The Spanish authority sanctions the Santander city council for violating the data minimization principle in a traffic fine notification

The Spanish data protection authority found a violation of the data minimization principle by a municipality but applied a specific sanction regime for public bodies, limiting itself to a declaration of infringement without a financial penalty.

Facts and context

The Spanish data protection authority (AEPD) today published a decision finding an infringement by the Santander city council for a breach related to the data minimization principle.

The case originated from a complaint by an individual who discovered, on 8 November 2024, a notification of denunciation for a parking violation on the windshield of their vehicle, which contained their full personal data, including their name, first names, and national identity document number.

Reasons for the decision

  • Data minimization obligation (Article 5(1)(c) of the GDPR): The authority found that a local police officer had placed on a vehicle a denunciation notice containing the full personal data of the vehicle holder. It considered that while collecting this information is necessary for the sanction procedure, displaying it on a document left in a public place is excessive and unnecessary. National road traffic legislation provides specific and secure notification channels (in-person notification, secure electronic means, or at home) which were not respected. By publicly exposing data not essential to merely inform of the existence of an infringement, the municipality processed data in a manner that was inadequate, irrelevant, and not limited to what is necessary for the purpose, thus violating the data minimization principle. The municipality acknowledged the facts, attributing them to human error during the recording and verification of the notice.

Authority's decision

Consequently, the authority declared that the Santander city council violated Article 5(1)(c) of the GDPR.

Furthermore, the authority ordered that its decision be communicated to the Ombudsman and made public once final, in accordance with the specific regime applicable to public bodies under Spanish law which excludes the imposition of a financial penalty in this case.

Lessons learned

This decision reminds that:

  • Placing documents containing full personal data (name, identification number) on a publicly exposed medium, such as a vehicle windshield, is contrary to the data minimization principle.
  • Failure to comply with notification procedures provided by specific sectoral legislation may constitute a violation of data protection principles.
  • The legitimacy of data collection for a given purpose does not authorize their communication by means that unnecessarily expose them to unauthorized third parties.
  • Human error, although acknowledged, does not relieve the data controller of responsibility in case of proven violation of GDPR principles.
  • Public bodies may be subject to national sanction regimes that, instead of an administrative fine, provide for a formal declaration of infringement and other measures.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire