The Spanish Data Protection Authority recently fined LVMH Iberia $70,000 – later reduced to €42,000, because an employee did not want her personal number to be added to a WhatsApp group for work. Shocking? Yes. Unexpected? No… remember GDPR?!
The story
The company used the phone number of this employee despite her explicit request not to be contacted. She had even sent an email to her managers confirming that she would only rejoin a WhatsApp group after she received a work phone (which had been promised but never provided) upon returning from her holiday. A day later, she was added to a new WhatsApp company group despite her request.
LVMH argued that WhatsApp was a non-intrusive way to organise tasks, and that the use of personal phones was “exceptional” not standard.” The AEPD disagreed. It found that the company had violated GDPR Article 6.1 by processing the employee’s personal data without consent, and also failed to respect her right to digital disconnection.
In 2025 we are more conscious than ever about how our data is processed and what we are, or are not comfortable sharing. Cases like this remind us that respecting boundaries is not only good practice, but also the law.
Where is the risk?
The way we communicate is changing, and not only in our personal lives but at work too. While apps like WhatsApp or Telegram might feel convenient, they are not always the right choice for workplace communication as they potentially mix the personal with the professional. We strongly suggest using related working applications such as Teams or Slack, or keep it simpler by sticking to the organisation’s email.
This will not only protect your employees’ privacy, but also helps your organisation stay on track with current legislation:
- GDPR as per the example above
- the increasingly strengthened Workers Protection Act looking at sexual harassment, requiring employers to take proactive action (such as training) to prevent sexual harassment.
- the incoming Employment Rights Bill which includes protection from sexual harassment by third parties.
WhatsApp is only one platform we use as an example but there are others. Simply put, using work systems for work communications means that communication can be overseen and managed where needed (for example an investigation). This leaves employees able to control the use of personal number, and therefore able to leave groups / bar numbers as they see fit – for communications outside the workplace.
Check your current practice
Looking at this case, does it resonate with your current practices? Or have you ever:
- added an employee’s personal number into a workplace WhatsApp or group chat without consent?
- contacted an employee during their holidays or outside agreed working hours?
- circulated personal email addresses or phone numbers instead of using official work channels?
- assumed that because someone once shared their number, it’s acceptable to keep using it for work purposes?
- chosen what’s easy over what’s within our control to oversee and administer when setting up communication channels?
What you can do
So, what can you do to protect your business and ensure you are GDPR compliant?
- Identify and collect only the personal data you need.
- Assess how long you will retain each data according to ICO standards, and keep this as your retention schedule.
- Create and share your (accurate) Employee Privacy Notice setting out exactly what information you hold and how it is used. You can generate one yourself via the Information Commissioners Office website; here.
- Create documentation including a record of your organisation processing activities for employee data, covering areas such as processing purposes, data sharing and retention. You can find more information and download your template here
- Store employee data securely with controlled access. One great way to do that is via a reputable HR Information System.
- Ensure data is accessible only for those who might need it and when they need it
- Provide regular training to your employees
- Carry out regular audits
Following these steps will require a bit of work from your side, but it will ensure you are keeping up with best practice, protecting your team and that you are compliant – avoiding damaging legal cases and expensive fines.
If you are concerned about not only your GDPR practices but also the wider way on how you operate as an organisation, we have created a very quick questionnaire to help you understand any gaps i your current practice which could introduce costly risks. You can complete it for free anytime here.
By Oscar Alvarez