Practical guide · GDPR

AEPD fines for publishing documents with personal data

8 min read

The Spanish Data Protection Agency (AEPD) can penalise both companies and public authorities that publish documents with personal data unredacted. This article covers the type of sanctions, the amounts and real cases that illustrate them.

Legal framework

The AEPD acts under the GDPR and Spain's LOPDGDD 3/2018. Publishing documents with personal data without a lawful basis or proper anonymization typically breaches articles 5, 6 and 32 of the GDPR.

Fine ranges

  • Minor infringements: up to €40,000.
  • Serious infringements: up to €300,000 or 2% of worldwide turnover.
  • Very serious infringements: up to €20 million or 4% of worldwide turnover.

Public-sector regime (LOPDGDD art. 77)

Public authorities covered by article 77 do not receive an economic fine, but rather a decision declaring the breach, mandatory corrective measures and possible disciplinary proposals.

Real cases

How to avoid the sanction

  1. Identify which documents are published or shared externally.
  2. Define default categories of data to anonymize.
  3. Use a tool that anonymizes the actual text layer and cleans metadata.
  4. Log the process and who reviews each version.
  5. Provide ongoing training to responsible staff.

How anonimIA helps

anonimIA reduces the risk by automating detection, anonymization and auditable logging of every published document.

Do you anonymise documents daily?

Stop redacting by hand. Automate it with anonimIA.

Upload your PDFs and get GDPR-compliant anonymised documents in seconds.

Try it free