20,000 Euro Fine Imposed on DOS MIL PALABRAS by the Spanish Authority for Unrestricted Dissemination of Minors' Personal Data

The Spanish authority sanctions a media outlet for broadcasting a viral video showing the assault of a minor, ruling that freedom of information does not justify a breach of the data minimization principle.

Facts and Context

The Spanish Data Protection Authority (AEPD) has today published a sanction decision against the company DOS MIL PALABRAS SL (including the imposition of a €20,000 fine) for breaches related to the dissemination of a video enabling the identification of a minor.

The case originated from an ex officio investigation by the authority concerning the publication by a media outlet of a video showing the physical assault of a man by a minor under 16 years old, a video that had previously been circulated on social networks.

Grounds for the Decision

  • Data minimization obligation (Article 5(1)(c) of the GDPR): The authority considered that the dissemination of the video, which allowed identification of the minor aggressor and his victim by their image and voice, constituted excessive data processing. It recalled that while freedom of information is a fundamental right, it must be balanced with the right to data protection, in accordance with Article 85 of the GDPR and Recital 4. Based on case law from the European Court of Human Rights (notably the judgment of 19 June 2012, application 1593/2006) and Spanish courts (STC 27/2020 and Sentencia 777/2021), the authority concluded that the dissemination of images of non-public persons, especially minors, was neither necessary nor proportionate to inform about the event. The fact that the video had previously gone viral on social networks does not exempt the controller from their own obligation to minimize the data processed.

Authority's Decision

Consequently, the authority imposed a €20,000 fine on DOS MIL PALABRAS SL.

Furthermore, the authority ordered the company to implement, within three months, corrective measures to ensure compliance with the minimization principle, notably by permanently ceasing the processing or applying techniques preventing any identification.

Lessons Learned

This decision confirms that:

  • Prior dissemination of personal data on social networks, even on a large scale, does not exempt a controller from their own obligations under the GDPR when they process it in turn.
  • In the journalistic context, freedom of information only justifies the dissemination of images or voices of identifiable persons if such processing is strictly necessary and proportionate to the informational purpose, which must be assessed on a case-by-case basis.
  • The protection of minors' data is strengthened and generally takes precedence over the public interest in being informed, strictly limiting the possibility of disseminating information enabling their identification, even if they are perpetrators of offenses.
  • Press bodies act as controllers and must, before any publication, ensure the lawfulness of the processing, notably by conducting a risk assessment and applying GDPR principles, including minimization.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire