AEPD (Spain) - PS-00304-2024
| AEPD - PS-00304-2024 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 5(1)(c) GDPR Article 5(2) GDPR Article 25 GDPR Article 58(2)(d) GDPR Article 7 LOPDGDD |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | 01.04.2025 |
| Decided: | |
| Published: | 25.06.2026 |
| Fine: | 20000.0 EUR |
| Parties: | El León de El Español Publicaciones, S.A. |
| National Case Number/Name: | PS-00304-2024 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Spanish; Castilian |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | bms |
The DPA fined a newspaper €20,000 for publishing an identifiable video of an assault victim and a minor assailant, since their identification was unnecessary for reporting the incident.
English Summary
Facts
El León de El Español Publicaciones, S.A., the controller, operates the Spanish digital newspaper „El Español“. It published an article concerning an assault and embedded a video showing both the victim and the assailant, who was a minor. Their image and voice were disclosed without applying techniques to prevent their direct or indirect identification. The controller also published the video through its accounts on two social media platforms.
The DPA initiated preliminary investigations ex officio after becoming aware of the dissemination of the video. It ordered the controller, as a precautionary measure, to immediately remove the content from the relevant URLs. The controller subsequently informed the DPA that it had removed the article and prevented access through both external links and its internal search engine. The DPA verified that the video was no longer available through the identified web addresses.
The DPA subsequently initiated disciplinary proceedings for a potential infringement of Article 5(1)(c) GDPR. The controller argued that the incident was newsworthy, the video had already gone viral and the publication was protected by freedom of information. It also claimed that the video was necessary to understand the news and that the assailant’s status as a minor should be assessed in light of his apparent maturity and awareness that he was being recorded.
Holding
The DPA found that the controller violated the data minimisation principle under Article 5(1)(c) GDPR.
The DPA clarified that the proceedings did not concern whether the incident was newsworthy or whether the controller could report on it. Instead, the relevant question was whether publishing the identifiable image and voice of the individuals was necessary and proportionate for that purpose.
According to the DPA, freedom of information and the right to data protection are not absolute. Under Article 85 GDPR, they must be reconciled on a case-by-case basis. In this case, the controller could have informed the public about the incident while using technical measures, such as blurring the individuals’ faces or altering the audio, to prevent their identification. Showing the individuals in an identifiable manner was therefore not necessary to achieve the journalistic purpose.
The DPA also rejected the argument that the previous virality of the video justified its republication. Each additional publication contributed to the further dissemination of the personal data and amplified the risks and adverse effects for the data subjects. Similarly, the fact that the affected individuals had not submitted a complaint did not prevent the DPA from exercising its supervisory powers ex officio.
The DPA gave particular weight to the vulnerability of the victim and to the fact that the assailant was a minor. It held that the best interests and enhanced protection of minors had to be taken into account irrespective of the minor’s alleged maturity or awareness of being recorded. The age at which a minor may consent under Article 7 LOPDGDD did not reduce the controller’s obligation to assess whether the disclosure was necessary.
The DPA further noted that, pursuant to Articles 5(2) and 25 GDPR, the controller was required to assess and document the risks of the processing and implement data protection by design and by default. As a professional media organisation regularly processing personal data, the controller was expected to apply a particularly high standard of diligence and to consider less intrusive methods of publication.
When determining the sanction, the DPA considered the unrestricted online dissemination of the data, the potentially unlimited audience, the controller’s negligence, the sensitive circumstances surrounding the victim and the minor, and the impact of the infringement on the rights of a minor. It therefore imposed a €20,000 fine.
Under Article 58(2)(d) GDPR, the DPA also ordered the controller to demonstrate, within three months after the decision became enforceable, that it had adopted measures to prevent the excessive publication or dissemination of personal data, particularly data concerning minors. It made the earlier precautionary measure definitive and required the permanent removal of the content, while allowing its restricted preservation where necessary as evidence for administrative, police or judicial proceedings.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish; Castilian original. Please refer to the Spanish; Castilian original for more details.
Case No.: EXP202313543
DECISION ON DISCIPLINARY PROCEEDINGS
Regarding the proceedings conducted by the Spanish Data Protection Agency and based on
the following
BACKGROUND
FIRST: On ***DATE.1 “11:41,” a news article was published in the newspaper
www.elespanol.com
***URL.1, with the title: “***TITLE.1,” which was recorded as evidence by the
AEPD.
The news article contains “(…)”.
In the video shown, the following details appear: embedded on the page, in the post on
the ***PLATFORM.1, the name “***PROFILE.1” “@PROFILE.1” “11:38
***DATE.2.” If you click the play button, you can watch the video in which, inside (…),
a young man appears talking to an older person, and you can hear the young man ask, (…) and
the older person respond: (…).
The same video also appears on the pages of ***PLATFORM.1, ***URL.2, in the
post by “El Español,” “@elespanolcom,” “1:22 p.m. ***DATE.5 14.7K views,” and
on ***PLATFORM.2 of the same newspaper, ***URL.3, dated ***DATE.1, with 59 likes and 122
comments. In the latter, the name “***PROFILE.1” “@PROFILE.1” is not visible, and it is
reported (…) that the news item was not flagged, as evidenced by the AEPD.
On ***DATE.1, the AEPD obtained a post on ***PLATFORM.1 from the
“***PROFILE.1” profile at 11:38 on ***DATE.2 with the text “(…)…” and images from
a video in which, inside (…), a young man is seen talking to an elderly person,
(…) and responding to the older person: (…).
Through the ***PLATFORM.1 profile “@PROFILE.1,” with a post published on
***DATE.2 at 11:38 a.m., the aforementioned video can be seen, with 2.3 million views, serving
as evidence of the aforementioned posts on file with the AEPD.
On ***DATE.3, the Director of the Spanish Data Protection Agency
ordered the ex officio initiation of preliminary investigative proceedings in connection with
information obtained through the media regarding a possible violation in the
processing of personal data related to the dissemination of a video. According to the information
published, the video in question was (…) recorded by a third party and subsequently disseminated
through various media outlets and social media platforms.
SECOND: The Subdirectorate General for Data Inspection proceeded to conduct
preliminary investigative proceedings to clarify the facts in question,
pursuant to the functions assigned to supervisory authorities under Article 57(1) and the
powers granted under Article 58(1) of Regulation (EU) 2016/679 (General Data
Protection Regulation
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 2/28
Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of
Title VII, Chapter I, Section Two, of the LOPDGDD,
-On ***DATE.3, we request the adoption of precautionary measures regarding the content of the
videos found at the specified web addresses, directed to the data controller: EL
LEÓN DE EL ESPAÑOL PUBLICACIONES SA (hereinafter, EE), para “remove the
aforementioned content from the web addresses from which it is accessible.”
On ***DATE.4, following a letter from EE stating that it had proceeded to “remove
the news article, preventing access to it both externally and through the
newspaper’s internal search engine,” the Inspector verified that the content had been erased from
the various platforms used by EE.
Evidence of the erasure of the content is recorded and included in the case file.
THIRD: According to the report generated by the AXESOR tool, the entity EL
LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A. is an SME incorporated in 2014,
with a turnover of 19,443,719 euros in 2023.
FOURTH: On April 1, 2025, the President of the AEPD issued the following decision:
“FIRST: TO INITIATE SANCTIONING PROCEEDINGS against EL LEÓN DE EL
ESPAÑOL PUBLICACIONES, S.A. (EL ESPAÑOL), with Tax ID No. A87115226, for the alleged
violation of Article 5.1.c) of the GDPR, in accordance with Article 83.5.a) of the GDPR and
classified as “very serious” for the purposes of the statute of limitations under Article 72.1.a).
SECOND: TO CONFIRM the provisional measure imposed on EL LEÓN DE EL
ESPAÑOL PUBLICACIONES, S.A. (EL ESPAÑOL), with Tax ID No. A87115226, since it is
considered that the continuation of the processing activities under review could further exacerbate
the irreversible risks to the privacy of the victim and the perpetrator—a minor—
(protection of personal dignity, personal threats, loss of control over
the right to self-determination and data availability), which could result in harm that is
difficult or impossible to remedy.
The provisional measure shall remain in effect until the final resolution of the proceedings, at
which time it shall be confirmed, modified, or lifted. “
FIFTH: Once the aforementioned decision to initiate proceedings was served in accordance with the rules established in
Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations
(hereinafter, LPACAP), on April 15, 2025, EE filed a written
statement of defense in which, in summary, it stated:
1-The alleged sanction for publishing unnecessary data in a report is
disproportionate and amounts to administrative censorship, especially considering that the
proceedings were initiated ex officio, without a complaint from any party, the undeniable virality
of the published content, and the fact that it was provoked by the protagonist of the events himself, which
constitutes a criminal offense. It refers to the case E/03409/2018, which was dismissed, regarding the necessity
to publish personal data, and which contradicts the findings of this proceeding.
2-Furthermore, there are judicial proceedings, both civil and criminal, that
guarantee the effective protection of the right to privacy and personal image of those
affected by the publication of information.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 3/28
“The defense of the right to data protection sought by this Agency is framed
within arguments more characteristic of the purported protection of the right to one’s own image
guaranteed by Organic Law 1/1982, of May 5, on the civil protection of the right to
honor, personal and family privacy, and one’s own image,” since the case involves the image and voice
of the data subjects, alluding without further justification to the right to data protection
having been violated, without expressing any reason or basis for such a ruling.”
3-It refers to the primacy given by case law to the right to freedom of information
over data protection regulations, a principle that has not been applied by the AEPD
, which fails to consider the social reality in which the rule must be applied—a reality in which it
cannot be ignored that the virality of news content, in and of itself, is a basis for
public relevance and interest by virtue of the content itself—an expression of its
community-wide significance, which is unequivocal in this case, as it involves acts of a
criminal nature.”
EE asserts that the requirements of public relevance and veracity are met, insofar as
the video at issue in this case demonstrates that the events reported occurred
exactly as narrated; therefore, a detailed analysis of
that criterion is not necessary.
It cites a cuenta-@PERFIL.2 where the post was published on ***DATE.2, which “as of
the date of this submission” has 6 million views, providing the
link, and in the copy provided, the face (…) can be seen with the text “(…)”; he also
provides another post made by a different account, indicating the link and stating that it has reached
500,000 views (Documents 1.1 and 1.2).”
Likewise, it points out that the account of a well-known (…) on its
***PLATFORM.3, providing a partial image of the video with the caption “(…) …,” and in another
subsequent post, the names (…) appear (Documents 1.3 and 1.4).
It provides coverage from other media outlets—without citing them all—such as, for example, “***STATION.1,” along with
a link to a video from @***PROFILE.3, from “20 minutos,” with the visible link to the news article dated
***DATE.2 and an image showing the person from behind (…) reporting that he has been identified (…) or, in
other media outlets, still frames from the video.
In this regard, the respondent states that “the public relevance acquired by the
video—which was the subject of reporting and republication in media outlets across the country—has been demonstrated.”
“To ignore, as the proposed sanction seeks to do, that the video achieved extremely
wide dissemination throughout the country—both on social media and in traditional
media—leads to a lack of due process, as it fails to make a decision that is contextualized and connected to
social reality, resulting in an undue interference with the right to freedom of
information and expression exercised by El Español.”
In this case, the defendant argues that it was the subject of the news story who, through
the assault observed, gave rise to the story’s creation, with the video itself
constituting the news story; thus, as the judgement states, it must “yield to the right to information
Due to the non-incidental role that the subject himself has assumed.”
EE argues that the video did not go viral as a result of the news story’s publication, but rather
that the news story was published by its newspaper as a result of the video going viral, a fact that must be
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 4/28
Recital. It adds that, furthermore, the video was already widely known and had gone viral at the
time the news story was published, which is why EE reported on it as
the relevant news story that it was.
EE argues that the video is ancillary to the information provided during the
news report; since it depicts the events in images, the video is the news itself. It cites
Supreme Court Judgement 241/2003 of March 14, which, among other issues, refers to the concept of
“accessory nature” in relation to the content of the written report
(conflict between the right to one’s own image and the right to information) in a case involving a
person “holding public office,” supplemented by Supreme Court Judgement 593/2022
of July 28, regarding a media outlet’s publication of images
taken from a video uploaded to YouTube with the subject’s consent.
4—“Regarding the aggressor’s status as a minor”
The respondent's recital states that in the present case, both the assailant and the person
recording the video—notwithstanding their minority status—are fully aware of the act
they have committed and its seriousness, which is why they flee the scene, as well as the
aggressor’s defiant and intimidating gestures toward a vulnerable and defenseless person—
behaviors that only serve to demonstrate that, despite being a minor, he possessed
sufficient maturity to understand the magnitude of his actions and,
consequently also to be the subject of a news story regarding
said act—an aspect that the Agency failed to take into account when assessing the alleged
violation of the principle of data minimisation, when it is indisputable that the minor is
aware that he is being recorded and gives his consent to it.
5—“Regarding the classification and characterization of the alleged violation and the amount of the
penalty”
-Both the video and the minor’s identity had already been widely disseminated
previously.
The assertion that the publication of the news story resulted in the complainant losing
disposition and control over their personal data, as it was disseminated over the internet without
restrictions, failed to take into account that this loss of control had already occurred
at the moment the video went viral—an event not attributable to the respondent.
It is not possible to consider that the respondent’s actions produced the same effect.
-Regarding the alleged negligent conduct, with reference to Article 83.2.b) of the GDPR,
the respondent points out that, without the video, the news story’s informational content would be empty
had the video been edited to anonymize the complainant’s personal data;
the video footage serves to help readers understand the context of the
news story.
“Once again, based on the premise that the requirements of public relevance and
truthfulness are met, it is not possible to consider the action negligent, given that
the journalist who published the information weighed these criteria and determined their
concurrence.”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 5/28
-Regarding the application of Article 83.2.g) of the GDPR, the minor’s status of special
vulnerability must be assessed in light of the level of maturity
demonstrated by his actions, as it is evident that he was aware of the acts he was
committing, as well as his clear physical superiority over the victim; therefore, in this
specific case, it was not exactly the minor who was in a situation of special
vulnerability.
In the final request, the minor urges that the violation be dismissed and, alternatively, that
the amount of the penalty be reduced.
SIXTH: On February 25, 2026, the Investigating Officer issued a proposed resolution as follows:
“FIRST: That the Presidency of the Spanish Data Protection Agency
Data impose a sanction on EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A., with
Tax ID No. A87115226, for a violation of Article 5.1.c) of the GDPR, as defined in
Article 83.5.a) of the GDPR, with a fine of 20,000 euros.
SECOND: That the Presidency of the Spanish Data Protection
Agency make definitive the provisional measure agreed upon during the
preliminary investigation proceedings and confirmed in the decision to initiate
this disciplinary proceeding. In that case, EE must be required to
bring its conduct into compliance with personal data protection regulations,
within the timeframe to be determined, to the extent specified, and to provide justification to this
Spanish Data Protection Agency regarding compliance with the corresponding
order
THIRD: That the Presidency of the Spanish Data Protection
Agency order EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A., pursuant to
Article 58.2.d) of the GDPR, within a maximum period of 3 months, counted
from the date the decision becomes enforceable, demonstrate that it has adopted the
necessary measures to ensure compliance with the provisions of Article
5.1.c) of the GDPR, preventing the excessive publication or dissemination of personal data
and, in particular, of minors.”
SEVENTH: On March 11, 2026, comments on the proposal were received, stating:
PREVIA—It asserts that imposing sanctions arising from the alleged publication of data that is not proportionate for
an informational purpose poses a danger to the media and society, even when
those affected have not taken any action because they do not feel
that their rights have been violated.
It reiterates that the exercise of the right to freedom of information may entail the loss
of control over personal data by the subjects of the news reports, and in this case,
such loss is proportionately necessary for the exercise of the right to freedom of information,
with a corresponding limitation on the right to data protection and privacy of those affected.
FIRST:-:-Reiterates that judicial proceedings exist to guarantee the right to one’s
own image, and that the AEPD’s arguments are more relevant to the purported
protection of the right to one’s own image guaranteed by Organic Law 1/1982.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 6/28
It considers that the response given—that these are distinct legal interests—is incorrect,
as it believes that the right to data protection and the right to one’s own image do protect the
same legal interest, which is none other than a person’s power of disposition over their
image and other personal characteristics such as their voice.
It reiterates the decision to dismiss proceedings E/03409/2018 in a section of
the reasoning that states that the right to information involves the processing of data
that does not require the prior consent of the data subject, although there are
limits, and points to the protection provided by the aforementioned Organic Law 1/1982.
-It asserts that the minor’s face is not even fully visible, since the
newspaper cropped out the only moment in which his full face was visible; in the published video,
only the back of the minor’s head can be seen, or at most the
side of his head. Recital: It considers that the possibility of using artificial intelligence to create
an identity reconstruction, generate detailed profiles, or
simulations based on what was published is impossible due to the quality of the video.
SECOND—Reiterates that the purpose of publishing the news story was the video itself,
having argued that the published video was incidental to the information regarding which
no response was received.
THIRD—It points out that the special protection afforded by the legal system to
minors regarding their rights to data protection, honor, privacy, and their own
image must always be assessed according to the level of maturity demonstrated by the
minor themselves; in this case, they were aware of the video recording and the seriousness of
the events, demonstrating sufficient maturity to understand the magnitude of
the events and therefore capable of being the subject of a news story regarding said
action. It requests that this be taken into account, as it is indisputable that the minor is
aware that they are being recorded and gives their consent to it, with the intention
of disseminating it, as they ultimately did.
-Regarding the best interests of the minor, the petitioner states that Article 7 of the LOPDGDD
establishes 14 years of age as the valid age for giving consent, considering that
at that age, minors already possess sufficient maturity to understand the implications involved.
FOURTH—Regarding the amount of the fine, the defendant considers it disproportionate given the nature of the right
that is at stake, which is an institutional guarantee; any measure that restricts it,
such as the penalty, must be interpreted narrowly in accordance with the criteria of necessity
and proportionality.
It notes that, at the time of the newspaper’s publication, the video already had
millions of views, while the views resulting from the news article were minimal
by comparison—a fact that must be taken into account in determining the amount of the alleged penalty.
EIGHTH: Based on the proceedings conducted in this case and the
documentation in the case file, the following have been established:
PROVEN FACTS
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 7/28
FIRST: On ***DATE.1 “11:41,” a news article was published in the newspaper
www.elespanol.com ***URL.1, with the title: “***TITLE.1.”
The news article states: “(…)”.
The post includes a video related to the incident, in which
the victim of the assault (…), as well as the assailant (…), can be seen, without the use of any
techniques that would prevent the identification of these individuals.
The same video also appears on the pages of ***PLATFORM.1, ***URL.2, with the
post: “El Español,” “@elespanolcom” 1:22 p.m. ***DATE.5 14.7K views,” and
on ***PLATFORM.2 of the same newspaper, ***URL.3, as of ***DATE.1, with 59 likes, 122
comments, and it is reported (…) that the news story was not flagged, as evidenced by
previous proceedings by the AEPD.
SECOND: On ***DATE.3, this Agency issued a precautionary measure addressed to the controller EE, requesting the immediate removal of the video published at the
URLs specified in the preceding established fact.
THIRD PARTY: On ***DATE.4, following a written notice from EE stating that it had proceeded with the
“removal of the news article, preventing access to it both externally and through the
newspaper’s internal search engine,” this Agency verified that the content of the video that is the subject of
this disciplinary proceeding no longer exists at the aforementioned web addresses, a fact
substantiated by the report on prior investigative proceedings.
LEGAL GROUNDS
I
Jurisdiction
In accordance with the powers granted to each supervisory authority by Article 58(2) of the
GDPR, and pursuant to Articles 47, 48(1), 64(2), and 68(1) of Organic Law
3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights
(hereinafter, LOPDGDD), the Presidency
of the Spanish Data Protection Agency has jurisdiction to rule on this proceeding.
Likewise, Article 63(2) of the LOPDGDD provides that: “Proceedings handled
by the Spanish Data Protection Agency shall be governed by the provisions of
Regulation (EU) 2016/679, this Organic Law, the
regulatory provisions issued in implementation thereof, and, to the extent they do not contradict them, on a
subsidiary basis, by the general rules on administrative proceedings.”
II
Preliminary Issues
Article 4(1) of the GDPR defines “personal data” as: “any information relating to an
identified or identifiable natural person (‘the data subject’); an identifiable natural person
shall be any person whose identity can be determined, directly or indirectly, in
particular by reference to an identifier such as a name, a number,
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 8/28
, location data, an online identifier, or one or more factors
specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of
that person.”
Article 4.2 of the GDPR defines “processing” as: “any operation or set of
operations performed on personal data or sets of personal data, whether
by automated means or not, such as collection, recording, organization,
structuring, storage, adaptation or alteration, retrieval, consultation, use,
disclosure by transmission, dissemination, or otherwise making available,
alignment or combination, restriction, erasure, or destruction.”
Recital 4 states: “The processing of personal data should be designed to
serve humanity. The right to data protection is not an
absolute right, but must be considered in relation to its role in society and
maintain a balance with other fundamental rights, in accordance with the principle of
proportionality. This Regulation respects all fundamental rights and
observes the freedoms and principles recognized in the CFR as enshrined in
the Treaties, in particular respect for private and family life, home, and
communications; data protection; freedom of
thought, conscience, and religion; freedom of expression and information;
freedom to conduct an enterprise, the right to an effective remedy and to a fair trial, and
cultural, religious, and linguistic diversity.”
Article 4(7) of the GDPR defines the controller as “the natural or
legal person, public authority, agency, or other body which, alone or jointly with others, determines
the purposes and means of the processing; if Union or Member State law
determines the purposes and means of the processing, the controller or the specific criteria
for its appointment may be established by Union or
Member States,” subject to administrative liability under the LOPDGDD, article
70.1.a).
In the present case, a news article was published that includes personal data of the individuals
in question, such as their age or municipality of residence, accompanied by a video in which
the two individuals in question can be seen, making it possible to identify them, which
constitutes the processing of personal data; therefore, the controller carrying out such processing is required to comply with the obligations set forth in the
GDPR and the LOPDGDD.
EE is a communications service provider that carries out this activity in its
capacity as the controller, since it is the entity that determines the purposes and means
of such activity, pursuant to Article 4.7 of the GDPR, which defines “controller”
processing” or “controller” as: “the natural or legal person, public authority,
agency, or other body which, alone or jointly with others, determines the purposes and means of the
processing; if Union or Member State law determines the purposes and
means of the processing, the controller or the specific criteria for its
appointment may be established by Union or Member State law.”
The controller determines the purposes of the processing—that is, why?,
what does it cover?, for what purpose?, how?, and what is it for? The purposes of the processing would
presumably be to provide information, present, and report on news regarding
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 9/28
current events—in this case, news stories.
The specific activity under consideration in this case affects the fundamental rights and freedoms
of natural persons, particularly their right to privacy with respect to
the processing of personal data by EE, as the entity that determines the
purposes and means of this processing activity, and must ensure, within the framework of its
responsibilities, powers, and capabilities, that said activity
meets the requirements of the GDPR and the LOPDGDD so that the safeguards established therein
may take full effect and effective and comprehensive protection of
data subjects—in particular, of those rights—may be ensured.
III
Response to the Allegations
In response to the allegations raised in these disciplinary proceedings, the
following should be noted:
Regarding the argument against the (preliminary) proposal, it should be noted that the Spanish Constitution,
in Article 20, expressly provides for certain limits on freedom of information,
such as the right to honor, privacy, one’s own image, and the protection of youth and
children.
However, it must also be taken into account—as already noted in the decision to
initiate proceedings, in the proposed resolution, and in this resolution—that freedom of information
and expression is not absolute, nor is the fundamental right to data protection. These are rights that must be balanced in their application, without
attempting to assert the supremacy of one over the other.
What is at issue in this case is not the legitimacy of the processing but rather the necessity and
proportionality of using personal data to accompany detailed information about
the events that occurred several months earlier, given that the juvenile assailant who
appears as the main figure has been located
It is worth noting, given its relevance to this case, the Supreme Administrative Court (SAN) decision of November 19, 2024,
Rec. 1241/2022, which, following Constitutional Case Law on the right to
personal data protection, reasons that “(…) the fundamental right to
data protection enshrined in Article 18.4 of the Spanish Constitution,
unlike the right to privacy under Article 18.1 of the Spanish Constitution, with which it shares the objective of
providing effective constitutional protection of personal and family privacy,
by shielding it from the knowledge of others and from third-party interference against one’s
will, seeks to guarantee that person the power to control their
personal data, its use, and its destination, with the purpose of preventing its unlawful trafficking and harm
to the dignity and rights of the data subject.
The right to data protection therefore has a broader scope than that of the
right to privacy, since the fundamental right to data protection extends its
protection not only to privacy in its dimension constitutionally protected by Art
18.1 of the Spanish Constitution, but also to the sphere of personal rights that fall within the realm of
private life and are inseparably linked to respect for personal dignity, such as the right
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 10/28
to honor, and to the full exercise of an individual’s rights. The fundamental right to
data protection extends the constitutional guarantee to those data that are
relevant to or have an impact on the exercise of any of an individual’s rights,
whether or not they are rights.
In this regard, it should be noted that the video shows him looking at the camera, and he
can be identified directly or indirectly; furthermore, the information provided in the
news report helps provide additional details to narrow the search and consider him
identifiable. Similarly, as the respondent herself has stated, the video
in question corresponds to others circulating on the web; thus, both directly and
indirectly, the assailant and the victim can be identified or are identifiable, which must
be considered personal data.
The right to personal data protection safeguards the image and voice of the
individuals appearing in the video, requiring that dissemination based on freedom of
information comply with the relevant requirements regarding legitimacy and the principles of the
regulations, among which is the principle of data minimization.
Regarding the claim that the video went viral—since it is unknown whether the first
video that led to the dissemination of its content was actually put into
circulation by the aggressor—the fact that it went viral on a massive scale should not, therefore, serve as a
justification for its publication in its entirety. In this case, the legitimacy of the
processing is not in question, but rather the necessity and proportionality of the personal data in order to accompany
detailed information about the events that occurred several months earlier, given that
the minor perpetrator who appears as the main subject has been located. This necessity and
proportionality in assessing the conflict of rights between the right to information and the right to
the protection of privacy and personal data of a minor—who is also a
vulnerable person—must, in this case, be weighed in favor of the latter, considering the
repercussions that the dissemination of their images may have—a point the respondent has not
mentioned in any of its complaints. The conflict in this case must not be resolved by
the prevalence or primacy of the right to information, but rather by reconciling it
with the right to data protection, under the premise of the prevalence of the best interests of the
minor, which will be established as applicable in this instance.
The right to personal data protection requires that the processing of the published data that
may have taken place comply with the relevant requirements regarding legitimacy and principles,
and in this case, it is not only a matter of protecting the image, but also of its dissemination
through a medium to which anyone with an internet connection could have had
access (digital media and social media). All of this without disputing in these proceedings
the legitimacy but rather the scope of the content of the data used as an accompaniment
to the news story, which cannot be disclosed as it takes precedence over the right to
freedom of information.
Regarding the argument against the proposal that the affected parties did not exercise any rights,
it should be noted that this is not a requirement for the protection of the right, the exercise of which
falls explicitly within the AEPD’s jurisdiction.
Regarding the public relevance of the events due to the video’s virality, it must be noted
once again that the respondent is an audiovisual news outlet operating within the
information society and long accustomed to processing personal data. Its media outlets
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 11/28
staff are dedicated to data processing and, given the knowledge they are expected to have of these
groups in their reporting work, must reconcile this with the special respect required by the regulations
on minors and digital media that apply to them as a safeguard of the
dignity of minors and vulnerable persons.
Regarding the closed proceeding E/03409/2018 cited by the respondent, it must be
noted that the decision specifically establishes the primacy of the right to information under certain
requirements and parameters applicable to that case, stating:
“Therefore, it must be taken into account that case law establishes the primacy of the
right to information over the right to data protection when,
in the specific case, the circumstances regarding the accuracy of the information
transmitted and its public relevance are present.”
It must be taken into account that in the present case there are distinguishing factors:
In the case of the file in question, it concerned a person in the public eye—a politician—
and did not involve a minor or vulnerable person (the victim) in any way; therefore,
the balancing test must be considerably different from that of the alleged
case.
Thus, the arguments raised cannot be taken into account.
-Regarding the preponderance or primacy of the right to information over the
dissemination of the video containing personal data, it must be noted that the respondent does not include
the rights and interests of the data subjects
parties involved—both of whom are vulnerable—(…), Recitals 153, as well as
Article 85, provide for the application of exemptions or exceptions to be established by the
Member State, only if they are necessary to reconcile the right to data protection
with the freedom of expression and information.
The articles cited by the respondent regarding the processing of personal data carried
out for journalistic purposes that could entail exemptions or exceptions, among
other things, the principles governing data processing, are limited to “only if they are necessary,” and only
“to reconcile the right to privacy with the rights to freedom of information.”
In the present case, the relevance of the matter or the fact that the events are of
public interest and newsworthy is not in dispute; rather, the issue concerns the limits that must be applied in
assessing the balancing of rights. Just as the news report did not include the
first and last names—which, according to the respondent, were already known and had been published on
social media—it was not necessary to show the image of those involved or include audio in order
to broadcast the news
The infringement involved—in terms of failing to respect the right to data protection
of the individuals concerned—means that the right to information cannot prevail, in the manner
argued by the respondent; however, it is possible to reconcile this right and ensure it is not rendered meaningless
through the use of certain tools. The use of tools that prevent the
identification of the individuals in the video demonstrates that an alternative exists that equally guarantees
the right to information.
Therefore, the arguments presented cannot be taken into account.
-Regarding the indisputable fact that the perpetrator of the assault is a minor, it is not possible, as
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 12/28
the respondent intends to assert—neither that the video was disseminated by the assailant himself, a claim that has not
been substantiated, nor that he was aware of what he was doing and possessed sufficient maturity to
understand his actions.
Furthermore, the aforementioned consideration of the minor’s best interests has not been addressed
in any way in the respondent’s arguments, which indicates that the respondent also failed to
take it into account when processing the personal data that constitutes the
minor’s identity, which is the subject of this case. It is the best interests of the child that
should prevail in any case, and this requires that the processing of personal data be adapted
to ensure that no further harmful effects occur to those involved,
given the intrusion posed by the universal dissemination of digital media and the harm
that this entails, along with the risks to the minor in particular.
The third argument made in the proposal—regarding the maturity conferred by being over 14
years of age to consent to processing—is unrelated to the specific act
alleged against the respondent, nor does it imply a diminution in the interest worthy of protection of
minors.
Hence the importance of compliance with and the provisions set forth in Article 25 of the
GDPR, titled “Data Protection by Design and by Default,” which states in
paragraph 2:
“The controller shall implement appropriate technical and organizational measures
to ensure that, by default, only personal data
necessary for each specific purpose of the processing are processed.
This obligation applies to the amount of personal data collected, the scope of its processing, its
storage period, and its accessibility. […]”, and these measures must be adapted to the risk
posed by the processing, taking into account the means of processing.
Therefore, the arguments raised cannot be taken into account.
- Regarding the seriousness of the violation, in Recital 83(2)(a) of the GDPR,
the respondent argues that the data was already circulating on social media.
In response, it should be noted that even if this is true, each instance of dissemination further contributes to
such dissemination and amplifies its effects, especially considering that the video remained online until
February 27, 2025, the date on which technical measures were implemented to prevent
identification.
Regarding the disagreement over the application of Article 83(2)(b), which indicates
negligent conduct, and the assertion that the video’s informational content was necessary to
understand the context—weighing public relevance and veracity—it has already been noted
that these two elements are neither decisive nor sufficient in this case for
the balancing of rights, given the social vulnerability of the victim and the
minor status of the perpetrator. Furthermore, the respondent is a commercial
entity specializing in public and audiovisual information that is presumed to have a
track record in which data processing and its specific aspects—such as those involving
vulnerable individuals—cannot be foreign to it.
It should be noted that the defendant acts as the controller for the processing of the news article
published along with the video in question. With regard to the degree of diligence required of the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 13/28
controller is required to exercise in order to comply with the obligations
imposed by personal data protection regulations, the Judgement of the National Court dated October 17, 2007 (Case No. 63/2006) is highly
illustrative,
which states, with regard to entities whose activities involve the continuous
processing of customer data, that: “(…) the Supreme Court has held that
negligence exists whenever a legal duty of care is disregarded, that is, when
the offender fails to act with the required diligence. And in assessing the degree of
diligence, special consideration must be given to whether or not the individual is a professional, and there is no
doubt that, in the case now under review, given that the appellant’s activity involves
involves the constant and extensive handling of personal data, there must be an emphasis on rigor and
the utmost care to comply with the relevant legal provisions.” Thus, denying the
existence of negligent conduct on the part of DMP would amount to acknowledging that
its conduct—whether by action or omission—was diligent. Obviously, this
perspective on the facts is not shared.
As for the argument made in the motion that the penalty is
disproportionate and constitutes a measure that restricts rights, it is reiterated
that this is not the case; rather, the sanction reconciles fundamental rights and can
coexist with freedom of information, especially considering the best interests of
minors as enshrined in, among other laws, Organic Law 1/1996 on the
Legal Protection of Minors, and Organic Law 8/2021 on Protection, and that this should
lead to taking it into account to the appropriate extent in any decision involving data on
minors, with special caution regarding its processing in digital media such as this
newspaper and social media.
Regarding the comparison of the amount of the penalty with that imposed in certain
you cite in your arguments against the proposal, it should be noted that, regarding the
comparison with potential penalties, it would be appropriate, where applicable, to compare them with
those that may have been imposed by this AEPD; in this regard, it should be clarified that in 2023
several penalties were imposed on media outlets for the same violated principle and the
public disclosure of personal data.
Therefore, the arguments raised cannot be taken into account.
IV
Right to Data Protection
These proceedings were initiated because EE published a video on social media
***PLATFORM.2 and ***PLATFORM.3, and in its online newspaper, in which (…) appeared,
which constitutes the processing of both individuals’ personal data.
Given the foregoing, it should first be noted that individuals have the right to
determine the use of their personal data, as well as its dissemination; consequently, there is no
doubt that a person whose personal data is disseminated in
violation of the legal system is entitled to protection.
Thus, Constitutional Court Ruling 292/2000, dated November 30, provides that “the content of the fundamental right to
data protection consists of the power to dispose of and control personal data,
which empowers the individual to decide which of those data to provide to a
third party—whether the State or a private individual—or which data that third party may collect, and that it also
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 14/28
allows the individual to know who possesses that personal data and for what purpose, and to
object to such possession or use. These powers of disposition and control over personal data, which constitute part of the content of the fundamental right to data protection
data protection, are legally embodied in the right to consent to the collection, acquisition, and
access to personal data, its subsequent storage and processing, as well as its
possible use or uses, by a third party, whether the State or a private individual. And that right to
consent to the disclosure and processing—whether computerized or not—of personal data
requires, as indispensable complements, on the one hand, the right to know at all
times who has access to that personal data and for what purpose it is being used, and, on
on the other hand, the ability to object to such possession and uses.”
The principles relating to processing are, on the one hand, the starting point and the
concluding clause of the legal framework for data protection; they constitute true
guiding rules of the system with a strong expansive force. On the other hand, because they are highly
specific, they are mandatory rules that are subject to violation.
More specifically, it is worth highlighting the principle set forth in Article 5.1.c) of the GDPR, which
provides that:
“1. Personal data shall be:
(…)
c) adequate, relevant, and limited to what is necessary in relation to the purposes for which
they are processed (“data minimisation”);”
Compliance with this principle requires, as a prerequisite, an assessment of the
necessity and proportionality of processing operations with
respect to their purpose, taking into account whether the intended purposes can be achieved or
not achieved in a less intrusive manner, as well as the risks to the protection of the fundamental rights and
freedoms of individuals.
Article 5.1.c) of the GDPR relates to Recital 39 of the GDPR, which states that
“(…) the specific purposes of the processing of personal data must be explicit and
legitimate, and must be determined at the time of collection. Personal data
must be adequate, relevant, and limited to what is necessary for the purposes for which
they are processed. This requires, in particular, ensuring that the
storage period is limited to a strict minimum. Personal data should only be processed if the purpose of the
processing could not reasonably be achieved by other means”
As can be inferred from the aforementioned Recital, this requirement of necessity is not met
when the intended objective can reasonably be achieved just as effectively by
other means that pose less risk to the rights and freedoms of the
data subjects, particularly with regard to the rights to respect for private life and
data protection, guaranteed by Articles 7 and 8 of the CFR
EU Charter of Fundamental Rights, since exceptions and restrictions to the right
to data protection must be established without exceeding the limits of what is strictly necessary (see, to that effect, the judgement of December 11, 2019,
Asociaţia de Proprietari bloc M5A-ScaraA, C-708/18, EU:C:2019:1064, paragraphs 46 and 47).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 15/28
In any case, the default settings must not include the
collection of personal data that is not necessary for the specific purpose of the
processing. In other words, if certain categories of data are unnecessary
or if detailed data are not needed because less granular data are sufficient,
then personal data should not be collected.
In this case, if another processing method could achieve the same objective and is
available under the terms described, or if processing personal data is not necessary to
achieve the same purpose, the processing of such personal data may be dispensed with, or it may be
processed to a lesser extent and with less intensity of use; this approach is preferable and
implies that no data processing is necessary, and
alternatively, that the collection of data is necessary for the established or
intended purpose and, if so, that it is proportionate.
Article 5(1)(c) of the GDPR reflects the principle of proportionality (see the judgement of
December 11, 2019, Asociaţia de Proprietari bloc M5A-ScaraA, C-708/18, EU:C:2019:1064,
paragraph 48), in the sense that, if alternatives exist to achieve the same purpose
intended by the respondent, the least intrusive option must be chosen. This principle is also
linked to that of the necessity of processing; both principles must be taken into account
from the moment that the use of personal data restricts rights and
freedoms—such as the right to data protection—when processing such data, and in this case,
also the right to dignity of the person who was slapped and of the minor.
V
Balance between the right to personal data protection and other fundamental rights and
freedoms
However, the fundamental right to personal data protection is not absolute,
since, where appropriate, it may yield to the prevalence of other rights and
freedoms that are also constitutionally recognized and protected, such as, for example, the
fundamental right to freedom of information or expression, with this being weighed on a case-by-
case-by-case basis.
In this regard, the Art 29 Working Party, in its Opinion 06/2014 on the
concept of the legitimate interest of the controller pursuant to
Article 7 of Directive 95/46/EC, when examining the legal basis for the legitimate interest under
Article 7(1)(f) of Directive 95/46/EC—which is fully transposable to the current Article 6(1)(f) of the
GDPR, includes the right to freedom of expression or information as one of the
circumstances in which the issue of legitimate interest may arise, stating that “without
prejudice to whether the interests of the controller will ultimately prevail
over the interests and data subject rights when the balancing test is
applied.”
That said, the fundamental rights to freedom of information and freedom of expression
are not absolute either. We can observe very clear limits established by the
courts in civil matters, regarding the right to reputation, to personal and
family privacy, and to one’s own image.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 16/28
Thus, we cite Supreme Court Ruling 50/2017, First Civil Chamber, dated January 27, 2017 (appeal
No. 2139/2015), which states:
“In this regard, it is settled case law (see, among the most recent, and as
a summary of legal doctrine, Judgement 605/2015, dated November 3) that the
abstract primacy of the freedoms of expression and information ‘can only
be overridden in a specific case by weighing the relative importance of honor and
privacy according to the specific circumstances at hand, provided that the
information and opinions disseminated relate to matters of
or public relevance (due to the persons involved or the subject matter), and that
in their communication there is no unnecessary use or employment of expressions
that are unequivocally offensive or humiliating, and, in the case of freedom of information,
provided that they are truthful, specifying in all cases that, within the scope of
protection of the right to privacy, the criterion for determining the legitimacy or
illegitimacy of intrusions is not that of truthfulness but rather that of the
of the disclosed fact—that is, that its communication to the public,
even if true, is necessary in light of the public interest of the matter
being reported” (emphasis added).
It is not a matter of giving one fundamental right precedence over another, but rather of finding
a balance between the two that allows for the reconciliation of both rights; a reconciliation
to which the European legislator itself refers in Article 85 of the GDPR. And one of the
factors to be taken into consideration is, precisely, whether the intrusion involved in the
processing of personal data—which is subject to sanctions—is necessary to achieve the
intended purpose; in this specific case, the publication of the news story.
At this point, it is necessary to refer to the case law that analyzes the relationship between
freedom of information and expression, on the one hand, and the rights of those affected by
informative content, on the other.
Thus, the European Court of Human Rights (ECHR), in its judgement of June 19,
2012, rendered in Case No. 1593/2006, states the following:
Although the press must not overstep certain limits, particularly with regard to
the reputation and rights of others or the proper administration of
justice, its duty is nonetheless to disseminate, in a manner consistent with its
obligations and responsibilities, information and ideas on all matters of
public interest (paragraph 48)
(…), the publication of photographs and articles whose sole purpose is to satisfy the
curiosity of a particular reader regarding the details of the private life of
a public figure cannot be considered to contribute to any debate of
general interest to society, even though the person is known to the
public. Under such circumstances, freedom of expression calls for a
stricter interpretation (…). (para. 50) (emphasis added)
(…) In assessing whether the authorities have struck a fair balance between two
protected values guaranteed by the Convention that may conflict with one another
in this type of case—the freedom of expression protected by Article 10 and the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 17/28
right to respect for private life enshrined in Article 8—the Court of
Justice must balance the public interest in the publication of the information and the
need to protect private life (see Hachette Filipacchi Associés v.
France, No. 71111/01, § 43, ECHR 2007-VII).(Paragraph 51)
It concludes that, since the parties affected by the news report were not public figures,
“the disclosure of their identity cannot be considered essential to
understanding the details of the case (paragraph 57),” and that “there is no doubt
that the protection of the most intimate sphere of a minor’s life—who had
become a victim of a custody dispute and had not entered the public sphere—
deserved special protection due to his vulnerable position.
(paragraph 59)” (emphasis added).
In this regard, and given the circumstances of the case at hand, in which
personal data—voice and image—have been disseminated as part of news content
that EE provides to its readers, it must be understood that the
limits established by case law regarding the necessary protection of the
fundamental rights of those affected.
It is worth noting Constitutional Court Ruling 27/2020, dated February 24, 2020 (appeal for constitutional protection 1379-2017)
which ruled on the unlawfulness of illustrating a news report on a
violent event with an image of the victim that had been taken from
***PLATAFORMA.2 without obtaining the consent of the copyright holder.
In that ruling, after noting that “we must once again emphasize that physical appearance, insofar as
it is a basic means of identification and external projection and an essential factor for
one’s very recognition as a person, constitutes the primary defining element of the
personal sphere of every individual (SSTC 156/2001, Legal Grounds 6 and 99/1994, Legal Grounds 5),” it concludes that
“the primary rule for ensuring the protection of this fundamental right is that
in order to capture, reproduce, and/or publish a person’s image, their
unequivocal consent is indispensable, and cases in which such authorization is not
required are exceptional (…)”
At this point, it is worth referring to Judgement 117/1994, of April 25
(RTC 1994\117), which states the following:
“when the right to one’s own image conflicts with other constitutionally protected
rights or interests, particularly the freedoms of
expression and information (Art. 20.1.a and d of the Spanish Constitution), the various
conflicting interests must be weighed, and, taking into account the specific circumstances of each case,
a decision must be made as to which interest deserves greater protection” (SSTC 105/1990, dated June 6;
72/2007, Legal Ground 5, and 156/2001, Legal Ground 6). (…) As is easily deducible, this occurs
not only when it conflicts with the rights to honor and privacy, but
also with the fundamental right to one’s own image, for example, in those
cases in which news reports disseminate photographs or video clips that can only
be understood as mere instruments for satisfying the curiosity
of others and have been included not for an informative purpose, but for the purpose
to satisfy the anticipation that, under such circumstances, a
particular news story may generate.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 18/28
(…) the image of an anonymous or unknown individual—that is to say, someone who
does not hold public office or practice a high-profile profession—even if captured
in a public place, may not be used without their express consent, except in
two cases. First, where the person appears in the
photograph in a purely incidental and insignificant manner, without playing
any prominent role. Second, in the event that the initially anonymous person’s participation in the
newsworthy event was principal or
prominent, in which case their fundamental right to their image must yield
to the right to information, precisely because of the non-incidental role that
the subject themselves has assumed. (…) Although the risks of intrusion have
increased exponentially with the widespread use of social media, to
ward them off we must continue to rely on the same basic principle that governs the
analog environment and affirm that the constitutional recognition of the
covered by Article 18 of the Spanish Constitution entails the individual’s right
to control the data circulating on social media that concerns them. Therefore,
we reiterate that, unless there is unequivocal authorization
for the capture, reproduction, or publication of the image by its owner,
any interference with the fundamental right to one’s own image must necessarily
be justified by an overriding public interest in having access to it and in
disseminating it. (…) Consent covers only that which constitutes the subject matter of
the declaration of intent. The holder of the fundamental right must authorize the
specific act of using their image and the purposes for which they grant such authorization. The
consent given, for example, for the capture of the image does not
extend to other subsequent acts, such as its publication or dissemination.”
In light of the foregoing, and given that it has been established that there has been
processing of personal data that constitutes an infringement of the fundamental right to
data protection for the participants appearing in the
aforementioned video, it must be noted that one of the individuals affected by this violation was
a minor at the time of the events. In this regard, it is worth noting some
of the numerous judicial rulings that highlight the enhanced protection
that should be afforded to minors against unlawful infringements of
their fundamental rights.
Thus, as stated by the Supreme Court, First Civil Chamber, in its Judgement
No. 1003/2008 of Oct. 23, 2008 (Case No. 174/2005, Second Legal Grounds):
“Article 18 of the Constitution generally recognizes the right to honor, to
personal and family privacy, and to one’s own image, and Article 20.1.d) recognizes the right to
freely communicate or receive truthful information through any means of dissemination,
specifying that this freedom is limited by respect for the rights
recognized in this title and “especially the right to honor, to privacy, to one’s
own image, and to the protection of youth and children.” In line with the
foregoing, the special protection that must be afforded to data concerning minors has been
enshrined in Organic Law 1/96 of January 15 on the Legal Protection of
Minors.
In interpreting these fundamental rights, the Constitutional Court has
consistently held that for the right to privacy to be legitimately invoked
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 19/28
as a limit on the right to freedom to receive or transmit information, it is necessary that
the news disseminated lack public interest or that, even if it is of public interest,
it lacks veracity, since in a democratic society that proclaims as one of
the principles inspiring its coexistence, respect for human dignity, the disclosure of facts pertaining to the private lives of individual citizens must not
be tolerated, nor should the dissemination of untrue news be tolerated,
not in the sense that they must correspond exactly to what actually happened, but in
the sense that the publisher has exercised the necessary diligence to
ensure that what is disclosed is not a mere rumor—Judgements of the Constitutional Court
54/2004, of April 15, and 61/2004, of April 19—.
However, in cases involving minors, constitutional
doctrine has established a sphere of heightened protection that requires extreme
caution regarding the information provided about them, even if such
information is in the public interest. Thus, the Constitutional Court has held that a minor’s legitimate interest
in preventing the disclosure of information regarding their family or personal life “appears to
impose an insurmountable limit on both freedom of expression and the
fundamental right to freely communicate truthful information, without the alleged truthfulness of
what is revealed exempting the media outlet from liability for intrusion into the
private lives of both minors,” even if the news story merits the designation of
neutral information—Constitutional Court Judgement of July 15, 1999—(the
underlining is ours).
Along the same lines, it is worth noting the ruling of the Supreme Court in its
Judgement 777/2021 of Nov. 11, 2021, (First Chamber, Civil, Case No. 6775/2020):
“In the words of Constitutional Court Ruling 158/2009, dated June 29, 2009 (Legal Ground 4):
“It should be recalled that, in accordance with Article 20.4 of the Spanish Constitution, the freedoms of expression and
information are limited by respect for the rights recognized in Title I, in the
laws implementing it,” and, “in particular, the right to honor, privacy, one’s
own image, and the protection of youth and children.” Likewise, due
consideration must be given to international standards for the protection of children (regarding
whose interpretive value under Art. 10.2 of the Spanish Constitution need not be emphasized), and, among these, in
particular, the United Nations Convention on the Rights of the Child (ratified
by Spain by an Instrument dated November 30, 1990), which guarantees the right of
children to the protection of the law against arbitrary or unlawful interference in their
private life (Art. 16), as well as the European Parliament Resolution on the CFR
European Charter of the Rights of the Child, which states that “every child has the right
not to be subjected by a third party to unjustified intrusions into his or her private life, into
that of his or her family, or to unlawful attacks on his or her honor” (paragraph 29 of § 8 of
Resolution A 3-0172/92 of July 8).
“In turn, Organic Law 1/1982 of May 5 on the Protection of the Right to Honor,
Privacy, and One’s Own Image, after establishing that no unlawful intrusion
shall be deemed to have occurred within the protected sphere when the right holder has given his or her
express consent to that effect (Art. 2), goes on to specify in Art. 3, with regard to
minors (and legally incapacitated persons), that their consent must be given by them
themselves, if their level of maturity permits it; otherwise, consent
must be given in writing by their legal representatives, who shall be
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 20/28
required to give prior notice to the Public Prosecutor’s Office of the proposed consent,
and the judge must rule if, within eight days, the Public Prosecutor’s Office
objects. (…)”
Therefore, media outlets process personal data in the
exercise of freedom of information and are responsible for doing so.
As controllers, they must comply with the obligations set forth in the
GDPR, among which we highlight, among others, verifying the existence of a
that legitimizes the processing of personal data, applying the principles
relating to processing or conducting risk assessments (Article 24 of the GDPR), and
conducting data protection impact assessments when necessary
(Article 35 of the GDPR).
The fact is that any processing of personal data entails risks to the rights
and freedoms of natural persons arising from such processing, which the controller
must identify, assess, and evaluate in order to implement technical
and organizational measures of all kinds to prevent or mitigate the materialization of the aforementioned risks
materialize. It must be taken into account that, at times, the materialization of
these risks can have a very significant impact on the rights and freedoms of
data subjects, and the harm may be irreversible and irreparable. Furthermore, the analysis of
these risks must take into account the clearly technological context of today.
In today’s technological context, marked by the exponential development of artificial
intelligence and its ability to analyze, identify, and associate voices and images with
unprecedented precision, the need to exercise extreme caution in the processing of this
personal data is reinforced. Artificial intelligence makes it possible, even from
minimal image fragments, to reconstruct identities, generate detailed profiles, or
create hyper-realistic simulations, which significantly increases the risks to
the rights and freedoms of natural persons.
All of this is in addition to compliance with the principle of data minimisation applicable to the
form and means by which information is provided and disseminated, given the immediate impact
on a natural person’s personal data. Thus, the controller must assess,
prior to carrying out the processing, whether the dissemination of
personal data is as non-intrusive as possible, analyzing and implementing, where
case, other ways of providing the information (alternative measures) that pose a
lower risk to the right to personal data protection, including
the right to privacy.
That is why the controller, before carrying out the processing,
processing—in accordance with their accountability (Article 5.2 of the GDPR)—must
conduct from the outset not only an active analysis of measures for the design of the
processing in order to comply with the principles of the GDPR, (one of which is
data minimisation) but also a risk analysis and document it for the specific
case in question, while also applying the principle of data minimisation to the
in order to adopt, if necessary in light of an individual’s circumstances,
the appropriate technical and organizational measures to reconcile the fundamental
right to freedom of information with the fundamental right to data protection.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 21/28
In this regard, it should be noted that current technology allows for the publication of information—
whether a video or an audio recording—without making the
participants identifiable; therefore, a media outlet could provide the information while
remaining compliant with data protection regulations.
Technical measures consisting of the use of technical procedures to prevent
the recognition and identification of the individuals concerned, which must be assessed
in each case by the controller.
As we can see, this is not a matter of giving one fundamental right precedence over another,
but rather of determining which carries greater weight in a specific case. Rather, it is a matter of
striking a balance between the two to achieve the purpose of the former
without undermining the latter, and always on a case-by-case basis. The reconciliation of these two rights
is set forth by the European legislature in Article 85 of the GDPR.
VI
Breach of Obligation. Data Minimisation
Every controller has obligations regarding data protection
data protection, as prescribed by the GDPR and the LOPDGDD, particularly—as
indicated—the assessment of the necessity and proportionality of data processing, the
accountability set forth in Article 5(2) of the GDPR, and the assessment of the
risks to fundamental rights and freedoms posed by the processing of personal data,
and the implementation of appropriate security measures.
These obligations do not cease to apply simply because the controller
is a media outlet.
Recital 79 of the GDPR states: “The protection of the rights and freedoms of
natural persons with regard to the processing of personal data requires the adoption of
appropriate technical and organizational measures to ensure compliance with
the requirements of this Regulation. In order to demonstrate compliance with
this Regulation, the controller must adopt internal policies and
implement measures that comply, in particular, with the principles of data protection by
design and by default. Such measures could consist, among other things, of minimizing
the processing of personal data, pseudonymisation of personal data as soon as possible,
and ensuring transparency regarding the purposes and processing of personal data,” which relates
to Article 25 of the GDPR, which establishes data protection by design and by
default, whereby the controller must implement technical and
organizational measures capable of effectively ensuring compliance with the
principles referred to in Article 5 of the GDPR.
Thus, the first paragraph of the aforementioned article provides for data protection by design,
stating that:
“1. Taking into account the state of the art, the cost of implementation, and the nature,
scope, context, and purpose of the processing, as well as the risks of varying likelihood and
severity that the processing poses to the rights and freedoms of natural persons
, the controller shall implement, both at the time of determining the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 22/28
means of processing as well as during the processing itself, appropriate technical and
organizational measures, such as pseudonymisation, designed to effectively
apply data protection principles, such as data minimisation, and to incorporate
the necessary safeguards into the processing, in order to comply with the requirements of this
Regulation and protect the data subject rights.”
To this end, the greatest risks that could arise shall be taken into account, as provided for
in Article 28.2 of the LPODGDD, which states:
()
“b. When the processing could deprive data subjects of their rights and freedoms or
could prevent them from exercising control over their personal data”
(…)
“e) When processing data of categories of data subjects in a situation
of particular vulnerability, and in particular, minors and persons with
disabilities.”
Both of these circumstances apply in the present case.
Of particular importance during this phase of determining the means of processing is the
implementation of appropriate technical and organizational measures in the
design of data processing operations and throughout their execution.
The second paragraph of Article 25 of the GDPR describes the principles of data protection
by default, stating that:
“2. The controller shall implement appropriate technical and organizational
measures to ensure that, by default, only personal data that is necessary for each of the specific purposes of the
processing is processed. This obligation applies to the amount of personal data collected, the
scope of its processing, its storage period, and its accessibility. Such
measures shall ensure, in particular, that, by default, personal data is not
accessible, without the data subject’s intervention, to an indeterminate number of
natural persons.” This paragraph is directly related to the obligation of the controller
to implement appropriate technical and organizational measures to ensure
that, by default, only the personal data necessary for the specific purpose are
processed, thereby establishing an explicit connection to the principles of data minimisation
and purpose limitation.
In this case, if we combine the dissemination of the video showing the victim and her assailant (with
all its nuances)—in which they can be recognized by third parties—with the factual account provided
provided by the news report—which remains publicly available for an extended period, with the possibility of
forwarding or copying the video—it is clear that there is a very high and highly probable risk that
the individuals concerned may suffer harm to their rights and freedoms. The clarification of
the possible purposes that may arise in the processing of the news alongside the videos
must focus not on the legitimacy of reporting, but rather on emphasizing, as has been
stated that, in this case, the defense of the rights of both the victim and the aggressor, given
that the videos are included, does not appear to be secondary to the interests advocated
by EE through the three broadcasts of the videos alongside the news story.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 23/28
It is considered that even if EE’s purpose was to report on the violent nature of the
assault, thereby illustrating the content of the message aimed at fostering the formation of
free public opinion, there has been a violation of the personal data of the assailant and the
victim, as they are identified or could be identified, and there is a lack of due necessity and
proportionality between the exercise of the right to freedom of information—given its
content, purpose, and context—and respect for the personal data of the assailant and the victim,
thereby infringing upon their right to data protection.
Consequently, it is considered that the known facts constitute a
violation, attributable to EE, for breach of Article 5.1.c) of the GDPR
VII
Classification of the violation of Article 5.1.c) of the GDPR and determination for purposes of
the statute of limitations
The known facts constitute an infringement, attributable to the respondent, of
Article 5.1.c) of the GDPR, to the extent set forth in the Legal Grounds
above, which, if confirmed, could constitute the infringement defined
in Article 83(5)(a) of the GDPR, which, under the heading “General Conditions for the
Imposition of Administrative Fines,” provides that:
“Infringements of the following provisions shall be subject, in accordance with
paragraph 2, with administrative fines of up to 20,000,000 EUR or, in the case
of an enterprise, an amount equivalent to up to 4% of the total
annual global turnover for the preceding financial year, whichever is the higher
amount:
a) the basic principles for processing, including the conditions for
consent pursuant to Articles 5, 6, 7, and 9;”
In this regard, Article 71 of the LOPDGDD establishes that “The following acts and conduct constitute violations
the acts and conduct referred to in paragraphs 4, 5, and 6 of Article 83 of
Regulation (EU) 2016/679, as well as those that are contrary to this
organic law.”
For the purposes of the statute of limitations, article 72 of the LOPDGDD states:
“1. Pursuant to the provisions of Article 83(5) of Regulation (EU) 2016/679,
infractions that constitute a
substantial breach of the articles mentioned therein and, in particular, the
following:
a) The processing of personal data in violation of the principles and safeguards established
in Article 5 of Regulation (EU) 2016/679.
VIII
Penalty for the violation of Article 5.1.c) of the GDPR
In order to determine the administrative fine to be imposed, the provisions
of Articles 83.1 and 83.2 of the GDPR must be observed, which state:
“Each supervisory authority shall ensure that the imposition of administrative fines
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 24/28
pursuant to this article for the infringements of this Regulation listed
in paragraphs 4, 5, and 6 are, in each individual case, effective, proportionate, and
dissuasive.”
“Administrative fines shall be imposed, depending on the circumstances of each
individual case, in addition to or in lieu of the measures set forth in Article 58,
paragraph 2, subparagraphs (a) through (h) and (j). When deciding whether to impose an administrative fine and its
amount in each individual case, due account shall be taken of:
(a) the nature, gravity, and duration of the violation, taking into account the nature,
scope, or purpose of the processing operation in question, as well as the number
of data subjects affected and the extent of the damages they have suffered;
b) whether the violation was intentional or due to negligence;
c) any measures taken by the controller or processor to mitigate
the harm suffered by the data subjects;
d) the degree of responsibility of the controller or processor, taking
into account the technical or organizational measures they have implemented pursuant to
Articles 25 and 32;
e) any previous violations committed by the controller or processor;
f) the degree of cooperation with the supervisory authority to remedy the
violation and mitigate its potential adverse effects;
g) the categories of personal data affected by the breach;
h) how the supervisory authority became aware of the breach, in particular
whether the controller or processor reported the breach and, if so, to what extent;
i) where the measures referred to in Article 58(2) have previously been ordered
against the controller or processor concerned in relation to the
same matter, compliance with those measures;
j) adherence to codes of conduct pursuant to Article 40 or to certification mechanisms
certification mechanisms approved pursuant to Article 42, and
k) any other aggravating or mitigating factors applicable to the circumstances of the case,
such as financial benefits obtained or losses avoided, directly or
indirectly, through the infringement.”
With regard to Article 83(2)(k) of the GDPR, Article 76 of the LOPDGDD,
“Penalties and Corrective Measures,” provides:
“2. In accordance with the provisions of Article 83(2)(k) of Regulation (EU) 2016/679, the following
may also be taken into account:
a) The ongoing nature of the infringement.
b) The connection between the offender’s activity and the processing of
personal data.
c) The benefits obtained as a result of committing the violation.
d) The possibility that the data subject’s conduct may have contributed to the commission of the
violation.
e) The existence of a merger by absorption occurring after the commission of the
violation, which cannot be attributed to the absorbing entity.
f) The impact on the rights of minors.
g) Having a data protection officer, where not mandatory.
h) The voluntary submission by the controller or processor to
alternative dispute resolution mechanisms, in cases where
disputes arise between them and any data subject.”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 25/28
In the present case, in recital, the seriousness of the possible violation is taken into
account, as is the impact it has on the data subjects.
A fine must be imposed, in addition to the adoption of measures.
The fine imposed must be, in each individual case, effective, proportionate, and
deterrent, in accordance with the provisions of Article 83(1) of the GDPR. Thus, the
turnover of EE (€19,443,719 in 2023) is taken into account as a
preliminary consideration.
For the purposes of deciding on the imposition of an administrative fine and its amount, based
on the established facts, the penalty to be imposed must be determined in accordance with
the following circumstances, as set forth in the aforementioned provisions.
-Article 83.2.a) of the GDPR:
“The nature, gravity, and duration of the infringement, taking into account the nature,
scope, or purpose of the processing operation in question, as well as the number
of data subjects affected and the level of damage they have suffered;”
The Agency considers that the nature of the infringement is very serious, since it results
in individuals losing control over their personal data, as it is
disseminated unrestricted via the internet in the online newspaper and on two social media platforms.
In this regard, the CJEU judgment of August 1, 2022, in Case C-184/20 (OT and Vyriausioji
tarnybinés etikos komisija) highlights the amplifying effect of the internet, stating that “102
Furthermore, it is established that such processing results in that personal data being
freely accessible on the internet to the general public as a whole and, as
a result, to a potentially unlimited number of people,” with implications for
significant damages should the aforementioned processing continue.
-Article 83(2)(b) of the GDPR.
“Intent or negligence in the violation”: EE’s conduct is considered to have been
negligent for failing to ensure a procedure that would guarantee data protection
in such sensitive circumstances, especially since techniques exist that
allow for the anonymity of the individuals appearing in the video that is the subject of
the proceedings.
-Article 83(2)(g) of the GDPR.
Categories of data affected by the violation: although no
“special categories of personal data,” as defined by the GDPR in
Article 9, the personal data referred to in the proceedings are of a
particularly sensitive nature, given the victim’s vulnerability and the special
situation of minors who must be protected, insofar as they
the individuals can be easily and quickly identified in conjunction with the rest of the news report, thereby increasing
the risks to their privacy.
Likewise, the following aggravating factors are considered:
The infringement of minors’ rights (Article 76.2(f) of the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 26/28
LOPDGDD). EE processed personal data belonging to a minor; therefore,
given the minor’s particular vulnerability, it can be considered that an infringement of their
right to personal data protection would have particularly significant implications and consequences
.
The amount of the applicable fine is €20,000 (twenty thousand euros).
IX
Corrective Measures
It is further agreed to require the data controller to adopt appropriate measures to
bring its actions into compliance with the regulations mentioned in this decision, in accordance with
provisions of Article 58(2)(d) of the GDPR, pursuant to which each supervisory authority may “order the controller or processor to ensure that processing
operations comply with the provisions of this Regulation, where appropriate,
in a specific manner and within a specified time limit…” The imposition of this
measure is compatible with the sanction consisting of an administrative fine, as
provided for in Art. 83(2) of the GDPR.
In the present case, these measures consist of requiring EE to, within a period of
THREE MONTHS from the date on which the final decision concluding
this proceeding becomes enforceable, adopt the following measures:
- Demonstrate that it has adopted the necessary measures to ensure compliance
with the provisions of Article 5.1.c) of the GDPR, to prevent the excessive publication or dissemination
of personal data, particularly that of minors.
In this case, compliance with the regulations requires the permanent cessation of the
processing to which the proceedings refer, with the permanent removal from the entity’s
website of the content referred to in the complaint.
This must be done in such a way as to prevent access to the personal data, its
dissemination, and access to the original by third parties, preventing—to the extent that the state of
technology permits—the re-upload or re-posting of exact copies or replicas by
Internet Users of the published content. In any case, its
storage shall be ensured for the purpose of safeguarding evidence that may be necessary in the
course of any police or administrative investigation or judicial proceedings that may
be initiated.
However, it should be noted that within the framework of the preliminary
investigative proceedings conducted by this Agency, it was agreed to require the aforementioned cessation of
processing from EE, as a precautionary measure subsequently confirmed in the decision to
initiate the present proceedings. Therefore, the measure ordered here amounts to
making the previously imposed precautionary measure definitive.
Finally, it should be noted that failure to comply with any order to adopt measures
imposed by this agency in the resolution of the present enforcement proceeding
may be considered an administrative violation in accordance with the provisions of the
GDPR, classified as an infringement under Articles 83.5 and 83.6, and such
conduct may lead to the initiation of further administrative disciplinary proceedings.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 27/28
Therefore, in accordance with applicable law and after assessing the criteria for
determining the severity of the sanctions whose existence has been established, the Presidency of the
Spanish Data Protection Agency RESOLVES:
FIRST: TO IMPOSE on EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A., with Tax ID No.
A87115226, for a violation of Article 5.1.c) of the GDPR, as defined in Article
83.5.a) of the GDPR, a fine of 20,000 euros.
SECOND: TO ORDER EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A., with Tax ID No.
A87115226, to demonstrate, pursuant to Article 58.2.d) of the GDPR, within a maximum period of three
months from the date this decision becomes final and enforceable, that it has adopted the
necessary measures to ensure compliance with the provisions of Article 5.1.c)
of the GDPR, preventing the excessive publication or dissemination of personal data and, in
particular, of minors, in accordance with the provisions of this Decision.
THIRD: NOTIFY EL LEÓN DE EL ESPAÑOL
PUBLICACIONES, S.A., of this decision.
FOURTH: This resolution shall become enforceable once the deadline for filing the
optional appeal for reconsideration has expired (one month from the day following notification
of this resolution) without the data subject having exercised this right. The
party subject to the sanction is hereby notified that they must pay the imposed sanction once this
resolution becomes enforceable, in accordance with the provisions of Art. 98.1.b) of Law
39/2015, of October 1, on the Common Administrative Procedure of
Public Administrations (hereinafter LPACAP), within the voluntary payment period
established in Art 68 of the General Collection Regulation, approved by Royal
Decree 939/2005, dated July 29, in conjunction with Art 62 of Law 58/2003, dated December 17,
December, by making a deposit, indicating the taxpayer identification number (NIF) of the party subject to the penalty and the
procedure number appearing at the top of this document, into the
restricted account No. IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code:
CAIXESBBXXX), opened in the name of the Spanish Data Protection Agency at the
bank CAIXABANK, S.A. Otherwise, collection will proceed during the
enforcement period.
Upon receipt of the notice and once it becomes enforceable, if the enforceability date falls between
the 1st and 15th of each month, inclusive, the deadline for voluntary payment
will be until the 20th of the following month or the next business day thereafter; and if it falls between
the 16th and the last day of each month, inclusive, the payment deadline will be until the 5th of the
second following month or the next business day thereafter.
In accordance with the provisions of Article 50 of the LOPDGDD, this
Resolution shall be made public. Publication shall take place once it has been notified to the
data subjects.
Against this resolution, which concludes the administrative proceedings pursuant to Article 48.6 of the
LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, the
data subjects may, at their discretion, file an appeal for reconsideration with the
Presidency of the Spanish Data Protection Agency within one month
from the day following notification of this resolution, or directly file an
administrative appeal with the Administrative Litigation Chamber of the Court of Appeal of C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 28/28
an administrative appeal before the Administrative Chamber of the National Court
National Court, in accordance with the provisions of Article 25 and paragraph 5 of the
fourth additional provision of Law 29/1998, of July 13, regulating the Jurisdiction
Administrative Litigation, within two months from the day following
notification of this decision, as provided for in Article 46.1 of the aforementioned Law.
Finally, it is noted that, in accordance with the provisions of Article 90.3(a) of the LPACAP,
the final administrative decision may be provisionally suspended if the data subject
expresses their intention to file a contentious-administrative appeal. If this is the
case, the data subject must formally notify the Agency of this fact in writing, addressed to
the Spanish Data Protection Agency, by submitting it through the Agency’s
Electronic Registry [https://sedeaepd.gob.es/sede-electronica-web/], or through
any of the other registries provided for in Art. 16.4 of the aforementioned LPCAP. The interested party
must also submit to the Agency the documentation proving that the
contentious-administrative appeal has been effectively filed. If the Agency is not notified of the
filing of the contentious-administrative appeal within two months from the
day following notification of this decision, it will consider the precautionary suspension
to have ended.
938-101025
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es




