{"id":121598,"date":"2025-06-11T17:57:24","date_gmt":"2025-06-11T15:57:24","guid":{"rendered":"https:\/\/aseryde.com\/?p=121598"},"modified":"2025-06-11T18:13:43","modified_gmt":"2025-06-11T16:13:43","slug":"la-aepd-advierte-las-empresas-deben-recabar-consentimiento-expreso-antes-de-anadir-moviles-personales-a-grupos-de-whatsapp","status":"publish","type":"post","link":"https:\/\/aseryde.com\/en\/la-aepd-advierte-las-empresas-deben-recabar-consentimiento-expreso-antes-de-anadir-moviles-personales-a-grupos-de-whatsapp\/","title":{"rendered":"The Spanish Data Protection Agency (AEPD) warns: companies must obtain express consent before adding personal mobile phones to WhatsApp groups."},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"121598\" class=\"elementor elementor-121598\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c7885fe elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c7885fe\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3f10bd5\" data-id=\"3f10bd5\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-d4b9805 elementor-widget elementor-widget-text-editor\" data-id=\"d4b9805\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Two recent resolutions from the Spanish Data Protection Agency (AEPD) \u2014<\/span><b>penalties of \u20ac2,000 and \u20ac70,000<\/b><span style=\"font-weight: 400;\">\u2014 confirm that including an employee in a corporate WhatsApp group or sending work-related messages to their private number constitutes data processing that requires a legitimate basis. Companies that ignore this requirement face heavy fines and the obligation to implement corrective measures.\u00a0<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-5e7a9ec elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"5e7a9ec\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7ace04a\" data-id=\"7ace04a\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f9c0b5b elementor-widget elementor-widget-spacer\" data-id=\"f9c0b5b\" data-element_type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ca6bd29 elementor-widget elementor-widget-text-editor\" data-id=\"ca6bd29\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Instant messaging has become the fast track to organizing shifts, distributing tasks or resolving incidents, but its use entails a legal risk that <\/span><b>Spanish Data Protection Agency<\/b><span style=\"font-weight: 400;\"> has just put it in black and white. In two cases made public in recent weeks, the authority has sanctioned two companies for adding employees&#039; personal numbers to WhatsApp groups without prior permission:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Andalusian Special Employment Center<\/b><span style=\"font-weight: 400;\">: fine of <\/span><b>2.000 \u20ac<\/b><span style=\"font-weight: 400;\"> for creating an internal chat with the personal phone number of a newly hired teleoperator.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Luxury retail company<\/b><span style=\"font-weight: 400;\">: fine of <\/span><b>70.000 \u20ac<\/b><span style=\"font-weight: 400;\"> (reducible to \u20ac42,000 for early payment) after reinstating a worker in the group on her own day off, despite her repeated opposition and having requested a corporate terminal.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">In both cases the AEPD concludes that the mobile number is a <\/span><b>personal data<\/b><span style=\"font-weight: 400;\">; your treatment (inclusion in the chat) needs a <\/span><b>basis of legitimacy<\/b><span style=\"font-weight: 400;\"> Valid: express consent, fulfillment of a contract that clearly requires it, or a well-balanced legitimate interest. The agency reminds us that consent in the workplace <\/span><b>must be free<\/b><span style=\"font-weight: 400;\">, something that is difficult to prove when the worker is in a subordinate position.<\/span><\/p>\n<p>\u00a0<\/p>\n<h4><b>What companies should do to avoid sanctions<\/b><\/h4>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Request formal and revocable authorization<\/b><b><br \/><\/b><span style=\"font-weight: 400;\"> Before using a private phone for work purposes, obtain written permission from the employee, informing them of the purposes and their right to withdraw it at any time.<\/span><span style=\"font-weight: 400;\"><br \/><br \/><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Provide corporate devices<\/b><b><br \/><\/b><span style=\"font-weight: 400;\"> If the operation requires mobile messaging, the safest method is to provide a company-issued smartphone; the device is a corporate device, and chats are considered a work tool.<\/span><span style=\"font-weight: 400;\"><br \/><br \/><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Create alternative channels<\/b><b><br \/><\/b><span style=\"font-weight: 400;\"> Internal newsletters, intranets, or proprietary apps minimize the need to access WhatsApp with personal data.<\/span><span style=\"font-weight: 400;\"><br \/><br \/><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Limit shipping hours<\/b><b><br \/><\/b><span style=\"font-weight: 400;\"> Messages outside of business hours violate not only the GDPR but also the <\/span><b>right to digital disconnection<\/b><span style=\"font-weight: 400;\"> contemplated in the Workers&#039; Statute and the Remote Work Law.<\/span><span style=\"font-weight: 400;\"><br \/><br \/><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Internal communications policy<\/b><b><br \/><\/b><span style=\"font-weight: 400;\"> Define in writing who manages the groups, what information can be shared, and how the withdrawal of a member who revokes their consent is handled.<\/span><span style=\"font-weight: 400;\"><br \/><br \/><\/span><\/li>\n<\/ol>\n<h4><b>The precedent of the \u201curgent route\u201d in teleworking<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">The Supreme Court (STS 2-4-2024) admitted that, in teleworking exceeding 30 %, the company can request the personal number <\/span><b>only<\/b><span style=\"font-weight: 400;\"> For duly accredited emergencies. The Spanish Agency for Data Protection (AEPD) and the Supreme Court agree: outside of this exceptional scenario, private mobile phones cannot be used.<\/span><\/p>\n<h4>\u00a0<\/h4>\n<h4><b>More inspections in 2025-2026<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">The AEPD itself announced in its Strategic Plan that it will strengthen surveillance over <\/span><b>Messaging apps in the workplace<\/b><span style=\"font-weight: 400;\">, just as it already does with video surveillance and geolocation. The exemplary sanctions aim to send a clear message: <\/span><b>The \u201canything goes\u201d on WhatsApp is over<\/b><span style=\"font-weight: 400;\"> and companies must adapt their protocols to European data protection regulations.<\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-weight: 400;\">Companies and HR departments have time to review practices and avoid financial scares that, as demonstrated by the record \u20ac70,000 fine, can seriously compromise their reputation and bottom line.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>Two recent resolutions from the Spanish Data Protection Agency (AEPD)\u2014penalties of \u20ac2,000 and \u20ac70,000\u2014confirm that including an employee in a corporate WhatsApp group or sending work-related messages to their private number constitutes data processing that requires a legitimate basis. Companies that ignore this requirement will be [\u2026]<\/p>","protected":false},"author":2,"featured_media":121600,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-121598","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sin-categoria"],"_links":{"self":[{"href":"https:\/\/aseryde.com\/en\/wp-json\/wp\/v2\/posts\/121598","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aseryde.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aseryde.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aseryde.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/aseryde.com\/en\/wp-json\/wp\/v2\/comments?post=121598"}],"version-history":[{"count":7,"href":"https:\/\/aseryde.com\/en\/wp-json\/wp\/v2\/posts\/121598\/revisions"}],"predecessor-version":[{"id":121606,"href":"https:\/\/aseryde.com\/en\/wp-json\/wp\/v2\/posts\/121598\/revisions\/121606"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aseryde.com\/en\/wp-json\/wp\/v2\/media\/121600"}],"wp:attachment":[{"href":"https:\/\/aseryde.com\/en\/wp-json\/wp\/v2\/media?parent=121598"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aseryde.com\/en\/wp-json\/wp\/v2\/categories?post=121598"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aseryde.com\/en\/wp-json\/wp\/v2\/tags?post=121598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}