Categories: Insights, Publications · News, Publications

Tag: Dismissal, Licenziamento, protezione dei dati personali


30 Oct 2025

Use of personal devices for business purposes. What are the employer’s risks?

The Spanish Data Protection Authority (i.e. “AEPD”) initiated sanction proceedings against a Spanish company belonging to an international group, following a complaint filed by a former employee.

The employee alleged that the company had added her personal mobile phone number to a corporate WhatsApp group, without her consent, for work-related purposes while waiting to receive a company phone – which she never actually received. Before taking a holiday, the employee had expressly notified the company by email that she would stop using her private number for work matters and had left the corporate WhatsApp group. However, only a few days later, her number was added again to a company group chat. The company argued that the inclusion was temporary, pending delivery of the business phone, and that WhatsApp groups were used solely for internal work communications among employees.

The AEPD, however, found that the use of the employee’s personal number without consent violated Article 6, paragraph 1, of the GDPR, which requires a lawful basis for any processing of personal data.

Legal basis and decision of the Authority

The Spanish Authority recalled that a personal mobile phone number is a personal data item, and that its use to include an employee in a corporate messaging group constitutes data processing which must rely on one of the legal bases set out in Article 6, paragraph 1, of the GDPR.

  • The GDPR requires that personal data be processed lawfully – Article 5 (1)(a).
  • For processing to be lawful, one of the following conditions must be met – Article 6 (1):
  • the data subject has given consent to the processing of their personal data for one or more specific purposes;
  • the processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the data subject’s request prior to entering into a contract;
  • the processing is necessary for compliance with a legal obligation to which the controller is subject;
  • [omitted].

In the case under review, there was no consent from the data subject, nor any contractual necessity or other legitimate ground for processing. Moreover, the Spanish Authority stated that the existence of an internal company policy on the use of mobile devices does not exempt the employer from the obligation to establish a proper legal basis for processing.

The company was therefore fined €70,000, reduced to €42,000 after it acknowledged the violation and opted to pay the reduced amount. The AEPD also ordered the company to adopt corrective measures to ensure future compliance with the GDPR.

Bring Your Own Device

BYOD (Bring Your Own Device) policies are corporate rules governing the use of personal devices – such as smartphones, laptops, or tablets – for work-related purposes.

In practice, a BYOD policy sets out how employees may use their personal devices to access corporate data, emails, or applications, and defines the relevant security measures.

It is always preferable for companies to provide corporate devices and maintain a clear separation between personal and business tools. However, if the employer decides to allow employees to use personal devices for business purposes, a documented internal policy should be adopted, regulating:

  • cybersecurity requirements,
  • limits on use,
  • measures to protect employee privacy,
  • procedures for deletion of corporate data,
  • information and consent obligations (where applicable).

Other related insights:

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

6 Feb 2026

Pay equity and transparency: draft implementing decree presented

Italy is among the first Member States to have adopted the draft implementing legislative decree of EU Directive 2023/970, which yesterday received its initial approval from the Council…

30 Jan 2026

A conviction for stalking can justify dismissal for just cause

With Ordinance No. 32952 of 17 December 2025, the Italian Supreme Court, Labour Section, ruled that a final conviction for stalking and abuse can justify dismissal for just…

30 Jan 2026

We continue to be a Great Place to Work!

For the third consecutive year, De Luca & Partners has been awarded the prestigious Great Place to Work® certification, a significant recognition of the value we place on…

29 Jan 2026

Italian Supreme Court: Employer Monitoring and the Use of Corporate Chats for Disciplinary Purposes

Corporate chats “intended for work-related communications by employees accessing them through company accounts constitute work tools, pursuant to Article 4, paragraph 2, of Law No. 300 of 1970,…

28 Jan 2026

Anti-union conduct: the Supreme Court moves beyond formalism and focuses on substance

With order no. 789 of 14 January 2026, the Italian Supreme Court addressed the issue of anti-union conduct by employers in relation to information and consultation obligations on…

27 Jan 2026

DID YOU KNOW THAT… the use of artificial intelligence may justify a dismissal for objective justified reason?

With Judgment No. 9135 of November 19, 2025, the Labour Section of the Court of Rome held that the dismissal for objective justified reason (i.e. “giustificato motivo oggettivo”,…