[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fkdqipv1pjXBrjSrkqqJEPE8IYtDIzqJFiu4ljVcAuIA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"6de71571-fd7b-450f-8271-0ae5b909629e","accidental-teams-recordings-cost-spanish-employer-335k-in-privacy-damages","f64d2a39-16ae-4c6b-b6b5-6b38b9ebcff8","Accidental Teams Recordings Cost Spanish Employer €335K in Privacy Damages","A Spanish employer accessed accidental Microsoft Teams recordings of private employee conversations months after they were created and used them in disciplinary proceedings — without the employee's knowledge or consent. The court ruled this violated fundamental rights to privacy and secrecy of communications, resulting in over €335,000 in damages. This case illustrates that accidental data collection carries the same legal weight as intentional collection: if personal data is captured, it must be governed by proper consent, retention, and access policies. Organisations that fail to establish clear communication monitoring policies — and enforce them technically — face significant legal and financial exposure under European data protection law.","**Immediate actions:**\n- Audit all collaboration platforms (Teams, Zoom, Slack) to identify any unintended or automatic recording configurations and disable them where no lawful basis exists.\n- Restrict access to stored recordings so that only authorised personnel with a documented legitimate purpose can retrieve them.\n\n**Policy & governance improvements:**\n- Draft and publish a clear, GDPR-compliant employee monitoring and communications policy that specifies what is recorded, for how long, who can access it, and under what lawful basis.\n- Implement a mandatory retention and deletion schedule for accidental or incidental recordings so they are automatically purged within a defined short window (e.g., 30 days) unless formally flagged under a lawful process.\n- Require documented legal-team sign-off before any employee communication recording is accessed or used in HR or disciplinary proceedings.\n\n**Detection & accountability measures:**\n- Enable audit logging on all collaboration platforms to record who accessed which recordings and when, creating a tamper-evident trail.\n- Conduct annual privacy impact assessments (DPIAs) on all employee-facing communication and collaboration tools to surface unintended data collection risks.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"GDPR Article 5(1)(a) – Lawfulness, fairness and transparency","GDPR Article 5(1)(e) – Storage limitation","GDPR Article 6 – Lawful basis for processing","GDPR Article 9 – Processing of special category data (where applicable)","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","NIST SP 800-53 AC-3 – Access Enforcement","NIST SP 800-53 AU-9 – Protection of Audit Information","NIST SP 800-53 PT-2 – Authority to Process Personally Identifiable Information","CIS Control 3 – Data Protection","CIS Control 6 – Access Control Management","ISO\u002FIEC 27001 Annex A 6.2 – Teleworking and remote access policies","ISO\u002FIEC 27701 – Privacy Information Management System (PIMS)","ITIL Service Design – Information Security Management","published","2026-07-01T14:20:20.651572+00:00","2026-07-01T14:20:20.529+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=TSJ_PV_-_1713\u002F2026&diff=52042&oldid=51953","tsj-pv-1713-2026-2e28d8","TSJ PV - 1713\u002F2026",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":40,"name":41,"slug":42,"description":43,"color":44},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":46,"name":47,"slug":48,"description":49,"color":50},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]