Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
SERVICIOS ESPECIALES, S.A.: Non-compliance with general data processing principles
The Spanish DPA imposed a fine on SERVICIOS ESPECIALES, S.A.
Full text
The Spanish DPA imposed a fine on SERVICIOS ESPECIALES, S.A. The case concerned a GDPR breach during an internal workplace conflict investigation: the company shared a report via email that included the full names, roles, and complaint details of the individuals involved, to the Works Committee and 15 additional employees. The DPA found this disclosure violated Article 5 (1) f) GDPR, as it failed to ensure the confidentiality of personal data. The original fine of EUR 200,000 was reduced to EUR 120,000 due to voluntary payment and acknowledgment of responsibility.
Industry: Employment
How it connects
Related across sources
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) CJEU Jan 12, 2023 Supervisory Authorities IP Address Supervision
C-340/21 VB v Natsionalna agentsia za prihodite C-340/21 (VB v Natsionalna agentsia) CJEU Dec 14, 2023 Integrity and Confidentiality Principle Data Breaches Notification Obligation
C-293/12 Digital Rights Ireland Ltd v Minister for Communications C-293/12 (Digital Rights Ireland) CJEU Apr 8, 2014 IP Address Storage Limitation Right to be Forgotten
C-623/17 Privacy International v Secretary of State C-623/17 (Privacy International) CJEU Oct 6, 2020 IP Address Material scope (GDPR) Legitimate Interest
CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is Processing: Communication of personal data in response to a request for access to documents constitutes processing. (¶69) Jun 29, 2010 Personal Data Legitimate Interest Right to Restriction
Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Oct 20, 2020 Privacy by Design & Default Privacy by Default Privacy by Design