Fino

CTPDA (Andalusia) · 2 December 2025

Dirección General de Innovación y Formación del Profesorado

About: Accountability, DPIA, Data principles, Data security, Transparency, Unlawful processing

FineNo fineViolation found
Regulator
CTPDA (Andalusia)
Decided
2 December 2025
Country
Spain
Sector
Not given
Regulator’s reference
RPS-2025/082
Fino case number
2025/ES/194
Export as PDF

What happened

The DPA held that the Ministry of Education and Sports of Andalusia’s provision of cloud-based educational services to public schools violated GDPR provisions relating to transparency, privacy by design, international data transfers and DPIA duties. The Ministry used Microsoft as a processor for this activity.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Accountability
  • DPIA
  • Data principles
  • Data security
  • Transparency
  • Unlawful processing

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2025/ES/194.