Unlawful Disclosure of Medical Data to Employer Triggers GDPR Fine
An individual unlawfully shared another person's sensitive medical data with their employer without a valid legal basis under GDPR, resulting in a €600 fine from the Austrian Data Protection Authority. Article 9 of GDPR establishes strict conditions for processing special category data such as health information, and the exception for legal claims under Article 9(2)(f) was inapplicable because the relevant claim was time-barred and no proceedings were active. This case highlights that individuals — not just organizations — bear personal responsibility for how they handle others' personal data. Even well-intentioned disclosures can constitute serious GDPR violations when no lawful basis exists, underscoring the need for broad data protection awareness beyond IT teams.
Tactical Insight
Immediate actions
- Train all staff and individuals handling personal data on GDPR lawful bases, particularly the strict conditions governing special category data under Article 9.
- Establish a clear internal review process requiring legal sign-off before any health or sensitive personal data is disclosed to third parties.
Long-term improvements
- Implement a data classification policy that flags health and special category data for heightened handling controls and mandatory justification logs.
- Develop and regularly update a data-sharing policy that explicitly maps permissible disclosures to their GDPR lawful bases.
- Conduct annual GDPR awareness refreshers for all personnel, including case studies on individual liability for unlawful data sharing.
Detection & accountability measures
- Maintain an audit log of all instances where personal data — especially health data — is shared externally, including the stated lawful basis.
- Designate a Data Protection Officer (DPO) or privacy contact point to advise on borderline disclosure decisions before action is taken.