{"id":16623,"date":"2024-09-23T07:32:38","date_gmt":"2024-09-23T07:32:38","guid":{"rendered":"https:\/\/businessadapter.es\/penalty-for-sharing-passwords-at-work\/"},"modified":"2024-12-11T10:44:55","modified_gmt":"2024-12-11T10:44:55","slug":"penalty-for-sharing-passwords-at-work","status":"publish","type":"post","link":"https:\/\/businessadapter.es\/en\/penalty-for-sharing-passwords-at-work\/","title":{"rendered":"Penalty for sharing passwords at work"},"content":{"rendered":"\n<h1><span style=\"color: #800000;\"><strong>Penalty for sharing passwords at work<\/strong><\/span><\/h1>\n<p style=\"text-align: justify;\">The <a href=\"https:\/\/businessadapter.es\/en\/who-is-the-data-controller\/\">Data Controller<\/a> has the obligation to train its employees in <a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/formacion-proteccion-datos-valencia\">data protection and digital rights<\/a>, not only because it is considered a legal obligation, deriving from Article 24.1 and 39.1 of the <a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\" target=\"_blank\" rel=\"noopener\">RGPD<\/a>, as well as 88.3 of the <a href=\"https:\/\/www.boe.es\/boe\/dias\/2018\/12\/06\/pdfs\/BOE-A-2018-16673.pdf\" target=\"_blank\" rel=\"noopener\">LOPDGDD<\/a>, but also because it is a fundamental part of the good health of any company.<\/p>\n<p style=\"text-align: justify;\">Who has never left their computer unlocked when they had to leave their place of work? Or who has never lent their access codes to a co-worker to check some information? <\/p>\n<h2><span style=\"color: #800000;\"><strong>Economic risks and loss of confidentiality<\/strong><\/span><\/h2>\n<p style=\"text-align: justify;\">But these practices, which may seem everyday and unimportant, can pose a high risk for <a href=\"https:\/\/businessadapter.es\/en\/who-is-the-data-controller\/\">data controllers<\/a>, both financially, due to the risk of penalties, as we shall see, and because of the danger to the confidentiality of the information processed by the company.  <\/p>\n<p style=\"text-align: justify;\">And as an example of this, we bring up <a href=\"https:\/\/apdcat.gencat.cat\/ca\/documentacio\/resolucions-dictamens-i-informes\/cercadorOn\/cercador-detall\/PS-13-2024-00001\" target=\"_blank\" rel=\"noopener\">Resolution PS 13\/2024<\/a> issued by l&#8217;Autoritat Catalana de Protecci\u00f3 de Dades<a href=\"https:\/\/apdcat.gencat.cat\/es\/inici\/index.html\" target=\"_blank\" rel=\"noopener\">(APDCAT<\/a>), in which an employee of a City Council was involved in the following situation<a href=\"https:\/\/businessadapter.es\/en\/\"><img decoding=\"async\" class=\" wp-image-15006 alignright\" src=\"https:\/\/businessadapter.es\/wp-content\/uploads\/2024\/09\/multa-300x300.png\" alt=\"\" width=\"378\" height=\"378\" srcset=\"https:\/\/businessadapter.es\/wp-content\/uploads\/2024\/09\/multa-300x300.png 300w, https:\/\/businessadapter.es\/wp-content\/uploads\/2024\/09\/multa-150x150.png 150w, https:\/\/businessadapter.es\/wp-content\/uploads\/2024\/09\/multa-50x50.png 50w, https:\/\/businessadapter.es\/wp-content\/uploads\/2024\/09\/multa-320x320.png 320w, https:\/\/businessadapter.es\/wp-content\/uploads\/2024\/09\/multa.png 512w\" sizes=\"(max-width: 378px) 100vw, 378px\" \/><\/a> was immersed in the following situation:<\/p>\n<p>City Hall personnel verbally requested the employee to provide a new employee with her personal access codes to certain platforms, which were necessary for the performance of her duties.<\/p>\n<p style=\"text-align: justify;\">It should be noted that the City did not generate personalized access codes for the new employee from the beginning of the provision of her professional services, but only at a later time.<\/p>\n<p>In this situation, the employee provided her personal access codes to the new employee.<\/p>\n<p>The Catalan supervisory authority notes the following in its resolution:<\/p>\n<h2><span style=\"color: #800000;\"><strong>Consent was not free  <\/strong><\/span><\/h2>\n<p style=\"text-align: justify;\">As regards the employee&#8217;s consent for a third party to use her personal access codes, it is considered that the employee of the City Council did not give her consent to the use of her codes in a free and voluntary manner, taking into account the employment relationship existing between her and the local corporation.<\/p>\n<p style=\"text-align: justify;\">On the other hand, if the employee had refused to provide her personal access codes to the external person who was performing support tasks, being necessary the use of such codes for the performance of her assigned functions, it could generate some negative consequence for the employee of the City Council on the part of the latter.<\/p>\n<h2><span style=\"color: #800000;\"><strong>The City Council is responsible for this situation<\/strong><\/span><\/h2>\n<p style=\"text-align: justify;\">With regard to the sharing of access credentials between the two workers, the City Council must be held responsible for its failure to provide the new worker with the necessary tools for the performance of the assigned functions, as in this case, the use of certain platforms that she had to access with a personal password. Therefore, the unlawful processing of this personal data is the responsibility of the City Council, and not of the workers. <\/p>\n<p style=\"text-align: justify;\">In the case under analysis, the Catalan supervisory authority stated that there had been an infringement of art. 5.1 a) <a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\" target=\"_blank\" rel=\"noopener\">RGPD<\/a>, constituting a very serious infringement, according to art. 83.5 of the <a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\" target=\"_blank\" rel=\"noopener\">RGPD<\/a> and art. 72.1 a) <a href=\"https:\/\/www.boe.es\/boe\/dias\/2018\/12\/06\/pdfs\/BOE-A-2018-16673.pdf\" target=\"_blank\" rel=\"noopener\">LOPDGDD.<\/a><\/p>\n<h2><span style=\"color: #800000;\"><strong>Recommendations<\/strong><\/span><\/h2>\n<p style=\"text-align: justify;\">If you are a worker, and to carry out your daily work you need to use users, passwords, PIN&#8217;s or any other access key that is considered personal, you cannot share it with anyone, because it is considered a processing of personal data and there is no legal basis of art. 6 <a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\" target=\"_blank\" rel=\"noopener\">RGPD<\/a> that justifies it.<\/p>\n<p style=\"text-align: justify;\">Companies cannot lose sight of the fact that legal entities are liable for the actions of their employees or workers, as stated by the Supreme Court<a href=\"https:\/\/www.icaoviedo.es\/res\/comun\/biblioteca\/3767\/TS.%20PROTECCION%20DE%20DATOS.pdf\" target=\"_blank\" rel=\"noopener\">(Judgment No. 543\/2022 (ECLI:ES:TS:2022:543):<\/a><\/p>\n<p style=\"text-align: justify;\">&#8220;<em>Finally, it should be recalled that legal entities are liable for the actions of their employees or workers. In this sense STC 246\/1991, of December 19, f.j 2. cannot be excused in its diligent performance, separately from the performance of its employees, but it is the &#8220;guilty&#8221; performance of these, consequence of the violation of the existing safety measures, which is the basis for the liability of the company in the sanctioning scope for &#8220;own&#8221; acts of its employees or positions, not those of third parties&#8221;.    <\/em><\/p>\n<p style=\"text-align: justify;\">In addition to what has been said so far, the most important thing is that all employees know their functions and that they are carried out applying at all times the provisions of the <a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/proteccion-datos-valencia\">data protection regulations<\/a>, obtaining <a href=\"https:\/\/www.incibe.es\/incibe\/formacion\/moocs\" target=\"_blank\" rel=\"noopener\">basic training on cybersecurity<\/a> to know how to react to events such as this and others such as security breaches and prevention of cybercrime, as well as training in <a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/formacion-proteccion-datos-valencia\">data protection and digital rights<\/a>, is very important to create or strengthen a culture in this area, avoiding sanction or reputational risks. <strong>Training is an investment<\/strong>.<\/p>\n<h2><span style=\"color: #800000;\"><strong>Business Adapter\u00ae at your service  <\/strong><\/span><\/h2>\n<p>If you need training or advice, contact us by email: <a href=\"mailto:info@businessadapter.es,%20\">info@businessadapter.es, <\/a> you can also call <a href=\"http:\/\/tel.961318804\">96 131 88 04<\/a>, or leave your message in this form:<\/p>\n<p>                    <\/p>\n<p><strong>[su_button url=&#8221;https:\/\/businessadapter.es\/contacto&#8221; target=&#8221;blank&#8221; background=&#8221;#f6f903&#8243; color=&#8221;#181818&#8243; size=&#8221;7&#8243; center=&#8221;yes&#8221; icon_color=&#8221;#000000&#8243;]Contact us, we will be pleased to help you.[\/su_button]<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Penalty for sharing passwords at work The Data Controller has the obligation to train its employees in data protection and [&hellip;]<\/p>\n","protected":false},"author":1373,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[75],"tags":[],"class_list":["post-16623","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16623","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/users\/1373"}],"replies":[{"embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/comments?post=16623"}],"version-history":[{"count":1,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16623\/revisions"}],"predecessor-version":[{"id":16625,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16623\/revisions\/16625"}],"wp:attachment":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/media?parent=16623"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/categories?post=16623"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/tags?post=16623"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}