The Sobrarbe region received a formal warning from the Spanish Data Protection Agency for improperly publishing personal citizen data in public council minutes. This oversight violated privacy regulations by disclosing sensitive identifiers and contact information during public sessions, highlighting significant gaps in how local entities handle public records versus private data protection requirements. The entity attempted to defend itself by claiming that the affected individual had not formally objected to the publications. However, the data protection authority determined that the exposure of personal details without a proper legal basis or prior consent constituted a clear infringement, regardless of whether the individual had explicitly requested cancellation at that time. This case is crucial for open data advocates, as it underscores the delicate balance between administrative transparency and individual privacy rights. It demonstrates that publishing data in open formats or public archives does not exempt organizations from GDPR compliance. Municipalities must implement robust governance structures, such as designated data protection officers, to ensure that openness does not inadvertently compromise citizen security or legal obligations.

Source:
Published on 2023-04-12