Back to Feed
PolicySep 8, 2026

AEPD (Spain) - ps-00256-2025

Spanish DPA fines notary for unlawful disclosure of cadastral data.

Summary

The Spanish Data Protection Agency (AEPD) has initiated sanctioning proceedings against a notary for violating Article 6(1) of the GDPR. The notary disclosed a cadastral certificate containing a data subject's personal information to a client without a valid legal basis, despite the client's stated intention to negotiate a property transaction. The AEPD found that while notaries may access such data under specific circumstances, this authorization does not extend to disclosing the complete certificate to third parties for purposes beyond the notary's official competences.

Full text

Help AEPD (Spain) - ps-00256-2025: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 10:01, 3 September 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators298 editsTag: Visual edit← Older edit Latest revision as of 09:46, 8 September 2026 view source Ls (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators390 editsmTag: Visual edit Line 97: Line 97: === Facts ====== Facts === A data subject filed a complaint with the DPA after receiving a letter from a third party concerning a plot of land. The third party asked the data subject to acknowledge that she was not the owner of the property so that the cadastral records could be amended. The letter was accompanied by a cadastral certificate containing the data subject’s name, surname and home address. The third party had also previously visited the data subject at that address.After receiving an in-person visit at her address, a data subject received a letter from a third party concerning a plot of land. The third party asked the data subject to acknowledge that she was not the owner of the property so that the cadastral records could be amended. The letter was accompanied by a cadastral certificate containing the data subject’s name, surname and home address. An investigation established that a notary, the controller, had obtained the cadastral certificate at the request of a client. The client had indicated that her son intended to enter into negotiations with the person registered as the owner of the property to purchase or rent it. The controller subsequently provided the certificate to the client.The data subject filed a complaint with the DPA which investigated the case. The investigation established that a notary, the controller, had obtained the cadastral certificate at the request of a client. The client had indicated that her son intended to enter into negotiations with the person registered as the owner of the property to purchase or rent it. The controller subsequently provided the certificate to the client. The certificate included the data subject’s name, surname and address. Ultimately, no transaction was ultimately formalized before the controller. The controller argued that access to the cadastral information had taken place in the context of preparatory steps for a potential property transaction and relied on the powers granted to notaries under Spanish cadastral legislation. No transaction was ultimately formalised before the controller.The controller argued that access to the cadastral information had taken place in the context of preparatory steps for a potential property transaction and relied on the powers granted to notaries under Spanish cadastral legislation. The DPA initiated sanctioning proceedings against the controller for a potential infringement of [[Article 6 GDPR|Article 6(1) GDPR]].The DPA initiated sanctioning proceedings against the controller for a potential infringement of [[Article 6 GDPR|Article 6(1) GDPR]]. Line 107: Line 107: The DPA held that the controller violated [[Article 6 GDPR|Article 6(1) GDPR]] by disclosing the cadastral certificate containing the data subject’s personal data to a third party without a valid legal basis.The DPA held that the controller violated [[Article 6 GDPR|Article 6(1) GDPR]] by disclosing the cadastral certificate containing the data subject’s personal data to a third party without a valid legal basis. The DPA noted that the data contained in the certificate, including the data subject’s name, surname and address, constituted protected cadastral data under Spanish law. Although the applicable cadastral legislation allows notaries to access protected cadastral information in certain circumstances, the DPA distinguished between the controller’s access to the information and its subsequent disclosure to the client.The DPA distinguished between (i) the controller’s access to the certificate and (ii) its subsequent disclosure to the client. In particular, the DPA considered that the rules allowing a notary to access protected cadastral data did not provide a legal basis for handing the complete certificate to the client. The certificate itself stated that the information could only be used for the exercise of the requesting party’s competences. The client subsequently used the information to visit the data subject’s home and send her a letter concerning the property.Regarding (i) the access to the certificate, the DPA noted that the applicable cadastral legislation indeed allows notaries to access protected cadastral information in certain circumstances. However, such authorization does not extend to (ii) the disclosure of the information. That finding was supported by the certificate itself which stated that the information could only be used for the exercise of the requesting party’s competences. On the contrary, in this case, the information was later on used to visit the data subject’s home and send her a letter concerning the property. Consequently, the DPA found that the disclosure constituted a separate processing operation for which none of the legal bases under [[Article 6 GDPR|Article 6(1) GDPR]] had been established.Consequently, the DPA found that the disclosure constituted a separate processing operation for which none of the legal bases under [[Article 6 GDPR|Article 6(1) GDPR]] had been established. Latest revision as of 09:46, 8 September 2026 AEPD - ps-00256-2025 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 6(1) GDPR Article 51 Spanish Real Estate Cadastre LawArticle 52 Spanish Real Estate Cadastre LawArticle 53 Spanish Real Estate Cadastre Law Type: Complaint Outcome: Upheld Started: 27.06.2024 Decided: Published: 01.09.2026 Fine: 2000.0 EUR Parties: n/a National Case Number/Name: ps-00256-2025 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Spanish Original Source: AEPD (in ES) Initial Contributor: bms The DPA fined a notary €2,000 for disclosing protected cadastral data, including a data subject’s name and address, to a client without a legal basis under Article 6(1) GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts After receiving an in-person visit at her address, a data subject received a letter from a third party concerning a plot of land. The third party asked the data subject to acknowledge that she was not the owner of the property so that the cadastral records could be amended. The letter was accompanied by a cadastral certificate containing the data subject’s name, surname and home address. The data subject filed a complaint with the DPA which investigated the case. The investigation established that a notary, the controller, had obtained the cadastral certificate at the request of a client. The client had indicated that her son intended to enter into negotiations with the person registered as the owner of the property to purchase or rent it. The controller subsequently provided the certificate to the client. The certificate included the data subject’s name, surname and address. Ultimately, no transaction was ultimately formalized before the controller. The controller argued that access to the cadastral information had taken place in the context of preparatory steps for a potential property transaction and relied on the powers granted to notaries under Spanish cadastral legislation. The DPA initiated sanctioning proceedings against the controller for a potential infringement of Article 6(1) GDPR. Holding The DPA held that the controller violated Article 6(1) GDPR by disclosing the cadastral certificate containing the data subject’s personal data to a third party without a valid legal basis. The DPA distinguished between (i) the controller’s access to the certificate and (ii) its subsequent disclosure t

Entities

AEPD (vendor)