Back to all lessons
Awareness Lessons
2 months ago

Employee Fined €1,000 for Sharing Customer Phone Number Without Legal Basis

An Austrian employee acting outside their professional authority shared a customer's personal phone number with a third party for entirely personal reasons, constituting an unlawful data transmission under GDPR. The core failure was a lack of understanding — or disregard — of the principle that personal data may only be processed when a legitimate legal basis exists, such as consent, contract, or legal obligation. 'Benevolence' or satisfying a third party's personal interest does not qualify as a lawful basis under Article 6 GDPR. This case highlights that GDPR liability can extend to individual employees, not just organisations, making personal accountability a real and enforceable consequence. It underscores how insider misuse of data — even seemingly minor disclosures — can result in regulatory sanctions.

Tactical Insight

Immediate actions

  • Conduct targeted GDPR refresher training for all staff with access to customer personal data, emphasising lawful basis requirements.
  • Audit access controls to ensure employees can only access personal data necessary for their specific role (data minimisation).

Policy & Governance improvements

  • Establish and enforce a clear Acceptable Use Policy for personal data that explicitly prohibits sharing data for personal reasons.
  • Implement a data sharing approval workflow requiring authorisation before any customer data is transmitted to third parties.
  • Define disciplinary consequences for unauthorised data disclosures in employment contracts and staff handbooks.

Detection & Monitoring measures

  • Deploy Data Loss Prevention (DLP) tools to flag or block unauthorised transmission of personal data via email, messaging, or other channels.
  • Enable audit logging of access to customer contact records to detect anomalous or unexplained lookups by employees.