Landlord Fined for Disclosing Tenant's Personal Data to Employer Under Duress
A Spanish landlord unlawfully shared a tenant's personal information — including alleged debts and identification details — with the tenant's employer as a coercive tactic to force vacation of the property. This constitutes a clear violation of GDPR's integrity and confidentiality principle under Article 5(1)(f), which requires personal data to be processed in a manner that ensures appropriate security and prevents unauthorised disclosure. The case illustrates that GDPR obligations apply to individuals acting as private data controllers, not just organisations. Even outside a corporate context, misusing personal data as leverage carries legal consequences and erodes trust in how private information is handled.
Tactical Insight
Immediate actions
- Train all staff and individuals who handle personal data that sharing it without a lawful basis — especially under threat or coercion — constitutes a GDPR violation.
- Establish a clear data-sharing policy that defines who is authorised to disclose personal data and under what legal grounds.
Long-term improvements
- Embed GDPR awareness into onboarding and ongoing training programmes, covering real-world scenarios such as landlord-tenant or employer-employee data handling.
- Implement documented data minimisation and purpose-limitation procedures to ensure personal data is only used for its originally stated purpose.
- Register data processing activities in a Record of Processing Activities (RoPA) to maintain accountability and traceability.
Detection & Response measures
- Establish a clear incident reporting channel so individuals can flag unauthorised disclosures of their personal data quickly.
- Conduct periodic privacy impact assessments to identify situations where personal data may be misused or shared without lawful basis.