Back to all lessons
Awareness Lessons
3 months ago

Unlawful Disclosure of Medical Data to Employer Triggers GDPR Fine

An individual unlawfully shared another person's sensitive medical data with their employer without a valid legal basis under GDPR, resulting in a €600 fine from the Austrian Data Protection Authority. Article 9 of GDPR establishes strict conditions for processing special category data such as health information, and the exception for legal claims under Article 9(2)(f) was inapplicable because the relevant claim was time-barred and no proceedings were active. This case highlights that individuals — not just organizations — bear personal responsibility for how they handle others' personal data. Even well-intentioned disclosures can constitute serious GDPR violations when no lawful basis exists, underscoring the need for broad data protection awareness beyond IT teams.

Tactical Insight

Immediate actions

  • Train all staff and individuals handling personal data on GDPR lawful bases, particularly the strict conditions governing special category data under Article 9.
  • Establish a clear internal review process requiring legal sign-off before any health or sensitive personal data is disclosed to third parties.

Long-term improvements

  • Implement a data classification policy that flags health and special category data for heightened handling controls and mandatory justification logs.
  • Develop and regularly update a data-sharing policy that explicitly maps permissible disclosures to their GDPR lawful bases.
  • Conduct annual GDPR awareness refreshers for all personnel, including case studies on individual liability for unlawful data sharing.

Detection & accountability measures

  • Maintain an audit log of all instances where personal data — especially health data — is shared externally, including the stated lawful basis.
  • Designate a Data Protection Officer (DPO) or privacy contact point to advise on borderline disclosure decisions before action is taken.