The Spanish authority fines a notary 2,000 euros for GDPR violation related to illegal disclosure of cadastral data
A notarial office was sanctioned for having communicated to its client a cadastral certificate containing the personal data of a third party, the authority having judged that this disclosure lacked a legal basis.
Facts and context
The Spanish data protection authority (AEPD) today published a sanction decision against the notarial office A.A.A. (including the imposition of a fine of 2,000 €) for breaches related to the unlawful communication of personal data.
The case originated from a complaint by a person who received a letter from a third party containing a cadastral certificate concerning them, and questioning how their data had been obtained.
Grounds for the decision
- Obligation of lawfulness of processing (Article 6(1) of the GDPR): The investigation revealed that the notarial office in question had obtained, at the request of its client B.B.B., a descriptive and graphic cadastral certificate from the Directorate General of the Cadastre. This document contained protected personal data of the complainant, including their name, surnames, and address. The notarial office then handed this certificate to its client, who used it to contact the complainant. The authority considered that while the notary could legitimately access this data in the course of their duties under national legislation (Real Decreto Legislativo 1/2004), its communication to the client constituted a separate processing operation. However, no legal basis provided for in Article 6(1) of the GDPR justified this disclosure, as the purpose of preparing a potential real estate transaction did not authorize the handing over of raw data to the client.
Authority's decision
Consequently, the authority imposed a fine of 2,000 € on A.A.A.
Furthermore, the authority ordered A.A.A. to adopt, within three months, the necessary measures to ensure the compliance of all its processing operations with Article 6(1) of the GDPR and to provide evidence thereof.
Lessons learned
This decision reminds that:
- Having legitimate access to personal data for the performance of a specific task does not in itself constitute a legal basis for communicating this data to third parties, including one's own client.
- Data obtained within a regulated professional framework, such as access to the cadastre by a notary, may only be used for the strict purpose that justified this access and may not be handed over to a client for their own procedures.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire