Practical guide · GDPR
AEPD fines for publishing documents with personal data
The Spanish Data Protection Agency (AEPD) can penalise both companies and public authorities that publish documents with personal data unredacted. This article covers the type of sanctions, the amounts and real cases that illustrate them.
Legal framework
The AEPD acts under the GDPR and Spain's LOPDGDD 3/2018. Publishing documents with personal data without a lawful basis or proper anonymization typically breaches articles 5, 6 and 32 of the GDPR.
Fine ranges
- Minor infringements: up to €40,000.
- Serious infringements: up to €300,000 or 2% of worldwide turnover.
- Very serious infringements: up to €20 million or 4% of worldwide turnover.
Public-sector regime (LOPDGDD art. 77)
Public authorities covered by article 77 do not receive an economic fine, but rather a decision declaring the breach, mandatory corrective measures and possible disciplinary proposals.
Real cases
- €15,000 fine for publishing documents with identifying data without a legal basis.
- Los Alcázares case: plenary minutes with a resident's name and debt.
- Judgment published with a visible ID.
How to avoid the sanction
- Identify which documents are published or shared externally.
- Define default categories of data to anonymize.
- Use a tool that anonymizes the actual text layer and cleans metadata.
- Log the process and who reviews each version.
- Provide ongoing training to responsible staff.
How anonimIA helps
anonimIA reduces the risk by automating detection, anonymization and auditable logging of every published document.
Do you anonymise documents daily?
Stop redacting by hand. Automate it with anonimIA.
Upload your PDFs and get GDPR-compliant anonymised documents in seconds.
Try it free