hallways, entrance, and management office). It records both video and audio. C\u002F Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 2\u002F10 The system consists of seven cameras; five of them are fixed and located in areas at risk of intrusion, and the other two cameras—one in the warehouse and the other in an office facing the street—both record 24 hours a day. There is no monitor; the images are viewed on the mobile phone of the security manager via a User name and password. The recordings are stored for 7 days in encrypted form on a server belonging to the security enterprise, and only the security manager of the defendant has access to them. The system’s operating manual, according to the defendant’s complaint, was communicated to all staff, as it was part of the office’s internal security procedures. The respondent states that there are informational signs regarding both video and audio recording next to the devices, which are accessible to all affected individuals. It provides photographs of the signs, but due to their size, it cannot be verified whether they actually also inform of the existence of audio recording and whether they comply with the requirements of Article 22.4 of the LOPDGDD. It provides photographs of the devices but does not provide images of the field of view of the cameras to verify whether, as the respondent claims, there are no cameras in restrooms, service areas, cafeterias, or employee break rooms. Regarding audio recording, the respondent asserts that it is necessary for two reasons: first, due to external risk, as they suffered a burglary in the year 2023 (they provide a copy of part of the police report); and second, because they had experienced prob","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_PS-00637-2025&diff=52809&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F5\u002F59\u002FLogoES.jpg","2026-08-26T13:40:57+00:00","2026-08-26T14:00:40.008706+00:00",7,[18,21],{"name":19,"type":20},"AEPD","vendor",{"name":22,"type":23},"CCTV","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,35,40],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":41},{"id":42,"icon":26,"name":43,"slug":44},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]