Enforcement
EN SPAIN DPA: Non-compliance with general data processing principles
€600 fine - Spanish Data Protection Authority (aepd)
Content
The Spanish DPA imposed a fine on an unknown data controller. The controller stored full copies of personal IDs for verification purposes. In this case, storing all the information found on an ID was unnecessary and infringed upon the principle of data minimization. The original fine of EUR 1,000 was reduced to EUR 600 due to immediate payment and admission of responsibility by the controller.
GDPR Articles: Art. 5 (1) c) GDPR
Industry: Not assigned