The Spanish authority sanctions the Directorate General of Traffic for excessive collection of personal data via its mobile application

The Spanish data protection authority found a violation of the data minimisation principle by the Directorate General of Traffic, whose mobile application collected and transmitted to a third party an excessive volume of personal data due to a misconfigured module, even though the data were not actively used.

Facts and context

The Spanish data protection authority (AEPD) today published a decision declaring a violation against the Directorate General of Traffic (DGT) for breaches related to the data minimisation principle in its mobile application.

The case originated from a complaint filed on 17 November 2023, denouncing the massive collection and transmission of personal data by the DGT's mobile application to a third-party company.

Grounds for the decision

  • Data minimisation obligation (Article 5(1)(c) of the GDPR): The authority established that the DGT's mobile application, through the integration of a third-party module intended for notification management, collected and transmitted a large and excessive volume of personal data. Among the 47 types of data were location, GPS coordinates, email address, advertising identifier, as well as numerous technical details about the device. Although the DGT claimed that this collection resulted from an erroneous and unintentional configuration and that the data were not exploited, the authority considered that the collection itself was disproportionate to the purpose of sending notifications. Even after the release of a corrective version (1.11.5), the investigation revealed that identifying data, such as the IP address, continued to be transmitted, thus violating the principle that data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.

Authority's decision

Consequently, the authority declared that the Directorate General of Traffic violated Article 5(1)(c) of the GDPR. In accordance with Spanish law applicable to public bodies, no financial penalty was imposed.

Furthermore, the authority ordered the notification of its decision to the Directorate General of Traffic and the Ombudsman, as well as its publication on its website.

Lessons learned

This decision confirms / specifies / recalls that:

  • The integration of third-party modules (SDKs) in a mobile application requires the data controller to precisely verify and control the data flows they generate, to ensure that no superfluous collection is performed by default.
  • The collection of personal data must be strictly limited to what is necessary in relation to the specific purpose pursued; collecting a wide range of technical data about the device and user for a simple notification service is deemed excessive.
  • A violation of the minimisation principle is constituted by the mere fact of excessive collection, regardless of the data controller's intent or the actual use of the collected data.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire