[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-PoniIipiHaPsuieXUL5C7YL2qxBoIMh_iHXhj8qNLM":3},{"article":4,"iocs":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":31},"131d0120-024b-4c24-9203-51143adee88b","AEPD (Spain) - ps-00287-2025","aepd-spain-ps-00287-2025-4ac220","Created page with \"{{DPAdecisionBOX |Jurisdiction=Spain |DPA-BG-Color= |DPAlogo=LogoES.jpg |DPA_Abbrevation=AEPD |DPA_With_Country=AEPD (Spain) |Case_Number_Name=ps-00287-2025 |ECLI= |Original_Source_Name_1=AEPD |Original_Source_Link_1=https:\u002F\u002Fwww.aepd.es\u002Fdocumento\u002Fps-00287-2025.pdf |Original_Source_Language_1=Spanish |Original_Source_Language__Code_1=ES |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Language_2= |Original_Source_Language__Code_2= |Type=Complaint...\" Show changes","Spain's data protection authority (AEPD) ruled that the Dirección General de Tráfico (DGT) violated GDPR Article 5(1)(c) by collecting and transmitting unnecessary personal data, including IP addresses and device information, via its mobile app. Although the DGT implemented changes, the AEPD found the infringement had already occurred, but no fine was imposed as the controller is a public authority.","Spain's AEPD finds DGT's mobile app collected unnecessary personal data.","Help AEPD (Spain) - ps-00287-2025: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 15:31, 1 October 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators346 edits Tag: Decisions [1.0] (No difference) Latest revision as of 15:31, 1 October 2026 AEPD - ps-00287-2025 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 5(1)(c) GDPR Article 77 of the Spanish Law on Personal Data Protection and Digital Rights Guarantee (LOPDGDD) Type: Complaint Outcome: Upheld Started: Decided: 17.11.2026 Published: Fine: n\u002Fa Parties: Dirección General de Tráfico (DGT) National Case Number\u002FName: ps-00287-2025 European Case Law Identifier: n\u002Fa Appeal: Unknown Original Language(s): Spanish Original Source: AEPD (in ES) Initial Contributor: bms The DPA found that a public authority’s mobile app collected more personal data than necessary, including IP and device data, in violation of Article 5(1)(c) GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A data subject lodged a complaint with the DPA against the Dirección General de Tráfico (DGT), the controller, the Spanish public authority responsible for traffic management, road safety and the administration of driving licences and vehicle records, after discovering that its mobile app transmitted numerous categories of personal and device data to a third-party service provider, the processor. The controller explained that the processor's software was integrated into the app to provide push notifications. However, the integration also enabled an optional functionality which transmitted usage and device data that were not necessary for providing those notifications. During its investigation, the DPA found that different versions of the app transmitted data including IP addresses, device information, country, language, app identifiers and information concerning the user's mobile network operator. The controller acknowledged that older versions of the app had transmitted personal data unnecessarily and implemented technical changes aimed at stopping the collection and transmission of such data. Holding The DPA held that the controller violated Article 5(1)(c) GDPR because the app collected and transmitted personal data that were not necessary for its intended purposes. In particular, the DPA considered that information such as IP addresses, country and mobile network operator data exceeded what was necessary for the app's functionality. The DPA also considered IP addresses to be personal data because they can allow a user to be identified when combined with other information. The controller's subsequent technical changes did not remove the infringement that had already occurred. Therefore, the DPA found a violation of Article 5(1)(c) GDPR. Since the controller was a public authority subject to Article 77 LOPDGDD, the DPA declared the infringement without imposing an administrative fine. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details. Case No.: EXP202317928 TABLE OF CONTENTS BACKGROUND..........................................................................................................2 FIRST: Filing of the Complaint........................................................................2 SECOND: Forwarding of the complaint and response from the respondent..................3 THIRD: Acceptance of the complaint for processing......................................................3 FOURTH: Preliminary investigative actions........................................................3 FIFTH: Decision to Initiate Disciplinary Proceedings..............................................33 SIXTH: Arguments Regarding the Agreement to Initiate Disciplinary Proceedings: Acknowledgment of Noncompliance and Measures Taken..............................................33 ESTABLISHED FACTS................................................................................................35 LEGAL GROUNDS.................................................................................................38 I Jurisdiction.........................................................................................................38 II Preliminary Issues...............................................................................................38 III Breach of Obligation. Data minimisation....................................................39 IV Classification of the violation of Article 5.1.c) of the GDPR and determination of the the statute of limitations.........................................................................................................41 V Notice of Violation..............................................................................................42 C\u002F Jorge Juan 6 www.aepd.es 28001 - Madrid sedeaepd.gob.es 2\u002F27 DECISION ON SANCTIONING PROCEEDINGS Regarding the proceedings conducted by the Spanish Data Protection Agency and based on the following: BACKGROUND FIRST: Filing of a Complaint On November 17, 2023, a complaint was filed with the Spanish Data Protection Authority regarding a possible violation attributable to the GENERAL DIRECTORATE OF TRAFFIC, Tax ID No. Q2816003D (hereinafter, D.G.T.). The facts brought to the attention of this authority were as follows: The complainant states that he installed the ***APP.1 app from the General Directorate of Traffic on his cell phone. According to the complainant, after using the app, he discovered that 47 pieces of information about his device (location, GPS coordinates, cookies, microphone status, IP address, etc.) are sent to ***COMPANY.1. The complainant believes that his data is being used in an unusual and unnecessary manner. Along with the complaint, he provides a screenshot showing the data that is allegedly sent to ***ENTERPRISE.1: - Screenshot of the ***APP.1 app, showing the following data captured by ***BROWSER.1 (unofficial translation from German):  App version  Pixel density  App installation date  Operating system build number  Battery level  App name  Unique identifier  CPU data  Screen resolution  Network carrier  Device name  Time zone  Email address  Headphone status  Advertising ID from ***SISTEMA.2  Cookies  Gender  ZIP code  Device boot time  Country C\u002F Jorge Juan 6 www.aepd.es 28001 - Madrid sedeaepd.gob.es 3\u002F27  Device language SECOND: Forwarding of the complaint and response from the respondent Pursuant to Article 65.4 of Organic Law 3\u002F2018, of December 5, on Data Protection and Guarantee of Digital Rights (hereinafter LOPDGDD), said complaint was forwarded to the D.G.T. so that it could proceed with its analysis and inform this Agency within one month of the actions taken to comply with the requirements set forth in data protection regulations. On January 23, 2024, a response was received from the respondent to the referral made by this Agency, in which the following documentation and statements were provided: - That the app incorporates the ***APP.2 plugin from ***ENTERPRISE.1 for managing push notifications sent to the User’s mobile device. Additionally, this plugin includes a feature that sends usage data from the mobile device to ***APP.2. This data transmission has been taking place since January 13, 2020. - That this transmission of data to ***APP.2 is a feature independent of notification management. While it is necessary to incorporate the ***APP.2 plugin to send push notifications to mobile devices (a required feature of the app), it is optional for that plugin to send usage data to ***APP.2. That with this data, ***APP.2 allows for the display of (anonymous) User information in real time on various d","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_ps-00287-2025&diff=53278&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F5\u002F59\u002FLogoES.jpg","2026-10-01T15:31:33+00:00","2026-10-01T16:00:18.697676+00:00",7,[18,21,24],{"name":19,"type":20},"AEPD","vendor",{"name":22,"type":23},"mobile app","product",{"name":25,"type":20},"DGT","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":26,"icon":28,"name":29,"slug":30},null,"Policy","policy",[32,37,42,44],{"category":33},{"id":34,"icon":28,"name":35,"slug":36},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":38},{"id":39,"icon":28,"name":40,"slug":41},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":43},{"id":26,"icon":28,"name":29,"slug":30},{"category":45},{"id":46,"icon":28,"name":47,"slug":48},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]