Skip to content
Enforcement
EN

Homeowners Association: Non-compliance with general data processing principles

€6,000 fine - Spanish Data Protection Authority (aepd)

€6,000 Fine
Homeowners Association
SPAIN
Non-compliance with general data processing principles

Content

The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on a homeowners' association. An apartment owner who had been a resident for 15 years had filed a complaint with the DPA due to the fact of having to show ID before using the communal pool. This request for personal data was based on measures to combat the covid-19 pandemic. During its investigation, the DPA found that the collection of the pesonal data through the ID check was unnecessary given the fact that the data subject had been a resident for 15 years, and thus violated the principle of data minimization set forth in Art. 5 (1) c) GDPR. Furthermore, the DPA found that the data subject had not been sufficiently informed about the processing of their personal data.

GDPR Articles: Art. 5 (1) c) GDPR, Art. 13 GDPR
Industry: Individuals and Private Associations