20/06/2024 – The Dutch Data Protection Authority (AP) has imposed a fine of 6,000 euros on the recruitment company Ambitious People Group (APG) for not promptly responding to erasure requests from three individuals. This blog discusses the AP's fine decision in detail and explains how you can avoid this within your organization.

What does the GDPR say?

Article 17(1) of the General Data Protection Regulation (GDPR) grants data subjects the right to have their personal data erased without undue delay. According to Recital 59 of the GDPR, arrangements must be in place to assist data subjects in exercising this right, such as means to submit a request electronically. The controller must respond to such requests within one month and provide reasons for any refusals. Under certain circumstances, this period can be extended by two months.

The complaints

Part of APG’s service involves contacting individuals, after they have registered on their website, with relevant job vacancies that match their profile. Consequently, APG includes personal data such as names, addresses, and phone numbers in their databases. In this case, APG contacted the involved individuals with vacancies after they had submitted erasure requests to APG. The individuals then filed complaints with the AP, claiming that APG had unjustly ignored their erasure requests.

APG’s defense

APG contends that such erasure requests can be centrally directed to the email address mentioned in their privacy statement, and they instruct their employees on how to handle data erasure requests. However, the individuals’ requests did not come through this email but were submitted directly to recruiters.

APG claims to have established adequate procedures for handling requests from data subjects and implemented sufficient policies for situations where a request is sent to a regular employee instead of the specified email address in the privacy statement. APG argues that the recruiters did not adequately handle the requests, resulting in the individuals being contacted with vacancies even after submitting erasure requests. APG believes there is no reason to impose a fine, as this was an exceptional situation caused by human error.

AP’s judgment

The AP states that the obligation under Article 17(1) GDPR is not different if data subjects do not submit their requests via the designated email address. This does not diminish the severity of the violation. APG is responsible for the actions of its employees and for ensuring policy compliance within the organization. This includes the responsibility to prevent human errors. The AP concludes that APG violated the GDPR by not adequately responding to the data erasure requests of the involved individuals and imposes a fine of 6,000 euros.

Lessons learned

This case once again shows that merely drafting policies is not sufficient if awareness within the organization is lacking. Simply having an internal policy that describes how the organization handles personal data and complies with GDPR obligations is not enough to meet the GDPR requirements. As data controller, you are responsible for the actions of your employees and must ensure a certain level of awareness to prevent privacy risks. Having a dedicated email address for (erasure) requests from data subjects can help comply with the GDPR, but it does not exempt an organization from the obligation to respond to such requests within 30 days.

Raising awareness of the privacy policy within your organization plays a crucial role and can be achieved through targeted staff training to avoid similar fines.

 

Do you want to know more?

Do you want to know how to effectively handle data subject requests within your organization? Do you want to increase your employees’ privacy awareness and strengthen your policies? Considerati offers specialized advice and customized training and can support you with various privacy issues.

Our services orContact