Spain's DGT Fined for Collecting Excessive Personal Data via Mobile App
The Dirección General de Tráfico violated GDPR's data minimisation principle (Article 5(1)(c)) by collecting and transmitting unnecessary personal data — including IP addresses and device identifiers — through its official mobile application. The root cause was a failure to design the app with privacy by design and by default principles, meaning data collection was not scoped to what was strictly necessary for the app's purpose. This matters because public sector organisations handle data for large populations and hold a heightened responsibility to model compliant data practices. Even though no fine was imposed due to the controller's public authority status, the reputational and corrective burden demonstrates that technical implementation decisions carry direct regulatory consequences.
Tactical Insight
Immediate actions
- Conduct a data mapping audit of all mobile and web applications to identify every data element collected, transmitted, or stored.
- Remove or anonymise any personal data fields (e.g., IP addresses, device identifiers) that are not strictly necessary for the stated application purpose.
Privacy by Design measures
- Embed a Privacy Impact Assessment (PIA/DPIA) as a mandatory gate in the software development lifecycle before any app release or update.
- Configure application backends to collect only the minimum data required by default, requiring explicit justification to add new data fields.
- Engage a Data Protection Officer (DPO) during the design phase of any citizen-facing digital service.
Governance & compliance monitoring
- Establish a recurring review cadence (at least annually) to reassess whether data collected by existing applications remains proportionate and necessary.
- Implement automated scanning tools to detect unexpected data transmission from mobile apps during QA testing and post-deployment monitoring.