UMA

Master 3D Circular

Universidad de Málaga

Teaching session · 3-hour journey (180 min)

Data Protection in Smart Cities

The EU regulatory framework for personal data as a key driver of smart-policy design in European cities — from GDPR principles to AI Act biometric bans.

Master 3D Circular Universidad de Málaga 1 session · EN

Session overview

What you will learn

Why it matters
Smart cities aggregate sensor, mobility, video and AI data. Without a sound data-protection layer, the whole policy fails legally and socially.
Legal lens
European Union law: GDPR, Law Enforcement Directive, ePrivacy, AI Act, Data Act and Data Governance Act — read together, not in isolation.
For whom
Designed for international students from different jurisdictions. All examples are mapped to EU law with comparative notes.

Regulatory map

The EU data layer for smart cities

GDPR

Reg. (EU) 2016/679

General data protection — principles, bases, rights, DPIA, transfers.

LED

Dir. (EU) 2016/680

Data processing by police and criminal-justice authorities.

ePrivacy

Dir. 2002/58/EC

Confidentiality of electronic communications and traffic data.

AI Act

Reg. (EU) 2024/1689

Risk-based AI rules — Art. 5 bans incl. real-time biometric ID in public spaces.

Data Act

Reg. (EU) 2023/2854

Access to and use of IoT-generated data; B2G data sharing.

DGA

Reg. (EU) 2022/868

Data altruism and re-use of protected public-sector data.

Agenda

A 3-hour journey

  1. 0–15′

    Framing

    Smart city as a data infrastructure. Why DP is a precondition, not a constraint. Charter Arts. 7–8.

  2. 15–45′

    EU framework deep-dive

    GDPR principles, Art. 6 bases for municipalities, LED vs GDPR, AI Act, Data Act, DGA.

  3. 45–75′

    Case-law clinic

    Schrems II, La Quadrature du Net, AEPD Mercadona, Bridges (UK CoA) — what each binds for cities.

  4. 75–90′

    Coffee break

    Informal Q&A and networking.

  5. 90–125′

    Practice I · Mini-DPIA

    Group work on the AI-CCTV pilot in Málaga's historic centre.

  6. 125–150′

    Practice II · Role-play

    Municipal Ethics Committee + new IoT smart-waste case (Case 3).

  7. 150–170′

    Structured debate

    Live remote biometric ID in public spaces — three teams, vote.

  8. 170–180′

    Quiz & takeaways

    15-question self-assessment + key takeaways and open Q&A.

Case law

The decisions that shape smart-city DP

CJEU
Schrems II
C-311/18 (2020)
Invalidated Privacy Shield; cities procuring US-based cloud must run transfer impact assessments.
CJEU
La Quadrature du Net
Joined C-511/18, C-512/18, C-520/18 (2020)
General retention of traffic and location data is incompatible with EU law except for narrow national-security cases.
AEPD
Mercadona
PS/00120/2021 — €2.5M
Facial-recognition CCTV in stores fined; transposable to municipal video analytics.
UK CoA
R (Bridges) v South Wales Police
[2020] EWCA Civ 1058
Persuasive: live facial recognition by police breached Art. 8 ECHR and DP law.

Practical work

Apply, don't just listen

Mini-DPIA

AI-CCTV pilot for crowd analytics in central Málaga. Identify risks, bases, mitigations.

Cloud procurement

Transfer-impact analysis when contracting a US hyperscaler for traffic data.

AEPD school case

Facial recognition for exam supervision — proportionality and Art. 9 GDPR.

Role-play

Municipal Ethics Committee debates a biometric ID deployment in public space.

Materials

Download the full pack

Slides — Data Protection in Smart Cities

PPTX

Ready

Handout — Theoretical reader

PDF

Ready

Case sheet — Practical exercises

PDF

Ready

Quiz — Self-assessment

PDF

Ready

Files are distributed by the instructor at the start of the session. Refer to your course intranet to retrieve them.

Citas verificadas

Verified sources & official links

Direct links to every decision cited in the slides and handout. All URLs verified.

CJEU — Schrems II
C-311/18, Grand Chamber, 16 Jul 2020 — ECLI:EU:C:2020:559
CJEU — La Quadrature du Net
Joined cases C-511/18, C-512/18 & C-520/18, Grand Chamber, 6 Oct 2020 — ECLI:EU:C:2020:791
AEPD — Mercadona
Sanctioning procedure PS/00120/2021 — facial recognition in supermarkets; fine €2,520,000
R (Bridges) v Chief Constable of South Wales Police
[2020] EWCA Civ 1058, 11 Aug 2020 — Court of Appeal (UK)
SyRI
Rb. Den Haag, 5 Feb 2020 — ECLI:NL:RBDHA:2020:865 (NJCM et al. / FNV v. Staat)
Garante (IT) — Università di Trento «Marvel»
Provv. n. 50, 26 gen 2023 — doc. web n. 9870014; sanzione €50.000 (smart-city audio sensors)
Autoriteit Persoonsgegevens (NL) — Clearview AI
Decision of 16 May 2024, published 3 Sept 2024 — fine €30.5M for unlawful facial-recognition database

Bibliografía

Publicaciones de María Luisa Gómez-Jiménez

Selección de trabajos propios sobre protección de datos, privacidad e inteligencia artificial en el ámbito del Derecho público.

  1. Gómez-Jiménez, María Luisa (2025). Del IoT a la inviolabilidad digital del domicilio en las viviendas inteligentes. Urban Red / Universidad de Málaga. Enlace
  2. Gómez-Jiménez, María Luisa (2022). Tecnologías habilitadoras digitales (THD) en un contexto de emergencia sanitaria: retos jurídicos y su proyección en las ciencias de la salud. Tirant lo Blanch, ISBN 978-84-1113-603-7. Enlace
  3. Gómez-Jiménez, María Luisa (2021). Automatización procedimental y sesgo electrónico: el procedimiento administrativo electrónico desde la inteligencia artificial. Aranzadi Thomson Reuters, ISBN 978-84-1346-877-8. Enlace
  4. Gómez-Jiménez, María Luisa (2020). Data privacy and human dignity: a legal approach in an interconnected world. En J. M. Puyol Montero (coord.), New challenges for law: Studies on the dignity of human life, pp. 121–140. ISBN 978-84-1313-830-5. Enlace
  5. Gómez-Jiménez, María Luisa (2020). Reconocimiento facial e identidad digital en la provisión de bienes y servicios en las ciudades inteligentes. Congreso AEPDA — Repositorio UMA. Enlace
  6. Gómez-Jiménez, María Luisa (1994–2026). Perfil completo de publicaciones (49 artículos, 23 libros, 103 capítulos). Dialnet — autor 637956. Enlace

FAQ

Frequently asked questions