AEPD (Spain) - ps-00256-2025
Spain's AEPD fines a notary €2,000 for GDPR violation.
Summary
Spain's data protection authority (AEPD) has fined a notary €2,000 for violating GDPR. The notary disclosed protected cadastral data, including a data subject's name and address, to a client without a legal basis. The disclosure occurred when the notary provided a cadastral certificate to a client whose son intended to negotiate a property purchase.
Full text
Help AEPD (Spain) - ps-00256-2025: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 10:00, 3 September 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators294 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 10:00, 3 September 2026 AEPD - ps-00256-2025 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 6(1) GDPR Article 51 Spanish Real Estate Cadastre LawArticle 52 Spanish Real Estate Cadastre LawArticle 53 Spanish Real Estate Cadastre Law Type: Complaint Outcome: Upheld Started: Decided: Published: 01.09.2026 Fine: 2000.0 EUR Parties: n/a National Case Number/Name: ps-00256-2025 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Spanish Original Source: AEPD (in ES) Initial Contributor: bms The DPA fined a notary €2,000 for disclosing protected cadastral data, including a data subject’s name and address, to a client without a legal basis under Article 6(1) GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A data subject filed a complaint with the DPA after receiving a letter from a third party concerning a plot of land. The third party asked the data subject to acknowledge that she was not the owner of the property so that the cadastral records could be amended. The letter was accompanied by a cadastral certificate containing the data subject’s name, surname and home address. The third party had also previously visited the data subject at that address. An investigation established that a notary, the controller, had obtained the cadastral certificate at the request of a client. The client had indicated that her son intended to enter into negotiations with the person registered as the owner of the property to purchase or rent it. The controller subsequently provided the certificate to the client. The controller argued that access to the cadastral information had taken place in the context of preparatory steps for a potential property transaction and relied on the powers granted to notaries under Spanish cadastral legislation. No transaction was ultimately formalised before the controller. The DPA initiated sanctioning proceedings against the controller for a potential infringement of Article 6(1) GDPR. Holding The DPA held that the controller violated Article 6(1) GDPR by disclosing the cadastral certificate containing the data subject’s personal data to a third party without a valid legal basis. The DPA noted that the data contained in the certificate, including the data subject’s name, surname and address, constituted protected cadastral data under Spanish law. Although the applicable cadastral legislation allows notaries to access protected cadastral information in certain circumstances, the DPA distinguished between the controller’s access to the information and its subsequent disclosure to the client. In particular, the DPA considered that the rules allowing a notary to access protected cadastral data did not provide a legal basis for handing the complete certificate to the client. The certificate itself stated that the information could only be used for the exercise of the requesting party’s competences. The client subsequently used the information to visit the data subject’s home and send her a letter concerning the property. Consequently, the DPA found that the disclosure constituted a separate processing operation for which none of the legal bases under Article 6(1) GDPR had been established. The DPA imposed a €2,000 fine for the infringement of Article 6(1) GDPR. In addition, pursuant to Article 58(2)(d) GDPR, it ordered the controller to demonstrate, within three months from the date on which the decision became final and enforceable, that appropriate measures had been adopted to ensure compliance with Article 6(1) GDPR in all personal data processing operations. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details. Case No.: EXP202410271 DECISION ON DISCIPLINARY PROCEEDINGS Regarding the proceedings conducted by the Spanish Data Protection Agency and based on the following BACKGROUND FIRST: On June 27, 2024, a complaint was filed with the Spanish Data Protection Agency regarding a possible violation attributable to A.A.A., with Tax ID No. ***NIF.1 (hereinafter, A.A.A. or the respondent). The facts brought to the attention of this authority are as follows: The complainant states that she received a letter from a third party, in which she was asked to sign a document acknowledging that she was not the owner of a property, thereby removing it from the land registry, in order to register said property in the name of the third party who signed the letter. The complainant asserts that she is not currently, nor has she ever been, the owner of the aforementioned property. She also notes that, some time ago, the third party appeared at her residence with the intention of speaking with her. She points out that she does not understand how the notary’s office could have provided her personal data to a third party. She also states that her son contacted the notary’s office named in the CFR (Notary’s Office in ***LOCALITY.1), which denied the data breach, and with the notary association of ***LOCALITY.2, which has not provided an explanation regarding the source of the data breach. Attached to the complaint are: The CFR mentioned in the complaint, dated May 22, 2024, sent by B.B.B. to the complainant. Descriptive and Graphic Cadastral Certificate for an agricultural parcel located in ***LOCALITY.1 with cadastral reference ***NUMBER.1, to which the second proven fact refers. SECOND: Pursuant to Article 65.4 of Organic Law 3/2018, of December 5, on data protection and the Guarantee of Digital Rights (hereinafter hereinafter “LOPDGDD”), said complaint was forwarded to the notary’s office mentioned in the letter dated May 22, 2024, so that it could analyze it and inform this Agency within one month of the actions taken to comply with the requirements set forth in data protection regulations. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 2/15 The notification of the referral of the complaint, which was carried out in accordance with the rules established in Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), was made on July 23, 2024, as evidenced by the acknowledgment of receipt on file. Following several communications with said notary’s office, on September 26, 2024, this Agency received a written response indicating that the notary’s office had not disclosed personal data to third parties without legal authorization to do so. Furthermore, it was noted that a man had contacted the notary’s office regarding some parcels of land for which a third party had requested, by letter, a correction to the cadastral record with the purpose of resolving a discrepancy. The man had attached a cadastral certificate on which his mother’s first and last names appeared. Although this certificate had not been requested by that notary’s office, but rather by a different notary’s office, as noted at the bottom of the certificate. The man was informed that the notary’s office in question had not issued the cadastral certificate in question. To clarify the matter, he would need to contact the notary’s office that had requested the documentation, as indicated at the bottom of the certificate. THIRD: On September 27, 2024, in accordance with Article 65 of the LOPDGDD, the complaint was accepted for processing. FOURTH: The Subdirectorate General for Data Inspection (hereinafter, SGID) proceeded to conduct preliminary investigati