Employee Fined €1,000 for Sharing Customer Phone Number Without Legal Basis
An Austrian employee acting outside their professional authority shared a customer's personal phone number with a third party for entirely personal reasons, constituting an unlawful data transmission under GDPR. The core failure was a lack of understanding — or disregard — of the principle that personal data may only be processed when a legitimate legal basis exists, such as consent, contract, or legal obligation. 'Benevolence' or satisfying a third party's personal interest does not qualify as a lawful basis under Article 6 GDPR. This case highlights that GDPR liability can extend to individual employees, not just organisations, making personal accountability a real and enforceable consequence. It underscores how insider misuse of data — even seemingly minor disclosures — can result in regulatory sanctions.
Tactical Insight
Immediate actions
- Conduct targeted GDPR refresher training for all staff with access to customer personal data, emphasising lawful basis requirements.
- Audit access controls to ensure employees can only access personal data necessary for their specific role (data minimisation).
Policy & Governance improvements
- Establish and enforce a clear Acceptable Use Policy for personal data that explicitly prohibits sharing data for personal reasons.
- Implement a data sharing approval workflow requiring authorisation before any customer data is transmitted to third parties.
- Define disciplinary consequences for unauthorised data disclosures in employment contracts and staff handbooks.
Detection & Monitoring measures
- Deploy Data Loss Prevention (DLP) tools to flag or block unauthorised transmission of personal data via email, messaging, or other channels.
- Enable audit logging of access to customer contact records to detect anomalous or unexplained lookups by employees.