Skip to content
Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Property Owner Community: Non-compliance with general data processing principles

The Spanish DPA (AEPD) has fined a property owners' community EUR 1,200.

€1,200 Fine
Property Owner Community
SPAIN
Art. 5 GDPR

Full text

The Spanish DPA (AEPD) has fined a property owners' community EUR 1,200. A property manager had sent a copy of the general meeting minutes to the director of the security company 'CMM Seguridad'. The document the said document contains the names and addresses of residents, a list of defaulters and the accounts with all income and expenses of the community. According to the controller, the purpose of sending the minutes in question to the security company was to inform them about the members of the Board of Directors appointed at the respective ordinary general meeting. Therefore, the controller should have limited to only providing this information or to transmitting the minutes document after it had been duly anonymized. For this reason, the DPA notes that the transmission of the full minutes would not have been necessary. As a result, the controller violated the principle of data minimization.

Industry: Individuals and Private Associations

How it connects

C-77/21 Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority… CJEU ·First Chamber Oct 20, 2022 Retention Period Storage Limitation Personal Data
C-268/21 Norra Stockholm Bygg AB v Per Nycander AB In Case C-268/21, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Swedish Supreme Court in proceedings between Norra Stockholm… CJEU ·Third Chamber Mar 2, 2023 Retention Period Anonymization Personal Data
C-175/20 SIA 'SS' v Valsts ieņēmumu dienests In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a… CJEU ·Fifth Chamber Feb 24, 2022 Retention Period Personal Data Legitimate Interest
C-446/21 Maximilian Schrems v Meta Platforms Ireland Limited In a preliminary ruling arising from proceedings between Maximilian Schrems and Meta Platforms Ireland Limited, the Court of Justice of the European Union interpreted GDPR… CJEU ·Fourth Chamber Oct 4, 2024 Retention Period Personal Data Marketing
Us I-4772/2023-10 A utility and municipal services enterprise, Zagrebački Holding d.o.o (the controller) provided users of its services with the option to request a copy of their bill via email. Where the name appearing in the email address differed from the user’s… US Zagreb - Us I-4772/2023-10 ·Administrative Court of Zagreb Jul 22, 2026 Personal Data Retention Period Controllers
C-741/21 GP v juris GmbH In Case C-741/21, the Court of Justice of the European Union (Third Chamber) addressed a preliminary reference from the Landgericht Saarbrücken in proceedings between data subject… CJEU ·Third Chamber Apr 11, 2024 Liability Personal Data Integrity and Confidentiality Principle