The Spanish authority initiates proceedings against the Directorate General of the Civil Guard for failure to conduct a data protection impact assessment regarding the Virtual Civil Guard Pilot project

The Spanish data protection authority found a violation against the Directorate General of the Civil Guard for failing to carry out a data protection impact assessment for a virtual assistant project, even though the project was cancelled before any implementation and data processing.

Facts and context

The Spanish data protection authority (AEPD) published a decision finding a violation against the Directorate General of the Civil Guard for failing to carry out a data protection impact assessment for its virtual assistant project based on artificial intelligence.

The case originated from a complaint dated 12 September 2023 concerning the "Virtual Civil Guard Pilot" project, which aimed to deploy avatars and artificial intelligence for public reception, without any impact assessment having been conducted.

Reasons for the decision

  • Obligation to carry out a data protection impact assessment (Article 35 of the GDPR): The authority rejected the Civil Guard's argument that the absence of actual data processing, due to contract termination before project execution, exempted it from conducting an impact assessment. The authority's reasoning is based on the fact that the obligation to conduct such an assessment arises from the design phase of processing likely to result in a high risk to the rights and freedoms of individuals, even before processing begins. The authority considered that the project, by its nature, met several criteria making the impact assessment mandatory. It involved the use of new technologies (artificial intelligence, machine learning, voice recognition, empathy engines), large-scale processing (deployment on interactive kiosks and a mobile application intended for thousands of users), as well as the processing of potentially sensitive data, such as voice and inferences on individuals' emotional state. The authority emphasized that voice and IP address constitute personal data and that the mere assertion in contractual documents that no personal data processing was planned was contradicted by the project's technical specifications, which included a user registration system (name, email, password). The subsequent contract termination therefore does not negate the initial violation of having designed and contracted a high-risk processing without the required prior assessment.

Authority's decision

Consequently, the authority declared that the Directorate General of the Civil Guard violated Article 35 of the GDPR. Prosecutions related to a possible violation of Article 25 of the GDPR were dismissed.

Lessons learned

This decision reminds that:
  • The obligation to conduct an impact assessment arises from the design phase of a project, before any data processing, and cannot be deferred.
  • The cancellation of a project or contract termination does not retroactively remove the violation of failing to conduct an impact assessment when required at the planning stage.
  • The technical specifications of a project prevail over contractual declarations; if the technology involves personal data processing, a clause stating otherwise is ineffective.
  • Processing combining the use of new technologies such as artificial intelligence, large-scale deployment, and analysis of data such as voice or emotions meets several criteria making the impact assessment mandatory.
  • The notion of personal data must be interpreted broadly and includes not only direct identifiers but also voice, IP addresses, and data inferred by artificial intelligence systems.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire