The Spanish authority initiates proceedings against the municipality of Coles for GDPR violation related to the disclosure of personal data
Facts and context
The Spanish data protection authority (AEPD) today published a decision declaring an infringement against the municipality of Coles for a breach of the confidentiality principle following the disclosure of personal data in a public place.
The case originated from a complaint filed on October 26, 2023, denouncing the posting of an administrative file on an electric pole near a construction site.
Grounds for the decision
After initially dismissing the complaint and then reopening it on appeal, the authority found the following breach:
- Integrity and confidentiality obligation (Article 5(1)(f) of the GDPR): The authority found that the municipality had placed an administrative document containing personal data and details of a sanction on a pole located in a public place. By making this document accessible to unauthorized third parties, the municipality failed to implement appropriate technical and organizational measures to ensure adequate data security. The authority concluded that this public exposure constituted a violation of the confidentiality principle, which requires processing data in a manner that protects against any unauthorized disclosure.
Authority's decision
Consequently, the authority declared that the municipality of Coles committed an infringement of Article 5(1)(f) of the GDPR. In accordance with Article 77 of the Spanish Organic Law 3/2018, which provides a specific regime for public administrations, no administrative fine was imposed.
Furthermore, the authority ordered the municipality of Coles to implement measures ensuring data confidentiality and to prove their effective application within three months.
Lessons learned
This decision reminds that:
- Personal data protection extends to physical media and requires preventing any exposure of paper documents in public places.
- The fact that certain data (such as the name of an administrator) are accessible in a public register does not justify their disclosure in a different context, such as an administrative sanction.
- The prompt removal of unauthorized data exposure does not suffice to negate the breach of the confidentiality principle, even if it may mitigate its severity.
- Sanction regimes applicable to public bodies may differ from those in the private sector, as illustrated by Spanish law which excludes monetary fines in favor of infringement declarations and corrective measures.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire