Skip to content
Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Certime S.A.: Non-compliance with general data processing principles

The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Certime S.A..

€5,000 Fine
Certime S.A.
SPAIN
Art. 5 GDPR

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Certime S.A.. The data subject had renewed her driver's license with the controller in 2009. After her address had changed in 2018, in 2019 she received mail from the controller to her new address without having informed the controller of the adress change. In the letter, the controller informed the data subject that her driver's license would soon expire. In response to a inquiry from the data subject as to where her new contact information came from, the controller informed her that its database was regularly updated using data obtained from the Spanish transport authority DGT (Dirección General de Tráfico). As the data subject had not given consent for such processing of her data, she filed a complaint against the controller with the Spanish DPA. An investigation by the DPA revealed that the company had indeed entered into a contract with DGT.

§

However, DGT had clarified that the purpose of the processing of contact data under the contract was to ensure the accuracy of the address when renewing a driver's license or when issuing medical reports so that it could be sent to the correct address. Nevertheless, the data subjects must request and consequently consent to such a change of address. Since these criteria were not met in the specific case, the DPA found a violation of the purpose limitation principle. GDPR Articles: Art. 5 (1) b) GDPR Industry: Public Sector and Education

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) CJEU Jan 12, 2023 Supervisory Authorities IP Address Supervision
T-318/24 GC T-318/24: EPSO access logs and Article 17 access requests under Regulation 2018/1725 An applicant (the data subject) participated in several EU staff selection procedures administered by the European Personnel Selection Office (EPSO), acting as controller, and… General Court Dec 3, 2025 Right of Access Personal Data Right to Restriction