Back to Feed
PolicyOct 6, 2026

AEPD (Spain) - ps-00287-2025

Spain's AEPD fines public authority for GDPR violation via mobile app.

Summary

Spain's AEPD found that the Dirección General de Tráfico's (DGT) mobile app collected and transmitted unnecessary personal and device data, including IP addresses and country information, to a third-party processor. This violated Article 5(1)(c) of the GDPR. Although the DGT made subsequent technical changes, the infringement that had already occurred was not removed. As the controller was a public authority, the infringement was declared without an administrative fine.

Full text

Help AEPD (Spain) - ps-00287-2025: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editNewer edit →VisualWikitext Revision as of 10:08, 2 October 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators355 editsTag: Visual edit← Older edit Revision as of 13:03, 6 October 2026 view source Mba (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators989 editsm Tag: Visual editNewer edit → Line 107: Line 107: The controller's subsequent technical changes did not remove the infringement that had already occurred. Therefore, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(c) GDPR]].The controller's subsequent technical changes did not remove the infringement that had already occurred. Therefore, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(c) GDPR]]. Since the controller was a public authority subject to [https://www.boe.es/buscar/act.php?id=BOE-A-2018-16673 Article 77 LOPDGDD], the DPA declared the infringement without imposing an administrative fine.Since the controller was a public authority subject to [https://www.boe.es/buscar/act.php?id=BOE-A-2018-16673 Article 77 LOPDGDD], the DPA found the infringement without imposing an administrative fine. == Comment ==== Comment == Revision as of 13:03, 6 October 2026 AEPD - ps-00287-2025 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 5(1)(c) GDPR Article 77 of the Spanish Law on Personal Data Protection and Digital Rights Guarantee (LOPDGDD) Type: Complaint Outcome: Upheld Started: Decided: 17.11.2026 Published: Fine: n/a Parties: Dirección General de Tráfico (DGT) National Case Number/Name: ps-00287-2025 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Spanish Original Source: AEPD (in ES) Initial Contributor: bms The DPA found that a public authority’s mobile app collected more personal data than necessary, including IP and device data, in violation of Article 5(1)(c) GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A data subject lodged a complaint with the DPA against the Dirección General de Tráfico (DGT), the controller, the Spanish public authority responsible for traffic management, road safety and the administration of driving licences and vehicle records, after discovering that its mobile app transmitted numerous categories of personal and device data to a third-party service provider, the processor. The controller explained that the processor's software was integrated into the app to provide push notifications. However, the integration also enabled an optional functionality which transmitted usage and device data that were not necessary for providing those notifications. During its investigation, the DPA found that different versions of the app transmitted data including IP addresses, device information, country, language, app identifiers and information concerning the user's mobile network operator. The controller acknowledged that older versions of the app had transmitted personal data unnecessarily and implemented technical changes aimed at stopping the collection and transmission of such data. Holding The DPA held that the controller violated Article 5(1)(c) GDPR because the app collected and transmitted personal data that were not necessary for its intended purposes. In particular, the DPA considered that information such as IP addresses, country and mobile network operator data exceeded what was necessary for the app's functionality. The DPA also considered IP addresses to be personal data because they can allow a user to be identified when combined with other information. The controller's subsequent technical changes did not remove the infringement that had already occurred. Therefore, the DPA found a violation of Article 5(1)(c) GDPR. Since the controller was a public authority subject to Article 77 LOPDGDD, the DPA found the infringement without imposing an administrative fine. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details. Case No.: EXP202317928 TABLE OF CONTENTS BACKGROUND..........................................................................................................2 FIRST: Filing of the Complaint........................................................................2 SECOND: Forwarding of the complaint and response from the respondent..................3 THIRD: Acceptance of the complaint for processing......................................................3 FOURTH: Preliminary investigative actions........................................................3 FIFTH: Decision to Initiate Disciplinary Proceedings..............................................33 SIXTH: Arguments Regarding the Agreement to Initiate Disciplinary Proceedings: Acknowledgment of Noncompliance and Measures Taken..............................................33 ESTABLISHED FACTS................................................................................................35 LEGAL GROUNDS.................................................................................................38 I Jurisdiction.........................................................................................................38 II Preliminary Issues...............................................................................................38 III Breach of Obligation. Data minimisation....................................................39 IV Classification of the violation of Article 5.1.c) of the GDPR and determination of the the statute of limitations.........................................................................................................41 V Notice of Violation..............................................................................................42 C/ Jorge Juan 6 www.aepd.es 28001 - Madrid sedeaepd.gob.es 2/27 DECISION ON SANCTIONING PROCEEDINGS Regarding the proceedings conducted by the Spanish Data Protection Agency and based on the following: BACKGROUND FIRST: Filing of a Complaint On November 17, 2023, a complaint was filed with the Spanish Data Protection Authority regarding a possible violation attributable to the GENERAL DIRECTORATE OF TRAFFIC, Tax ID No. Q2816003D (hereinafter, D.G.T.). The facts brought to the attention of this authority were as follows: The complainant states that he installed the ***APP.1 app from the General Directorate of Traffic on his cell phone. According to the complainant, after using the app, he discovered that 47 pieces of information about his device (location, GPS coordinates, cookies, microphone status, IP address, etc.) are sent to ***COMPANY.1. The complainant believes that his data is being used in an unusual and unnecessary manner. Along with the complaint, he provides a screenshot showing the data that is allegedly sent to ***ENTERPRISE.1: - Screenshot of the ***APP.1 app, showing the following data captured by ***BROWSER.1 (unofficial translation from German):  App version  Pixel density  App installation date  Operating system build number  Battery level  App name  Unique identifier  CPU data  Screen resolution  Network carrier  Device name  Time zone  Email address  Headphone status  Advertising ID from ***SISTEMA.2  Cookies  Gender  ZIP code  Device boot time  Country C/ Jorge Juan 6 www.aepd.es 28001 - Madrid sedeaepd.gob.es 3/27  Device language SECOND: Forwarding of the complaint and response from the respondent Pursuant to Article 65.4 of Organic Law 3/2018, of December 5, on Data Protection and Guarantee of Digital Rights (hereinafter LOPDGDD), said complaint was forwarded to the D.G.T. so that it could proceed with its analysis and infor

Entities

AEPD (vendor)mobile app (product)