Cybersecurity Policy Report, Spanish Employer Fined Over Exposure of Harassment Victim’s Data, (Apr 2, 2025)
The Spanish data protection authority, Agencia Espanola de Proteccion de Datos (AEPD), has imposed a fine of 120,000 euros ($130,000) against a company accused of publishing without her consent the identity of a complainant in a workplace harassment case.
The AEPD found that Servicios Especiales SA violated the European Union’s General Data Protection Regulation by publishing the employee’s first and last name, along with the word “complainant” in an e-mail to employees regarding the resolution of the harassment case. The AEPD’s decision is available only in Spanish and was machine translated for the purposes of reporting.
On April 15, 2024, the company opened a workplace harassment investigation, and the complainant detailed the facts concerning her experience via e-mail to the investigative committee and in several interviews, AEPD said.
A later company e-mail announcing the resolution of the case revealed the identities of each of the complainants by their full names and positions. The company sent the same resolutions to a number of recipients, making the complainants clearly identifiable, AEPD noted.
The complainant alleged she suffered an anxiety attack, resulting in her being placed on sick leave, and did not authorize the disclosure of her identity.
News: InternationalLegislation DataPrivacy LitigationEnforcement GDPR