The Spanish authority sanctions the Generalitat Valenciana for a data breach related to the RIVIA system

The Spanish authority found a breach of the integrity and confidentiality principle (Article 5.1.f) of the GDPR against a public administration, following a data breach resulting from the exploitation of known vulnerabilities and the absence of basic security measures, such as two-factor authentication.

Facts and context

The Spanish data protection authority (AEPD) today published a decision finding a breach against the Government of the Valencian Community for failures related to the principle of integrity and confidentiality of personal data.

The case originated from a data breach notification by the data protection officer of the Government of the Valencian Community on October 2, 2023, following an alert from the National Cryptologic Center.

Reasons for the decision

  • Obligation of integrity and confidentiality (Article 5, paragraph 1, point f) of the GDPR): The authority found a data breach on the RIVIA IT system, which allowed the exfiltration of personal data (name, first name, identity document number, address, contact details) by an unauthorized third party. The investigation revealed that access was obtained via compromised credentials, exploiting a SQL code injection vulnerability, a well-known security flaw. The authority emphasized that fundamental security measures were lacking, notably a two-factor authentication mechanism and robust password management policies. Furthermore, the absence of early detection systems allowed massive data exfiltration over a prolonged period without triggering an alert. The authority concluded that, although the security obligation is a reinforced obligation of means, the absence of these appropriate technical and organizational measures in the face of known and materialized risks constituted negligence attributable to the controller, resulting in a loss of confidentiality and thus directly violating this principle.

Authority's decision

Consequently, the authority found a violation of Article 5, paragraph 1, point f) of the GDPR by the Government of the Valencian Community but did not impose a fine as it cannot do so against public entities.

Moreover, the authority ordered that its decision be made public after notification to the interested parties and communicated to the Ombudsman.

Lessons learned

This decision reminds that:

  • The absence of basic security measures, such as two-factor authentication or protection against common vulnerabilities (e.g., those listed by OWASP), constitutes a significant failure in implementing appropriate security.
  • Corrective measures implemented after a data breach, although necessary, do not cancel the initial breach; compliance assessment is based on the state of measures at the time of the incident.
  • Compliance with national security frameworks or holding certifications not specific to information security (such as ISO 9001) does not presume GDPR compliance and does not exempt from a dedicated data protection risk analysis.
  • A data breach resulting from manifestly insufficient security measures can be qualified as a direct breach of the integrity and confidentiality principle (Article 5.1.f), and not only a breach of the obligation to secure processing (Article 32).
  • The controller's responsibility includes implementing effective monitoring and detection mechanisms to identify and quickly respond to suspicious activities, such as massive data exfiltration.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire