The Spanish authority sanctions the Government of Cantabria for a security breach exposing 150,000 personal data in 2024

The Spanish data protection authority (AEPD) declared a violation of the security obligation against the Government of Cantabria following a cyberattack that exposed the data of 150,000 students. Under the specific Spanish national law applicable to public bodies, no fine was imposed, but binding corrective measures were enforced.

Facts and context

The Spanish Data Protection Agency (AEPD) issued a decision declaring an infringement against the Government of Cantabria for failures related to the security of a school management application.

The procedure was initiated by the AEPD itself following a massive data breach on the "Yedra" application, used for managing students in non-university educational institutions in Cantabria and counting about 250,000 users.

Grounds for the decision

  • Obligation to ensure the security of processing (Article 32 of the GDPR): The authority found that the technical and organizational measures implemented by the Government of Cantabria were insufficient to guarantee a level of security appropriate to the risk. The success of a cyberattack between April 1 and April 8, 2024, which allowed the exfiltration of 150,000 records, demonstrated the existence of vulnerabilities and the inadequacy of the system's protections. The compromised data included sensitive information (name, first name, identity card number, contact details, address, family data, photographs) concerning a potentially vulnerable population, minor students.

Decision of the authority

Consequently, the authority declared that the Government of Cantabria committed an infringement of Article 32 of the GDPR.

Furthermore, the authority ordered the Government of Cantabria to implement, within three months, appropriate technical and organizational measures to ensure data security. The body must also justify these measures and inform the authority of the development and deployment status of the new "ALTAMIRA" application and its security features.

Lessons learned

This decision reminds that:

  • The specific sanction regime applicable to public bodies in certain Member States (here, the absence of a fine in favor of corrective measures) does not exempt them from complying with their substantive obligations under the GDPR, notably regarding security.
  • The materialization of a data breach by cyberattack constitutes major evidence of the insufficiency of the technical and organizational security measures previously implemented by the controller.
  • The assessment of the required level of security under Article 32 of the GDPR must imperatively take into account the nature of the data (photographs, identity numbers) and the vulnerability of the data subjects concerned (students, potentially minors).

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire