Legitimacy: DPA Austria Finds Non-Compliant Disclosure of Personal Data

 
Establishing Legal Grounds for Processing, Defining Data Processing
A sports association published, on its website, the personal data (name, telephone number and email address) of the team leader of a sports team; the publication was unlawful because the data did not have any access restrictions (the details were published in the unrestricted areas, where a user was not required to log in), and the legitimate interests of the individual outweighed those of the association (which could not justify its claim of efficiency by disclosing the unrestricted personal data). 
 

  
Background Facts:
  • the Austrian Data Protection Authority ("DPA") reviews a complaint against a sports association ("Association"), alleging violations of the: 

Relevance to Business Activities:
  • establishing legal grounds for processing and defining data processing considerations:
    • background:
      • an individual ("Complainant") alleged that the Association unlawfully processed his personal data by publishing it on its website:
        • including his:
          • name;
          • telephone number; and
          • email address.
        • which can be accessed by all website visitors.
      • the Complainant is a team leader in the Association's sports team:
        • details of the team and their leaders are published on the Association's website as a standard practice.
    • legal framework:
      • GDPR:
        • article 6 states that processing shall be lawful if the:
          • data subject has given consent to the processing of his or her personal data for one or more specific purposes;Control or
          • processing is necessary:
            • for the:
              • performance of a contract to which the data subject is a party;Control
              • compliance with a legal obligation to which the controller is subject;Control
              • performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;Control or
              • legitimate interests pursued by the controller or third party:Control
                • except where the interests are overridden by the interests or fundamental rights and freedoms of data subjects.Risk
            • in order to:
              • take steps at the request of the data subject prior to entering into a contract;Control or
              • protect the vital interests of the data subject or another natural person.Control
        • article 7(4) states that freely given consent can be assessed by considering if the consent was a prerequisite for the: 
          • performance of a contract or provision of a service;Control and
          • processing of personal data which is not necessary for the performance of that contract.Control
    • findings and outcome:
      • the Association unlawfully processed the Complainant's personal data: 
        • by failing to:
          • restrict the access to personal details of team members to authorized users:
            • the details of the team leaders and members were published in the unrestricted areas, where a user was not required to log in.Risk
          • justify how the communication would be faster or efficient by releasing the personal data of the team members without restrictions:
            • the interests of the Association do not outweigh the Complainant's interests.Risk
        • the deletion of the personal data during the proceedings does not eliminate the infringement or the negative consequences on the Complainant:
          • the personal data was already published in the public domain, even if for a limited period of time.Risk

Comments

Popular posts from this blog

Olivia: The New Tool from Garante Privacy to Help Protect Your Data

Navigating the Future of Recruitment: Understanding ICO recommendations on AI Tools

Italy: Garante's new guidelines on cookies and similar tracking technologies