APDCAT (Catalonia) - PS-0036/2026
Facts — On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing lease. The documents expressly disclosed the identities of the applicants. On 9 May 2025, the controller replaced the original documents with revised versions in which the applicants’ names and surnames were partially redacted, leaving only their initials visible. However, the redaction was performed manually and did not effectively conceal the information, as it remained possible to infer the length of the names and surnames and to identify some of their letters. In addition to the applicants’ identifying information, the documents disclosed detailed financial data, including the exact annual net income of each household. They also revealed information concerning particularly sensitive personal circumstances, including dependency, gender-based violence and addiction, which had been used to calculate the applicants’ respective scores. No adequate anonymisation or redaction measures had been implemented. In July and November 2025, the DPA requested that the controller provide specific information concerning certain aspects of the processing. The controller’s failure to respond or cooperate hindered the DPA’s ability to exercise its investigative powers. Holding — The DPA held that the controller violated Article 5(1)(c) GDPR by publishing personal data that were not necessary for the purpose pursued. The DPA acknowledged that publishing information about the procedure could serve the objective of administrative transparency. However, transparency did not justify disclosing identifying data together with detailed financial information and sensitive personal or family circumstances. The controller had to limit the processing to data that were necessary and proportionate to that objective and consider less intrusive alternatives. The DPA found that the controller’s subsequent redaction did not amount to effective anonymisation. Although most of the characters had been concealed, the applicants could still potentially be reidentified from their initials, the length of their names and surnames and other contextual information. This risk was particularly significant because the municipality had only 277 inhabitants. The controller should therefore have applied complete anonymisation or a pseudonymisation method preventing direct or indirect identification. The DPA also held that the controller violated Article 5(1)(f) GDPR and the duty of confidentiality under Article 5 LOPDGDD. The published documents disclosed the applicants’ exact household income, household composition and scores linked to circumstances such as dependency, addiction, gender-based violence, single-parent status and age. Although this information was relevant to assessing the applications, it was unnecessary to make it publicly accessible in a form linked to identifiable individuals. The DPA considered that the violations of the data-minimisation and confidentiality principles constituted a medial concurrence of infringements. The failure to anonymise the applicants’ identities was the necessary means through which their sensitive personal and family circumstances were disclosed. Nevertheless, the DPA formally declared separate violations of Articles 5(1)(c) and 5(1)(f) GDPR. Additionally, the DPA held that the controller violated Article 31 GDPR by failing to respond to two information requests. This failure breached the controller’s duty to cooperate with the supervisory authority and obstructed the exercise of the DPA’s investigative powers.
How it connects
Related across sources
Full text
Case Identification Resolution of sanctioning proceeding no. PS-0036/2026, concerning the Town Hall of Madremanya. Background 1. On May 8, 2025, a complaint was filed with the Catalan Data Protection Authority against the Madremanya City Council, alleging a potential violation of personal data protection regulations. The complainant stated that, on May 8, 2025, the Madremanya Town Hall published on its electronic notice board two minutes related to the tendering procedure for a social housing lease contract, identified by file number (...). According to the complainant, these minutes contained personal data of the applicants, both identifying and financial (first and last names and net annual income), as well as particularly sensitive information regarding situations of dependency and gender-based violence, without any anonymization or pseudonymization measures having been adopted. The complainant provided a copy of the two acts. 2. On May 13, 2025, the Authority received a new submission from the complainant in which they expanded on the facts reported. Thus, it was reported that the City Council had unredacted the two minutes and on May 9, 2025, had replaced them with the same document, leaving only the applicants' first and last names visible, but manually censoring the content. Likewise, the scoring tables for remuneration, or for situations of dependency or gender-based violence, remained visible. 3. The Authority opened a preliminary information phase (No. IP-0360/2025) to determine whether the facts could warrant the initiation of an enforcement proceeding, in accordance with Article 7 of Decree 278/1993, of November 9, on the sanctioning procedure applicable to the areas of competence of the Generalitat, and Article 55.2 of Law 39/2015, of October 1, on the common administrative procedure of public administrations (LPAC). In this information phase, on July 9, 2025, the entity under investigation was required to provide information on the legal basis that authorized the publication of the record with non-anonymized data and to indicate the period of time during which the document was accessible. 4. On November 6, 2025, the Town Hall of Madremanya was again required to respond due to the entity's lack of response to the previous request, with the warning that if they did not, they could be committing an infringement of data protection regulations. 5. On May 14, 2025, also during this preliminary information phase, the Authority's Inspection Area conducted a series of online checks regarding the facts that were the subject of the complaint. Thus, it was found that the City Council had indeed unsealed the original records and published documents that only included the initials of the names and surnames, with their content censored. However, the score obtained by each applicant was maintained without any anonymization measures. 6. On April 28, 2026, the Director of the Catalan Data Protection Authority decided to initiate an enforcement proceeding against the Madremanya City Council for 3 alleged infringements: an infringement provided for in Article 83.5.a in relation to Article 5.1.c; another infringement provided for in Article 83(5)(a) in relation to Article 5(1)(f); and a third infringement provided for in Article 83(4)(a) in relation to Article 31; all of them of the Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR). This initiation agreement was notified to the entity concerned on April 28, 2026, and it was granted a 10-business-day period to submit objections and propose the collection of evidence it deemed appropriate to defend its interests. The deadline has long since passed, and no objections have been filed. Established Facts 1. On May 8, 2025, the Madremanya City Council published on the notice board of its electronic headquarters two minutes related to the bidding process for a social housing lease contract, in which the identity of the applicants was expressly mentioned. On May 9, 2025, the Town Hall replaced the initial documents with new versions that displayed only the first names and surnames, with the rest of the letters obscured through a manual redaction process. However, this technique allowed the length of the first and last names to be inferred, as well as partially identifying some of the letters. 2. The aforementioned records incorporated, in addition to identifying data for the applicants, economic information regarding the exact annual net income of the household, as well as data related to particularly sensitive personal circumstances, such as situations of dependency, gender-based violence or addictions, used for the assignment of the corresponding score, without adequate anonymization measures having been adopted. 3. On July 9, 2025, and November 6, 2025, this Authority required the City Council of Madremanya to provide specific information about certain circumstances related to the facts brought to its attention. The lack of response and cooperation from the City Council has hindered this Authority's inspection functions. Legal Basis 1. The LPAC and Article 15 of Decree 278/1993, as provided for in Transitional Provision 2 of Law 32/2010 of October 1, on the Catalan Data Protection Authority, are applicable to this proceeding. In accordance with Articles 5 and 8 of Law 32/2010, the resolution of the sanctioning procedure is the responsibility of the Director of the Catalan Data Protection Authority. 2. In accordance with Article 64.2.f of the LPAC and in conformity with the agreement initiating this proceeding, it is appropriate to issue this resolution without a prior proposed resolution, since the entity charged has not filed objections to the agreement initiating the proceeding. This agreement contained a precise statement on the imputed liability. 3. With respect to the facts described in the first point of the established facts section, relating to the principle of minimization, we must refer to Article 5.1.c of the GDPR, which provides that: "1. Personal data shall be: (…) adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed ('data minimization')." In this case, despite the lack of response from the City Council to the requests addressed to it, it is understood that the purpose was to comply with the principle of administrative transparency and to make its activities and decisions public. However, this principle has certain limits, especially when personal data is involved. Article 24.2 of Law 19/2014, of December 29, on Transparency, Access to Public Information, and Good Governance, states that "if it is other information that contains personal data not included in Article 23, the information may be accessed, after a prior reasoned balancing of the public interest in disclosure and the rights of the affected individuals (...)." Initially, it should be noted that Article 5.1.c of the GDPR establishes that personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are to be processed. In this regard, Recital 39 of the GDPR states that personal data should only be processed if the purpose of the processing cannot be reasonably achieved by other, less intrusive means. This principle implies that data controllers must limit the processing of personal data to the minimum necessary for the achievement of the intended purpose, and must only carry out those processing operations that are necessary and proportionate in light of the purpose that justifies them. In this regard, the ECJ judgment of August 1, 2022, Case C-184/20, states that: "As regards, next, the requirement of necessity, of recital 39 of the of the GDPR it follows that this requirement is met when the general interest objective pursued cannot be reasonably achieved with the same effectiveness by other, less restrictive means of the data subjects' fundamental rights, in particular the rights to respect for private life and to the protection of personal data guaranteed by Articles 7 and 8 of the Charter, since exceptions and limitations in relation to the principle of protection of such data must be applied only to the extent that is strictly necessary (see, in this regard, judgment of June 22, 2021, Latvijas Republikas Saeima (Penalty points), C-439/19, EU:C:2021:504, paragraph 110 and the case law cited)." Furthermore, as reiterated case law has made clear (for all, judgment C-39/16, of March 3), in order to determine whether a restrictive measure of a fundamental right complies with the principle of proportionality, it must meet three requirements: that it is capable of achieving the objective proposed (judgment of suitability); that it is necessary, in the sense that no other, more moderate measure exists to achieve this purpose with the same effectiveness (judgment of necessity); and, finally, that it be proportionate or balanced, in that it derives more benefits or advantages for the general interest than harms to other conflicting goods or values (judgment of proportionality in the strict sense strict), that is, if the interference caused by the said measure in the rights holder subject to restriction is the minimum necessary to achieve the legitimate purpose sought by its adoption. In the present case, while it is true that the publication of applicants' identifying data may be required by the principle of administrative transparency, this circumstance does not, under any circumstances, justify the disclosure of identifying information associated with particularly sensitive data, nor can it be considered, in the terms required by data protection regulations, a necessary measure, let alone one that is strictly proportional. Initially, the identifying data were published without any anonymization measures. Subsequently, a new publication was made in which only the initials of the first and last names were kept visible, with the rest of the characters hidden through manual censorship. However, this technique does not guarantee effective anonymization, since, given the demographic characteristics of the municipality of Madremanya, which according to data from IDESCAT had 277 inhabitants in 2025, the combination of initials, the length of first and last names, and other contextual elements can allow for the re-identification of the affected individuals. Therefore, the mere partial concealment of identifying data is not an adequate measure to prevent the identification of the applicants, nor does it comply with the required guarantees in data protection law, especially when dealing with sensitive information. In this context, it would have been necessary to implement measures of complete anonymization in the publications made on the electronic portal or, alternatively, the use of pseudonymization systems that would prevent the direct or indirect identification of the applicants, thus ensuring effective compliance with the principles of data minimization. During the processing of this procedure, the fact described in the first point of the proven facts section has been established, which constitutes the infringement provided for in Article 83.5.a of the GDPR, which typifies the violation of "the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9," and among which is the principle of data minimization. The conduct at issue here is classified as a very serious offense in Article 72.1.a of the LOPDGDD, as follows: "a) The processing of personal data that violates the principles and guarantees established in Article 5 of Regulation (EU) 2016/679." 4. With regard to the fact described in point 2 of the proven facts section, concerning the violation of the principle of confidentiality, we must refer to Article 5.1.f of the GDPR, which provides that: "1. Personal data shall be: (...) f) processed in a manner that guarantees an adequate level of security for the personal data, including protection against unauthorized or unlawful processing and against its accidental loss, destruction, or damage, by applying appropriate technical and organizational measures ("integrity and confidentiality")." This principle of integrity and confidentiality provided for by the GDPR must be complemented by the duty of confidentiality set forth in Article 5 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), which states: "Article 5. Duty of confidentiality. 1. Data controllers and processors, as well as all persons who intervene in any phase of data processing, are subject to the duty of confidentiality referred to in Article 5(1)(f) of Regulation (EU) 2016/679. 2. The general obligation set forth in the preceding paragraph is complementary to the duties of professional secrecy in accordance with applicable regulations. 3. The obligations established in the preceding paragraphs remain in effect even after the obligated party's relationship with the data controller or processor has ended." In the present case, in addition to the dissemination of the applicants' identifying data, detailed information regarding their household was published. Specifically, the household's annual net income, the number of people in it, and a score linked to years of residency in the municipality were made public. Additionally, the assignment of individual scores associated with personal or family circumstances was disclosed, such as situations of dependency, addictions, domestic violence, single-parenthood, as well as being under 30 or over 65 years of age. In this context, a score of between 0 and 5 points was awarded, with 1 point assigned for each family member who was in one of the aforementioned circumstances. This information, while it may be relevant for evaluation purposes in the contract award procedure, does not in any case require its complete and visible publication for all citizens, linked to the identity of the affected individuals. However, in the present case, it must be considered that this would be a case of a medial concurrence of offenses, since the two offenses imputed are closely linked, to the extent that one is a necessary means for the commission of the other. In this regard, the failure to apply the principle of data minimization, by failing to anonymize the identity of the applicants, led to a violation of the principle of confidentiality in the disclosure of particularly sensitive personal circumstances of their family unit. In accordance with the foregoing, the fact set forth in point 2 of the proven facts section constitutes the infringement provided for in Article 83.5(a) of the GDPR, which classifies a breach of the "basic principles for processing," among which is the principle of confidentiality. APDCAT Processor: 07/17/2026 10:456/8 In turn, this conduct has been classified as a very serious infringement in Article 72.1.i of the LOPDGDD, as follows: "i) Violation of the duty of confidentiality established in Article 5 of this Organic Law." 5. With regard to the fact described in point 3 of the proven facts section, concerning the lack of cooperation by the Madremanya City Council, we must refer to Article 31 of the GDPR, which provides that: "The controller and the processor and, where applicable, their representatives shall cooperate with the supervisory authority that requests it in the performance of its tasks." This provision must be related to the investigation powers conferred on the supervisory authority, as provided for in Article 58(1) of the GDPR, which, in paragraph a, provides the following: "1. Each supervisory authority shall have all of the following investigative powers: a) Order the controller and the processor and, where applicable, the representative of the controller or the processor, to provide any information they require for the performance of their duties. (...)" In this case, the lack of cooperation by the Madremanya Town Hall is imputed to its failure to comply with the two information requests issued by this Authority. This conduct constitutes a breach of the duty to cooperate with this Authority and likewise demonstrates a low level of responsibility on the part of the entity concerned regarding the guarantee of the right to the protection of personal data. In accordance with the foregoing, the fact set forth in point 3 of the proven facts section constitutes the infringement provided for in Article 83(4)(a) of the GDPR, which typifies the breach of "the obligations of the controller and the processor under Articles 8, 11, 25 to 39, 42 and 43" among which is the one set forth in Article 31 of the GDPR. In turn, this conduct is classified as a serious infringement in Article 73 of the LOPDGDD, as follows: "o) Failure to cooperate with the supervisory authorities in the performance of their functions in cases not provided for in Article 72 of this organic law." 6. Article 77.2 of the LOPDGDD provides that, in the case of infringements committed by the controllers or processors listed in Article 77.1 of the same law, the competent data protection authority: "(...) shall issue a resolution declaring the infringement and, where appropriate, establishing the measures to be taken to cease the conduct or correct the effects of the infringement committed, with the exception of that provided for in Article 58(2)(i) of the Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016. The resolution shall be notified to the controller or processor, to the body to which it is hierarchically subordinate, if applicable, and to the affected data subjects, if applicable." In terms similar to the LOPDGDD, Article 21.2 of Law 32/2010 provides the following: "2. In the case of infringements committed in relation to publicly-owned files, the Director of the Catalan Data Protection Authority shall issue a resolution declaring the infringement and establishing the measures to be taken to correct its effects (...)." Pursuant to this authority, the Madremanya Town Council is hereby required to, at the earliest opportunity and in any event within a maximum of 10 days from the day after notification of this resolution, remove the posters. as soon as possible, and in any case within a maximum of 10 days from the day after the notification of this resolution, proceed to remove the following documents from the website and, where applicable, replace them with others that have effective anonymization measures: - Minutes of the opening of proposals. - Minutes of the evaluation of proposals. - Minutes of the verification of the evaluation of proposals. Once the corrective measure described has been adopted within the specified period, the Madremanya City Council must inform the Authority within the following 10 days, without prejudice to this Authority's inspection powers to carry out the corresponding verifications. Resolution Therefore, I resolve: 1. To declare that the Madremanya City Council has committed 3 violations: one violation provided for in Article 83.5.a in relation to Article 5.1.c; another violation provided for in Article 83.5.a in relation to Article 5.1.f; and a third infringement provided for in Article 83.4.a in relation to Article 31, all of the GDPR. 2. Require the Madremanya City Council to adopt the corrective measures indicated in the 6th legal basis and to provide evidence to this Authority of the actions taken to comply. 3. Notify this resolution to the Madremanya Town Council. 4. Communicate the resolution to the Ombudsman, in accordance with Article 77.5 of the LOPDGDD. 5. Order that this resolution be published on the Authority's electronic headquarters, in accordance with Article 17 of Law 32/2010 of October 1. This resolution, which exhausts the administrative appeal process in accordance with Articles 26.2 of the Law 32/2010 and 14.3 of Decree 48/2003, of February 20, 2003, which approves the Statute of the Catalan Data Protection Agency, the entity concerned may file an appeal with the Director of the Catalan Data Protection Authority within one month from the day after its notification, in accordance with Articles 123 and following of Law 39/2015. An administrative appeal may also be filed directly with the Barcelona administrative courts within two months from the day after its notification, in accordance with Law 29/1998, of July 13, which regulates the administrative litigation jurisdiction. The Director