Duyurular
Spanish Supervisory Authority Fines UNIQLO EUROPE, LTD for Violations of Article 5.1(f) and 32 of the GDPR
Data Protection Law
On September 2, 2024, the European Data Protection Board ("EDPB") published on its official website the news that the complainant in this case, whose employment contract had been terminated, requested access to their payroll information for July 2022. In response to this request, the controller sent an email to the complainant with an attached PDF document containing his payroll and the payroll of 446 other staff members.
According to the announcement;
- The documentation in the file offers clear indications that UNIQLO violated article 5.1.f) of the GDPR, by not duly guaranteeing the confidentiality and integrity of the personal data of its employees, having been brought to the attention of an unauthorized third party. This duty of confidentiality and integrity must be understood as having the purpose of preventing data leaks that are not consented by the data subject.
- The documentation shows the violation of article 32.1 of the GDPR, due to the failure to adopt appropriate technical and organisational measures.
As a result;
- The Spanish Supervisory Authority, AEPD imposed a total fine of 450,000 Euros for the infringement, which was reduced to 270,000 Euros, based on provisions in the Spanish law allowing for a reduction in the fine amount when a controller voluntarily pays the fine and acknowledges responsibility for the violation.
You can reach further information here.
You can reach the Spanish SA’s press release (in Spanish) here.
Kind regards,
Zumbul Attorneyssat-Law
Türkçe
English