Categories: Insights, Publications · News, Publications

Tag: Dismissal, Licenziamento, protezione dei dati personali


30 Oct 2025

Use of personal devices for business purposes. What are the employer’s risks?

The Spanish Data Protection Authority (i.e. “AEPD”) initiated sanction proceedings against a Spanish company belonging to an international group, following a complaint filed by a former employee.

The employee alleged that the company had added her personal mobile phone number to a corporate WhatsApp group, without her consent, for work-related purposes while waiting to receive a company phone – which she never actually received. Before taking a holiday, the employee had expressly notified the company by email that she would stop using her private number for work matters and had left the corporate WhatsApp group. However, only a few days later, her number was added again to a company group chat. The company argued that the inclusion was temporary, pending delivery of the business phone, and that WhatsApp groups were used solely for internal work communications among employees.

The AEPD, however, found that the use of the employee’s personal number without consent violated Article 6, paragraph 1, of the GDPR, which requires a lawful basis for any processing of personal data.

Legal basis and decision of the Authority

The Spanish Authority recalled that a personal mobile phone number is a personal data item, and that its use to include an employee in a corporate messaging group constitutes data processing which must rely on one of the legal bases set out in Article 6, paragraph 1, of the GDPR.

  • The GDPR requires that personal data be processed lawfully – Article 5 (1)(a).
  • For processing to be lawful, one of the following conditions must be met – Article 6 (1):
  • the data subject has given consent to the processing of their personal data for one or more specific purposes;
  • the processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the data subject’s request prior to entering into a contract;
  • the processing is necessary for compliance with a legal obligation to which the controller is subject;
  • [omitted].

In the case under review, there was no consent from the data subject, nor any contractual necessity or other legitimate ground for processing. Moreover, the Spanish Authority stated that the existence of an internal company policy on the use of mobile devices does not exempt the employer from the obligation to establish a proper legal basis for processing.

The company was therefore fined €70,000, reduced to €42,000 after it acknowledged the violation and opted to pay the reduced amount. The AEPD also ordered the company to adopt corrective measures to ensure future compliance with the GDPR.

Bring Your Own Device

BYOD (Bring Your Own Device) policies are corporate rules governing the use of personal devices – such as smartphones, laptops, or tablets – for work-related purposes.

In practice, a BYOD policy sets out how employees may use their personal devices to access corporate data, emails, or applications, and defines the relevant security measures.

It is always preferable for companies to provide corporate devices and maintain a clear separation between personal and business tools. However, if the employer decides to allow employees to use personal devices for business purposes, a documented internal policy should be adopted, regulating:

  • cybersecurity requirements,
  • limits on use,
  • measures to protect employee privacy,
  • procedures for deletion of corporate data,
  • information and consent obligations (where applicable).

Other related insights:

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

3 Aug 2026

Pay Transparency: the first requests from employees are starting to arrive (Il Sole 24 Ore, 3 august 2026 – Vittorio De Luca)

Two months after the decree. Since Legislative Decree 96/2026 came into force on 7 June, according to a flash survey conducted by GIDP, 8% of HR directors have…

30 Jul 2026

Corporate controls and data protection: what balance?

A recent judgment of the Court of Pisa, No. 800 of 13 June 2026, addresses a topic of particular interest for companies: the delicate balance between the protection…

30 Jul 2026

Unfair dismissal and reinstatement: the employee must repay the payment in lieu of notice

With order no. 22187 of 28 June 2026, the Italian Supreme Court addressed the issue of whether payment in lieu of notice paid to an employee must be…

30 Jul 2026

Did you know that… an employee’s natural incapacity does not prevent the time limit for challenging a dismissal from running?

In judgment no. 23486 of 18 July 2026, the Joint Chambers of the Italian Supreme Court (i.e. “Corte di Cassazione”) held that the natural incapacity of an employee…

22 Jul 2026

An employee may not steer clients toward a competitor before resigning (Camera di Commercio Francese in Italia, 22 July 2026 – Vittorio De Luca, Silvia Zulato)

With Order No. 1723 of 26 May 2026, the Italian Supreme Court (Corte di Cassazione) confirmed the liability of an employee who, prior to the termination of his…

20 Jul 2026

Access to Naspi (Top24 Lavoro Ai – Il Sole 24 Ore, 20 July 2026 – Vittorio De Luca e Alessandra Zilla)

Regulatory Framework  The New Social Insurance for Employment (NASpI), introduced by Legislative Decree No. 22 of 4 March 2015, is the primary income support scheme for employees who…