The Spanish authority sanctions the Complutense University of Madrid for violating the data minimization principle regarding a victim of gender-based violence
Facts and context
The case originated from a complaint by a candidate in a selection process who accused the university of revealing her status as a victim of gender-based violence, initially communicated to obtain a fee waiver, in a resolution notified to another candidate during an appeal procedure.
Reasons for the decision
- Data minimization obligation (Article 5(1)(c) of the GDPR): The authority found that the Complutense University of Madrid violated the minimization principle by communicating sensitive data about the complainant to a third party, another candidate. The authority considered that while collecting information about the status as a victim of gender-based violence was legitimate for fee exemption and assessment of positive action measures, explicitly including it with the complainant's full name in a resolution notified to a competitor was excessive and unnecessary. The university could have justified its decision by simply stating that the conditions set by the competition rules were not met, without revealing the intimate nature of the complainant's personal situation. The argument of transparency and the other candidate's right to defense was dismissed, as the authority considered these rights do not justify disclosing sensitive data when less intrusive alternatives exist to ensure the legality of the process.
Authority's decision
Consequently, the authority found a violation of Article 5(1)(c) of the GDPR by the Complutense University of Madrid.
Furthermore, the authority ordered the university to bring its processing operations into compliance with the data minimization principle and to provide evidence of the measures taken within three months.
Lessons learned
This decision reminds that:
- The minimization principle must be applied at every stage of processing, including when communicating decisions; legitimate collection of data does not justify its subsequent disclosure if not strictly necessary.
- The right to defense of third parties and the transparency principle in administrative procedures are not absolute and do not legitimize the communication of sensitive personal data when the objective can be achieved by less intrusive means.
- The reasoning of an administrative act does not require revealing intimate and sensitive circumstances of a person to third parties; it is sufficient to refer to legal conditions and factual conclusions without detailing the underlying personal data.
- Data controllers have an enhanced protection obligation regarding data concerning vulnerable persons to avoid any risk of stigmatization.
- The voluntary provision of data by the data subject does not exempt the controller from the obligation to limit further dissemination of this information to what is strictly necessary.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire