The Spanish authority sanctions the Ministry of Agriculture, Livestock and Rural Development of Castilla y León for a breach affecting 43,000 individuals

The Spanish data protection authority (AEPD) has sanctioned the Ministry of Agriculture of Castilla y León for failing to implement basic security measures, which allowed the exfiltration of data of 43,000 pet owners through the impersonation of a legitimate user's credentials.

Facts and context

The Spanish data protection authority (AEPD) today published a decision finding an infringement against the Ministry of Agriculture, Livestock and Rural Development of the Junta of Castilla y León for shortcomings related to the security of personal data.

The case originated from a data breach notification by the Ministry on October 13, 2023, following an alert from the National Cryptologic Center (CCN), and was supplemented by three complaints from data subjects.

Grounds for the decision

  • Obligation to ensure the integrity and confidentiality of data (Article 5(1)(f) of the GDPR): The authority considered that the Ministry had not implemented appropriate technical and organizational measures to protect the data of the pet identification system. The exfiltration of data of 43,000 individuals was made possible by exploiting several vulnerabilities, including a deficient credential management policy, the absence of mechanisms to detect abnormal activities (such as more than 70,000 massive consultations from a single IP address over several months), and a system configuration that allowed extensive access to data. The fact that the incident was only detected several months after its start, and by a third party, confirmed the insufficiency of the security measures in place.

Authority's decision

Consequently, the authority declared that the Ministry of Agriculture, Livestock and Rural Development of the Junta of Castilla y León committed an infringement of Article 5(1)(f) of the GDPR.

Furthermore, the authority ordered the publication of its decision and its communication to the Ombudsman.

Lessons learned

This decision reminds that:
  • The controller cannot exempt itself from responsibility for security by invoking the actions of its processor; it is responsible for ensuring the implementation of adequate measures.
  • Data security is not limited to preventing unauthorized access but also includes implementing proactive detection mechanisms to identify and respond quickly to suspicious activities, such as massive and unusual requests.
  • A robust credential and password management policy is a fundamental security measure to prevent illegitimate access resulting from compromised user accounts.
  • Access rights configuration must strictly apply the principle of least privilege to prevent a user account, even legitimate, from accessing data beyond its authorization scope.
  • Detection of a data breach by an external third party is a strong indication of inadequate internal monitoring and control measures by the controller.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire