News

🚨 SS2I Inappropriate legal basis 🚨

Legal basis | 28/03/2025

πŸ“ Greece | HDPA | €150,000 Fine

πŸ”
Following a complaint, the Hellenic Data Protection Authority (HDPA) investigated an IT services company (SS2I) regarding the processing of employee data.

❌ Issue Identified:
Employees were forced to give their consent for the processing of their personal data.

πŸ’‘ Key Point:
πŸ‘‰ Consent cannot be considered freely given when there is a relationship of subordination between the data subject and the controller.
πŸ‘‰ In the workplace, employees must have a genuine choice, and must not suffer consequences or discrimination for refusing.

πŸ“œ Violations Noted:

  • Articles 5.1.a and 5.2 of the GDPR: Principle of lawfulness and accountability.
  • Article 6.1.a of the GDPR: Use of consent as an inappropriate legal basis.

βš–οΈ Consequences:
πŸ’Έ Administrative fine of €150,000
πŸ“‰ Damage to reputation
πŸ”§ Obligation to bring data processing activities into compliance

πŸ“’ Key Takeaway:
Consent is not the default legal basis in an employment context.
Controllers should consider other valid grounds (e.g., performance of a contract, legal obligation, legitimate interest) depending on the processing purpose.



Back to news list

Explore all our areas of expertise:

]]>