[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2ZU30xx2xmTqBIHGCqUHaOBPlRLHt0WJRyP92BFPf1c":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"4b8dac0d-7f74-4332-90bf-c77853c3a706","unauthorized-teams-recordings-after-meeting-end-lead-to-court-ruling-against-employer","cf6b12ce-e838-41cf-b726-62ed6309e350","Unauthorized Teams Recordings After Meeting End Lead to Court Ruling Against Employer","A Spanish court ruled that Microsoft Teams continued recording after a meeting ended without the employee's knowledge or consent, violating their reasonable expectation of privacy. The employer's failure to inform employees of recording practices — and their subsequent use of those recordings as evidence — constituted a breach of fundamental privacy rights. This case highlights that technical capability to record does not equate to legal authorization to do so, and that improper data collection can result in evidence being inadmissible and significant financial liability. Organizations must align their conferencing tool configurations with applicable privacy laws and ensure employees are transparently informed of any monitoring or recording practices.","**Immediate actions:**\n- Audit all video conferencing platform settings (e.g., Microsoft Teams, Zoom) to ensure recordings stop automatically when meetings end and cannot extend beyond the session.\n- Review and revoke any unauthorized access to stored meeting recordings until a formal data governance policy is in place.\n\n**Policy & Transparency measures:**\n- Establish a written, clearly communicated recording policy that specifies when, how, and by whom meetings may be recorded, and obtain explicit employee consent.\n- Ensure all employees receive training on their rights regarding workplace monitoring and recording practices before any such tools are deployed.\n\n**Long-term improvements:**\n- Implement Data Protection Impact Assessments (DPIAs) for any workplace monitoring technologies before deployment to identify and mitigate privacy risks.\n- Appoint or consult a Data Protection Officer (DPO) to ensure ongoing compliance with GDPR and local labor privacy regulations.\n- Define and enforce data retention limits for meeting recordings, with automatic deletion schedules aligned to legal requirements.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5 (Principles of data processing)","GDPR Article 6 (Lawfulness of processing)","GDPR Article 13 (Transparency and information obligations)","GDPR Article 35 (Data Protection Impact Assessment)","NIST SP 800-53 AC-3 (Access Enforcement)","NIST SP 800-53 PT-2 (Authority to Process Personally Identifiable Information)","CIS Control 3 (Data Protection)","CIS Control 14 (Security Awareness and Skills Training)","ISO\u002FIEC 27001 A.18.1 (Compliance with legal and contractual requirements)","ITIL Service Design — Privacy and Data Management","published","2026-07-01T10:20:52.537214+00:00","2026-07-01T10:20:52.226+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=TSJ_PV_-_1713\u002F2026&diff=52041&oldid=51953","tsj-pv-1713-2026-54178d","TSJ PV - 1713\u002F2026",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]