Spain Spain

Homeowners Association

6,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2022-05-11.

Rank · Sector
#59
of 351 in Individuals and Private Associations
Rank · Spain
#473
of 1,075
Rank · All fines
#1,624
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2022-05-11
Controller / Processor
Homeowners Association
Sector
Individuals and Private Associations
Quoted Articles
Art. 5 (1) c) GDPR, Art. 13 GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on a homeowners' association.
An apartment owner who had been a resident for 15 years had filed a complaint with the DPA due to the fact of having to show ID before using the communal pool. This request for personal data was based on measures to combat the covid-19 pandemic.
During its investigation, the DPA found that the collection of the pesonal data through the ID check was unnecessary given the fact that the data subject had been a resident for 15 years, and thus violated the principle of data minimization set forth in Art. 5 (1) c) GDPR. Furthermore, the DPA found that the data subject had not been sufficiently informed about the processing of their personal data.

Open original source Links to the regulator's original publication or another source.

Related fines