The Spanish authority initiates proceedings against HOY VOY A CONDUCIR for a serious security breach affecting 264,435 individuals

A data breach affecting over 264,000 individuals, resulting from known technical vulnerabilities left unaddressed for several years, led the Spanish authority to sanction a driving school for failing to meet its security obligations, despite a significant fine reduction for cooperation.

Facts and context

The Spanish data protection authority (AEPD) today published a sanction decision against the company Hoy Voy a Conducir, S.L. (including the imposition of a €30,000 fine) for failures related to the security of personal data.

The case began after the authority became aware, on 27 September 2024, of the sale online of a database containing over 200,000 records allegedly belonging to the company, which operates a network of 38 franchised driving schools.

Grounds for the decision

  • Obligation to ensure the security of processing (Article 32 of the GDPR): The authority found a massive data breach affecting 264,435 individuals, including minors, and containing names, first names, dates of birth, contact details, and identification numbers (DNI, NIE, passport). The investigation revealed that the incident resulted from technical vulnerabilities due to outdated IT infrastructure, which the company had been aware of since April 2021 without taking the necessary corrective measures before January 2025. The authority qualified this inaction as serious negligence, aggravated by the fact that the company ignored several external alerts, notably from the National Police, and delayed activating its incident management protocol after discovering the leak.

Authority's decision

Consequently, the authority imposed a fine of €30,000 on Hoy Voy a Conducir, S.L. This final amount results from a reduction for acknowledgment of responsibility and voluntary payment, the initial sanction having been set at €50,000.

Lessons learned

This decision reminds that:

  • Awareness of a technical vulnerability, even if not yet exploited, requires the data controller to act without delay to correct it, under penalty of having their negligence qualified as serious in case of an incident.
  • Ignoring security alerts, whether from third parties or authorities, and delaying the activation of incident response protocols are aggravating factors demonstrating a failure to exercise due diligence.
  • The processing of national identification numbers requires a particularly high level of security, as their disclosure can lead to significant risks for the data subjects, such as identity theft.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire