Spain Spain

Unknown

1,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2026-03-01.

Rank · Sector
#549
of 597 in Industry and Commerce
Rank · Spain
#858
of 1,075
Rank · All fines
#2,723
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2026-03-01
Controller / Processor
Unknown
Sector
Industry and Commerce
Quoted Articles
Art. 5 (1) c) GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The Italian DPA has imposed a fine of EUR 1,000 on a unknown data controller. The controller had been appointed to issue an energy performance certificate for a data subject. In that context, the controller requested a full copy of the front of their ID card alongside other information. Requesting a full copy of the ID card infringed the principle of data minimisation, as a full copy includes data that is not necessary for the purpose of authorising a natural person.

Open original source Links to the regulator's original publication or another source.

Related fines