[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgtSp8WX8gMrO3eTCF1e93NMbSIqauooDcU0mu915LQQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"5001bd2b-14cf-4468-8cc2-583cabdf4536","spains-dgt-fined-for-collecting-excessive-personal-data-via-mobile-app","131d0120-024b-4c24-9203-51143adee88b","Spain's DGT Fined for Collecting Excessive Personal Data via Mobile App","The Dirección General de Tráfico violated GDPR's data minimisation principle (Article 5(1)(c)) by collecting and transmitting unnecessary personal data — including IP addresses and device identifiers — through its official mobile application. The root cause was a failure to design the app with privacy by design and by default principles, meaning data collection was not scoped to what was strictly necessary for the app's purpose. This matters because public sector organisations handle data for large populations and hold a heightened responsibility to model compliant data practices. Even though no fine was imposed due to the controller's public authority status, the reputational and corrective burden demonstrates that technical implementation decisions carry direct regulatory consequences.","**Immediate actions:**\n- Conduct a data mapping audit of all mobile and web applications to identify every data element collected, transmitted, or stored.\n- Remove or anonymise any personal data fields (e.g., IP addresses, device identifiers) that are not strictly necessary for the stated application purpose.\n\n**Privacy by Design measures:**\n- Embed a Privacy Impact Assessment (PIA\u002FDPIA) as a mandatory gate in the software development lifecycle before any app release or update.\n- Configure application backends to collect only the minimum data required by default, requiring explicit justification to add new data fields.\n- Engage a Data Protection Officer (DPO) during the design phase of any citizen-facing digital service.\n\n**Governance & compliance monitoring:**\n- Establish a recurring review cadence (at least annually) to reassess whether data collected by existing applications remains proportionate and necessary.\n- Implement automated scanning tools to detect unexpected data transmission from mobile apps during QA testing and post-deployment monitoring.",[12,13,14,15,16,17,18,19,20],"GDPR Article 5(1)(c) — Data Minimisation","GDPR Article 25 — Data Protection by Design and by Default","GDPR Article 35 — Data Protection Impact Assessment (DPIA)","NIST Privacy Framework PR.DS-P1 — Data minimisation practices","NIST SP 800-53 RA-3 — Risk Assessment","NIST SP 800-53 SI-12 — Information Management and Retention","CIS Control 3 — Data Protection (Subcontrol 3.1: Establish and Maintain a Data Management Process)","ISO\u002FIEC 29101 — Privacy Architecture Framework","ITIL Service Design — Privacy and data handling requirements in service design","published","2026-10-01T16:20:36.616866+00:00","2026-10-01T16:20:36.501+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_ps-00287-2025&diff=53278&oldid=0","aepd-spain-ps-00287-2025-4ac220","AEPD (Spain) - ps-00287-2025",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":42,"name":43,"slug":44,"description":45,"color":46},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]