Quirón Prevención – €50,000 Fine (Spain, 2024)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Quirón Prevención, a workplace safety company, was fined €30,000 for failing to protect personal data in a mediation report. The report included unredacted personal information of employees, which was shared without proper security measures. This case underlines the importance of safeguarding personal data in workplace communications.
What happened
Quirón Prevención disclosed personal data in a mediation report without proper redaction.
Who was affected
An employee involved in a workplace harassment case and the data subject who filed the complaint.
What the authority found
The Spanish DPA found that Quirón Prevención violated GDPR by not implementing adequate data protection measures.
Why this matters
This case serves as a warning to companies about the necessity of protecting personal data in all communications. It highlights the potential financial consequences of data breaches.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
A data subject claimed she suffered from harassment in her workplace. She filed a complaint with the Labour and Social Security Inspectorate (la Inspección de Trabajo y Seguridad). Then, the data subject and an employee involved took part in the mediation proceedings held by employer, i.e. [https://www.quironprevencion.com/es Quirón Prevención] (the controller). The controller sent a mediation report to the data subject. However, the data subject’s and employee’s data (name and surname, ID, mobile number and email) were not redacted. The controller crossed out the data subject’s personal data after the request of the data subject. The data subject lodged a complaint with the Spanish DPA (AEPD), claiming violation of personal data security. The DPA upheld the complaint. The controller violated Article 5(1)(f) GDPR and Article 32 GDPR. According to the DPA, the controller didn’t implement appropriate technical and organisational measures to guarantee data confidentiality. In particular, at the stage of document preparation and disclosure there were no data anonymization techniques present. Because of that, unlawful disclosure of documents containing personal data took place. The DPA issued a fine of €30,000 for a violation of Article 5(1)(f) GDPR and €20,000 for a violation of Article 32 GDPR. The original fine of €50,000 was reduced to €30,000 due to voluntary payment and admission of responsibility.
Related Enforcement Actions (0)
No other enforcement actions found for Quirón Prevención in ES
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
9 September 2024
Authority
Agencia Española de Protección de Datos
Fine Amount
€50,000
About this data
Cite as: Cookie Fines. Quirón Prevención - Spain (2024). Retrieved from cookiefines.eu
Last updated: