The Spanish authority closes a case against an individual due to lack of culpable intent
The Spanish data protection authority closed a case initiated against an individual for using a third party's data without a legal basis in an administrative procedure, due to the absence of culpability (intent or negligence) on their part.
Facts and context
The Spanish data protection authority (AEPD) published a decision to close a case against an individual for processing data without a legal basis.
The case originated from a complaint by a person whose personal data (name, first name, and tax identification number) were used without their consent to present them as the interested party in an administrative procedure with a ministry.
Reasons for the decision
- Obligation of lawfulness of processing (Article 6 of the GDPR): The authority found that the accused had used the complainant's name, first name, and tax identification number by designating them as the "interested party" in an electronic form submitted to an administration, while registering themselves as their "representative." This data processing was carried out without any of the legal bases provided for in Article 6 of the GDPR being applicable, notably the consent of the data subject. However, the authority qualified this action as a "manifest error," considering that the accused had incorrectly filled out the form: the complainant was actually the recipient of the letter and not the interested party within the meaning of the administrative procedure. Applying the principle of culpability derived from Spanish administrative law (Article 28 of Law 40/2015), which requires the presence of intent (dolo) or negligence (culpa) to sanction, the authority considered that these elements were not met. Given the isolated and erroneous nature of the act, it concluded the absence of administrative liability, although the processing was objectively unlawful.
Authority's decision
Consequently, the authority closed the case against the accused.
Lessons learned
This decision reminds that:
- The mere finding of a technical breach of the GDPR may not be sufficient to trigger an administrative sanction; the authority must also establish the existence of culpability (intent or negligence) on the part of the controller.
- The isolated and manifestly erroneous nature of data processing, resulting from a misunderstanding of an administrative form, can be a determining factor to exclude the controller's culpability.
- An individual who determines the purposes and means of processing, even within the framework of a single and erroneous administrative procedure, is qualified as a controller and is required to comply with the obligations of the GDPR.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire