The Spanish authority closes another case against an individual following their criminal conviction for unauthorized dissemination of a video of sexual assault on a minor
The Spanish data protection authority closed a procedure for unlawful data processing, considering that the facts had already been judged and sanctioned by a criminal court.
Facts and context
The Spanish data protection authority (AEPD) published a decision to close a procedure initiated against an individual for the unauthorized dissemination of a video of sexual assault on a minor.
The case began following the authority's awareness of a press article reporting the live broadcast on a social network of the sexual assault of a minor.
Reasons for the decision
- Lack of legal basis for processing (Article 6(1) of the GDPR): The authority examined the dissemination by the person concerned of a video showing the sexual assault of a minor, recorded and shared on a messaging application. This processing of personal data, including images of the victim naked and in a vulnerable state, was carried out without any legal basis. However, the authority noted that these facts had already been the subject of a criminal procedure, resulting in the conviction of the person concerned for an offense of disclosure of secrets by a sentence dated ***FECHA.8.
Decision of the authority
Consequently, the authority decided to close the procedure initiated against A.A.A.
Lessons learned
This decision recalls that:
- A final criminal conviction for facts also constituting a violation of the GDPR may lead the supervisory authority to close its own sanction procedure, considering that the responsibility of the perpetrator has already been established and sanctioned.
- The non-consensual dissemination of intimate images, particularly those of a minor victim of an offense, constitutes an extremely serious unlawful data processing that falls within the competence of both data protection authorities and criminal courts.
- The mere receipt and sharing of unlawful content via private messaging constitutes processing of personal data engaging the responsibility of the disseminator, even if the content is subsequently deleted.
- Supervisory authorities may initiate investigations based on public information, such as press articles, to open inquiries into potential GDPR violations.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire