# Persónuvernd (Island) - 2025010358

- Type: Enforcement
- Source: Persónuvernd (Island)
- Date: 2026-07-01
- Original: https://gdprhub.eu/index.php?title=Persónuvernd_(Island)_-_2025010358
- Canonical: https://overview.legal/posts/83499
- Topics: Monitoring, Supervisory Authorities, Cloud Computing, Integrity and Confidentiality Principle, Personal Data, Human Resources, Controllers, Employees, Access Controls, Accountability

## Summary

Facts — The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT department. The controller had a Microsoft Office 365 subscription, which included OneDrive and Delve for each employee. OneDrive is a cloud storage service linked to a user account, where files may be stored online rather than only locally. The data subject lodged a complaint with the Icelandic DPA (Persónuvernd) against the controller. She argued that she had been subject to unlawful electronic surveillance during her employment and that colleagues had gained unauthorised access to her computer. According to the data subject, the controller had configured her work computer and the software installed on it in such a way that colleagues and supervisors could monitor her work and view personal data stored on her desktop. She claimed that all of her data was automatically saved to a shared OneDrive of the controller and integrated into Delve. According to the data subject, through Delve her personal data was accessible to her colleagues, including passwords, personal work documents, employee-related documents, payslips and a medical certificate. She also claimed that she had witnessed a colleague opening those documents on the colleague’s own work computer. The controller denied that it had subjected the data subject to electronic surveillance or that the access controls for her file storage areas were inadequate. It argued that OneDrive was a personal file storage area assigned to each employee, that employees could access other employees’ documents only if those documents had been shared with them, and that the data subject’s personal data had been adequately secured through access controls. Holding — The DPA found no evidence that a shared enterprise OneDrive existed to which the data subject’s personal data had been automatically copied or linked. Instead, it found that the relevant OneDrive was the data subject’s personal OneDrive, assigned to her as an employee under the controller’s corporate Microsoft 365 subscription. The DPA also discovered no indication that the data subject’s colleagues or supervisors had access to her OneDrive desktop folder through permissions in the folder’s security settings. Although the “Everyone” group appeared in the list of users or groups in the security settings, the evidence submitted with the complaint did not show that this group had any defined access rights. Nor did the fact that the data subject had access to a colleague’s file prove that the controller’s access controls were defective, since the evidence indicated that employees could grant each other access to files stored in their respective file storage areas. The DPA further held that Delve view counts could not, on their own, prove that unauthorised third parties had viewed the data subject’s documents. The view count was not broken down by user and could include views by the document owner herself. It could therefore only show that the relevant document had been opened a certain number of times by users who had access to it, not that unauthorised access had occurred. The DPA therefore concluded that it was unproven that the controller had carried out electronic monitoring of the data subject or that unauthorised colleagues had accessed personal data stored in her file storage areas. It also held that the controller had ensured appropriate security of the data subject’s personal data through access controls, in accordance with Article 5(1)(f) GDPR, Article 5(2) GDPR and Article 32(1) GDPR.

## Full text

The Icelandic Data Protection Authority has ruled that it has not been proven that BL ehf. conducted electronic monitoring of the complainant, more specifically online monitoring, while she worked for the company. The parties disputed, among other things, what understanding should be given to the submitted case documents that contained settings in the complainant's file areas while she worked for BL ehf., as well as various matters relating to the further functioning of certain software solutions. The Icelandic Data Protection Authority concluded, among other things, that nothing had emerged to indicate that there had been a shared OneDrive for BL ehf. as the complainant claimed. Furthermore, the Icelandic Data Protection Authority considered that it could not be concluded from the case documents that the complainant's colleagues or superiors had had access to her desktop on OneDrive through permissions in the desktop's security settings. The Data Protection Authority also considered that data showing that the complainant had access to a document stored on a colleague's OneDrive could not, on its own, confirm that access controls were faulty, as it could have been concluded from the case data that colleagues could grant each other access to data in their file areas. Finally, the Data Protection Authority did not consider it possible to accept the conclusions that the complainant drew from the viewing figures of documents in the Delve software, which were not broken down by user. The agency did not consider it possible to draw any other conclusion than that the documents in question had been viewed a certain number of times by those who had access to them, including by their owner. Therefore, the conclusion that an unauthorized person had had access to the documents could not be drawn from the figure alone. The Data Protection Authority's conclusion was therefore that it was unproven that BL ehf. had conducted electronic monitoring of the complainant and that unauthorized colleagues had viewed her personal information stored in her file areas at the company. It was also the conclusion of the Data Protection Authority that BL ehf. had ensured adequate security of the complainant's personal information in the aforementioned file areas, in accordance with the data protection legislation, to the extent that the institution considered it necessary to investigate the subject of the complaint. The decision-makers' complaint about BL ehf., in case no. 2025010358 (previously 2024010028):Case procedure1. On 5 January 2024, the Data Protection Authority received a complaint, together with supporting documents, from [A] (hereinafter the complainant) about online monitoring that she claims to have been subjected to over a [specified] period by BL ehf. (hereinafter BL or the company) while she was working for the company.2. The Data Protection Authority invited BL to comment on the complaint by letter dated 18 December 2024 and the company's responses were received by letter dated 8 January 2025, along with accompanying documents. The complainant was given the opportunity to submit comments on BL's responses by letter dated 10 September 2024 and received by letter dated 24 September 2025. BL was given the opportunity to submit comments on the complainant's responses by letter dated 29 September 2024 and received by letter dated 12 February 2025. The complainant was given the opportunity to submit comments on BL's responses by letter dated 24 September 2024 and received by letter dated 10 March 2025, along with accompanying documents. BL was given the opportunity to submit comments on the complainant's responses by letter dated 31 September 2025. and they were received by letter dated 6 May 2018. The complainant was given the opportunity to submit comments on BL's responses by email on 20 June 2018, if she considered it necessary, and they were received by letter dated 3 July 2018. The Data Protection Authority received an email on 12 March 2026 from the complainant, along with data that she requested to be submitted, to shed further light on her complaints.3. In resolving the case, all of the above-mentioned data has been taken into account, although not all of them are specifically explained in the following ruling.Subject of dispute 4. There is a dispute about the intended online monitoring and inspection of the complainant's personal data by BL and, in that context, whether access controls on the complainant's file areas at the company were in accordance with Act No. 90/2018 on Privacy and Processing of Personal Data.Facts of the case and available data5. It is known that the complainant started working at BL on [date] [year] and was therefore given a computer that was installed by the company's IT department. BL has a subscription to Microsoft Office 365, which includes, among other things, OneDrive for each employee, and the user's desktop is part of it. Delve is software that was also part of Microsoft Office 365 and, according to BL, it was accessible to employees but not in general use at the company. According to information on the Microsoft website, the company stopped offering Delve as of December 2024 and its functionality was implemented in the company's other software solutions.6. OneDrive is a user's personal online drive and its purpose is to store data related to the account that is logged into the drive. The user's data will then be created on OneDrive, instead of on the computer itself. OneDrive is usually installed on the computers of employees of companies that use Microsoft Office 365 to ensure that there are copies of the employee's work data, but the backup function is optional. In the case of a company subscription, such as BL, the company controls on behalf of users whether the aforementioned function is turned on or not, for example, through group policy. When a company distributes access to OneDrive to an employee, from its company subscription to Microsoft Office 365, this can usually be seen in the name of the drive on the employee's computer, where the company's name is appended to the name OneDrive. 7. Delve was part of Microsoft Office 365 at the time of the complaint, but it can be described as a data window that showed the user the files that they had access to, both their own and those of others. Examples include files that the user had worked on themselves; files that others had shared with them and new files on the user's OneDrive drive. Behind Delve was the Microsoft Graph tool that created a probability tree of what would be most interesting to show the user from the files they had access to. Delve also received information from SharePoint and Teams, which are also part of Microsoft Office 365, about how many times a file had been opened by those who had access to it and displayed information about the number of views (e.g. views) of each document. This number included both the times the file owner had opened it and the times others had access to it. Delve, however, did not provide access to files itself. If a user saw a reference to a file on their own OneDrive in their Delve account, which they had not shared with others, but the view count showed that it had been opened a certain number of times, then it was the user themselves who had opened the file all the times.8. A user can view in the properties of each file or folder on their computer's drives, whether OneDrive, hard drives or other drives, under security settings, a list that shows whether and what permissions specific users and/or groups have. Permissions can be defined either positively, i.e. by taking a position on individual permissions, or negatively, which usually means that no permissions have been granted to the selected user or group.9. The accompanying complaint included, among other things, an employment contract between the complainant and BL, dated [date] [year]; two images of Delve functionality; a screenshot of the complainant's interaction with BL's IT department; an image of the complainant's user profile in Delve; a copy of the complainant's sick leave certificate that was saved on her computer; a screenshot of general information in the complainant's desktop properties; screenshot of the permissions that were in effect on the complainant's desktop; screenshot of information about the location of the desktop folder files; screenshot showing the documents saved in OneDrive; copy of the complainant's communication with a former colleague.10. Attached to BL's objection letter from December 18, 2024 were two screenshots of a specific user's desktop settings; three screenshots of information about Delve on the Microsoft website; a screenshot of an overview of software included in BL's Microsoft Office 365 subscription; a screenshot of the complainant's accompanying document showing the functionality of Delve, along with additional BL markings; a screenshot of the updated user profile interface in Delve; a screenshot of information under the content menu of the user profile in Delve, along with BL markings; a screenshot of the complainant's accompanying document showing the functionality of Delve, along with additional BL markings.11. Attached to the complainant's letter of objection from 10 March 2025 was a video of Delve in action and a document showing a comparison of the settings of two desktops.12. Attached to the complainant's email from 12 March 2026 were screenshots of email communications between the complainant and Microsoft Privacy, from 17 November to 5 December 2024.Parties' viewsMain views of the complainant13. The complainant claims that she was subjected to unlawful electronic surveillance by BL during her employment with the company, which violated Act No. 90/2018 on the Protection of Personal Data and the Processing of Personal Data, Regulation (EU) 2016/679 and the Data Protection Regulation No. 50/2023 on electronic surveillance. The cyber surveillance was ongoing, carried out using automated equipment and in an area normally visited by a limited number of people. 14. The complainant believes that BL has adjusted the settings on her work computer and the software on it in such a way that her colleagues and superiors have been able to monitor her work and view personal data on her desktop. More specifically, all of the complainant's data has been automatically saved to BL's shared OneDrive and integrated with Delve. The data included a medical certificate containing sensitive personal data as well as data containing sensitive information, such as passwords, personal work documents, employee interviews and pay slips. The complainant claims to have asked her colleague to confirm the above and claims to have personally seen the colleague open all of the complainant's aforementioned data via the colleague's work computer. 15. The complainant argues that the cyber surveillance in question was contrary to the principles of points 1–6. 1. paragraph. Article 8. Act No. 90/2018. The processing was not fair, transparent or proportionate, and technical and organizational measures were not taken to ensure adequate security of personal data.Through Delve, the complainant's personal data was made available to other employees. There, she claims, for example, to have seen, based on the number of views of a document that stored her password and was saved on the computer's desktop, that thirteen parties had seen the password. The complainant believes that the number of views in question only counts the number of times other users have opened or viewed the document, but that clicks from the document owner are not included. If a document has not been shared with others, the number of views should therefore be zero.16. In the complainant's opinion, the scope of the intended monitoring was far beyond what was necessary given the nature of the complainant's work. Delve stores information longer than necessary and users have limited control over when information is removed. Access controls were also inadequate. It was also mandatory to carry out a privacy impact assessment (PIA) for the processing. Main views of BL17. BL's argument is that it is unproven that the company conducted online monitoring of the complainant as described in the complaint. On the contrary, the company believes that the data it has submitted for the investigation of the case shows the opposite, i.e. that employees' data access was access controlled and the security of the complainant's personal information was therefore ensured. The supporting documents to the complaint show a standard OneDrive setup and employees only have access to other employees' documents if they have been shared with them, and the same applies to Delve. OneDrive is an access-controlled private area for employees, in accordance with Microsoft's security standards. A desktop is part of it and allows employees to access their workspace even if they log in to another computer owned by the company. However, other employees do not have access to that area. The data provided shows that the group everyone had no rights on the complainant's desktop, there was no check mark in the allow box, which means that no permissions were present. If the complainant has saved a medical certificate on his desktop or on OneDrive, no one else has had access to it. There is no such thing as a common OneDrive for the company, but access is granted on an individual basis.18. BL refers to the fact that employees' data access was controlled as described above and that the processing was therefore lawful, fair and transparent, cf. point 1. of the first paragraph of Article 8 of Act No. 90/2018 and that the information was obtained for a clearly specified, lawful and objective purpose, cf. point 2. of the same paragraph. The proportionality and security of the processing were likewise ensured by the access control. Premises and conclusion Scope of the case19. According to point 3. of the second paragraph of Article 39 of Act No. 90/2018, the Data Protection Authority decides whether a complaint provides sufficient grounds for investigation and can rule on whether a violation has occurred. With reference to the above-mentioned authority and Article 28 of the Data Protection Authority's procedural rules No. 1150/2023, the agency has decided to limit the resolution of this case to the intended online monitoring of the complainant and the inspection of her personal information by BL and in that context whether the company's access controls were such that appropriate security of the information was ensured, cf. point 6. of the 1st paragraph and the 2nd paragraph of Article 8 and the 1st paragraph of Article 27 of Act No. 90/2018, cf. point f. of the 1st paragraph and the 2nd paragraph of Article 5 and the 1st paragraph of Article 32 of Regulation (EU) 2016/679. In deciding on the above-mentioned delimitation, the Data Protection Authority has, among other things, taken into account what has been stated in the responses of both parties to the case as well as the case documents, which the agency believes will lead to the conclusion that the main dispute between the parties to the case relates to the above-mentioned complaints. This ruling will therefore not take a position on BL's general authority to use the software solutions that are under discussion in the case.Legal environment20. This case concerns the alleged online monitoring and inspection of the complainant's personal information by BL and the company's arrangements for access controls in the complainant's file areas while she worked for the company. The case therefore concerns the processing of personal information that falls within the scope of Act No. 90/2018 on the Protection of Personal Information and the Processing of Personal Information and thus the authority of the Data Protection Authority, cf. Paragraph 1 of Article 4, Paragraph 2 of Article 1 and Paragraph 1 of Article 39. of the Act.21. BL is considered the controller of the processing, cf. point 6 of Article 3 of Act No. 90/2018 and point 7 of Article 4 of Regulation (EU) 2016/679.22. The processing of personal data must, among other things, be compatible with the principles of paragraph 1 of Article 8 of Act No. 90/2018, cf. paragraph 1 of Article 5 of Regulation (EU) 2016/679. The principles stipulate, among other things, that personal data shall be processed lawfully, fairly and transparently in relation to the data subject, cf. point 1 of the Act and point a of the Regulation, and that they shall be processed in such a way that appropriate security of personal data is ensured, cf. point 6 of the Act and point f of the Regulation. According to the 2nd paragraph of Article 8 of the Act, cf. the 2nd paragraph of Article 5 of the Regulation, the controller is responsible for ensuring that the processing of personal data always complies with the principles of data protection legislation and must be able to demonstrate this.23. Further provisions on information security are contained in the 1st paragraph of Article 27 of Act No. 90/2018 on the Protection of Personal Data and the Processing of Personal Data and Article 32 of Regulation (EU) 2016/679. It states that the controller and the processor shall take appropriate technical and organizational measures to ensure adequate security of personal data, taking into account the state of the art, the cost of implementation, the nature, scope, context and purposes of the processing and the risk, varying in likelihood and severity, to the rights and freedoms of individuals. Article 32(2) also states of the regulation that when assessing the adequacy of security, particular account shall be taken of the risk posed by the processing, in particular with regard to, inter alia, unauthorized access to them. Conclusion 24. In her complaint, the complainant has based, among other things, on the fact that BL had conducted electronic monitoring of her, more specifically online monitoring, and that her colleagues had unauthorized access to her computer desktop, where, among other things, medical certificates and documents containing sensitive personal information were found, cf. discussion in paragraphs 14 and 15. The complainant argues that the submitted data and the conclusions she draws from them support her complaint. BL has, however, denied that the company had conducted electronic monitoring of the complainant and that access controls to its file area were faulty, so that unauthorized persons had access to it. In this context, BL relies, among other things, on the available data in the case and the company's understanding of what can be read from them about the settings on the complainant's computer and the functionality of the software in question. BL also relies on the fact that employee data access was access controlled and the security of the complainant's personal information was therefore ensured.25. As previously stated, OneDrive is each user's personal network drive, cf. discussion in paragraph 6. Among the things that the complainant has referred to in support of her case is that the access controls on her desktop were arranged in such a way that the desktop and everything on it were automatically copied to or interconnected with what she calls BL's shared OneDrive. In the opinion of the Data Protection Authority, the aforementioned statement of the complainant is not supported by the data that the complainant has submitted, nor by anything else that has emerged during the investigation of the case. In view of the above and after having independently assessed the available data in the case, cf. discussion in paragraphs 9–12, in the opinion of the Data Protection Authority, there is nothing to indicate that there was a shared OneDrive for the company, as alleged in the complaint, but rather that the OneDrive in question was the complainant's personal OneDrive that was assigned to her from BL's corporate subscription as an employee of the company, cf. discussion in paragraph 6.26. The case data also do not indicate that the complainant's colleagues or superiors had access to the complainant's desktop on her OneDrive through permission to that effect in the desktop's security settings, cf. discussion in paragraph 8. Although the group was all on the list of those who had access to the complainant's desktop on OneDrive, it can be seen from the attached documents to the complaint that this group had no defined permissions. The case data therefore do not indicate that this group had the rights to see the contents of the complainant's desktop and examine it in more detail.27. The complainant has relied on the fact that certain information from Delve supports her complaint that access controls were faulty at BL. The supporting documents to the complaint included, among other things, a picture of the complainant's colleague's user profile on Delve, which showed a subpage with recent documents and email attachments. There was a reference to a document whose location was said to be on this particular colleague's OneDrive. As previously explained, Delve only showed its user files that the user himself had access to, cf. the discussion in paragraph 7. The submitted document therefore shows, in the opinion of the Data Protection Authority, nothing more than that the complainant had access to this colleague's document. On the other hand, the screenshot does not confirm that access controls were faulty on the part of BL, as it can be concluded from the case data that users were able to grant each other access to their data stored in their file area.28. The complainant has also pointed out that her completed questionnaire for an employee interview, which she sent to her manager, appeared in Delve. Again, it is important to note that this was a document belonging to the complainant herself, which she had access to and which was therefore displayed to her when viewing her own user profile in Delve. Nothing has been presented to support the complainant's conclusions that others than herself, and those to whom she made documents available, had access to her documents.29 Finally, the complainant has relied on the fact that the view count of her documents published in Delve supports her complaint, as the number showed how often others than herself viewed the documents. She thus concludes that thirteen parties saw a document on her desktop that stored passwords, cf. discussion in paragraph 15. The Data Protection Authority does not consider it possible to accept this conclusion.In the opinion of the Authority, it cannot be seen otherwise than that the number of views in question showed the total number of times a file had been opened by those who had access to it, without breakdown, and no user was excluded, including the owner of the document, cf. the discussion in paragraph 7. As in the present case, it is not considered possible to draw any other conclusion from the above-mentioned statement of the complainant than that the document in question with a password was opened thirteen times by those who had access to it. On the other hand, the conclusion cannot be drawn from the above alone that an unauthorized person had access to the document.30. In accordance with all of the above, the investigation by the Data Protection Authority has not revealed that the processing of personal data complained of, including electronic monitoring and the alleged inspection of the complainant's personal data, was carried out by BL. In accordance with the Authority's respected powers, the Authority does not consider there to be any grounds for further investigation in this regard. It is therefore considered unproven that the processing of personal data, which consists of electronic monitoring of the complainant and inspection of her personal data, has taken place.31. The Data Protection Authority also considers that BL has demonstrated in a satisfactory manner, to the extent that the institution considered it necessary to investigate the subject of the complaint, that access controls were in such a way that the appropriate security of the complainant's personal data was ensured, cf. point 6. of the 1st paragraph and the 2nd paragraph of Article 8 and the 1st paragraph of Article 27 of Act No. 90/2018, cf. point f. of the 1st paragraph and the 2nd paragraph of Article 5 and the 1st paragraph of Article 32 of Regulation (EU) 2016/679. Ruling: It is not proven that BL ehf. has conducted electronic monitoring with [A] and that unauthorized colleagues have viewed her personal information stored in her file areas at the company, in accordance with the complaint.BL ehf. ensured adequate security of [A]'s personal information in her file areas at the company in accordance with point 6. 1. paragraph. 8. article. Act no. 90/2018, cf. 2. paragraph. of the same provision.Personal Data Protection, 1. July 2026Bjarni Freyr Rúnarsson Ósk Óskarsdóttir

---
Generated by overview.legal · https://overview.legal/posts/83499 · 2026-08-24
