Back to all lessons
Awareness Lessons
2 months ago

Catalan Council Fined for Publishing Unredacted Personal Data and Ignoring DPA Requests

The Madremanya City Council exposed sensitive financial and personal data of social housing applicants by publishing documents without adequate redaction, a fundamental failure in data handling procedures. Compounding the breach, the council failed to respond to two formal information requests from the APDCAT, actively obstructing the regulatory investigation. This case illustrates that GDPR violations are not limited to technical breaches — procedural failures and non-cooperation with supervisory authorities carry their own significant penalties. Public sector bodies often underestimate their data protection obligations, particularly around document publication and regulatory engagement. The dual failure here — improper disclosure and non-cooperation — demonstrates how gaps in both technical controls and organisational accountability can escalate regulatory consequences.

Tactical Insight

Immediate actions

  • Establish a mandatory redaction review process for all documents containing personal data before any public publication.
  • Designate a responsible Data Protection Officer (DPO) point of contact to ensure timely responses to regulatory authority inquiries.
  • Audit all recently published documents to identify and remove any inadequately redacted personal or financial data.

Long-term improvements

  • Implement a formal Data Protection Impact Assessment (DPIA) procedure for any activity involving publication of documents containing personal data.
  • Create and maintain a documented records of processing activities (RoPA) register aligned with GDPR Article 30 requirements.
  • Develop staff training programmes focused on data minimisation, redaction techniques, and GDPR obligations specific to public sector entities.

Governance & compliance measures

  • Establish a clear internal escalation and response protocol for handling supervisory authority requests within legally required timeframes.
  • Schedule periodic compliance audits to verify that data publication workflows incorporate appropriate privacy controls.
  • Appoint or formally empower a DPO with sufficient authority and resources to enforce data protection policies across all departments.