Awareness Lessons
last month
Spanish Notary Fined for Unlawful Disclosure of Personal Cadastral Data
A Spanish notary disclosed a data subject's name and address via a cadastral certificate to a third-party client without establishing a valid legal basis, violating GDPR Article 6. The core failure was treating a client's interest in a property negotiation as sufficient justification to share another person's protected personal data — it was not. This case highlights that professionals handling sensitive records must rigorously verify lawful grounds before any disclosure, regardless of how routine the request may appear. Even well-intentioned data sharing without proper legal basis constitutes a GDPR violation and can result in regulatory fines and reputational harm.
Tactical Insight
Immediate actions
- Establish and enforce a written data disclosure policy requiring documented legal basis before sharing any personal data with third parties.
- Train all staff and practitioners on GDPR Article 6 lawful bases, with specific examples relevant to notarial and cadastral data requests.
Process & Access Controls
- Implement a formal request review checklist that verifies the requestor's identity, relationship to the data, and applicable legal grounds before any disclosure.
- Restrict access to cadastral and personal records so that only authorized personnel with a verified need can retrieve and share such data.
Long-term improvements
- Conduct regular GDPR compliance audits specific to data-sharing workflows within notarial and legal professional practices.
- Appoint or designate a Data Protection Officer (DPO) or compliance advisor to review edge-case disclosure requests and maintain accountability.
- Log all data disclosure requests and decisions to create an auditable trail for regulatory review.