Back to Feed
Privacy FinesSep 10, 2026

APDCAT (Catalonia) - PS-01092025

APDCAT fines public sector group €5,250 for unlawful audio recording disclosure.

Summary

The Catalan Data Protection Authority (APDCAT) has fined a public-sector organization €5,250 for unlawfully disclosing an employee's audio recording of a conversation to four additional recipients. The disclosure violated Article 5(1)(a) of GDPR, as the recording was personal data and its sharing was not legally justified, despite the controller's arguments about labor relations and security functions of the recipients.

Full text

Help APDCAT (Catalonia) - PS-01092025: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 15:37, 10 September 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators307 edits Tag: Decisions [1.0] (No difference) Latest revision as of 15:37, 10 September 2026 APDCAT - PS-01092025 Authority: APDCAT (Catalonia) Jurisdiction: Spain Relevant Law: Article 5(1)(a) GDPR Article 6 GDPR Article 12 GDPR Article 15 GDPR Type: Complaint Outcome: Upheld Started: 12.03.2025 Decided: Published: 05.06.2026 Fine: 3150.0 EUR Parties: n/a National Case Number/Name: PS-01092025 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Catalan Original Source: APDCAT (in CA) Initial Contributor: bms The DPA fined a public-sector group €5,250 for unlawfully disclosing an employee's access-request audio recording to four additional recipients, in breach of Article 5(1)(a) GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts On 22 January 2025, an employee and trade union representative of a public-sector organisation, the data subject, emailed the DPO requesting access to and a copy of a recording of a telephone conversation he had held that day with another employee. The conversation concerned the activation of a psychological support protocol for a driver who had been involved in an accident. The data subject sent his request to the DPO while copying seven other recipients, including the generic email address of his trade union section. On 19 February 2025, the DPO replied to the data subject and attached the requested audio recording. However, the DPO also copied four other recipients to the response, including three employees of the controller and the generic trade union mailbox. As a result, the recording was disclosed to all four additional recipients. The controller argued that the three employees had functions related to labour relations, security and the management of the access request and that the trade union address had also been included in the data subject's original email. It further argued that the wording and recipients of the original request could have created the impression that the data subject intended the response to be shared with them. Holding The DPA held that the controller violated Article 5(1)(a) GDPR by unlawfully disclosing the recording to four recipients other than the data subject. The DPA considered that, under Articles 12 and 15 GDPR, information provided in response to an access request must be provided to the data subject exercising that right. The fact that other persons had professional responsibilities relating to labour relations or security did not, by itself, justify their access to the recording. Even if informing them about the handling of the request had been necessary, this could have been achieved without disclosing the recording itself. Similarly, the fact that the data subject had copied other recipients, including the trade union mailbox, in his original request did not amount to an unequivocal indication that he wanted the recording disclosed to them. The DPA acknowledged that the wording of the request could have created some ambiguity. However, since the request had been addressed to the DPO and concerned access to the data subject's personal data, it had to be treated as an exercise of the right of access under Article 15 GDPR. If the DPO had doubts about the scope of the request or the intended recipients, the DPO should have sought clarification before disclosing the recording. Consequently, there was no legal basis under Article 6 GDPR for communicating the recording to the additional recipients. The DPA therefore found an infringement of the principle of lawfulness under Article 5(1)(a) GDPR. The DPA imposed a €5,250 fine. Among other factors, it took into account that the disclosure was an isolated incident affecting four recipients and occurred within the controller's internal or employment environment. It also considered as mitigating factors the ambiguity created by the data subject copying several recipients in his original request and the subsequent implementation of encryption measures. Previous data protection infringements by the controller were considered an aggravating factor. The controller subsequently acknowledged its responsibility and voluntarily paid the fine, which resulted in a cumulative 40% reduction to €3,150 according to Spanish Administrative Law (39/2015). The controller also instructed the four additional recipients to delete both the email and the audio recording. Since this corrective action had already been taken, the DPA did not order any further corrective measures. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Catalan original. Please refer to the Catalan original for more details. "In this resolution, references to the affected entity have been redacted in order to comply with Article 17.2 of Law 32/2010, since if the name of the affected entity were disclosed, the affected individuals could also be identified." Case Identification Resolution of enforcement proceeding no. PS-0109/2025 concerning (...). Background 1. On March 12, 2025, and February 23, 2025, complaints were received by the Catalan Data Protection Authority Two written complaints regarding an alleged violation of personal data protection regulations, concerning the entities that make up the (...), group, mentioned in the heading (hereinafter, (...)). The complainant is a union representative at the public company (...), which is part of the (...) group, and stated the following: - That, on January 22, 2025, in exercising the right of access provided for in Article 15 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR), the free movement of such data (GDPR), requested for personal reasons from the Data Protection Officer (DPO) of (...) access to and a copy of a telephone conversation held on January 22, 2024, with the head (...) of (...), regarding the activation of a psychological support protocol for a driver who had hit a pedestrian. - That, on February 19, 2025, the DPO sent him a copy of the conversation by email electronic mail, in an unencrypted, password-free audio file, and with copies to several people, as well as to the email of the union chapter to which he belonged, which, according to the complainant, is accessed by many people. - That the conversation was private and that, furthermore, it referred to an employee's health status. - That, after this email was sent, several employees confirmed to him that they had heard the conversation. - That, coincidentally, the email was sent a few weeks after the affected person had filed a complaint with (...) for a very serious security breach. To prove this, he submitted, among other things, a video showing his email account, the email sent by the DPD of (...) on 02/19/2025 at 12:41 PM, the subject "REQUEST FOR IMAGES AND TELEPHONE CONVERSATION," which contained the aforementioned audio file; in the video file, it was shown how the file was clicked on and the entire conversation was heard. 2. The Authority opened a preliminary information phase regarding the complaints PAGE: 2 of 14 COPY GENERATION DATE AND TIME: 06/05/2026 11:58 This document is a true copy of the original electronic document. You can verify its validity at https://tramits.apdcat.cat/Ciutadania/ValidarDocuments.aspx?csv=7213843a-b65b-4e74-84d1-8ef0fa69b34f The recipient of this document must handle the secure verification code (CSV) in the header of this document with caution

Entities

APDCAT (vendor)