The Spanish authority sanctions the Ayuntamiento de Canals for a GDPR violation related to the disclosure of personal exam data
The Spanish Data Protection Authority (AEPD) declared a GDPR violation by a municipality without imposing a fine, applying the specific regime provided by national law for public entities.
Facts and context
The Spanish Data Protection Authority (AEPD) today published a decision declaring an infringement against the municipality of Canals for failures related to the security of personal data.
The case originated from a citizen's social media post denouncing the discovery, on May 1, 2024, of documents containing personal data abandoned in a public place.
Reasons for the decision
- Obligation of integrity and confidentiality (Article 5(1)(f) of the GDPR): The authority found that exam copies from a training organized by the municipality were found in the street. These documents, which contained the name, first names, and national identity card number (DNI) of three students, had not been destroyed and were accessible to third parties, as evidenced by their dissemination on social media. The municipality acknowledged its negligence, explaining that a human error led to the documents intended for destruction ending up in a public trash bin. The authority concluded that the absence of adequate organizational measures to ensure the secure destruction of documents constituted a failure to ensure data confidentiality.
Authority's decision
Consequently, the authority declared that the municipality of Canals violated Article 5(1)(f) of the GDPR. In accordance with Article 77 of the Spanish Organic Law on Data Protection, which provides a specific regime for public entities, no fine was imposed, with the declaration of infringement being the measure taken.
Furthermore, the authority ordered that its decision be communicated to the Ombudsman and made public after notification to the parties.
Lessons
This decision reminds that:
- The security of personal data also applies to physical documents, whose destruction must follow a formalized and controlled procedure to avoid any accidental disclosure.
- Simple negligence or human error in managing documents to be destroyed is sufficient to constitute a breach of the security obligation, engaging the data controller's responsibility.
- Abandoning documents containing personal data in a public place constitutes a clear violation of the principle of integrity and confidentiality, regardless of the number of data subjects involved.
- The sanction regime applicable to public entities in Spain generally leads to a simple declaration of infringement without a monetary fine.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire