Back to all lessons
Awareness Lessons
last month

Notary Fined for Unlawful Disclosure of Personal Data Without Legal Basis

A Spanish notary disclosed a cadastral certificate containing personal data to a third-party client without a valid legal basis under GDPR Article 6(1), despite the client's stated intention being a property negotiation. While notaries may access certain data in the course of their official duties, that access right does not automatically authorize sharing complete personal records with private parties for purposes outside their official competences. This case highlights a critical distinction between lawful access to data and lawful disclosure of that data — they require separate and independent legal justifications. The violation matters because even well-intentioned data sharing, such as facilitating a legitimate property transaction, can constitute a serious breach if the proper legal basis is not established before disclosure.

Tactical Insight

Immediate actions

  • Establish and enforce a written data-sharing policy that requires staff to verify a documented legal basis before disclosing any personal data to third parties.
  • Conduct an urgent review of all current data-disclosure practices to identify any instances where personal records are shared without an explicit legal basis.

Process & Governance improvements

  • Implement a formal data-request approval workflow that requires sign-off confirming lawful basis (e.g., consent, legal obligation, legitimate interest) before any personal data leaves the organization.
  • Maintain a data-sharing register documenting who received personal data, under what legal basis, and for what stated purpose.
  • Clearly define and communicate the boundaries of role-based data access versus data disclosure rights for all staff handling personal records.

Training & Awareness measures

  • Deliver mandatory GDPR training to all staff that explicitly distinguishes between the right to *access* personal data and the right to *disclose* it to third parties.
  • Run periodic scenario-based refresher exercises covering common high-risk situations, such as client requests for documents containing third-party personal information.