AEPD (Spain) - PS-00480-2025
| AEPD - PS-00480-2025 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 6(1)(f) GDPR Article 27 GDPR Article 5(3) ePrivacy Directive 2002/58/EC Article 22(2) LSSI |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | 02.10.2025 |
| Decided: | 14.11.2025 |
| Published: | |
| Fine: | 72,000 |
| Parties: | Tiger Media Inc. |
| National Case Number/Name: | PS-00480-2025 |
| European Case Law Identifier: | n/a |
| Appeal: | Not appealed |
| Original Language(s): | Spanish |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | bms |
The DPA fined an adult ad network for placing advertising cookies without consent, unlawfully relying on legitimate interest and lacking an EU representative.
English Summary
Facts
Tiger Media Inc., the controller, operated an advertising platform for publishers and advertisers of adult products and services. The platform acted as an ad network, connecting publishers offering advertising space with advertisers seeking to display ads on those websites.
Through this platform, the controller processed personal data of users visiting publishers’ websites where its ads were displayed. This included IP addresses, device and browser information, website URLs, referral URLs, clicks, impressions and cookie identifiers.
According to the controller, the data were processed for ad delivery, fraud prevention, frequency capping, performance measurement and service improvement.
The controller argued that it did not carry out behavioural advertising or profiling. It claimed that any targeting was limited to contextual factors, such as country and language. The controller relied mainly on legitimate interest as a legal basis and argued that publishers, as independent controllers of their own websites, were responsible for obtaining any consent required for cookies.
The DPA investigated the controller’s platform and several Spanish websites using it. It found that cookies linked to the controller’s platform were installed on users’ devices without prior consent. These cookies were used for advertising-related purposes, including measuring ad performance, improving ad relevance, limiting frequency and detecting fraud.
The AEPD also noted that the controller was not established in the EU. Although the controller stated that it had appointed a representative in Northern Ireland and was in the process of changing representative, the DPA considered that it did not have a valid representative established in the Union.
Holding
The AEPD held that the controller violated Article 6 GDPR by processing personal data without a valid legal basis. The DPA emphasised that the LSSI, the Spanish law implementing the ePrivacy Directive require prior consent for storing or accessing information on a user’s device through cookies, unless an exemption applies.
The DPA distinguished between the placement or reading of cookies, which is governed by the cookie rules, and the subsequent processing of personal data obtained through those cookies, which must comply with the GDPR. Since the cookies were installed without consent, the subsequent processing of the data collected through them could not be considered lawful.
The AEPD rejected the controller’s reliance on legitimate interest under Article 6(1)(f) GDPR. It found that users had not received clear information and had not consented to the use of cookies. Moreover, users of the affected websites did not have a reasonable expectation that their browsing-related data would be processed by a third-party advertising network for advertising purposes. Therefore, the processing did not pass the balancing test required under Article 6(1)(f) GDPR.
The DPA also held that the controller violated Article 27 GDPR. Since the controller was not established in the EU but processed personal data of users in Spain in connection with its advertising services, it was required to appoint a representative established in an EU Member State. A representative in Northern Ireland did not meet this requirement.
The AEPD fined the controller €120,000 in total: €70,000 for the violation of Article 6 GDPR and €50,000 for the violation of Article 27 GDPR. Pursuant to Article 85 of the Spanish administrative Law 39/2015, the notice of initiation informed the controller of the possibility of acknowledging liability and making a voluntary payment of the proposed penalty, which would entail two cumulative reductions of 20% each. With the application of these two reductions, the final penalty was set at €72,000, and its payment resulted in the termination of the proceedings.
The AEPD also ordered the controller to adopt corrective measures within three months. In particular, the controller had to ensure compliance with Article 6 GDPR, ensure compliance with the Spanish cookie rules by the service providers using its cookies, appoint an EU representative and notify the AEPD of the measures adopted.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.
1/24
• File No.: EXP202405210
RESOLUTION TERMINATING THE PROCEEDINGS BY ACKNOWLEDGMENT OF LIABILITY AND VOLUNTARY PAYMENT
Regarding the proceedings initiated by the Spanish Data Protection Agency and based on the following BACKGROUND:
FIRST: On October 2, 2025, the Presidency of the Spanish Data Protection Agency agreed to initiate sanctioning proceedings against TIGER MEDIA INC.
(hereinafter, T.M.I.), by means of the agreement transcribed below:
<< File No.: EXP202405210
AGREEMENT TO INITIATE SANCTIONING PROCEEDINGS
Based on the actions carried out by the Spanish Data Protection Agency and the following
FACTS
FIRST: The Spanish Data Protection Agency has become aware of
certain facts that could constitute a possible infringement attributable to TIGER MEDIA
INC. with Tax Identification Number 830104493 (hereinafter, T.M.I.).
This Agency has become aware of the existence of a possible violation of the
Data Protection Regulations, in relation to the processing of personal data
derived from the activity of the platform ***PLATFORM.1 (owned by T.M.I.),
as an advertising network (Ad Network) for publishers and advertisers of adult products and
services, which, therefore, does not act as a generalist Ad Network. SECOND: As a consequence of the known facts, on April 8, 2024, the Presidency of the Spanish Data Protection Agency instructed the Sub-Directorate General for Data Inspection (SGID) to initiate the preliminary investigation proceedings referred to in Article 67 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD).
THIRD: The Deputy Directorate General for Data Inspection carried out
preliminary investigative actions to clarify the facts in question, by virtue of the functions assigned to the supervisory authorities in
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
2/24
Article 57.1 and the powers granted in Article 58.1 of Regulation (EU)
2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VIII of the LOPDGDD.
As a result of the actions carried out, the following facts have been obtained:
On 28/11/2024, in response to the request for information from this Agency, T.M.I. submitted the following information and statements:
1. That T.M.I. is the owner and operator of the platform
***PLATFORM.1.
2. Provides a Record of Processing Activities which states, among other things:
- That the data controller is T.M.I.
- That, in relation to end users who interact with the websites where ads served by
***PLATFORM.1 are displayed, it states:
The following data is processed:
• Technical information:
o Device details: device type, operating system, browser information.
o IP address: used to deduce country, time zone, and locale settings.
• Usage data:
o URL of the website displaying the ad.
o Referral URL.
o User interactions such as clicks and impressions.
• Location data:
o IP address. • Electronic identification data:
or Cookies: ***PLATFORM.1 relies on publishers to implement consent mechanisms (cookies, banners, and CMPs) to comply with local regulations, including the GDPR and the ePrivacy Directive.
The purposes are as follows:
• Sending and displaying advertising to end users on publishers' websites.
• Monitoring clicks to avoid showing campaigns that have already been clicked.
• Fraud detection and prevention.
• Measuring advertising performance, including conversion tracking to evaluate the effectiveness of advertising campaigns.
• Service improvement. Development and improvement of services, including bug fixes. C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
3/24
The legal basis for processing is legitimate interest (sending advertising) and consent when necessary.
1. They do not process or collect sensitive data: the data they process is minimal and includes IP addresses, for fraud detection and sending advertising, and identifiers in cookies for basic analytics and frequency limitation.
2. They do not engage in profiling or behavioral advertising.
3. They do not collect consent directly since they do not control the publishers' websites.
4. The legal basis for processing personal data is legitimate interest in processing minimal data strictly limited to the purposes of:
- Sending advertising to users.
- Preventing fraud and ensuring the integrity of the platform. - Measuring advertising performance for publishers and advertisers.
Publishers, as independent controllers, are responsible for complying with local laws regarding consent for cookies and other tracking technologies.
1. They are not required to conduct impact assessments because they do not engage in large-scale profiling, behavioral advertising, or any high-risk processing as defined in Article 35 of the GDPR.
2. They have not appointed a Data Protection Officer (DPO) because it was not required under the GDPR.
They do not:
- Process sensitive data on a large scale.
- Systematically monitor data subjects.
- Process minimal personal data such as IP addresses and cookie identifiers only for limited purposes such as fraud prevention or advertising.
1. They have a representative as defined in Article 35 of the GDPR. 27 located in Northern Ireland,
acknowledge that they have published their data in the privacy policy and that
they are in the process of changing their representative to one located in an EU Member State and will then update their privacy policy.
On June 23, 2025, the website ***PLATFORM.1 was checked:
1. The privacy policy states, among other things:
- T.M.I. is the data controller.
- This privacy policy applies both to the website itself and
also to its advertising on third-party websites if they include a link
to this privacy policy.
—And it also states:
The text is in English, and its unofficial translation into Spanish is:
“[...]
Publisher website data: When an end user browses a publisher's website using our technologies, we may collect information such as the operating system, the URL of the website displaying our ads, the referring URL, browser information, country, time zone, local settings (e.g., preferred language), and IP address to support ad delivery and performance analysis.
If we combine or link non-personal, demographic, or technical data with personal data to directly or indirectly identify an individual, we treat the combined information as personal data.
[...]
Cookies and automatic data collection technologies
Our website and the publisher websites that display our ads may We use cookies (small pieces of data placed on your device) and similar automatic data collection technologies. These technologies help us distinguish users and provide a better, more personalized browsing experience. They also allow us to: Estimate audience size and usage patterns for ads served on publisher websites. Deliver, measure, and optimize advertising based on factors such as location or device type. Monitor and prevent fraudulent activity related to ad impressions or clicks. Collect aggregate statistics, such as the popularity or effectiveness of specific ads. You can refuse to accept browser cookies by activating the appropriate setting in your browser.
[...] Cookies on publisher websites: When you visit a publisher's website where ads from PLATFORM.1 or our advertising partners appear, they may place cookies on your device. These cookies allow us to: Deliver ads Relevant information based on contextual data, such as the publisher's website content.
Measure ad performance (e.g., impressions, clicks) and optimize future ad placements.
Ensure compliance with publisher agreements and detect fraud.
PLATFORM.1 does not conduct behavioral advertising and does not track your browsing behavior across multiple websites for targeting purposes.
Managing Cookies on Publisher Websites
The use of cookies on publisher websites is governed by the publisher's own cookie policies. However, if PLATFORM.1 sets cookies as part of its ad delivery services, you can manage your cookie preferences through browser settings or the opt-out mechanisms provided in our cookie policy.
For users in regions such as the European Economic Area (EEA) or California, you may have additional rights to control cookies through consent banners or opt-out tools. on publishers' websites.
Web beacons and similar technologies
Our website and publisher websites that display ads from
***PLATFORM.1 may use web beacons (small transparent images or objects, also known as clear GIFs, pixel tags, and single-pixel GIFs). These technologies help us and our partners to:
Count visitors on special pages or advertisements.
Collect statistics on the effectiveness of advertisements, such as how often they are viewed or clicked.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
5/24
Verify system and server integrity to improve service reliability.
Web beacons are typically used in conjunction with cookies and do not collect personal data on their own. However, when combined with cookies, they can contribute to the data used to deliver ads or analyze performance.
[...]
Category of personal data
Purpose of processing
Legal basis for processing
... ... ...
Publisher interaction data.
Contextual information, such as website content, ad placement details, and user engagement on publisher websites.
To deliver contextually relevant ads and monitor ad placement compliance.
Legitimate interests.
... ... ...
Cookies on publisher websites: IP address, browser type, referring URL, device information.
[...] To deliver ads,
detect fraud, measure
ad performance, and improve
ad targeting based on
contextual information.
Legitimate interests/Consent
(where necessary).
[...]”
1. The cookie policy states:
The text is in English, and its unofficial translation into Spanish is:
“[...]
Types of cookies we use
We may use the following types of cookies:
[...]
Advertising, tracking, or targeting cookies. These cookies allow us to deliver and
optimize ads by recording information about your interactions with
ads, such as clicks, impressions, and contextual details. Although
***PLATFORM.1 does not engage in behavioral targeting across all
websites, these cookies allow us to improve the relevance of the ads that
appear on publishers' websites. These are typically
persistent cookies that can last up to one year.
[...]
Please see our Cookie Table for a list of the individual first-party and third-party cookies that may be used on this website and their specific purposes.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
6/24
[...]”
2. The published cookie table states:
The text is in English, and its unofficial translation into Spanish is:
“[...]
Cookies used on editorial websites that display ads ***PLATFORM.1
Category Name Domain Purpose
Duration
Data
Exchange
Segmentation
(…)
***PLATFORM.1
Records
consulted
ads for
frequency
limitation and
relevance. 3 days
None
Segmentation
(…) (…)
Records
consulted
ads for
frequency
limiting and
relevance. 3 days
None
Segmentation
(…) (…)
Identifies
anonymous users
for fraud detection.
1 year
None
Segmentation
(…)
***PLATFOR
MA.1
Identifies
anonymous users
for fraud detection.
1
years
None
no
[...]”
3. The end-user consent policy states:
The text is in English, and its unofficial translation into Spanish is:
“[...]
Responsibilities as a publisher of ***PLATFORM.1
As a publisher using ***PLATFORM.1 services, you are responsible for
ensuring that they are properly disclosed to users in the EEA and the UK
and that legally valid consent is obtained where required.
Failure to comply with this policy may result in limitations, suspension, or termination of
your access to ***PLATFORM.1 services.
Requirements relating to properties under your control
If you use ***PLATFORM.1 services on any website, application, or other
property controlled by you, your affiliates, or your clients, you must comply with the following
obligations for users in the EEA and the UK:
1. Obtaining user consent.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
7/24
Obtain legally valid consent before: Using cookies or other local storage technologies for purposes that require consent under applicable law (e.g., non-essential cookies used for personalization or tracking). Collecting, sharing, or processing personal data to personalize advertisements or for other purposes that require user consent. Consent must be informed, freely given, specific, and unambiguous. Do not use pre-ticked boxes, implied consent, or any method that does not constitute an affirmative action by the user.
[...]”
4. The terms of service state:
The text is in English, and its unofficial translation into Spanish is:
“[...]
1.3 Participation as an Advertiser (a) You are responsible for all: I) ad selection options (“targets”) and all ad content, ad information and URLs (“creatives”), generated by you or for you; and
[...]
On June 23, 2025, it was verified that:
The following websites, among others, are listed online in directories associated with the use of ***PLATFORM.1.
(...)
1. Regarding the website ***URL.1/, tests performed with the developer tools of (...) revealed that:
- Persistent cookies are installed without consent, such as the cookie
(...), the latter two associated with the domain ***PLATFORM.1.
1. Regarding the website ***URL.2, tests performed with the developer tools of (...) revealed that:
- Persistent cookies are installed without consent, such as the cookie
(...).
1. Regarding the website ***URL.3: tests performed with the developer tools of (...) revealed that:
- Persistent cookies are installed without consent. The purpose of these cookies is unknown.
- The privacy policy (...) states, among other things, that cookies from ***PLATFORM.1 are used to display targeted advertising based on language and country. It also states that cookies from (...) and social media cookies are used.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
8/24
On June 26, 2025, it was verified that:
The following websites, among others, are published online in lists associated with the use of ***PLATFORM.1:
***URL.4
Regarding ***URL.4, the details of the call or HTTP request are included in the proceedings, incorporated by the Inspection Services of this AEPD.
On June 27, 2025, it was verified that:
According to the service ***SERVICE.1, as of On October 15, 2024, a table of cookies used by ***PLATFORM.1 was published, showing that the cookie
(…), associated with the domain ***PLATFORM.1, is categorized as
“Marketing” and, according to its unofficial translation from English, its purpose is
“to identify anonymous users.”
LEGAL BASIS
I
Jurisdiction
In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR) and as established in Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter LOPDGDD), the Presidency of the Spanish Data Protection Agency.
II. Procedure
Article 63.2 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) also stipulates that: “The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the implementing regulations issued thereunder, and, insofar as they do not contradict them, subsidiarily, by the general rules on administrative procedures.”
In accordance with Article 64 of the LOPDGDD, and taking into account the characteristics of the alleged infringements committed, a sanctioning procedure is initiated.
The procedure will have a maximum duration of twelve months from the date of the initiation agreement. After this period, the procedure will expire, and the Agency will be notified.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
9/24
Consequently, the proceedings will be archived, in accordance with the provisions of
Article 64 of the LOPDGDD.
If no objections are raised to this initiation agreement within the stipulated period, it
may be considered a proposed resolution, as established in Article
64.2.f) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP).
III
Preliminary Issues
Article 4.1) of the GDPR defines "personal data" as: "any information relating to an identified or identifiable natural person ("data subject"); An identifiable natural person is any person whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
Article 4.2 of the GDPR defines "processing" as: "any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction." Article 4.7 of the GDPR defines the "controller" as:
"the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing; where the purposes and means of the processing are determined by Union or Member State law, the controller or the specific criteria for its appointment may be laid down by Union or Member State law."
Article 4.8 of the GDPR, in turn, defines the "processor" as the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
In this case, in accordance with Articles 4.1 and 4.2 of the GDPR,
personal data processing is established, since T.M.I.
processes, through its platform ***PLATFORM.1, among other processing activities,
personal data such as device characteristics,
browser, operating system, IP address, and cookies regarding visitors to the publishers' websites, in order to send them advertising.
T.M.I. carries out this activity as the data controller, given that
it is the entity that determines the purposes and means of such activity pursuant to Article 4.7 of the
GDPR.
IV
Obligation breached. Lawfulness of Processing
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
10/24
Article 6 of the GDPR, which governs the lawfulness of processing, establishes the following:
"1. Processing shall be lawful only if at least one of the following conditions applies:
a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
b) processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract;
c) processing is necessary for compliance with a legal obligation to which the controller is subject;
d) processing is necessary in order to protect the vital interests of the data subject or of another natural person;
e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
f) processing is necessary for the purposes of the legitimate interests pursued by the controller." pursued
by the controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
The provisions of point (f) of the first paragraph shall not apply to processing carried out by public authorities in the exercise of their functions.
2. Member States may maintain or introduce more specific provisions to adapt the application of the rules of this Regulation with regard to processing pursuant to points (c) and (e) of paragraph 1, by laying down more precisely specific processing requirements and other measures to ensure lawful and fair processing, including other specific processing situations as referred to in Chapter IX.
3. The basis for processing referred to in points (c) and (e) of paragraph 1 shall be established by: (a) Union law, or (b) the law of the Member State to which the controller is subject.
The The purpose of the processing must be specified in that legal basis or, with regard to the processing referred to in paragraph 1(e), it must be necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. That legal basis may contain specific provisions to adapt the application of rules in this Regulation, including, among others: the general conditions governing the lawfulness of the processing by the controller; the types of data being processed; the data subjects; the entities to which personal data may be disclosed and the purposes of such disclosure; the purpose limitation; the periods for which the data will be stored; and the processing operations and procedures, including measures to ensure lawful and fair processing, such as those relating to other specific processing situations under Chapter IX. Union or Member State law must pursue an objective of the public interest and be proportionate to the legitimate aim pursued.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
11/24
4. Where processing for a purpose other than that for which the personal data were collected is not based on the data subject's consent or on Union or Member State law which is a necessary and proportionate measure in a democratic society to safeguard the objectives referred to in Article 23(1), the controller, in order to determine whether processing for another purpose is compatible with the purpose for which the personal data were initially collected, shall take into account, inter alia:
(a) any relationship between the purposes for which the personal data were collected and the purposes of the further processing envisaged;
(b) the context in which the personal data were collected, in particular with regard to the relationship between the data subjects and the controller;
(c) the nature of the personal data, in particular where special categories of personal data are processed, in accordance with with Article 9, or personal data
relating to criminal convictions and offenses, in accordance with Article 10;
(d) the possible consequences for data subjects of the envisaged further processing;
(e) the existence of appropriate safeguards, which may include encryption or
pseudonymization."
***PLATFORM.1 offers a meeting point for publishers and advertisers,
forming an Ad Network whose activity is that of an SSP (Supply Side Platform) for
publishers, allowing them to sell their inventory (advertising space on websites, apps,
…), as well as a DSP (Demand Side Platform) for advertisers, where they
can access publishers' inventory to display their ads.
In this case, T.M.I. is the owner of the platform ***PLATAFORMA.1, an advertising network for publishers and advertisers of adult products and services. This network connects advertisers with publishers who offer advertising space for ads to be displayed. The ads are therefore only shown to users of adult websites. This is achieved through the ***PLATAFORMA.1 cookie, which is installed by publishers on their websites for advertising purposes. Apparently, no profiling is carried out, and users are "only" segmented by language and country. As an example, this Agency has verified that the ***PLATAFORMA.1 cookie is used on Spanish websites, with checks performed on three of them, namely:
(...) The investigation revealed that the cookie is installed without user consent. In this regard, Article... Article 22.2 of Law 34/2002, of July 11, on Information Society Services and Electronic Commerce, requires the express consent of the data subjects for the storage and access of information obtained through cookies:
“2. Service providers may use data storage and retrieval devices on the terminal equipment of recipients, provided that they have given their consent after being provided with clear and complete information about their use, in particular, about the purposes of the processing of data, in accordance with the provisions of Organic Law 15/1999, of December 13, on the protection of personal data.”
Article 22.2 of Law 34/2002, of July 11, on Information Society Services and Electronic Commerce, requires the express consent of the data subjects for the storage and access of information obtained through cookies:
“2. Service providers may use data storage and retrieval devices on the terminal equipment of recipients, provided that they have given their consent after being provided with clear and complete information about their use, in particular, about the purposes of the processing of data, in accordance with the provisions of Organic Law 15/1999, of December 13, on the protection of personal data.” Section 22.2 of the aforementioned LSSI refers exclusively to the use of storage and retrieval devices. Therefore, the use of data once the cookie information has been extracted is governed by the GDPR. In other words, the processing that takes place after storing or accessing the information stored on a user's terminal equipment must comply with the GDPR.
For this reason, this Agency states in its "Cookie Guide":
"It should also be noted that cookie owners, insofar as they determine the purposes and means of processing, are responsible for the personal information collected by those cookies and for subsequent data processing."
It has therefore been verified that information is sent to the domain ***DOMAIN.1 regarding language, IP address (which is always sent due to technical requirements), information related to the browser and operating system used, the address of the visited website, and a parameter "c" whose purpose could not be determined. T.M.I. states that the purposes of cookies are as follows:
- Sending and displaying advertising to end users on the publishers' websites.
- Monitoring clicks to avoid showing campaigns that have already been clicked.
- Detecting and preventing fraud.
- Measuring advertising performance, including tracking conversions to evaluate the effectiveness of advertising campaigns.
- Improving the service, including developing and improving services, and correcting errors.
T.M.I. states that the legal basis for this processing is legitimate interest, and that the publishers' websites are responsible for collecting consent for placing and reading cookies, when necessary.
Therefore, T.M.I. maintains that the legal basis for the processing it carries out for the purposes it pursues is legitimate interest. However, this legal basis is not applicable. Article 6.1 of the GDPR establishes, in a specific manner, the conditions that legitimize the processing of personal data, including the data subject's consent (point a) and the legitimate interest pursued (point f). In the present case, it is not established that the users have given their prior, free, and informed consent for the use of their data for the purposes described, as they do not even consent to the installation of cookies on their terminal equipment, an essential requirement under Article 22.2 of the LSSI.The CJEU, in its Judgment of 1 October 2019, Case C-673/17 (Planet49), has declared that the installation of cookies can only be based on the valid consent of the user, and that such consent must be active, specific, and informed, expressly excluding the sufficiency of tacit or presumed consent. In this case, the prior consent of the data subjects was not obtained.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
13/24
Furthermore, it is not possible to maintain that the legal basis is the prevailing legitimate interest, since the users of the affected pages do not have a reasonable expectation that their browsing data will be used for advertising purposes by third parties, as they are not provided with clear information or a prior acceptance mechanism. On the contrary, this type of processing is carried out
unexpectedly and contrary to fundamental rights and freedoms, with
data obtained in violation of the provisions of the LSSI (Spanish Law on Information Society Services and Electronic Commerce), so it does not pass the
balancing test required by Article 6.1.f) of the GDPR.
Furthermore, the European Data Protection Board's Report on the work
undertaken by the Cookie Banner Taskforce, adopted on 17 January 2023, includes the conclusion of the working group members that the absence
of informed consent for the installation and retrieval of the information
stored in the cookie means that the subsequent processing cannot be compliant
with the GDPR.
24. In this regard, the task force members considered that non-compliance
found concerning Article 5(3) of the ePrivacy Directive (in particular when no valid
consent is obtained where required) means that the subsequent processing
cannot comply with the GDPR. Furthermore, the task force members confirmed that the
legal basis for the placement/reading of cookies pursuant to Article 5(3) cannot
be the legitimate interests of the controller.
Consequently, since none of the legal bases provided for in Article 6.1 of the GDPR apply, the data processing carried out by T.M.I. must be considered
unlawful, which constitutes a presumed infringement of said provision.
Therefore, in accordance with the evidence available at this time
and in accordance with the agreement to initiate sanction proceedings, it is considered that the known facts could constitute an infringement attributable to T.M.I., for
violation of the aforementioned article. V
Classification of the infringement of Article 6 of the GDPR and qualification for the purposes of
statute of limitations
Article 83.5 of the GDPR classifies as an administrative infringement the violation of the following article, which shall be sanctioned, in accordance with paragraph 2, with administrative fines of up to EUR 20,000,000 or, in the case of an undertaking, up to 4% of its total global annual turnover of the preceding financial year, whichever is higher:
"(a) the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7 and 9;"
For its part, the LOPDGDD, in its Article 71, Infringements, states that:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
14/24
“The acts and conduct referred to in paragraphs 4, 5 and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law, constitute infringements.”
For the sole purpose of determining the statute of limitations, Article 72.1 of the LOPDGDD (Spanish Data Protection Act) establishes the following:
"In accordance with the provisions of Article 83.5 of Regulation (EU) 2016/679, the following infringements are considered very serious and shall be subject to a three-year statute of limitations:
(b) The processing of personal data without any of the conditions for lawful processing established in Article 6 of Regulation (EU) 2016/679 being met."
"(b) The processing of personal data without any of the conditions for lawful processing established in Article 6 of Regulation (EU) 2016/679 being met."
"(c) The processing of personal data without any of the conditions for lawful processing established in Article 6 of Regulation (EU) 2016/679 being met."
(d) The processing of personal data without any of the conditions for lawful processing established in Article 6 of Regulation (EU) 2016/679 being met."
(e) The processing of personal data without any of the conditions for lawful processing being met.
(f) The processing of personal data without any of the conditions for lawful processing established in Article 6 of Regulation (EU) 2016/679 being met.
(f) The processing of personal data without any of the conditions for lawful processing established in Article 6 of Regulation (EU) 2016/679 are met.
(f) The processing of personal data without any of the conditions for lawful processing established in Article 83.5 of Regulation (EU) 2016/679 are considered very serious infringements and shall be subject to a three-year statute of limitations."
(f) The processing of personal data without any of the conditions for lawful processing established in Article 83.5 of Regulation (EU) 2016/679 are considered very serious infringements.
(f) The processing of personal data without any of the conditions for lawful processing established in Article 83.5 of Regulation (EU) 2016/679 are considered very serious infringements.
VI. Proposed Sanction
In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR must be observed. These articles state:
“1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article for infringements of this Regulation referred to in paragraphs 4, 9 and 6 is, in each individual case, effective, proportionate and dissuasive.
2. Administrative fines shall be imposed, depending on the circumstances of each individual case, as an additional measure to, or in lieu of, the measures provided for in Article 58(2)(a) to (h) and (j). When deciding on the imposition of an administrative fine and its amount in each individual case, due consideration shall be given to:
(a) the nature, seriousness and duration of the infringement, taking into account the nature, scope or purpose of the processing operation concerned and the number of a) the data subjects affected and the level of damage suffered;
b) whether the infringement was intentional or negligent;
c) any measures taken by the controller or processor to remedy the damage suffered by the data subjects;
d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures implemented pursuant to Articles 25 and 32;
e) any previous infringements committed by the controller or processor;
f) the degree of cooperation with the supervisory authority in order to remedy the infringement and mitigate its possible adverse effects;
g) the categories of personal data affected by the infringement;
h) how the supervisory authority became aware of the infringement, in particular whether and, if so, to what extent the controller or processor notified the infringement;
i) where the measures referred to in Article 58(2) have been previously ordered against the controller or processor that it relates to the same matter, compliance with said measures;
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
15/24
j) adherence to codes of conduct pursuant to Article 40 or to approved certification mechanisms pursuant to Article 42, and
k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement.”
In the present case, considering the seriousness of the possible infringement, and paying particular attention to the consequences that its commission causes for those affected, a fine would be appropriate, in addition to the adoption of measures, if applicable.
The fine imposed must be, in each individual case, effective, proportionate, and dissuasive, in accordance with the provisions of Article 83.1 of the GDPR.
For the purposes of deciding on the imposition of an administrative fine and its amount,
in accordance with the evidence available at this time of the
initiation of the sanctioning procedure, and without prejudice to the outcome of the
investigation, it is considered appropriate to determine the sanction to be imposed in accordance with the following circumstances, contemplated in the aforementioned provisions.
Preliminary considerations are based on the following circumstances:
• The categories of personal data affected by the infringement (Article 83.2, letter g) of the GDPR): Technical information (type of device, operating system, browser information, IP address), usage data (URL of the website displaying the advertisement, referral URL, user interactions such as clicks and impressions), location data (IP address), and electronic identification data (cookies) were obtained from users of all websites where the ***PLATFORM.1 cookie is installed, including (...). All of this refers to the
viewing of “adult” advertisements. In general, the more sensitive the
data, the more weight the supervisory authority can give to this factor. Furthermore, the
amount of data relating to each data subject is relevant, given that
the infringement of the right to privacy and the protection of personal data
increases with the amount of data (Guidelines on calculating fines, paragraphs 57 and 58).
The balance of the circumstances contemplated in Article 83.2 of the GDPR, with respect to
the infringement committed by violating the provisions of Article 6 of the GDPR,
allows for an initial administrative fine of €70,000.
Therefore, in accordance with the evidence available at this time, and in accordance with the initiation of sanctioning proceedings, it is considered that the known facts could constitute an infringement attributable to T.M.I., for violation of the aforementioned article.
VII
Obligation not fulfilled. Article 27 GDPR
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
16/24
Representatives of controllers or processors not established in the Union:
1. Where Article 3(2) applies, the controller or processor shall designate a representative in the Union in writing.
2. The obligation laid down in paragraph 1 of this Article shall not apply:
(a) to processing that is occasional, does not include large-scale processing of special categories of data referred to in Article 9(1), or personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to pose a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing; or
(b) to public authorities or bodies.
3. The representative shall be established in one of the Member States where the data subjects whose personal data are processed in the context of an offer of goods or services, or whose behavior is being monitored, are located.
4. The controller or processor shall instruct the representative to handle, together with or instead of the controller or processor, inquiries, in particular from supervisory authorities and data subjects, on all matters relating to the processing, in order to ensure compliance with this Regulation.
5. The appointment of a representative by the controller or processor shall be without prejudice to any action that may be taken against the controller or processor. Regarding the scope of the GDPR, Article 3, paragraph 2, of the GDPR states the following: “This Regulation applies to the processing of personal data of data subjects in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services to such data subjects in the Union, irrespective of whether payment is required…”. It has been proven that T.M.I. offers its adult advertising services on at least three Spanish websites. From the documentation submitted by T.M.I., this company indicates that it has a representative located in Northern Ireland. It also acknowledges that it has published its data in its privacy policy and that it is in the process of changing its representative to one located in an EU Member State, at which point it will update its privacy policy. Therefore, it can be deduced that it does not currently have a representative in the EU. Thus, in accordance with the available evidence, At this point in the agreement
to initiate sanctioning proceedings, it is considered that the known facts
could constitute an infringement, attributable to T.M.I., for violation of the
article transcribed above.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
17/24
VIII
Classification of the infringement of Article 27 of the GDPR and qualification for the purposes of
statute of limitations
Article 83.4 of the GDPR classifies as an administrative infringement the violation of the
following article, which will be sanctioned, in accordance with paragraph 2, with administrative fines
of up to EUR 10,000,000 or, in the case of an undertaking, of
an amount equivalent to up to 2% of the total annual global turnover of the preceding financial year, whichever is higher:
"a) the obligations of the controller and the processor pursuant to Articles 8, 11, 25
to 39, 42 and 43;"
For its part, the LOPDGDD, in its Article 71, Infringements, states that:
"The acts and conduct referred to in paragraphs 4, 5 and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law, constitute infringements."
For the sole purpose of the statute of limitations, Article 73 of the LOPDGDD establishes the following:
"In accordance with the provisions of Article 83.4 of Regulation (EU) 2016/679, infringements that constitute a substantial violation of the articles mentioned therein are considered serious and will be subject to a two-year statute of limitations, and in particular, the following:
(h) Failure to comply with the obligation to appoint a representative of the controller or processor not established in the territory of the European Union,
in accordance with the provisions of Article 27 of Regulation (EU) 2016/679."
IX
Proposed Sanction
In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR must be observed. These provisions state:
"1. Each supervisory authority shall ensure that the imposition of administrative fines under this Article for infringements of this Regulation referred to in paragraphs 4, 9 and 6 is, in each individual case, effective, proportionate and dissuasive.
2. Administrative fines shall be imposed, depending on the circumstances of each individual case, as an additional measure to, or in lieu of, the measures provided for in Article 58(2)(a) to (h) and (j)." When deciding on the imposition of an administrative fine and its amount in each individual case, due consideration shall be given to:
a) the nature, seriousness, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage suffered;
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
18/24
b) the intent or negligence in the infringement;
c) any measures taken by the controller or processor to mitigate the damage suffered by the data subjects;
d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures they have implemented pursuant to Articles 25 and 32;
e) any prior infringements committed by the controller or processor; (f) the degree of cooperation with the supervisory authority in order to remedy the infringement and mitigate its possible adverse effects;
(g) the categories of personal data affected by the infringement;
(h) how the supervisory authority became aware of the infringement, in particular whether and, if so, to what extent the controller or processor notified the infringement;
(i) where the measures referred to in Article 58(2) have been previously ordered against the controller or processor concerned in relation to the same matter, compliance with those measures; (j) adherence to codes of conduct pursuant to Article 40 or to approved certification mechanisms pursuant to Article 42, and (k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement.” In the present case, considering the seriousness of the potential infringement, and paying particular attention to the consequences of its commission for those affected, a fine would be appropriate, in addition to the adoption of measures, if applicable. For the purposes of deciding on the imposition of an administrative fine and its amount, in accordance with the evidence available at this time of the initiation of the sanctioning procedure, and without prejudice to the outcome of the investigation, it is considered appropriate to determine the sanction to be imposed according to the following circumstances, contemplated in the aforementioned provisions. It is considered that the following circumstances exist beforehand: The nature, seriousness, and Duration of the infringement, taking into account the
nature, scope, or purpose of the processing operation in question, as well as
the number of data subjects affected and the level of damage they have suffered (Article 83.2(a) of the GDPR): the representative of a controller
or processor not established in the Union not only serves as a contact,
but is also responsible for carrying out the functions of cooperation with the supervisory authorities,
and the entire regulatory compliance system provided for in the GDPR may be affected.
The assessment of the circumstances contemplated in Article 83.2 of the GDPR with respect to
the infringement committed by violating the provisions of Article 27 of the GDPR allows for an initial administrative fine of €50,000.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
19/24
X
Corrective measures
If confirmed The resolution issued may establish the corrective measures that the infringing entity must adopt to end the non-compliance with personal data protection legislation, in this case Article 27 and Article 6 of the GDPR, in accordance with the provisions of Article 58.2(d) of the GDPR, according to which each supervisory authority may "require the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specific manner and within a specified time frame..." Thus, the responsible entity may be required to adapt its actions to the personal data protection regulations, to the extent expressed in the preceding Legal Grounds. This document establishes the alleged infringement committed and the facts that could give rise to this possible breach of data protection regulations, from which the measures to be adopted are clearly inferred, without prejudice to the type of The specific procedures, mechanisms, or instruments for implementing them correspond to the sanctioned party, since it is the data controller who fully knows their organization and must decide, based on proactive responsibility and a risk-based approach, how to comply with the GDPR and the LOPDGDD.
However, in this case, regardless of the above, in accordance with the evidence currently available regarding the initiation of the sanctioning procedure, the resolution adopted may require T.M.I. to adopt the following measures within a maximum period of 3 months from the date of enforcement of the final resolution of this procedure:
- Demonstrate the adoption of the necessary measures to guarantee compliance with the provisions of Article 6 of the GDPR.
- Demonstrate the adoption of the necessary measures to guarantee compliance with the provisions of Article 22.2 of the LSSI by the service providers. that use the ***PLATFORM.1 cookie.
- Have a Representative before the EU
The imposition of these measures is compatible with the sanction consisting of an administrative fine, as provided for in Article 83.2 of the GDPR.It is hereby advised that failure to comply with any order to adopt measures imposed by this agency in the resolution of this sanctioning procedure may be considered an administrative infringement in accordance with the provisions of the GDPR, specifically classified as an infringement in Articles 83.5 and 83.6, and such conduct may lead to the initiation of further administrative sanctioning proceedings.
Furthermore, it is noted that neither acknowledgment of the infringement committed nor, where applicable, voluntary payment of the proposed amounts, exempts from the obligation to adopt the appropriate measures to cease the conduct or correct the effects of the infringement committed, and from the obligation to demonstrate compliance with this obligation to the Spanish Data Protection Agency (AEPD).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
20/24 Therefore, in light of the foregoing, the President of the Spanish Data Protection Agency hereby resolves:
FIRST: To initiate sanctioning proceedings against TIGER MEDIA INC., with Tax Identification Number (NIF) 830104493, for the alleged infringement of:
- Article 6 GDPR, as defined in Article 83.5 GDPR
- Article 27 GDPR, as defined in Article 83.4 GDPR
SECOND: To appoint R.R.R. as investigating officer and S.S.S. as secretary,
indicating that they may be challenged, if necessary, in accordance with the provisions of Articles 23 and 24 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector (LRJSP).
THIRD: To incorporate into the file, for evidentiary purposes, the documents obtained and generated by the General Sub-Directorate of Data Inspection in the actions prior to the initiation of this sanctioning procedure.
FOURTH: That, for the purposes set forth in Article 64.2 b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, the applicable sanction would be an administrative fine of €70,000.00 for the infringement of Article 6 of the GDPR and €50,000.00 for the infringement of Article 27 of the same Regulation, without prejudice to the outcome of the investigation. FIFTH: NOTIFY TIGER MEDIA INC., with Tax Identification Number (NIF) 830104493, of this agreement,
granting it a hearing period of ten business days to submit any
arguments and present any evidence it deems appropriate. In its written
arguments, it must provide its Tax Identification Number (NIF) and the procedure number shown in the
heading of this document.
In accordance with the provisions of Article 85 of the LPACAP (Law on Administrative Procedure and Common Administrative Procedure), it may acknowledge its
responsibility within the period granted for submitting arguments to
this initiation agreement; this will entail a 20% reduction of the
sanction to be imposed in this procedure. With the application of this
reduction, the sanction would be set at 96,000 EUROS, and the
procedure will be resolved with the imposition of this sanction.
Likewise, you may, at any time prior to the resolution of these proceedings, make voluntary payment of the proposed penalty, which will result in a 20% reduction. With this reduction, the penalty will be set at €96,000, and payment will terminate the proceedings, without prejudice to the imposition of any corresponding measures. The reduction for voluntary payment of the penalty is cumulative with the reduction applicable for acknowledging responsibility, provided that this acknowledgment of responsibility is made within the period granted for submitting allegations to the initiation of the proceedings. The voluntary payment of the amount referred to in the preceding paragraph may be made at any time prior to the resolution. In this case, if both reductions were to be applied, the amount of the penalty would be set at €72,000.
In any case, the effectiveness of either of the aforementioned reductions will be conditional upon the withdrawal or waiver of any administrative action or appeal against the penalty. Should you choose to make a voluntary payment of either of the amounts indicated above (€96,000 or €72,000), you must do so by depositing the funds into account number IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX) held in the name of the Spanish Data Protection Agency at CAIXABANK, S.A., indicating in the payment details the reference number of the procedure shown in the heading of this document and the reason for the reduction in the amount you are applying for. You must also send proof of payment to the General Sub-Directorate of Inspection to continue with the procedure in accordance with the amount deposited. Finally, please note that, in accordance with Article 112.1 of the LPACAP, no appeal may be filed against this decision. No administrative appeal is available.
1479-010725
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency
>>
SECOND: On November 14, 2025, T.M.I. paid the fine of €72,000.00, taking advantage of the two reductions provided for in the aforementioned initial agreement. This implies acknowledgment of responsibility for the facts referred to in the initial agreement and their legal classification.
THIRD: The aforementioned initial agreement stated that, should the infringement be confirmed, the responsible party could be ordered to adopt appropriate measures to bring its actions into compliance with the regulations mentioned in this act, in accordance with Article 58.2 d) of the GDPR, which states that each supervisory authority may "require the controller or processor to ensure that the operations of treatment comply with the provisions of this Regulation, where applicable, in a specific manner and within a specified timeframe…”.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
22/24 Having acknowledged responsibility for the infringement, the imposition of the measures included in the initial agreement is warranted.
LEGAL BASIS
I
Jurisdiction
In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR) and as established in Articles 47, 48.1, 64.2 and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter LOPDGDD), the Presidency of the Spanish Data Protection Agency is competent to resolve this procedure.
Likewise, Article 63.2 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) stipulates that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the implementing regulations issued thereunder, and, insofar as they do not contradict them, subsidiarily, by the general rules on administrative procedures."
II
Termination of the Procedure
Article 85 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), under the heading
“Termination in Sanctioning Procedures,” provides the following:
“1. Once a sanctioning procedure has been initiated, if the offender acknowledges their responsibility, the procedure may be resolved by imposing the appropriate sanction.
2. When the sanction is solely pecuniary, or when a pecuniary sanction and a non-pecuniary sanction may be imposed but the impropriety of the latter has been justified, voluntary payment by the alleged offender, at any time prior to the resolution, will imply the termination of the procedure, except with regard to restoring the altered situation or determining compensation for damages caused by the commission of the infraction.
3. In both cases, when the If the sanction is solely monetary, the competent body for resolving the procedure will apply reductions of at least 20% to the proposed sanction amount, and these reductions are cumulative.
These reductions must be specified in the notification initiating the procedure, and their effectiveness is conditional upon the withdrawal or waiver of any administrative action or appeal against the sanction.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
23/24
The percentage reduction provided for in this section may be increased by regulation.
III
Voluntary Payment and Acknowledgment of Responsibility
In accordance with the provisions of Article 85 of the LPACAP, the notified initiation agreement informed the parties of the possibility of acknowledging responsibility and making voluntary payment of the proposed sanction, which would entail two cumulative reductions of 20% each. With the application of these two reductions, the penalty would be set at €72,000.00, and its payment would imply the termination of the proceedings, without prejudice to the imposition of the corresponding measures. Following notification of the aforementioned initiation agreement, T.M.I. has acknowledged responsibility and voluntarily paid the penalty, taking advantage of the two reductions provided for. In accordance with section 3 of Article 85 of the LPACAP (Law on the Common Administrative Procedure of Public Administrations), the effectiveness of these reductions is conditional upon the withdrawal or waiver of any administrative action or appeal against the penalty. It should be noted that, in accordance with the provisions of the LPACAP, as well as the jurisprudence of the Supreme Court on this matter, the exercise of voluntary payment by the alleged offender does not exempt the administration from the obligation to resolve and notify all proceedings, regardless of how they were initiated. Similarly, Article 88 of the aforementioned regulation establishes that the resolution
that concludes the procedure will decide all the issues raised by the
interested parties and those others arising from it.Therefore, in accordance with applicable legislation and having assessed the criteria for
graduating the sanctions, the Presidency of the Spanish Data Protection Agency RESOLVES:
FIRST: TO DECLARE the commission of the infringements and CONFIRM the sanctions
determined in the operative part of the initial agreement transcribed in this resolution.
The sum of the aforementioned amounts totals €120,000.00.
Having proceeded with TIGER MEDIA INC.'s prompt payment and acknowledgment of
responsibility, pursuant to Article 85 of the LPACAP (Law on Administrative Procedure), a reduction of
40% of the aforementioned total is applied, resulting in a final amount of €72,000.00.
The effectiveness of these reductions is conditional, in any case, upon the
withdrawal or waiver of any action or appeal through administrative channels.
SECOND: DECLARE the termination of procedure EXP202405210, in accordance with the provisions of Article 85 of the LPACAP.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
24/24
THIRD: ORDER TIGER MEDIA INC. to notify the Agency, within 3 months of this resolution becoming final and enforceable, of the adoption of the measures described in the legal grounds of the initiation agreement transcribed in this resolution.
FOURTH: NOTIFY TIGER MEDIA INC. of this resolution.
FIFTH: In accordance with the provisions of Article 85 of the LPACAP, which conditions the reduction for voluntary payment and acknowledgment of liability on the withdrawal or waiver of any action or appeal through administrative channels, this resolution will become final and fully enforceable upon notification.
In accordance with Article 50 of the LOPDGDD, this
Resolution will be made public. Publication will take place once the resolution has been
notified to the interested parties.
Against this resolution, which concludes the administrative process as stipulated by
Article Pursuant to Article 114.1.c) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, interested parties may file an administrative appeal with the Administrative Chamber of the National Court, in accordance with the provisions of Article 25 and paragraph 5 of the fourth additional provision of Law 29/1998, of July 13, regulating the Administrative Jurisdiction, within two months from the day following notification of this act, as provided for in Article 46.1 of the aforementioned Law. However, in accordance with the provisions of Article 90.3.a) of the LPACAP, the final administrative decision may be provisionally suspended if the interested party expresses their intention to file an administrative appeal. If this is the case, the interested party must formally notify the Spanish Data Protection Agency in writing, submitting it through the Agency's Electronic Registry [https://sedeaepd.gob.es/sede-electronica-web/], or through any of the other registries provided for in Article 16.4 of Law 39/2015, of October 1. They must also provide the Agency with documentation proving the effective filing of the administrative appeal. If the Agency does not receive notification of the filing of the administrative appeal within two months from the day following notification of this resolution, the precautionary suspension will be terminated. 1259-101025
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es




