[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2RUwMLhFMxm_AnbfPp8KgwxPxn3IvGraNewqKRtL5jM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"bf7ad45e-ca3b-4945-b40e-2fcc1c0dedfb","spanish-notary-fined-for-unlawful-disclosure-of-personal-cadastral-data","97bb9bf8-0848-49b7-8ecf-dfca3123e686","Spanish Notary Fined for Unlawful Disclosure of Personal Cadastral Data","A Spanish notary disclosed a data subject's name and address via a cadastral certificate to a third-party client without establishing a valid legal basis, violating GDPR Article 6. The core failure was treating a client's interest in a property negotiation as sufficient justification to share another person's protected personal data — it was not. This case highlights that professionals handling sensitive records must rigorously verify lawful grounds before any disclosure, regardless of how routine the request may appear. Even well-intentioned data sharing without proper legal basis constitutes a GDPR violation and can result in regulatory fines and reputational harm.","**Immediate actions:**\n- Establish and enforce a written data disclosure policy requiring documented legal basis before sharing any personal data with third parties.\n- Train all staff and practitioners on GDPR Article 6 lawful bases, with specific examples relevant to notarial and cadastral data requests.\n\n**Process & Access Controls:**\n- Implement a formal request review checklist that verifies the requestor's identity, relationship to the data, and applicable legal grounds before any disclosure.\n- Restrict access to cadastral and personal records so that only authorized personnel with a verified need can retrieve and share such data.\n\n**Long-term improvements:**\n- Conduct regular GDPR compliance audits specific to data-sharing workflows within notarial and legal professional practices.\n- Appoint or designate a Data Protection Officer (DPO) or compliance advisor to review edge-case disclosure requests and maintain accountability.\n- Log all data disclosure requests and decisions to create an auditable trail for regulatory review.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 6 (Lawfulness of processing)","GDPR Article 5(1)(b) (Purpose limitation)","GDPR Article 5(1)(f) (Integrity and confidentiality)","NIST SP 800-53 AC-3 (Access Enforcement)","NIST SP 800-53 AC-22 (Publicly Accessible Content)","NIST Privacy Framework PR.AC-4","CIS Control 3 (Data Protection)","CIS Control 6 (Access Control Management)","ISO\u002FIEC 27001 A.8.2 (Information Classification)","ISO\u002FIEC 27001 A.9.4 (Information Access Restriction)","published","2026-09-03T13:20:22.826929+00:00","2026-09-03T13:20:22.729+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_ps-00256-2025&diff=52902&oldid=0","aepd-spain-ps-00256-2025-6a64be","AEPD (Spain) - ps-00256-2025",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]