Two ANSPDCP fines that started from a mundane habit: a file with medical data that circulated internally.
The National Supervisory Authority for Personal Data Processing (ANSPDCP) recently announced the conclusion of an investigation closed in December 2025, which resulted in two fines for breaches related to data minimisation and security of processing. The case is relevant for any employer, because it stems from a seemingly mundane situation: the internal circulation of an Excel file.
The investigation was triggered after the controller submitted a personal data breach notification, in line with the incident reporting obligations. In essence, internally an Excel file was repeatedly distributed which contained a register of current and former employees, including medical data (information from medical certificates).
During the checks, the Authority found that there were no sufficient technical and organisational measures to ensure the security of the data and the resilience of the processing systems. The vulnerability made possible unauthorised access to the personal data of a significant number of data subjects.
The ANSPDCP imposed two separate fines:
In addition, a corrective measure was imposed: the implementation, through a technical and organisational procedure, of all processes that involve personal data processing, including a monitoring and control mechanism for the rapid identification of security incidents.
1) Data minimisation (Art. 5(1)(c) GDPR)
The principle says, in plain terms, that an organisation must work with data that is adequate, relevant and limited to what is necessary for the intended purpose. A register "rich" in information, distributed by email or via an internal share, is exactly the kind of practice that can quickly go beyond what is necessary, especially when it includes sensitive information such as medical data.
2) Accountability (Art. 5(2) GDPR)
It is not enough to "believe" you comply with the rules. You must be able to demonstrate that you have clear processes, decisions, controls and evidence: who has access, why, how it is shared, how long it is kept, who approves and who checks.
3) Security of processing (Art. 32 GDPR)
GDPR requires technical and organisational measures appropriate to the risk, including the ability to ensure the confidentiality, integrity, availability and resilience of processing systems and services. In other words: not just "we have passwords", but real controls, proportionate to the sensitivity of the data and to the possible impact on people.
Excel files are convenient but hard to control: they are easily copied, forwarded, saved locally, end up in shared folders and become impossible to track. When medical data is also involved, the risk increases significantly. Even without a "spectacular" breach, the mere lack of control over access and distribution can lead to unauthorised access and, consequently, to penalties.
In practice, prevention comes down to a few very clear decisions:
First, reduce the data in registers. If a department needs to know that a person is on sick leave, in most cases it does not need the details from the certificate. Keep the information strictly necessary for the purpose and limit access to the rest.
Then, take sensitive data out of "files that circulate". For HR, use a system (HRIS, DMS, ticketing) with role-based access control, an audit log and sharing rules. If a file must still be used, set firm rules: named access, minimum permissions, a download ban where possible, expiry, traceability.
Introduce security measures appropriate to the risk: access policies, multi-factor authentication, encryption where appropriate, segmentation of rights, logging, alerts on unusual distribution, DLP (Data Loss Prevention) controls to block the internal/external sending of files with sensitive content.
Last but not least, put down on paper and into practice a process for monitoring and control of processing, so that incidents are detected quickly, investigated and stopped at the source. It was precisely this area that the Authority also highlighted in the corrective measure it imposed.
The message of this penalty is simple: there need not be a sophisticated attack for serious consequences to arise. Sometimes, the risk comes from an "inherited" internal habit — an Excel file that circulates and contains more than it should. A pragmatic review of HR flows, access and sharing rules can quickly reduce the risk and prevent costs, wasted time and reputational exposure.
Excel files are convenient but hard to control: they are easily copied, forwarded, saved locally and end up in shared folders, becoming impossible to track. When they also contain medical data — a special category of data protected by Art. 9 GDPR — the mere lack of control over access and distribution can lead to unauthorised access and, consequently, to penalties, even without a sophisticated attack.
It can be. If the technical and organisational measures appropriate to the risk are missing and the file becomes accessible to unauthorised persons, this amounts to unauthorised access to personal data, that is, a security breach within the meaning of Art. 32 and 33 GDPR. In the case fined by the ANSPDCP, precisely such an incident triggered the investigation and the notification to the Authority.
Stop the distribution and immediately restrict access to the file, document which data and how many data subjects were affected, assess the risk to individuals' rights and record the incident in the internal register. If the risk is not mitigated, notify the ANSPDCP within 72 hours (Art. 33 GDPR) and, where appropriate, inform the data subjects (Art. 34). Then fix the cause: reduce the data, take sensitive information out of files that circulate and introduce access control.
Reduce the data in registers to what is strictly necessary for the purpose, take sensitive data out of files that circulate and use a system (HRIS, DMS, ticketing) with role-based access control, an audit log and sharing rules. Add security measures appropriate to the risk — multi-factor authentication, encryption, logging, alerts and DLP controls — and put in place a monitoring and control process that detects incidents quickly.
We analyse your HR data flows and build the security and control measures that fit the risk.