Back to all lessons
Awareness Lessons
5 days ago

DGT Mobile App Violates GDPR Data Minimization by Over-Collecting User Data

Spain's traffic authority (DGT) deployed a mobile application that collected and transmitted more personal data than necessary — including IP addresses and device identifiers — to a third-party processor, violating the GDPR principle of data minimization under Article 5(1)(c). The root cause was a failure to rigorously assess what data was genuinely required before the app was released, combined with insufficient oversight of what the third-party processor received. This case illustrates that privacy obligations must be designed into systems from the outset, not retrofitted after a regulator intervenes. Even though DGT made technical corrections, the infringement had already occurred, demonstrating that reactive fixes cannot undo regulatory exposure. Organizations must treat data minimization as a non-negotiable engineering requirement, not an afterthought.

Tactical Insight

Immediate actions

  • Conduct a data flow audit of all mobile and web applications to identify unnecessary personal data collection and transmission.
  • Review and update Data Processing Agreements (DPAs) with all third-party processors to explicitly restrict the categories of data they may receive.

Long-term improvements

  • Embed Privacy by Design principles into the software development lifecycle (SDLC), requiring a Data Protection Impact Assessment (DPIA) before any new app release.
  • Establish a vendor/supply-chain risk management program that includes technical controls verifying what data third-party SDKs and processors actually receive.
  • Define and enforce a data minimization policy that mandates documented justification for every personal data field collected by any application.

Detection & Monitoring measures

  • Implement continuous network traffic monitoring to detect unexpected or excessive data transmissions from applications to external endpoints.
  • Schedule regular privacy compliance audits (at least annually) covering all customer-facing applications and their third-party integrations.