[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5DxSoWQ1JyZYS7_kmbxJ_DqbUwXNjrB5KW5q_SOBCic":3},{"article":4,"iocs":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":31},"7cd6a0f1-caa1-4979-a8cb-522bb2828ee1","AEPD (Spain) - ps-00287-2025","aepd-spain-ps-00287-2025-b3cc7d","← Older revision Revision as of 10:08, 2 October 2026 Line 100: Line 100: The controller acknowledged that older versions of the app had transmitted personal data unnecessarily and implemented technical changes aimed at stopping the collection and transmission of such data. The controller acknowledged that older versions of the app had transmitted personal data unnecessarily and implemented technical changes aimed at stopping the collection and transmission of such data. === Holding === === Holding === The DPA held that the controller violated [[Article 5 GDPR|Article 5(1)(c) GDPR]] because the app collected and transmitted personal data that were not necessary for its intended purposes. The DPA held that the controller violated [[Article 5 GDPR|Article 5(1)(c) GDPR]] because the app collected and transmitted personal data that were not necessary for its intended purposes. Line 109: Line 107: The controller's subsequent technical changes did not remove the infringement that had already occurred. Therefore, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(c) GDPR]]. The controller's subsequent technical changes did not remove the infringement that had already occurred. Therefore, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(c) GDPR]]. Since the controller was a public authority subject to Article 77 LOPDGDD, the DPA declared the infringement without imposing an administrative fine. Since the controller was a public authority subject to [https:\u002F\u002Fwww.boe.es\u002Fbuscar\u002Fact.php?id=BOE-A-2018-16673 Article 77 LOPDGDD], the DPA declared the infringement without imposing an administrative fine. == Comment == == Comment ==","Spain's data protection authority (AEPD) found the Dirección General de Tráfico's (DGT) mobile app violated Article 5(1)(c) of GDPR. The app collected and transmitted personal data, including IP and device information, that was not necessary for its intended purpose of providing push notifications. Although the controller implemented technical changes, the infringement had already occurred.","Spain's AEPD finds DGT's app violated GDPR by collecting unnecessary personal data.","Help AEPD (Spain) - ps-00287-2025: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 15:31, 1 October 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators349 edits Tag: Decisions [1.0] Latest revision as of 10:08, 2 October 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators349 editsTag: Visual edit Line 100: Line 100: The controller acknowledged that older versions of the app had transmitted personal data unnecessarily and implemented technical changes aimed at stopping the collection and transmission of such data.The controller acknowledged that older versions of the app had transmitted personal data unnecessarily and implemented technical changes aimed at stopping the collection and transmission of such data. === Holding ====== Holding === The DPA held that the controller violated [[Article 5 GDPR|Article 5(1)(c) GDPR]] because the app collected and transmitted personal data that were not necessary for its intended purposes.The DPA held that the controller violated [[Article 5 GDPR|Article 5(1)(c) GDPR]] because the app collected and transmitted personal data that were not necessary for its intended purposes. Line 109: Line 107: The controller's subsequent technical changes did not remove the infringement that had already occurred. Therefore, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(c) GDPR]].The controller's subsequent technical changes did not remove the infringement that had already occurred. Therefore, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(c) GDPR]]. Since the controller was a public authority subject to Article 77 LOPDGDD, the DPA declared the infringement without imposing an administrative fine.Since the controller was a public authority subject to [https:\u002F\u002Fwww.boe.es\u002Fbuscar\u002Fact.php?id=BOE-A-2018-16673 Article 77 LOPDGDD], the DPA declared the infringement without imposing an administrative fine. == Comment ==== Comment == Latest revision as of 10:08, 2 October 2026 AEPD - ps-00287-2025 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 5(1)(c) GDPR Article 77 of the Spanish Law on Personal Data Protection and Digital Rights Guarantee (LOPDGDD) Type: Complaint Outcome: Upheld Started: Decided: 17.11.2026 Published: Fine: n\u002Fa Parties: Dirección General de Tráfico (DGT) National Case Number\u002FName: ps-00287-2025 European Case Law Identifier: n\u002Fa Appeal: Unknown Original Language(s): Spanish Original Source: AEPD (in ES) Initial Contributor: bms The DPA found that a public authority’s mobile app collected more personal data than necessary, including IP and device data, in violation of Article 5(1)(c) GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A data subject lodged a complaint with the DPA against the Dirección General de Tráfico (DGT), the controller, the Spanish public authority responsible for traffic management, road safety and the administration of driving licences and vehicle records, after discovering that its mobile app transmitted numerous categories of personal and device data to a third-party service provider, the processor. The controller explained that the processor's software was integrated into the app to provide push notifications. However, the integration also enabled an optional functionality which transmitted usage and device data that were not necessary for providing those notifications. During its investigation, the DPA found that different versions of the app transmitted data including IP addresses, device information, country, language, app identifiers and information concerning the user's mobile network operator. The controller acknowledged that older versions of the app had transmitted personal data unnecessarily and implemented technical changes aimed at stopping the collection and transmission of such data. Holding The DPA held that the controller violated Article 5(1)(c) GDPR because the app collected and transmitted personal data that were not necessary for its intended purposes. In particular, the DPA considered that information such as IP addresses, country and mobile network operator data exceeded what was necessary for the app's functionality. The DPA also considered IP addresses to be personal data because they can allow a user to be identified when combined with other information. The controller's subsequent technical changes did not remove the infringement that had already occurred. Therefore, the DPA found a violation of Article 5(1)(c) GDPR. Since the controller was a public authority subject to Article 77 LOPDGDD, the DPA declared the infringement without imposing an administrative fine. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details. Case No.: EXP202317928 TABLE OF CONTENTS BACKGROUND..........................................................................................................2 FIRST: Filing of the Complaint........................................................................2 SECOND: Forwarding of the complaint and response from the respondent..................3 THIRD: Acceptance of the complaint for processing......................................................3 FOURTH: Preliminary investigative actions........................................................3 FIFTH: Decision to Initiate Disciplinary Proceedings..............................................33 SIXTH: Arguments Regarding the Agreement to Initiate Disciplinary Proceedings: Acknowledgment of Noncompliance and Measures Taken..............................................33 ESTABLISHED FACTS................................................................................................35 LEGAL GROUNDS.................................................................................................38 I Jurisdiction.........................................................................................................38 II Preliminary Issues...............................................................................................38 III Breach of Obligation. Data minimisation....................................................39 IV Classification of the violation of Article 5.1.c) of the GDPR and determination of the the statute of limitations.........................................................................................................41 V Notice of Violation..............................................................................................42 C\u002F Jorge Juan 6 www.aepd.es 28001 - Madrid sedeaepd.gob.es 2\u002F27 DECISION ON SANCTIONING PROCEEDINGS Regarding the proceedings conducted by the Spanish Data Protection Agency and based on the following: BACKGROUND FIRST: Filing of a Complaint On November 17, 2023, a complaint was filed with the Spanish Data Protection Authority regarding a possible violation attributable to the GENERAL DIRECTORATE OF TRAFFIC, Tax ID No. Q2816003D (hereinafter, D.G.T.). The facts brought to the attention of this authority were as follows: The complainant states that he installed the ***APP.1 app from the General Directorate of Traffic on his cell phone. According to the complainant, after using the app, he discovered that 47 pieces of information about his device (location, GPS coordinates, cookies, microphone status, IP address, etc.) are sent to ***COMPANY.1. The complainant believes that his data is being used in an unusual and unnecessary manner. Along with the complaint, he provides a screenshot showing the data that is allegedly sent to ***ENTERPRISE.1: - Screenshot of the ***APP.1 app, showing the following data captured by ***BROWSER.1 (unofficia","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_ps-00287-2025&diff=53285&oldid=53278","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F5\u002F59\u002FLogoES.jpg","2026-10-02T10:08:23+00:00","2026-10-02T12:00:17.01223+00:00",7,[18,21,24],{"name":19,"type":20},"AEPD","vendor",{"name":22,"type":23},"mobile app","product",{"name":25,"type":20},"DGT","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":26,"icon":28,"name":29,"slug":30},null,"Policy","policy",[32,37,42,44],{"category":33},{"id":34,"icon":28,"name":35,"slug":36},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":38},{"id":39,"icon":28,"name":40,"slug":41},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":43},{"id":26,"icon":28,"name":29,"slug":30},{"category":45},{"id":46,"icon":28,"name":47,"slug":48},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]