Back to all lessons
Awareness Lessons
last month

Spanish Notary Fined for Unlawful Disclosure of Personal Cadastral Data

A Spanish notary disclosed a data subject's name and address via a cadastral certificate to a third-party client without establishing a valid legal basis, violating GDPR Article 6. The core failure was treating a client's interest in a property negotiation as sufficient justification to share another person's protected personal data — it was not. This case highlights that professionals handling sensitive records must rigorously verify lawful grounds before any disclosure, regardless of how routine the request may appear. Even well-intentioned data sharing without proper legal basis constitutes a GDPR violation and can result in regulatory fines and reputational harm.

Tactical Insight

Immediate actions

  • Establish and enforce a written data disclosure policy requiring documented legal basis before sharing any personal data with third parties.
  • Train all staff and practitioners on GDPR Article 6 lawful bases, with specific examples relevant to notarial and cadastral data requests.

Process & Access Controls

  • Implement a formal request review checklist that verifies the requestor's identity, relationship to the data, and applicable legal grounds before any disclosure.
  • Restrict access to cadastral and personal records so that only authorized personnel with a verified need can retrieve and share such data.

Long-term improvements

  • Conduct regular GDPR compliance audits specific to data-sharing workflows within notarial and legal professional practices.
  • Appoint or designate a Data Protection Officer (DPO) or compliance advisor to review edge-case disclosure requests and maintain accountability.
  • Log all data disclosure requests and decisions to create an auditable trail for regulatory review.