Logo AZ - 35 Años entregando soluciones legales

Spain | Company Fined for Forcing Employees to Install Work Apps on Their Cell Phones

Jul 29, 2026

This case serves as a significant example of the standards that may be set by the new Data Protection Law once it takes effect, particularly regarding workplace monitoring, the use of personal devices, and the proportionate processing of employees’ personal data.

The Spanish Data Protection Agency (AEPD)—the public authority responsible for safeguarding privacy and data protection, similar to the one that will be established in Chile starting in December of this year—imposed a fine of 200,000 euros (Case No.: EXP202411411) on a passenger transportation company.

In that ruling, the agency found that the company had violated multiple provisions of the General Data Protection Regulation (GDPR) by requiring its drivers to use their personal mobile devices and download apps that collected excessive amounts of data.

The complainant, a driver for the transportation company, stated that the company required him to use his personal cell phone for work purposes and to download four apps that continuously monitored his location, messages, calls, and other activity metrics, without having been sufficiently informed about the scope of this data collection.

For its part, the company explained that, while it provided company phones based on availability, it paid a monthly allowance to employees who used their personal devices to cover expenses. It also noted that these apps were essential tools for operational management and integration with third-party service platforms.

Given this situation, the AEPD found that the required applications requested permissions to access a wide variety of data that exceeded what was strictly necessary for the employment relationship, such as physical condition information, audio recording, photos, videos, and continuous geolocation.

In the agency’s view, this constituted a clear violation of the principle of data minimization. Furthermore, it determined that the consent given by employees for this processing was neither freely given nor valid, as it was imposed as a condition for performing their duties due to a lack of sufficient company-issued devices.

As stated in the ruling, “(…) it must be taken into account that the validly given consent of the data subjects—in this case, the employees—to use their personal devices for work cannot always be considered a legitimate basis.”

For its part, regarding consent to data processing, it states that “Without the aforementioned conditions, the consent given by employees cannot be considered valid, since it is not a free, specific, informed, and unambiguous expression of their will.”

It also explains that “In the case in question, employees are required by (…) to download the aforementioned applications onto their personal cell phones as a condition for performing their duties, which implies that free consent is not being obtained under the terms of the GDPR, but rather an imposition that nullifies the validity of the consent established in Article 6 of the GDPR as the legal basis for processing.”

Furthermore, the ruling notes that the employer failed in its duty to transparently inform employees, as it did not provide sufficient details regarding the scope of the data collected or the protocols for managing the deactivation of these applications at the end of the workday.

Consequently, the AEPD concludes that the company’s conduct constitutes a series of serious and very serious violations, imposing a total financial penalty of 200,000 euros.

Consequently, the company is ordered to take corrective measures within a maximum period of two months, and must demonstrate that data processing complies with the principle of data minimization, that a valid legal basis exists, and that employees are properly informed about monitoring and their right to disconnect.

Although this ruling was issued under the European General Data Protection Regulation, it serves as a relevant example of the criteria that could begin to apply in Chile with the entry into force of the new Personal Data Protection Law starting in December of this year, particularly regarding workplace monitoring, the use of personal devices, and the proportionate processing of employees’ personal data.

For more information on these issues, please contact our Labor Group:

Jorge Arredondo | Partner | jarredondo@az.cl

Jocelyn Aros | Director Labor Group | jaros@az.cl

Felipe Neira | Senior Associate | fneira@az.cl

Palmira Valdivia | Associate | pvaldivia@az.cl

Manuel Sepúlveda | Associate | msepulveda@az.cl

Catalina Díaz | Associate | cdiazp@az.cl


Be part of our multimedia platform and you can receive the latest legal news, events, podcazt and webinars.

Subscribe to our Newsletter here.

Te podría interesar