Fundació Universitat Oberta de Catalunya (FUOC) – €31,000 Fine (Spain, 2024)

€31,000DPA APDCAT21 March 2024Spain
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Fundació Universitat Oberta de Catalunya (FUOC) was fined €31,000 for publishing sensitive personal data of minors without proper safeguards. This case is important because it underscores the need for organizations to protect the privacy of individuals, especially vulnerable groups like children.

What happened

A student project containing non-anonymized sensitive data about 54 minors was made publicly accessible online.

Who was affected

The minors whose sensitive personal data, including names and test scores, were published without anonymization.

What the authority found

The Catalan Data Protection Authority found that FUOC violated data protection rules by allowing public access to sensitive information without proper data minimization.

Why this matters

This ruling serves as a reminder for educational institutions and organizations to prioritize data protection and ensure that sensitive information is handled appropriately to avoid similar penalties.

GDPR Articles Cited

AI-verified

Art. 9(GDPR)
Art. 5(1)(c) GDPR
Art. 5(2) GDPR
Art. 83(5)(a) GDPR
View original scraped data
Art. 5(1)(c) GDPR
Art. 5(2) GDPR
Art. 9(GDPR)
Art. 83(5)(a) GDPR

Original data from scraper before AI verification against source document.

Entities Involved

Fundació Universitat Oberta de Catalunya (FUOC)
Autoritat Catalana de Protecció de Dades (APDCAT)
Source verified 13 March 2026
articles corrected
Full Legal Summary
Detailed

In 2000, a student at the Universitat Oberta de Catalunya (UOC) conducted a study for her practicum project involving 54 minors at a secondary school, collecting highly sensitive personal data, including cognitive and psychological test results. In January 2001, the student completed the project, which included names and test scores without anonymization or pseudonymization. On 16 February 2010, the controller, the Fundació per a la Universitat Oberta de Catalunya (FUOC), published the project in its open-access institutional repository (O2), making the data publicly accessible. On 7 August 2023, the data subject, one of the students evaluated in the 2000 study, discovered the document by Googling her name and filed a complaint with the Catalan DPA. She alleged that her full name and intelligence scores appeared in the annexes of the published project. On 8 August 2023, the DPA’s inspection team verified that the report was accessible online and contained non-anonymized personal data of the data subject and other minors. On 1 March 2024, after receiving a request for information from the DPA, the controller removed the document from public access. On 4 June 2024, the DPA initiated a sanctioning procedure against the controller for violating the GDPR. On 10 September 2024, the Catalan Data Protection Authority (APDCAT) found that the Fundació per a la Universitat Oberta de Catalunya (FUOC), as controller of the O2 institutional repository, had infringed Article 5(1)(c) GDPR (data minimisation) in connection with Article 83(5)(a) GDPR, by allowing the long-term public accessibility of a student project that disclosed non-anonymized sensitive personal data of 54 minors. The DPA imposed a fine of €31,000.

Related Enforcement Actions (0)

No other enforcement actions found for Fundació Universitat Oberta de Catalunya (FUOC) in ES

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

21 March 2024

Authority

DPA APDCAT

Fine Amount

€31,000

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Fundació Universitat Oberta de Catalunya (FUOC) - Spain (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: