News

πŸ‡ͺπŸ‡Έ Garbage: Lack of data confidentiality, a club sanctioned

Confidentiality & Security | 26/03/2025

⚠️ Using a Document Shredder Can Prevent Penalties! ⚠️

Source : PS-00460-2024

πŸ† A Spanish football club fined for throwing personal data in the trash! πŸ—‘οΈπŸ“„

πŸ” The Facts

πŸ“… In October 2024, the AEPD sanctioned Club Rápido de Bouzas, a sports association in Vigo, for violating the GDPR.
πŸš” The local police discovered 1,444 player information forms, including many related to children, discarded in a public container near a stadium.

πŸ“‚ Exposed Data:
Names, surnames, addresses, phone numbers
πŸ“ž
Parental information
πŸ‘¨‍πŸ‘©‍πŸ‘§, photographs πŸ“Έ
Copies of identity documents
πŸ†” and banking details πŸ’³

❌ Violations Identified
πŸ”΄ Breach of Article 5(1)(f) of the GDPRLack of confidentiality and failure to implement security measures.
πŸ”΄ Breach of Article 32 of the GDPRNo technical and organizational measures were in place to ensure data security.
πŸ’‘ Throwing away documents containing personal data without prior destruction is a GDPR violation!

βš–οΈ Penalty
πŸ’° €1,000 fine, reduced to €600 after immediate payment and acknowledgment of responsibility.
πŸ“Œ AEPD Recommendation: Ensure proper data retention periods, as some records were kept far beyond the necessary timeframe.

πŸ›‘οΈ Best Practices to Avoid This Type of Fine
βœ… Always use a document shredder to dispose of paper files containing personal data.
βœ… Implement a data retention and destruction policy.
βœ… Train your teams on best practices for data protection.

⚠️ Negligence can be costly! 🚨 Make sure you properly manage both paper and digital documents to avoid GDPR violations.

Back to news list

Explore all our areas of expertise:

]]>