APDCAT (Catalonia) - PS-0036/2026
Catalonia DPA fines city council for publishing sensitive applicant data and non-cooperation.
Summary
The Catalan Data Protection Authority (APDCAT) fined the Madremanya City Council for violating GDPR. The council published sensitive financial and personal data of social housing applicants without adequate redaction and failed to respond to two information requests from the DPA. This non-cooperation hindered the DPA's investigative powers.
Full text
Help APDCAT (Catalonia) - PS-0036/2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 14:21, 3 August 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators240 editsTag: Visual edit← Older edit Latest revision as of 11:45, 4 August 2026 view source Fm (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators102 editsTag: Visual edit (2 intermediate revisions by the same user not shown)Line 100: Line 100: }}}} The DPA held that a city council violated [[Article 5 GDPR|Articles 5(1)(c)]], [[Article 5 GDPR|5(1)(f)]] and [[Article 31 GDPR|31 GDPR]] by publishing identifiable applicants’ financial and sensitive data and failing to answer two information requests.The DPA held that a city council violated [[Article 5 GDPR|Articles 5(1)(c)]], [[Article 5 GDPR|5(1)(f)]] and [[Article 31 GDPR|31 GDPR]] by publishing financial and sensitive data of applicants for social housing and failing to answer two information requests of the DPA. == English Summary ==== English Summary == Line 111: Line 111: In addition to the applicants’ identifying information, the documents disclosed detailed financial data, including the exact annual net income of each household. They also revealed information concerning particularly sensitive personal circumstances, including dependency, gender-based violence and addiction, which had been used to calculate the applicants’ respective scores. No adequate anonymisation or redaction measures had been implemented.In addition to the applicants’ identifying information, the documents disclosed detailed financial data, including the exact annual net income of each household. They also revealed information concerning particularly sensitive personal circumstances, including dependency, gender-based violence and addiction, which had been used to calculate the applicants’ respective scores. No adequate anonymisation or redaction measures had been implemented. In July 2025, the DPA requested that the controller provide specific information concerning certain aspects of the processing. The controller’s failure to respond or cooperate hindered the DPA’s ability to exercise its investigative powers.In July and November 2025, the DPA requested that the controller provide specific information concerning certain aspects of the processing. The controller’s failure to respond or cooperate hindered the DPA’s ability to exercise its investigative powers. === Holding ====== Holding === The DPA held that the controller violated [[Article 5 GDPR|Article 5(1)(c) GDPR]] by publishing personal data that were not necessary for the purpose pursued.The DPA held that the controller violated [[Article 5 GDPR|Article 5(1)(c) GDPR]] by publishing personal data that were not necessary for the purpose pursued. Latest revision as of 11:45, 4 August 2026 APDCAT - PS-0036/2026 Authority: APDCAT (Catalonia) Jurisdiction: Spain Relevant Law: Article 5(1)(c) GDPR Article 5(1)(f) GDPR Article 31 GDPR Article 5 LOPDGDDArticle 77 LOPDGDD Type: Complaint Outcome: Upheld Started: 28.04.2026 Decided: 17.07.2026 Published: Fine: n/a Parties: Ajuntament de Madremanya National Case Number/Name: PS-0036/2026 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Catalan; Valencian Original Source: APDCAT (in CA) Initial Contributor: bms The DPA held that a city council violated Articles 5(1)(c), 5(1)(f) and 31 GDPR by publishing financial and sensitive data of applicants for social housing and failing to answer two information requests of the DPA. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing lease. The documents expressly disclosed the identities of the applicants. On 9 May 2025, the controller replaced the original documents with revised versions in which the applicants’ names and surnames were partially redacted, leaving only their initials visible. However, the redaction was performed manually and did not effectively conceal the information, as it remained possible to infer the length of the names and surnames and to identify some of their letters. In addition to the applicants’ identifying information, the documents disclosed detailed financial data, including the exact annual net income of each household. They also revealed information concerning particularly sensitive personal circumstances, including dependency, gender-based violence and addiction, which had been used to calculate the applicants’ respective scores. No adequate anonymisation or redaction measures had been implemented. In July and November 2025, the DPA requested that the controller provide specific information concerning certain aspects of the processing. The controller’s failure to respond or cooperate hindered the DPA’s ability to exercise its investigative powers. Holding The DPA held that the controller violated Article 5(1)(c) GDPR by publishing personal data that were not necessary for the purpose pursued. The DPA acknowledged that publishing information about the procedure could serve the objective of administrative transparency. However, transparency did not justify disclosing identifying data together with detailed financial information and sensitive personal or family circumstances. The controller had to limit the processing to data that were necessary and proportionate to that objective and consider less intrusive alternatives. The DPA found that the controller’s subsequent redaction did not amount to effective anonymisation. Although most of the characters had been concealed, the applicants could still potentially be reidentified from their initials, the length of their names and surnames and other contextual information. This risk was particularly significant because the municipality had only 277 inhabitants. The controller should therefore have applied complete anonymisation or a pseudonymisation method preventing direct or indirect identification. The DPA also held that the controller violated Article 5(1)(f) GDPR and the duty of confidentiality under Article 5 LOPDGDD. The published documents disclosed the applicants’ exact household income, household composition and scores linked to circumstances such as dependency, addiction, gender-based violence, single-parent status and age. Although this information was relevant to assessing the applications, it was unnecessary to make it publicly accessible in a form linked to identifiable individuals. The DPA considered that the violations of the data-minimisation and confidentiality principles constituted a medial concurrence of infringements. The failure to anonymise the applicants’ identities was the necessary means through which their sensitive personal and family circumstances were disclosed. Nevertheless, the DPA formally declared separate violations of Articles 5(1)(c) and 5(1)(f) GDPR. Additionally, the DPA held that the controller violated Article 31 GDPR by failing to respond to two information requests. This failure breached the controller’s duty to cooperate with the supervisory authority and obstructed the exercise of the DPA’s investigative powers. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Catalan; Valencian original. Please refer to the Catalan; Valencian original for more details. Case Identification Resolution of sanctioning proceeding no. PS-0036/2026, concerning the Town Hall of Madremanya. Background 1. On May 8, 2025, a complaint was filed with the Catalan Data Protection Authority against the Madremanya City Council, alleging a potential violation