{"id":14504,"date":"2023-09-11T07:00:42","date_gmt":"2023-09-11T07:00:42","guid":{"rendered":"https:\/\/letslaw.es\/?p=14504"},"modified":"2023-09-06T10:44:05","modified_gmt":"2023-09-06T10:44:05","slug":"sanction-of-10000-euros-to-gymoogymnasios-by-the-aepd-for-forcing-its-clients-to-transfer-their-health-data","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/sanction-of-10000-euros-to-gymoogymnasios-by-the-aepd-for-forcing-its-clients-to-transfer-their-health-data\/","title":{"rendered":"Sanction of 10,000 euros to Gymoogymnasios by the AEPD for forcing its clients to transfer their health data"},"content":{"rendered":"<p>In the digital age, the preservation of personal information becomes a crucial issue as we live in an increasingly interconnected world. The privacy and security of personal data stand as fundamental pillars in this context.<\/p>\n<p>Recently, Gymoogimnasios, a well-known gym chain, <strong>was fined 10,000 euros by the AEPD<\/strong> due to its practice of requiring customers to share personal data about their health as a requirement for booking activities and accessing gym facilities.<\/p>\n<p>To fulfill this request, <strong>they were required to accept a box<\/strong>, without which it was not possible to complete the registration process through the application used to make reservations.<\/p>\n<p>The AEPD has concluded that this action constitutes unnecessary and disproportionate data processing.<\/p>\n<p>This case illustrates the legal keys to data protection and the serious consequences of not complying with current regulations.<\/p>\n<h2>Legal keys to data protection<\/h2>\n<p>Compliance with the legal keys of data protection is essential not only <strong>to avoid this type of sanctions<\/strong>, but also to <strong>protect people&#8217;s privacy<\/strong>, maintain a solid reputation and compete effectively in today&#8217;s market.<\/p>\n<p>It is not only a matter of legal compliance, but also a demonstration of responsibility and respect for the fundamental privacy rights of people in the digital age.<\/p>\n<p>In this sense, the most important legal aspects or keys to take into account when processing personal data are the following:<\/p>\n<ul>\n<li><strong>Informed consent:<\/strong> Companies must obtain informed consent from individuals before collecting their personal data. This consent must be specific and free, meaning that people must have the option to refuse without consequences.<\/li>\n<li><strong>Limited purpose:<\/strong> Personal data may only be collected and processed for specific and legitimate purposes. In the case of Gymoogymnasios, the collection of customer health data must have a clear and legal justification, such as ensuring safety during physical exercise.<\/li>\n<li><strong>Data minimization:<\/strong> Only data necessary for the intended purpose should be collected. Individuals cannot be required to provide additional information that is not relevant to the activity.<\/li>\n<li><strong>Data security:<\/strong> Companies have an obligation to protect personal data from unauthorized access or disclosure. This involves the implementation of appropriate security measures.<\/li>\n<\/ul>\n<h2>Consequences of transferring personal health data<\/h2>\n<p>The GDPR thoroughly regulates the processing of health data. This is mainly carried out in its article 9. <strong>Health data is of a particularly sensitive nature<\/strong>, and the aforementioned article establishes that, in principle, the processing of health data is prohibited unless one of the specific conditions is met. listed therein.<\/p>\n<p>These conditions include the <strong>explicit consent of the data subject<\/strong>, the need for medical treatment, the management of insurance claims and other special circumstances.<\/p>\n<p>When companies like Gymoogimnasios force or induce their clients to give up this type of data without complying with the provisions of data protection laws, they face serious consequences, as evidenced in this case.<\/p>\n<h3>Significant fines, damage the reputation and criminal sanctions<\/h3>\n<p>On the one hand, it is clear that data protection authorities, such as the AEPD in Spain, can impose <strong>significant fines<\/strong> on companies that violate data protection laws.<\/p>\n<p>This type of action can result in companies that do not adequately protect the personal data of their customers suffering <strong>damage to their reputation.<\/strong> Customers may lose trust in the company, leading to long-term loss of business.<\/p>\n<p>Additionally, individuals whose health data is collected illegally may themselves <strong>take legal action<\/strong> against the company. This can result in costly litigation and damage to the company&#8217;s image. And, in extreme cases, serious violations of the principles enshrined in the protection of personal data can lead to <strong>criminal sanctions<\/strong>, including the possibility of imprisonment for those responsible for companies that fail to comply.<\/p>\n<p>Ultimately, the Gymoogimnasios case and the sanction imposed by the AEPD highlight the critical importance of complying with data protection laws.<\/p>\n<p>Forcing customers to give up their personal health data without their proper consent and clear legal justification can have significant financial and legal consequences for companies.<\/p>\n<p>In the era of digital privacy, <strong>personal data protection must be a priority<\/strong> for all organizations that handle sensitive personal information.<\/p>\n<p>At Letslaw we are experts in <a title=\"Data protection lawyers - Letslaw\" href=\"https:\/\/letslaw.es\/en\/privacy-data-protection-lawyers\/\">Data Protection<\/a> and we can advise you on everything you need.<\/p>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/14504#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>In the digital age, the preservation of personal information becomes a crucial issue as we live in an increasingly interconnected world. The privacy and security of personal data stand as fundamental pillars in this context.<\/p>\n","protected":false},"author":2,"featured_media":14502,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[243],"tags":[],"class_list":["post-14504","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/14504","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=14504"}],"version-history":[{"count":3,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/14504\/revisions"}],"predecessor-version":[{"id":14507,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/14504\/revisions\/14507"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/14502"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=14504"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=14504"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=14504"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}