Back to all lessons
Awareness Lessons
last week

Spain's DGT App Violated GDPR Data Minimisation by Collecting Unnecessary Device Data

The DGT's mobile app collected and transmitted personal data — including IP addresses and device identifiers — that was not required to deliver its core function of push notifications, violating GDPR's data minimisation principle under Article 5(1)(c). This reflects a failure to conduct adequate privacy-by-design reviews before deployment, where data collection scope was broader than technically necessary. The fact that the controller only made corrections after regulatory scrutiny highlights a reactive rather than proactive approach to privacy compliance. This case matters because unnecessary data collection expands the attack surface, increases breach impact, and exposes organisations to significant regulatory and reputational risk.

Tactical Insight

Immediate actions

  • Audit all data fields currently collected by mobile and web applications and remove any not strictly necessary for the stated purpose.
  • Conduct a Data Protection Impact Assessment (DPIA) for existing apps that handle personal data to identify minimisation gaps.

Long-term improvements

  • Embed Privacy by Design principles into the software development lifecycle so data minimisation is evaluated before deployment, not after.
  • Establish a formal data inventory and classification process that maps each data element to a specific, documented processing purpose.
  • Implement periodic privacy compliance reviews for all customer-facing applications on a defined schedule (e.g., annually or upon major updates).

Detection & governance measures

  • Deploy network traffic analysis or API monitoring to detect unexpected or undocumented categories of personal data being transmitted.
  • Assign a designated privacy owner for each application who is accountable for ongoing GDPR compliance and must sign off on data collection changes.