AEPD (Spain) - EXP202301678
| AEPD - EXP202301678 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 5(1)(b) GDPR Article 5(1)(a) GDPR Article 5(1)(f) GDPR Article 6(1)(e) GDPR Article 6(1)(c) GDPR Article 6(1)(f) GDPR Article 6(4) GDPR Article 14 GDPR Article 14(5)(c) GDPR Art. 19.2 LOPDGDD |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | 27.12.2022 |
| Decided: | 15.04.2025 |
| Published: | 28.08.2025 |
| Fine: | 500,000 EUR |
| Parties: | CÁMARA DE COMERCIO, INDUSTRIA, SERVICIOS Y NAVEGACIÓN DE ESPAÑA (Chamber of Commerce) |
| National Case Number/Name: | EXP202301678 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Spanish |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | ap |
The DPA fined the Spanish Chamber of Commerce €500,000 for transferring self-employed persons’ tax identity numbers to private companies without a legal basis.
English Summary
Facts
Institut per a la Cultura Democratica a L’era Digital (also known as Xnet) is a digital rights non-profit organisation. Xnet filed a complaint with the DPA on 27 December 2022, regarding the processing of personal data of self-employed people by both public authorities and private companies. One of the public authorities investigated by the DPA was the Chamber of Commerce (the controller), who received data from the Tax Authority based on a contract. The controller maintained a publicly available census of information related to Spanish enterprises (including natural persons). The controller also provided private companies (such as Camerdata) with a database containing additional information, such as self-employed persons’ Tax Identity Number (NIF in Spanish).
According to Xnet, once someone registers as self-employed with the Tax Agency their personal data is treated as information of professional interest. This means that if it matches private information (e.g. if someone works from home), their data such as personal address is easily accessible on the Internet. This means that if someone works from home, their personal address is easily accessible on the Internet. Financial information and legal incidents (including their credit scores and likelihood of nonpayment) are also available in some cases. This personal data can be processed and sold on the Internet by private companies.
The controller argued that its processing of personal data was lawful; it maintained the publicly available census under legal obligation (Article 6(1)(c) GDPR) and public interest (Article 6(1)(e) GDPR). It also relied on legitimate interest (Article 6(1)(f) GDPR) to transfer the data to third parties. Finally, the controller argued that it did not provide private companies with data subjects’ NIF, but instead provided this data in an encrypted form that was then decrypted by the recipients. These recipients were the controllers of the personal data, as they did not receive instructions from the Chamber of Commerce.
Holding
The DPA stated that the Chamber of Commerce was a controller when transferring the data to private companies such as CAMERDATA; the Chamber of Commerce does not have the legal obligation under Spanish law to disclose this data to private entities, and therefore it has determined the purposes and means to do so. The DPA dismissed the argument of the controller that it did not provide CAMERDATA with data subjects’ NIF; hashing this data pseudonymises it, meaning it still falls under the scope of the GDPR. Furthermore, the controller transferred the data to CAMERDATA, regardless of whether this was in plain text or hash form.
The DPA found a violation of Article 5(1)(a) and 6(1) GDPR, as the controller transferred data to CAMERDATA without a legal basis. The DPA clarified that the Chamber of Commerce has the legal obligation under national law[1] to maintain a public census of enterprises.[2] Disclosing this information was not in the scope of the controller’s obligation to maintain a public census, meaning the controller could not rely on legal obligation (Article 6(1)(c) GDPR) or public interest (Article 6(1)(e) GDPR) as a legal basis. Furthermore, the controller’s agreement with the Tax Authority prohibited the transfer of data received from the Tax Authority to third parties.
The DPA held that the controller could not rely on legitimate interest (Article 6(1)(f) GDPR). Under national law, Article 19(2) LOPDGDD establishes a presumption of a legitimate interest legal basis, however, this is limited to the contact information of individual entrepreneurs. The DPA emphasised that personal data such as names and NIF still have a personal nature even when used for business purposes. The controller had not demonstrated that it had a legal basis for processing data beyond contact information, in accordance with the principle of accountability (Article 5(2) GDPR). Finally, the DPA stated that the data subjects would not reasonably expect their NIF to be processed in this way, especially considering the fact that they were not informed of the processing.
The DPA also found a violation of Article 5(1)(b) and (f) GDPR. The controller violated the principle of purpose limitation (Article 5(1)(b) GDPR), as the transfer of data was incompatible with the initial purpose of maintaining a public census of Spanish enterprises. The DPA found the purpose of providing data to CAMERDATA for commercial and marketing purposes incompatible with the initial purpose of creating and maintaining a public census, in accordance with Article 6(4) GDPR. In addition, the Tax Agency prohibits the controller from transferring data obtained from it to third parties. Therefore, the controller also violated the principle of integrity and confidentiality by disclosing the data to unauthorised third parties. The DPA reiterated that the controller transferred the data to CAMERDATA, even if it was in hash form.
Finally, the DPA found a violation of Article 14 GDPR. The controller did not comply with its information obligations. Article 14(5)(c) GDPR, sets an exception to information obligations if expressly laid down in Union or Member State law. Under national law, the controller does not have the obligation to inform data subjects of the processing to create the public census. However, this exception does not apply to the transfer of data to CAMERDATA, as it is not one of the controller’s obligations under Spanish law. The DPA also dismissed the argument that informing all self-employed persons in Spain (more than 1.5 million people) is a disproportionate effort. In this case, the controller did not assess how the processing would affect data subjects.
The DPA fined the controller €500,000 in total (€100,000 for the violation of each Article mentioned above). The DPA considered this a severe violation of the GDPR, and took into account the fact that the controller was aware of the unlawful processing and the sensitive nature of data subjects’ NIF. In addition, the DPA ordered the controller to cease transferring data to CAMERDATA.
Comment
The DPA investigated several organisations following the complaint from Xnet. You can read the DPA's press release here. You can also read the GDPRhub summary of the fine against INFORMA D&B, against DEYDE DATACENTRIC, and against CAMERDATA.
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.
1/204
File No.: EXP202301678
SANCTIONING PROCEDURE RESOLUTION
From the procedure initiated by the Spanish Data Protection Agency and based on the following
BACKGROUND
FIRST: The Spanish Data Protection Agency has learned through a complaint from the association Institut per a la Cultura Democratica a L´era Digital (Institute for Democratic Culture in the Digital Age), received on December 27, 2022, of certain facts that could violate personal data protection legislation.
In order to clarify the facts brought to the attention of this Agency, on April 13, 2023, through an internal note, the Director of the Spanish Data Protection Agency urged the Subdirectorate General of Inspection to initiate preliminary investigations—provided for in Article 67 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD)—with various entities, including the Spanish Chamber of Commerce, Industry, Services, and Navigation, with Tax Identification Number (NIF) Q2802216H (hereinafter, the Spanish Chamber or CDE), the entity against which this sanctioning procedure is being conducted.
The internal note ordering the General Subdirectorate of Inspection to open preliminary investigations reflects, among others, the following issues:
“[…] Specifically, it is reported that, from the moment someone registers
as self-employed by registering in the census of economic activities of the
State Tax Administration Agency, the name, ID number, telephone number,
email address, and address that are reported are treated as information of
professional interest. As a result of this processing, if the data
coincides with private data, for example, in the case of those who work
from their personal address, this information on self-employed workers
is exposed on the internet, easily accessible from search engines. In addition
to the above, in some cases, the data that appears when accessing one of the
links, in addition to the name and surname, ID number, address, email address,
telephone number, and business activity, refers to financial information or judicial incidents
and probabilities of default, having been obtained from the Commercial Registry, Official Gazette of the State, chambers of commerce, etc.
[…]”
The complaint received by the Agency explains that individuals interested in
registering as self-employed entrepreneurs must provide their name, ID number,
a telephone number, email address, and address. This data is subsequently processed by the
State Tax Administration Agency (AEAT), the Spanish Chamber of Commerce, the
company CAMERDATA, and various private consulting firms. It also explains that the
processing chains currently in place between the AEAT, the CDE,
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 2/204
CAMERDATA, and private consulting firms lead to the data of self-employed entrepreneurs
that coincide with their personal data being exposed and even being
sold online, potentially leading to various violations of personal data protection regulations.
The complaint filed with the Agency includes an attachment entitled
"The Sale of Data of Self-Employed Individuals," which, according to its first page, corresponds to "Section 5 of the report: Privacy,
Data Protection vs. Institutionalized Abuse: https://xnet-x.net/es/datos-por-liebre-xnet-abusos-reforma-ley-proteccion-datos/." The attached document includes,
among others, the following screenshots:
(i) Screenshot of the results obtained—the document states—after a
Google search for the first and last name of a self-employed entrepreneur.
It shows the results corresponding to the websites www.expansion.com and
https://autonomos.axesor.es. The individual's data is illegible because it is
shaded and supposedly corresponds to the first and last name of the self-employed entrepreneur. The document indicates that clicking on any of these links provides access,
in addition to the name and surname, to data such as ID, address, email, telephone number, business activity, and even financial information,
legal incidents, and probability of default.
(ii) Screenshot of information supposedly associated with the same person
as mentioned above, whose personal data is illegible because it is shaded, obtained by
viewing a rating page. The document states:
“[…] is a self-employed person whose business is registered in ***LOCALITY.1,
***PROVINCE.1. The CNAE activity of the business is wholesale trade of food products, beverages, and tobacco, and its SIC activity is groceries in general.
Our reports will provide you with the most complete information on the business activity, such as the NIF (Tax Identification Number), telephone number, address in ***LOCALITY.1
(***PROVINCE.1), credit scoring and rating, probability of default and
maximum solvency capacity, legal incidents […].
Furthermore, our researched reports on the commercial activity of […] are
especially indicated for high-risk transactions and/or for delinquent clients […] The information contained in this file is only an excerpt of all the
information on self-employed persons and professionals available on axesor […] You can also
access the reports of executives or directors whose name matches
[…] (if they exist according to the publications in the Official Gazette of the Commercial Registry).
(iii) Screenshot of the result of a search conducted—the document states—
through the CDE website, in the Public Business Census. It states that "If you wish to obtain more information, consult the Camerdata Online Business File."
SECOND: The Subdirectorate General of Inspection proceeds to carry out preliminary investigative actions to clarify the facts in question, pursuant to the functions assigned to the supervisory authorities in Article 57.1 and the powers granted in Article 58.1, both of Regulation (EU) 2016/679
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 3/204
(General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VII, Chapter I, Section Two, of the LOPDGDD. It is known, among others, that the following details are included in the Report
signed by the acting inspector, from which these excerpts are transcribed:
<< […]
RESULTS OF THE INVESTIGATION ACTIONS
On 18/10/2023, it was verified that:
1. On the website www.expansion.com, a self-employed person was selected from the self-employed directory, verifying that the published data included only the first and last name, postal code, province, municipality, year the activity began, activity, SIC, and CNAE (National Tax Code). It is noted that the data was provided by AXESOR CONOCER
PARA DECIDIR S.A. It is also noted that for further information about the self-employed person, a link to the website autonomos.axesor.es is provided.
Clicking on this link redirects you to the website autonomos.axesor.es, which displays
exclusively the details of your first and last name, postal code, municipality, province,
CNAE (National Tax Code), SIC (National Tax Code), and information about your activity.
The autonomos.axesor.es website also includes the following text: "Our reports will provide you with the most complete information about the business activity of […], such as the NIF (Tax Identification Number), telephone number, address in Madrid (Madrid), credit rating,
probability of default, and maximum solvency capacity. Legal incidents...".
2. By selecting any self-employed person on the website www.axesor.es, you can view
exclusively their first and last name, postal code, municipality, province, CNAE (National Tax Code), SIC (National Tax Code), and information about their activity.
Searching the first and last name of that self-employed person using the search engine www.google.com and restricting the search results to the domain einforma.es yields no search results.
Searching the first and last name of that self-employed person using the search engine www.google.com and restricting the search results to the domain axesor.es yields
search results, but they do not match the first and last name searched.
Searching the first and last name of that self-employed person using the search engine www.google.com and restricting the search results to the domain expansion.com yields search results, but they do not match the first and last name searched.
3. That on the einforma.com website, when a search is performed by first and last name,
results are displayed, showing only the first and last name,
province, and activity of the related company.
4. On the censo.camara.es website, by searching the name field
and entering the surname of a self-employed person, results are displayed with data for
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 4/204
name and surname, postal address, postal code, province, municipality, and activity.
A link is also provided to the Camerdata Online business file
(www.camerdata.es) for more information.
5. The AEAT processing activity log, section 5.42 "Census of Economic Activities", states:
As of 17/10/2023, it was verified that:
1. The AEAT processing activity log, section 5.42 "Census of Economic Activities", states:
"Description of the activity
Tax control: management, settlement, and collection of the tax on economic activities.
Purpose
Effective application of the state tax and customs system.
Interested parties
Business owners, professionals, and artists
Data
NIF/DNI, Name and Surname, Address
Commercial information
Processing
Collection
Recording
Storage
Structuring
Modification
Updating
Copying
Analysis
Consultation
Extraction
Dissemination
Interconnection
Restriction
Deletion
Destruction
Other
Recipients
INE
Other Autonomous Community bodies
Provincial Councils
Other administrative bodies Local
Chambers of Commerce, Industry and Navigation
Basque Provincial Councils, Chartered Community of Navarre
[…]”
6. Within the information on data protection published online by the AEAT, section 3.6 “Recipients” states:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 5/204
“In accordance with Article 95 of the General Tax Law, all data,
reports, or background information obtained by the Tax Authority in the
performance of its functions are confidential and may only be
used for the effective application of taxes or resources whose management
it is entrusted with and for the imposition of appropriate sanctions, without
being able to be transferred or communicated to third parties.
However, Article 95 of the General Tax Law also establishes a
series of specific cases where the Tax Agency may
transfer or communicate data to third parties, which may be two Types:
-Transfers or communications of data in cases such as collaboration in the
fulfillment of tax obligations with other public administrations, the
fight against tax crime and fraud in different areas, the
collaboration with investigations by judicial bodies and the Public Prosecutor's Office,
the control of the Tax Agency's own activity.
In these cases, in accordance with Article 6 of EU Regulation 2016/679, it will not be
necessary to obtain the citizen's express consent for these transfers or communications to be
made. On the other hand, in accordance
with Article 14 of EU Regulation 2016/670, if a transfer or communication occurs, it will not be necessary to inform the citizen.
-Other transfers and communications that are not expressly contemplated in
Article 95, and that are necessary within the scope of collaboration between
public administrations to facilitate the provision of public services to the
citizen.
In these cases, it will always be necessary for the Administration requesting the
data to have the express consent of the Citizen.
[…]"
7. That the URL https://sede.agenciatributaria.gob.es/Sede/condiciones-uso-sede-electronica/datos-personales.html contains a first section with a hyperlink with the text "Data Protection Information" that redirects to the URL of the following point. Further down in the "Help" section, there is another hyperlink with the text
"Data Protection Information for the interested party."
8. That the URL https://sede.agenciatributaria.gob.es/Sede/condiciones-uso-sede-electronica/datos-personales/informacion-sobre-proteccion-datos.html contains:
"Data Protection Information." The State Tax Administration Agency (hereinafter "Tax Agency") is responsible for all personal data processing carried out in the course of its activities, unless otherwise indicated in a specific processing.
These processing operations will be carried out on the personal data of individuals
who use the services it offers in the course of its activities, who may be
taxpayers, their representatives, public employees, or
any other person who uses its services. Hereinafter, we will refer to them
as data subjects.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 6/204
In relation to the use of the Tax Agency website by interested parties, it is hereby reported that […]”
As a result of the request for information made by the inspection, dated 02/11/2023, the Data Protection Officer of the AEAT, as stated,
sends the following information and statements to this agency:
1. That in relation to the data protection information regarding the data provided to the census of entrepreneurs, professionals, and withholding agents (forms 036 and 037)
and the transfer of this data to CÁMARA, it is hereby stated that it is provided:
a. Through the record of processing activities "processing 5.1 Census"
at the URL https://sede.agenciatributaria.gob.es/Sede/todas-
gestiones/procedimientos-notributarios/tratamiento-datos-
personales/tratamiento-datos-personales/informacioninteresado-sobre-
protección-datos/5-registro-actividades-tratamiento/5_1-censo.html.
b. When forms 036 and 037 are completed, the following text appears on the "sign and send" screen:
"In accordance with Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, and Article 11 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights, you are hereby informed that the personal data you are about to provide will be processed by the State Tax Administration Agency for the purpose of effectively applying the state tax and customs system.
You can find more information on possible processing, transfers, and the
procedure for exercising the rights established in articles 15 to 22
of the regulation at the following link (https://sede.aqenciatributaria.qob.es/Sede/condiciones-uso-sede-electronica/datos-personales.html)
c. Furthermore, the record of the information provided is available on the electronic site at the following URL:
https://sede.agenciatributaria.gob.es/Sede/procedimientoini/ZA02.shtml
https://sede.agenciatributaria.gob.es/static_files/Sede/Procedimiento_ayuda/ZA
02/drIAE_CamCom08.pdf
2. Regarding the data transferred, it is stated that it is found in Annex I of the
Agreement signed between the AEAT (Tax Agency) and the CHAMBER (Accessible Chamber). at
https://www.boe.es/buscar/doc.php?id=BOE-A-2019-18316.
It is verified, in accordance with said Agreement and Law 4/2014, that the data transferred
in accordance with Article 8 of Law 4/2014 are "Company census data" and "Economic Activities Tax Data."
3. That the transfer of company census data according to Article 8 of Law 4/2014 does not
require the consent of the interested party since it is carried out based on regulations
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 7/204
related to chamber matters. It is carried out based on the legal obligation of Article 8 of Law 4/2014.
4. That in Article 22.3 of the Royal Decree 669/2015, of July 17, which implements Law 4/2014, of April 1, Basic Law of the Official Chambers of Commerce, Industry, Services, and Navigation, in relation to the electoral register, states:
“3. The State Tax Administration Agency, as well as the other territorial administrations competent in tax matters, will collaborate
with the governing bodies of the Chambers to provide them with the
information necessary for the preparation and establishment of the registers,
ensuring that only the employees of
each Chamber determined by the plenary session will have access to said information, with the mandatory duty of confidentiality regarding
said data. To this end, the State Tax Administration Agency
will provide the information derived from the Economic Activities Tax census, along with the necessary company data contained in other censuses it prepares and manages, in
particular the Census of Entrepreneurs, Professionals, and Withholding Taxpayers.
5. That "Regarding the information authorized for transfer related to the Economic Activities Tax (IAE) and that of a census nature, understood as that contained in the Census of Entrepreneurs, Professionals, and Withholding Taxpayers, the content of which is established in art. 5 of Royal Decree 1065/2007, of July 27, which approves the General Regulations for tax management and inspection actions and procedures and for the development of common rules for tax application procedures, is carried out only for the preparation of the public business census.
6. That the IAE information exchange protocol located at
https://sede.agenciatributaria.gob.es/static_files/Sede/Procedimiento_ayuda/ZA02/pInt
ercambioIAE2006.pdf states that the transferred data may only be used for the purposes contemplated by the regulations and not for other uses. >>
(Emphasis added)
--In relation to CAMERDATA, S.A., the Report issued by the Data Inspectorate states the following:
<<As a result of the request for information made by the inspectorate,
on 11/14/2023, CAMERDATA sent this agency the following information and statements:
1. That, with regard to self-employed individuals, they process the following data, among others:
“NIF”:
Meaning:
tax identification number
Source of data:
Public business census published by CÁMARA in accordance with the
provisions of Law 4/2014 (hereinafter Public Business Census).
It is provided to:
Clients who request the business information services offered by CAMERDATA, including, on the one hand, entities in the sector
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 8/204
known as infomediary or information reusing companies
(AXESOR, CERVED, DATACENTRIC, EQUIFAX, IBERINFORM,
MOODY'S) and, on the other hand, end-clients who request it for their exclusive internal use.
"Company name"
Meaning:
The way in which the company identifies itself with respect to its formal obligations,
usually with the agents with which it interacts, such as
Social Security, the Treasury, suppliers, or customers. Known as the
Company name.
Data source:
Public business census.
Provided to:
Clients who request the business information services offered by CAMERDATA, including, on the one hand, entities in the sector known as infomediary or information reusing companies (AXESOR, CERVED, DATACENTRIC, EQUIFAX, IBERINFORM, MOODY'S) and, on the other hand, end-clients who request it for their exclusive internal use.
"generic email"
Meaning:
The company's general contact email.
Data source:
Kompass, through data enrichment from the public business census.
Provided to:
End-clients who request it for their exclusive internal use.
"address"
Meaning:
Company address consisting of street name, street number, and the rest of the address.
Data source:
Public business census.
It is provided to:
Clients who request the business information services offered by CAMERDATA, including, on the one hand, entities in the sector known as infomediary companies or information reusers (AXESOR, CERVED, DATACENTRIC, EQUIFAX, IBERINFORM, MOODY'S) and, on the other hand, end-clients who request it for their exclusive internal use.
"postal code"
Meaning:
Postal code of the company's address.
Data source:
Public business census.
It is provided to:
Clients who request the business information services offered by CAMERDATA, including, on the one hand, entities in the sector known as infomediary companies or information reusers (AXESOR, CERVED, DATACENTRIC, EQUIFAX, IBERINFORM,
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 9/204
MOODY'S) and, on the other hand, end-clients who request it for their exclusive internal use.
To the company DMOVO to carry out the address normalization process.
"municipality"
Meaning:
City of the company's address.
Data source:
Public business census.
It is provided to:
Clients who request the business information services
offered by CAMERDATA, including, on the one hand, entities in the sector
known as infomediary or information reusing companies
(AXESOR, CERVED, DATACENTRIC, EQUIFAX, IBERINFORM,
MOODY'S) and, on the other hand, end-clients who request it for their exclusive internal use.
To the company DMOVO to carry out the address normalization process.
"province"
Meaning:
Province of the company's address.
Data source:
DMOVO. Obtained during the address normalization process
each time a new business census is uploaded.
It is provided to:
Clients who request the business information services offered by CAMERDATA, including, on the one hand, entities in the sector known as infomediary companies or information reusers
(AXESOR, CERVED, DATACENTRIC, EQUIFAX, IBERINFORM, MOODY'S) and, on the other hand, end-clients who request it for their exclusive internal use.
"Telephone"
Meaning:
General contact telephone number for the company.
Data source:
INFORMA and DATACENTRIC. Obtained during the data enrichment process of the business census.
It is provided to:
Clients who request the business information services offered by CAMERDATA, including, on the one hand, entities in the sector known as infomediary companies or information reusers (AXESOR, CERVED, DATACENTRIC, EQUIFAX, IBERINFORM, MOODY'S) and, on the other hand, end-clients who request it for their exclusive internal use.
"Company type"
Meaning:
Legal form of the company.
Data source:
Public business census.
It is transferred to:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 10/204
To clients requesting the business information services offered by CAMERDATA, including, on the one hand, entities in the sector known as infomediary companies or information reusers
(AXESOR, CERVED, DATACENTRIC, EQUIFAX, IBERINFORM,
MOODY'S) and, on the other hand, end-clients requesting it for their exclusive internal use.
"Company type"
Meaning:
Indicator of the company name type.
Data source:
DMOVO. Obtained during the name standardization process each
time a new business census is uploaded.
It is provided to:
Clients requesting the business information services offered by CAMERDATA, including, on the one hand, entities in the sector known as infomediary companies or information reusers
(AXESOR, CERVED, DATACENTRIC, EQUIFAX, IBERINFORM, MOODY'S) and, on the other hand, end-user clients requesting it for their exclusive internal use.
To the company DMOVO to carry out the address normalization process.
It provides an extract from its database relating to 500 records, where the "Company Name" column contains first and last names, the "Company Type" column contains "11 SELF-EMPLOYED", and the "Address" column contains what appears to be street names and street numbers in all records, and floor and door numbers in some records. The "Company Gender" column also includes a "V" or "M" depending on whether the name in the "Company Name" column is considered male or female.
2. They process data on a total of 1,665,049 self-employed workers, although not all registries contain all the data.
3. Regarding the infomediary sector, they state:
a. They collect, analyze, transform, and process information from the public/private sector to create value-added products for third-party companies or the general public, serving as a tool for effective decision-making.
b. That the entities that use its services and products are all
IBEX 35 entities, all financial institutions, public administrations, including state security forces and bodies, SMEs and
individual entrepreneurs for their commercial and business activities,
any entity required to access information in compliance with
various laws that require it, any citizen, or non-profit
entities.
c. “Companies in the infomediary sector have been operating in the market for more than two decades, and the reuse and distribution of information that can be freely obtained from the various existing public sources in their broadest sense and context are vital to their performance.
In a world where both access to and transparency of information are key to the security of any commercial transaction, companies in this sector are the benchmark that provides the necessary security to global commercial traffic and acts as an essential element in driving the overall economy by applying the best information processing techniques to ensure its quality, security, veracity, and reliability. The work of infomediary companies should therefore be considered of general public interest.
Additionally, it is important to highlight the work being done for SMEs,
as an essential part of the Spanish business fabric. Thus, on the one hand, it allows
individual entrepreneurs with limited resources to use high-value-added information systems
without having to assume high individual costs
for direct consultation with the source of origin regarding their customers
and suppliers. On the other hand, it also makes their own business information
accessible to their suppliers and financial institutions in order to
promote their business activity and operations.
The infomediary sector is increasingly essential when it comes to streamlining and
improving business management, and the direct impact of the opportunities
generated is greater at both the economic and political and/or social levels.
Furthermore, this sector interacts with other sectors, generating value in
many of its activities. Therefore, when assessing this sector, it is necessary to take into account that it grows both vertically, like other sectors,
and horizontally, making this undeniable transversality complex to assess.
The performance of the infomediary sector has a direct impact not only on the
information community, but is also highly significant in business activity and employment in the Spanish economy. According to data taken
from the Infomediary Sector Report presented on April 14, 2023:
- As of December 31, 2019, there were 700 active infomediary companies
identified in Spain.
- The aggregate sales for the 2019 financial year of the 591 infomediary companies
for which financial data are available amounted to €2,543,042,052.
- The aggregate number of employees in fiscal year 2019 for the 588 companies
for which employee data is available amounted to 21,998.
- The combined subscribed capital as of December 31, 2020, of the 700 companies
identified as infomediaries amounted to €311,911,961.
d. That the main sources of data used by companies in the
sector to create the services and products they provide to society
are:
• Official Gazettes, State, Autonomous Community, and
Provincial.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 12/204
• Official Gazette of the Commercial Registry and Intellectual Property.
• Public business census of the Chambers of Commerce, regulated by
Law 4/2014, of April 1, Basic Law of the Official Chambers of Commerce,
Industry, Services, and Navigation.
• Open, unprotected information from the Real Estate Cadastre according to the
Revised Text of the Real Estate Cadastre Law (TRLCI), approved by
Royal Legislative Decree 1/2004, of March 5.
• Professional guides and directories.
•Telephone service subscriber guides.
•Any source referenced by the public administrations themselves
in the OpenData catalog under the Open Data Initiative of the Government
of Spain.
4. Regarding the information provided to data subjects according to Article 14 of the GDPR, the following is stated:
a. It is considered a disproportionate effort according to Article 14.5.b and
Recital 62 of the GDPR and according to Report WP260.rev01 17/ES (last revised
of April 11, 2018) to send a communication to each data subject to
notify them of the processing as a self-employed person or individual entrepreneur.
i. That there are 1,665,049 self-employed persons in the CAMERDATA database who should be notified, which is an unaffordable cost.
ii. That according to the budget of MEYDIS S.L. and Sociedad Estatal de Correos y Comunicaciones S.A., the handling,
distribution, and materials of the Communications amounts to €9,409,000
and €4,266,900, respectively.
Provides a copy of the budgets from MEYDIS, S.L. dated 01/07/2021
which state the amount of "1,600,000." No total price is stated.
Provides a copy of the budgets from CORREOS where the aforementioned budget is not
stated, but the text "CAMERDATA BUDGET, 2021 COMMUNICATION CAMPAIGN" and "TOTAL BUDGET FOR 1,650,000 SHIPMENTS" are stated.
iii. That CAMERDATA has annual revenues in 2019, 2020,
2021, and 2022 of €941,238.83, €836,093.46, and €885,999.51. €895,950.29
respectively.
Provides a copy of the audited annual accounts as of December 31, 2019,
December 31, 2020, fiscal year 2021, and December 31, 2022, with the aforementioned figures in the
section "1. Net turnover."
b. That due to this disproportionate effort, they have initiated a process of
publishing the following text on the websites of the chambers of commerce, which
is currently published in the Chambers of Commerce of Madrid, Valencia,
Barcelona, Sabadell, Girona, Alicante, and Castellón.
"Information for self-employed workers regarding the protection of personal
data.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 13/204
This notice informs all self-employed persons of the processing of their personal data by Camerdata and the companies associated with ASEDIE that are subject to its code of conduct for the sector.
The data protection intermediary listed herein is: Axesor,
Datacentric, Iberinform, Informa, and also Equifax.
The data processed by CAMERDATA and related companies has been legitimately collected by CAMERDATA and obtained from an official census prepared by a public body. The data is collected by the self-employed person in the exercise of an activity listed in Royal Decree 2007 (RD 475/2007).
The purpose of processing this data is to send commercial and marketing communications, offering various goods or services that may be of interest to you, as well as commercial information about the business activities carried out by the Self-Employed Person.
If you wish to exercise your rights of access, rectification, deletion, restriction of processing, or object to the processing of your contact data, you can send your request to the addresses indicated below. We remind you that you can exercise your right to object to receiving commercial communications centrally, using the Robinson List services at:
https://www.listarobinson.es/:
ASEDIE member companies that are subject to its Code of Conduct: CAMERDATA, S.A. Avda. Diagonal, 452, 3rd floor, 08006 Barcelona, or by sending an email to: informacion@camerdata.es.
In all cases, please attach a copy of a document that proves your identity (ID, passport, or similar).
You can also contact CAMERDATA's Data Protection Officer using the same contact information provided to exercise your rights.
You can also find additional information about CAMERDATA's processing of your data at the following link:
https://www.camerdata.es/politica-privacidad
AXESOR CONOCER PARA DECIDIR S.A.
[…]
You can also contact AXESOR's Data Protection Officer using the same contact information provided to exercise your rights.
You can also find additional information about AXESOR's processing of your data at the following link:
https://www.axesor.es/informacion-tratamientos-rgpd
DATACENTRIC S.A.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 14/204
[…]
You can also contact the Data Protection Officer of
DATACENTRIC using the same contact information as those provided to exercise your rights.
You can also consult additional information about the processing of
your data by DATACENTRIC at the following link:
https://www.datacentric.es/politica-de-privacidad/
IBERINFORM S.A.
[…]
You can also contact the Data Protection Officer of
IBERINFORM using the same contact information as those provided to exercise your rights.You can also consult additional information about the processing of your data by IBERINFORM at the following link: https://www.iberinform.es/aviso-legal#section6
INFORMA S.A.
[…]
You can also contact INFORMA's Data Protection Officer using the same contact information provided to exercise your rights.
You can also consult additional information about INFORMA's processing of your data at the following link: https://www.informa.es/textos-legales
Company not associated with ASEDIE
EQUIFAX S.A.
[…]
You can also contact EQUIFAX's Data Protection Officer using the same contact information provided to exercise your rights.
You can also consult additional information about EQUIFAX's processing of your data at the following link:
https://www2.equifax.es/ederechos/asnef_20024.html.”
c. Incorporate the above text into bulletins and newsletters that the Chambers publish periodically, thereby achieving greater dissemination of the information.
d. That it is intended, beginning in 2024 and subsequently annually, to disseminate the information text in several
major circulation newspapers in Spain.
e. That it considers that these measures meet the criteria for validating
the exception to the obligation to report individually.
5. Regarding ASEDIE's code of conduct, it states:
"[…]
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 15/204
In the performance of its statutory functions, ASEDIE has developed the Code of Conduct for the Infomediary Sector (hereinafter, the Code of Conduct or Code).
" In drafting the Code, the opinions of the main stakeholders involved in one way or another in the infomediary sector were taken into account, especially the members, both in the legal and business aspects, but also consultants and other individuals with knowledge of the relevant aspects of the sector. The need for legal certainty and strengthening the members' commitment to regulatory compliance regarding data protection, understood as an essential business requirement, have led the ASEDIE statutory bodies to consider it necessary to promote the Code of Conduct. The Code establishes a general framework that must be complied with by all ASEDIE member companies. In any case, any action arising from compliance with the Code of Conduct will be carried out in strict compliance with current regulations, in particular, competition regulations and regulations that apply to the protection of personal data. In developing and improving the Code, ASEDIE has enjoyed significant collaboration and involvement from the AEPD, although there have been discrepancies that have led the Association to challenge the denial of approval of the Code through legal proceedings.
[…]”
On January 22, 2024, the draft content of the ASEDIE Code of Conduct was obtained from the internet and incorporated into the file through a formality.
6. Regarding the processing of the business database in the case of self-employed individuals, it states that:
a. “The specific purpose of the processing is the development of a business information system or service with quality data for the promotion,
directly or indirectly, of the goods or services of a company, organization, or
person that carries out a business or professional activity, whether on its own behalf or on behalf of a third party.”
b. That they are based on legitimate interest, and states:
"Camerdata processes the personal data of natural persons insofar as they relate to their status as sole proprietors or independent professionals, that is, exclusively related to their business activity. In such cases, it is presumed to be covered by legitimate interest pursuant to Article 6.1 f) of the GDPR, unless proven otherwise, provided that the following requirements are met:
(ii) That the processing relates solely to the data necessary for the purposes indicated in point b.- of this response, which allows the data controller's clients, or the data controllers themselves, to maintain relationships with the data subject in the context of the business or professional development of the activity that the data subject operates or carries out, respectively, as a sole proprietor or independent professional.
For these purposes, processing covered by Article 6.1 f) of the GDPR will be considered lawful, subject to the considerations set out below.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 16/204
(ii) The processing is carried out in accordance with the provisions of Article 19 of the LOPDGDD, that is, provided that the following requirements are met:
- That the processing relates solely to the data necessary for professional identification.
- That the purpose of the processing is solely to maintain relations of any kind with the legal entity for which the data subject provides their services, or with the business or professional activity carried out by the individual entrepreneur or independent professional.
The legitimate interest set forth in the preceding sections extends, provided that these requirements are met, to the event that the data is processed to strictly provide information on the economic activity carried out by individual entrepreneurs and independent professionals, and to assist third-party clients of the data controllers in decision-making for the purposes of contacting, initiating, and maintaining business or professional relationships, thereby promoting business or economic development.
The use of data for processing purposes intended to establish a relationship with the data subjects in their personal, non-business, or professional capacity will not be covered by the presumption of legitimate interest established in
cases (i) and (ii).
Apart from these two cases, in accordance with the provisions of Recital
(47) and Article 6.1.f) of the GDPR, when these data are processed outside the scope,
criteria, and/or purposes indicated, the data controller, or the
third party on whose behalf the controller acts, must have carried out a
balancing of its legitimate interest and the interests, rights, and
freedoms of the data subjects, which determines that the intended processing does not
violate those interests, rights, and freedoms of the data subject, and must in all
cases apply the necessary security measures.
Legitimate interest of the controller or third parties.
The existence of a legitimate interest on the part of Camerdata and its clients
(to whom it provides services related to the purpose of the processing)
in processing the indicated personal data is based on
the need to know the identifying data of individual entrepreneurs
and independent professionals, as a necessary piece of data within the
total set of business or professional data offered in the
various information products and services marketed by Camerdata.
Data that is relevant to the commercial or professional relationships of
the data subjects and that may only be processed for those purposes, such that
it cannot be used for direct relationships with individuals.
Camerdata's legitimate interest would be twofold. On the one hand, this derives from its
role as a source of financing, inherent to all business activity, and, on the
other hand, it contributes to the development and promotion of business or
professional relationships, offering a quality information system to stakeholders
within the business community and individuals, providing coverage for the legal security
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 17/204
required by the parties to any commercial or contractual relationship
in their market operations, thereby satisfying a general economic and social interest.
Indeed, it should be noted that Camerdata obtains data from public
sources and its processing of the data is intended to increase data quality and thus offer interested clients an
information system on companies operating throughout the country, thereby fulfilling a general interest for the business sector.
Camerdata's data processing also underlies a legitimate interest of its clients and the data subjects themselves, who need to know this information, either to publicize its services and products, to offer them to third parties, to carry out commercial or professional transactions with third parties, or even to be able to exercise the appropriate legal actions that may apply. Furthermore, access to, knowledge of, and evaluation of such business data is increasingly required by law, for example, by Law 10/2010 on the prevention of money laundering and terrorist financing.
Therefore, we are dealing with a process of business data that generally guarantees the legitimate interest of any third party to know this information. It should be noted, once again, that the sources from which the information is obtained and processed for these purposes are considered public in the broadest sense, either because the publication of the data
responds to the requirement and application of a legal norm that requires that such information be known and accessible to everyone, or because it has been manifestly made public by the data subject.
Fundamental rights and freedoms of the data subjects:
The fundamental rights and freedoms of the data subjects are the general ones
that require the protection of personal data, with none specifically highlighted in this particular situation.
In any case, they will not be violated by the processing described
in this document, because:
1. The information of the data subjects subject to processing will be limited
solely to the type of business or professional data, and for the
purposes and according to the scope set forth in this document.
2. The data has been obtained from public sources.
3. The exercise of the rights of data subjects regulated in
Articles 15 to 22 of the GDPR is guaranteed.
Furthermore, the data subjects themselves have an interest in the processing of their business or professional data, as they can access the Camerdata database to contact third-party businesses or professionals to offer their services and products, and they have an interest in being located
by third parties who access the Camerdata database to initiate business relationships.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 18/204
Furthermore, and in compliance with the data minimization principle (Article 5.1.c of the EU GDPR), the data processed, listed in point 1 of this response, are relevant, adequate, and limited to what is
strictly necessary for the purpose for which they are processed.
Result of the weighting:
1st - The processing of this information is lawful: The processing of the data is
necessary to achieve the intended business and economic-social purposes.
2nd - The sources from which the information is obtained are considered
public sources in the broadest sense, either because the publication of the
data responds to the requirement and application of a legal norm that requires
that said information be known and accessible to the general public. In
this sense, the data may be obtained from the following sources:
a) Public sources: Primarily those cited above.
b) Data that the data subject has manifestly made public. It will be
understood that this type of data may be subject to processing, on the
basis of the lawfulness of legitimate interest, to the extent that Article 9.2. Section e)
of the GDPR allows the processing of special categories of data due to the fact that the data subject has manifestly made them public. Therefore, all the more reason for processing data that do not fall within these categories, as is the case with the data processing carried out by data controllers.
c) Any other public sources, provided that their processing is not impeded by legal regulations or by the rights of the legitimate author or beneficiary of the file from which the data originated, and the data controller has, prior to creating the file, weighed up their legitimate interest or that of the third party to whom the service is provided and the interests or fundamental rights and freedoms of the data subject that require the protection of personal data. In the processing of public sources referred to in this paragraph, data controllers shall comply with the processing principles of Article 5 of the GDPR.
3. - The categories of data processed are minimally invasive of the data subject's
right to privacy, as they are data limited to the performance
of a business or professional activity, and at no time are there
data from their family sphere, much less data from special categories of data (Article 9 GDPR).
Furthermore, the Camerdata business database does not include any
credit or financial solvency information.
4. - Part of the legitimate interest considered for processing this information is the harm that not processing this information would pose to the general interest of commercial traffic, in the terms set forth, given the
legal certainty that this information provides in any market transaction. The
lack of informative references regarding the business activity of these stakeholders in the market would have direct and clearly negative repercussions on economic activity, with the consequent harm to general economic activity.
5th - The principle of the free circulation of data, established and protected by the European regulations on the matter (GDPR).
6th - The intended purposes for the processing of this data by Camerdata do not differ from those of the data sources: the publicity of official registries and the public business census of the Chambers of Commerce (the main sources for obtaining this information).
These purposes are intended to offer users the necessary transparency and legal certainty. This fact, along with the widespread and recognized
existence of business information systems in the market and in society in general, directly influences the existence of a
reasonable expectation, on the part of interested parties, about the possibility that
their business or professional performance data may be
processed. Sometimes, the interested parties themselves directly
make the information public or allow its dissemination because they are interested in
having their contact information and business or professional activities known.
7. In the case of data that is public for any reason, the
Judgment of the Court of Justice of the European Union of November 24, 2011 (Joined Cases C-468/10 and C-469/10) indicates, in its
Recitals (44) and (45), that when data are contained in publicly accessible sources, the data controller and, where applicable, the third party or parties to whom the data are communicated, do not access data relating to the private life of the data subject, given that the information is already public knowledge.
As a result, there is a minor impact on the rights of the data subject, which must be assessed at its fair value in the balance with the legitimate interest pursued by the data controller or by the third party or parties to whom the data are communicated.
7. Regarding the processing involved in the transfer of the company database to third-party entities in the case of self-employed individuals, the Spanish Chamber of Commerce states that it is based on legitimate interest and the purpose indicated in the previous point.
A copy of the contract dated February 15, 2016, signed between CAMERDATA and CHAMBER, is provided, which states that […]:
a. CHAMBER is the transferor and CAMERDATA is the transferee.
b. “[…]
V. Based on the aforementioned data received from the collaborating public authorities (currently the State Agency of the Tax Administration, the Provincial Council of Navarra, and the Chambers of Commerce of the Basque Country), the Spanish Chamber of Commerce prepares the public business census under the name "Basic Business Census," guaranteeing confidentiality in the processing and the exclusive use of the information received.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 20/204
[…]”
c. “That business information is one of the traditional areas where the
Chambers of Commerce, in accordance with their functions and purposes, have been
providing services to companies. With the primary objective of properly
and coordinately managing these services, the now defunct High Council of
Chambers of Commerce (now replaced by the Spanish Chamber of Commerce)
and the Chambers of Commerce established in 1985 the commercial company CAMERDATA,
S.A., a chamber instrumental entity for the development of said activity.
According to Article 4 of the Bylaws of CAMERDATA, S.A., its corporate purpose is the development and operation of a business information system and the applications derived from it.”
d. “[…]CAMERDATA, S.A. has been developing and commercially operating a business information system called the "Spanish Business File," which is a separate database from the "Basic Business Census" prepared by the Spanish Chamber of Commerce. However, in order to develop it, it is interested in obtaining a copy of the business information from the "Basic Business Census."
e. “[…]
First. Purpose.
By this Agreement, the Assignor assigns and transfers to the Assignee, who, in turn, receives and acquires for itself a copy of all the business data contained in the Basic Business Census referred to in the previous Exhibit V (hereinafter the Assigned Database), updated as of January 2016, which contains the information fields indicated in Annex 1 of 3,160,984 Business Registries.
For these purposes, the Business Registry is understood to include all the information fields in Annex 1 relating to each of the companies listed in the Assigned Database, with the company's NIF (Tax Identification Number) being used as the identifier for said registry.
[…]
f. The fields “Company NIF,” “Company name or corporate name,” “Main address,” “Business address,” “IAE (Tax Identification Number)” are listed in Annex 1. “IAE activity.”
g. “Second.- Purpose.
The Assignee will include the business data from the Assigned Database and its periodic updates in its Spanish Business File, and will process, complete, and enhance them under the terms agreed
in this Agreement for the purpose of commercially offering it to interested companies and third parties as a database of information on companies operating in Spanish territory.”
h. "12.2.- The Transferor also states that the Transferred Database and its
updates contain data relating to individual entrepreneurs and data
of natural persons who provide services to legal entities, relating
solely to their first and last names, the functions or positions held, as well as
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 21/204
the professional postal or email address, telephone number, and fax number,
all in accordance with the provisions of Article 2 of the RLOPD."
i. ANNEX 2 to the transfer agreement of February 15, 2016, with the "Conditions of the Transfer of the Transferred Database," states that:
i. "The data included in the Transferred Database and its updates are obtained from the public business census regulated by Law 4/2014, prepared by the Transferor under the name of the Basic Business Census."
ii. Obligations of CAMERDATA:
"B) Obligations of the Transferee
b. 1) The Transferee undertakes to incorporate the information from the Transferred Database into the Spanish Business File and to process and market it under the terms agreed in the Agreement and its Annexes.
b.2) The Assignee undertakes to always keep the business data in the Spanish Company File up to date and, to this end, undertakes to:
(i) Obtain from the Assignor all updates to the Assigned Database that the Assignor periodically makes within fifteen (15) business days following the date on which it receives written communication to that effect from the Assignor.
(ii) Not to assign or market the Assigned Database or its updates, and to make no copies other than backup copies.
(iii) Incorporate into the Spanish Company File the updated information from the Company Records of the Assigned Database within thirty (30) business days following the date on which it receives it from the Assignor and to process it in the terms indicated in the following paragraph b.4).
(iv) Carry out said update by overwriting the Spanish Companies File with the information from the Assigned Database updated for each Administration Code submitted. Consequently, the Assignee will be obliged to delete from the Spanish Companies File the information from the Assigned Database previously submitted regarding said Administration Codes. This information will be completely replaced and without effect. The Assignee will not be able to use said information for the purpose of the Contract or for any other purpose; it may only keep it blocked and available to the Public Administrations, Judges, and Courts to address any potential liabilities that may arise from the processing and marketing of said information during the statute of limitations for the purposes of the same. b.3) The Transferee may only inform interested third parties that the source of information in the Spanish Business File
referring to the fields in Annex I of the Contract corresponds to the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 22/204
Basic Business Census when said file has incorporated
the information from the Transferor's latest updated Transferred Database. Otherwise, it may not inform said source.
b.4) Upon receipt of the Transferred Database or its update, the
Transferee shall:
(i) Standardize names and addresses expressed in
different elements (for example: street / rua / Kale / carrer, standardizing all of them as a street) without this implying
any modification to the essential content of the business information
contained in said Transferred Database.
(ii) Incorporate the information from the Transferred Database or its
updates processed in this way into the Spanish Company File owned by the Assignee.
b.5) The Spanish Company File that the Assignee develops and
markets will have the following characteristics:
(i) The company record and its fields in the Transferred Database indicated in Annex 1 of the Contract. The
remaining fields of said File included by the Assignee will not
modify, alter, or contradict the fields in the Transferred Database and its updates.
(ii) Fields developed by the Assignee based on algorithms
created by it.
(iii) Fields provided by the Assignee: such as Legal Form,
main activity, registered office, branches, business activity.
(iv) Fields provided by other legitimate and up-to-date sources: Business name, telephone number, fax number, National Tax Code (CNAE), website, date of incorporation, number of employees, turnover, imports/exports, positions (up to 5 positions with full names), company type (to distinguish between self-employed individuals not covered by Section 2 or 3), geodetic coordinates (in three universal systems), or others.
[…]”
Provides a copy of the contract dated July 1, 2022, signed between CAMERDATA and INFORMA D&B S.A.U. (hereinafter INFORMA), which states:
a. CAMERDATA authorizes INFORMA to market its database of self-employed workers through BUREAU VAN DIJK EDITIONS ELETRONIQUES SRL (hereinafter BVD), a MOODY'S ANALYTICS company.
b. That INFORMA will be responsible and agrees that MOODY'S ANALYTICS may only use the information for:
“Marketing services.
NIF enhancement (given a document, the requested fields from the database provided will be returned).
Preparation of commercial and business reports for the individual entrepreneur in his or her business capacity, never in relation to his or her personal activity.
Segmentation in sales and pricing processes
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 23/204
Provision of fraud prevention services related to the validation
of information and identifiers
Credit and asset solvency services (Analytics Scores services) in their business aspect."
Provides a copy of the contract dated 09/29/2022 and signed between CAMERDATA and
INFORMA, which states that:
a. INFORMA provides CAMERDATA with company information that appears in its database so that CAMERDATA can include it in its database and market it. This information includes, among other
data, the CIF (Tax ID number), company name, full address, company telephone number,
sales.
Informa also provides CAMERDATA with the FIBAEMP PRENORMALIZED file so that CAMERDATA can include it in its database and market it to its clients. The content of this file includes the following information: CIF/NIF (Tax Identification Number), name or company name, company status, and
date of the data, National Economic Registry (CNAE), website, and date of the data.
b. CAMERDATA provides INFORMA with the file of Spanish companies
(FIBAEMP) so that INFORMA can include this information in its file and market it to its clients. This information includes: CIF/NIF (Tax Identification Number), name or company name (for sole proprietors),
IAE (Tax Identification Number), full address (street, municipality, province), and telephone numbers.
In addition, CAMERDATA provides INFORMA with the FIBAEMP PRENORMALIZED file so that INFORMA can process it and return the FIBAEMP PRENORMALIZED file to CAMERDATA. The contents of said FIBAEMP PRENORM file include the CIF/NIF (Tax Identification Number), name
or company name, and IAE (economic activity).
c. CAMERDATA authorizes INFORMA to market its database of
individual entrepreneurs to the company BVD.
d. That BVD may only use the information for:
"Marketing services.
NIF enrichment (given a document, the requested fields
from the database provided will be returned).
Preparation of commercial and business reports for the individual entrepreneur
in its business aspect, never regarding its personal activity.
Segmentation in sales and pricing processes.
Provision of fraud prevention services related to the validation
of information and identifiers.
Credit and asset solvency services (Analytics
Scoring services) in its business aspect."
e. “SEVENTH. DATA PROTECTION
7.1 In the provision of information between the parties,
Both parties expressly submit to Regulation (EU) 2016/679 of the
European Parliament and of the Council of April 27, 2016 (hereinafter,
GDPR), Organic Law 3/2018 of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter, LOPDGDD),
Law 34/2002 of July 11, on Information Society Services and Electronic Commerce (hereinafter, LSSI), and all other applicable regulations on this matter.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 24/204
For these purposes, CAMERDATA declares that the data it communicates under this Agreement (Camerdata file) contains personal data of: individual entrepreneurs (data subjects) related to their commercial activity,
and never to their private sphere, and that this is a lawful processing under the terms of Article 6.1.f) of the GDPR and, to the extent that CAMERDATA guarantees that the data originate from what has been known as publicly available sources, CAMERDATA guarantees that the data may be used to establish a relationship with said data subjects in their capacity as individual entrepreneurs.
Similarly, INFORMA declares that the data it provides under this Agreement (Informa File) contains personal data of contact persons (data subjects), related to their professional location and for the purpose of maintaining relations of any kind with the legal entity for which the data subject provides their services, and never with their private sphere, and that this is a lawful processing under the terms of Article 6.1.f) of the GDPR and, to the extent that INFORMA guarantees that the The same
come from what has been known as publicly available sources
and telephone surveys of the companies themselves, such that INFORMA
guarantees that they may be used to contact interested parties, provided that the purpose is to maintain relations of any kind
with the legal entity for which the interested party provides their services.
That both INFORMA and CAMERDATA are responsible for their respective
data privacy policies and will adapt them, where appropriate, to the
requirements established in the regulations to ensure compliance with
the applicable legislation.
Likewise, as a result of CAMERDATA transferring the data contained in the Camerdata File to
INFORMA, INFORMA will be considered the data controller,
committing to comply with all legal obligations that apply to it
as such.
Additionally, as a result of INFORMA transferring the data contained in the Informa File to
CAMERDATA, CAMERDATA will be responsible for the processing of The same, agreeing to
comply with all legal obligations applicable to it as such.
[…]”
Provides a copy of the contracts dated 09/15/2009, 07/25/2012 (extension of the previous contract),
07/25/2014 (extension of the previous contract), and 05/24/2018, signed between CAMERDATA
and AXESOR CONOCER PARA DECIDIR S.A. (hereinafter AXESOR) or, in its
previous name, INFOTEL Información y Telecomunicaciones, S.A. (hereinafter INFOTEL), which state that:
a. The contract dated 09/15/2009 states that:
i. “l.- That INFOTEL, as a commercial company, is a provider of business and commercial information and has a comprehensive data warehouse with data on commercial and non-commercial entities, businesses, and self-employed entrepreneurs through its website, www.axesor.es.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 25/204
ll.- That CAMERDATA is a company created by the Chambers of Commerce to compile files on business activities carried out within its scope of activity, as well as to offer a public information service on the information contained, among others, in its file called Individual Entrepreneurs, in accordance with the provisions of Basic Law 3/1993 of March 22, 1993, Official Chambers of Commerce, Industry, and Navigation, and in accordance with Organic Law 15/1999 on the Protection of Personal Data. Data.
III.- That INFOTEL is interested in accessing said public information,
obtaining a list of business activities of Self-Employed Business Owners in order to allow it to enrich part of
its file, specifically the Self-Employed Business Owners that INFOTEL
obtains from various publicly accessible sources, and who are part of the
Data Warehouse that INFOTEL or its Clients use in their commercial prospecting
activities to carry out promotional and advertising marketing
actions, in addition to providing said business and commercial
information to its clients through the services and
products of its website www.axesor.es.”
ii. “FIRST: PURPOSE.
Through this document, CAMERDATA will provide
INFOTEL:
1. Information contained in its proprietary file, called
Individual Entrepreneurs, in accordance with the service details
contained in the ANNEX to this contract, which is incorporated
herein for all purposes. The information to be provided comes from the
file prepared by CAMERDATA based on the management and registration data of Self-Employed Persons in the Chambers of Commerce, as well as,
insofar as the telephone number field is not provided at the source, from the
telecommunication service subscriber lists.”
iii. That the ANNEX to the contract contains the identifiers,
name (company name and business name, if available), full address
(initials, street, number, other address, postal code,
municipality, province, county), IAE (Economic Activities Tax), telephone number corresponding to the headquarters address, among
other data.
iv. "In the use of the information in the CAMERDATA file covered by this contract for the enrichment of the records of the INFOTEL Data Warehouse, so that the owner of the data provided may exercise the rights that they have under the provisions of Organic Law 15/1999, since the exception of Article 2.3 of Royal Decree 1720/2007 no longer applies, INFOTEL will inform its clients that in any advertising or commercial prospecting actions they carry out following consultation with this Data Warehouse, they must always include the following mandatory information:
"In accordance with Article 2.3 of Royal Decree 1720/2007, of the Regulation implementing Law 15/1999, of December 13, on Data Protection; Regarding personal data, the contact data of individual entrepreneurs used are outside the scope of said Law. However, if circumstances arise in the future that would cause your data
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 26/204
to fall under the protection of the LOPD, you may exercise your rights of Access,
Rectification, Cancellation, and Opposition by contacting Infotel
Information and Communications, attaching an official document proving your identity to buzoncliente@axesor.es or by fax to
902101062.INFOTEL must inform its clients that they must use such information solely and exclusively to promote products or services directly related to the sector to which the activities provided belong. They may not use it for any purpose other than those indicated above, nor may they communicate it to third parties, even for its preservation. "
b. The contract dated July 25, 2012 states that CAMERDATA
will provide AXESOR with the data of legal entities and physical companies
with the following data, among others:
i. "CIF" with the description "legal/physical sequential CIF"
ii. "company name"
iii. "street", "number", "other" with the description of "other address
(staircase, floor, door, etc.)"
iv. For legal entities only: "postal code", "municipality",
"province", "region", "telephone", "fax".
c. The contract dated May 24, 2018 states the title "ADDENDUM TO THE DATA SUPPLY CONTRACT, SIGNED ON SEPTEMBER 15, 2009 BETWEEN CAMERDATA S.A. AND INFOTEL
INFORMACIÓN Y TELECOMUNICACIONES S.A. (CURRENTLY AXESOR CONOCER PARA DECIDIR S.A.)” and it is stated that:
i. CAMERDATA (or THE OWNER) and AXESOR adapt the previous contract,
signed on 09/15/2009, to the GDPR.
ii. That CAMERDATA is the transferor of the data and responsible for their
processing, and AXESOR is the transferee.
iii. That CAMERDATA guarantees that it has a sufficient legal basis for
the transfer that is the object of the contract, as well as the legality of the construction
of the file.
iv. That “For these purposes, CAMERDATA declares that the data
contained in its directory of Companies and entrepreneurs and that it provides under
the aforementioned Contract (hereinafter the FILE) contains personal data of natural persons identified as
individual entrepreneurs (hereinafter, the INTERESTED PARTIES or
RECIPIENTS), considering that the processing carried out
on them is They refer only in that capacity, that is,
strictly in relation to the commercial activity, never to
their private sphere."
v. "AXESOR will manage and respond directly and on its own behalf
to the rights conferred by the GDPR that it receives directly on its behalf
from the INTERESTED PARTIES, in the manner and timeframes indicated in the
regulations."
vi. "CAMERDATA will manage and respond directly and on its own behalf
to the rights conferred by the GDPR that it receives directly on its behalf
from the INTERESTED PARTIES, in the manner and timeframes indicated in the
regulations."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 27/204
vii. AXESOR's obligations state "1. Use the personal
data being processed, or those collected for inclusion,
only for the provision of the services indicated in the Main
Contract."
AXESOR's role in relation to the processing is not explicitly stated.
viii. That the data protection obligations common to both parties state:
"FOURTH. DATA PROTECTION OBLIGATIONS COMMON TO THE PARTIES.
1. ASEDIE Code of Conduct: As long as both parties are members of the Multisector Information Association (ASEDIE),
they are subject to compliance with the Code of Conduct on Data Protection approved by the Association, and must extend the
obligations imposed therein to the services that CAMERDATA
provides to AXESOR in the Original Contract, and AXESOR, for its part, to the
services it provides to its clients, using for this purpose the records of the
FILE, as established in Annex I of said Code of Conduct.
[…]
2. Management of the rights of the INTERESTED PARTIES:
The parties must immediately communicate, in any case
no later than every Friday, and failing that, on the last business day of the
week, all effectively processed requests for deletion,
rectification, or objection of data from those Self-Employed Persons who have
proven the cessation of their business activity and therefore
cease to be considered Individual Entrepreneurs, or who are
in a special situation that means that the processing of their data by each
party implies a potential violation of their
fundamental rights.
Communications of the deletion of each party's data
must be sent in a list that groups all the deletions made
per week, by sending an email including the
encrypted references or with any other equivalent security measure
to the following email addresses:
Send to Axesor: bcgestionrobinson@axesor.es
Send to Camerdata: informatica@camerdata.es
3. Security Breach Notifications:
Each party shall notify the other, using the information in the "Data Protection Notifications" section of this addendum, as
immediately as possible, of any destruction, loss, alteration,
disclosure, or access to Personal Data of which it becomes aware
and which affects the processing of the other party ("Security Breach"), always within 24 hours of
becoming aware of it.
The party that has suffered a security breach must cooperate
with the other party to mitigate any effects that may affect the data
it processes.
It shall be the responsibility of the party that suffers the security breach to
notify the DATA SUBJECTS and the supervisory authority, in
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 28/204
cases where this is required as indicated in the GDPR, as well as to be liable for any damages suffered by the other party.
4. Security measures applicable to the data provided:
THE OWNER and AXESOR will adopt the necessary technical and
organizational measures to guarantee the security,
confidentiality, and integrity of the personal data and
prevent its alteration, loss, processing, or unauthorized access in
accordance with the provisions of the GDPR, and taking into account the state
of technology, the nature of the data, and the risks to which they are
exposed.
Provides a copy of the contract dated July 29, 2008, signed between CAMERDATA and
IBERINFORM INTERNACIONAL S.A. (hereinafter IBERINFORM or THE CLIENT),
which states that:
"l.- CAMERDATA is a company created by the Chambers of Commerce to
create files of the business activities carried out within its
area of operation (called the Spanish Business File), as well as to
offer public information services on the information contained in
said file, in accordance with the provisions of Basic Law 3/1993 of March 22, on the Official Chambers of Commerce, Industry, and Navigation.
lI.- THE CLIENT is interested in accessing said public
information, obtaining a list of business activities.
[…]
FIRST: PURPOSE.
The purpose of this contract is to regulate the conditions for the provision to the
CLIENT, by CAMERDATA, of the training contained in the CAMERDATA Spanish Company File (hereinafter, the File), in
accordance with the details of the services specified in the ANNEX to
this contract, which is incorporated herein for all purposes.
Second: Conditions of Supply and Use
CAMERDATA will provide the CLIENT with a list of company information, according to the characteristics (search profile, information fields, format, and technical support) specified in the ANNEX (point
1).
[…]
Fourth: Data Protection
Within the framework of this contract, both parties agree to comply with the
current legislation on the protection of personal data.
In particular, CAMERDATA, as the owner of the ESF, is responsible for it before
any administrative or judicial body. However, all information contained in the FEE relates to commercial companies and individual entrepreneurs solely in their commercial aspect, falling outside the scope of data protection legislation, in accordance with Article 2 of the Implementing Regulation of Law 15/1999, of December 13.
The CLIENT will use the information provided to enrich its
own files.
If the CLIENT carries out commercial prospecting campaigns with the information provided, they must inform CAMERDATA in advance and include the following mandatory information:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 29/204
"The list of commercial addresses used for this advertising campaign has been prepared by Camerdata, S.A. (Av.
Diagonal, 452, 3rd floor, 08006 Barcelona, telephone 902 21 42 21,
dptocalidad@camerdata.es), an entity owned by the Chambers of Commerce and responsible for the Spanish Business File, from which
you may inquire about the origin of the data.
In accordance with Article 2 of the Regulation implementing Law
15/1999, of December 13, on the Protection of Personal Data, these data are retained. excluded from the scope of the LOPD.
However, in accordance with the General Telecommunications Law, in
Article 38.3-h), you may cancel your electronic data when
the requirements established in the aforementioned article are met.
Furthermore, in this case, when the information provided relates to
individual entrepreneurs, the CLIENT must include on the labels or
shipping media the business activity codes of these individuals, included in the
list provided, in order to identify that we are addressing them in their commercial
capacity (Example: Business Act: 1, 7). The CLIENT agrees to use
said information to incorporate it into the reports it prepares for its
clients, as well as to partially transmit it in the development of its
commercial activities.
The CLIENT will not use said information for purposes other than those
indicated above.
[…]”
And the ANNEX to the contract contains the following information: “Company name (company name),” “Full address,” “Available telephone and fax numbers,” “Tax ID Number,” among others.
Provides a copy of the contract dated April 25, 2017, and May 24, 2018 (ADDENDUM TO THE
BROKERAGE AGREEMENT SIGNED ON APRIL 25, 2017, BETWEEN
CAMERDATA S.A. AND DATACENTRIC, PDM, S.A.), July 19, 2019, and signed between
CAMERDATA and DATACENTRIC PDM S.A. (hereinafter DATACENTRIC), which states
that:
a. The contract of April 25, 2017 states:
i. “FIRST. PURPOSE
The purpose of this contract is to regulate the terms of collaboration between CAMERDATA and DATACENTRIC regarding the provision of the following services:
- The transfer of the Self-Employed Persons file by CAMERDATA to DATACENTRIC so that DATACENTRIC can use it in its business activities.
- The transfer of data or information fields by DATACENTRIC to CAMERDATA for computer processing.
The content of the services and products subject to transfer is regulated in the following Stipulation.
SECOND. DATA SUPPLY CONDITIONS
CAMERDATA will transfer the Self-Employed Persons (individual entrepreneurs) database to DATACENTRIC in the Premium category. This modality
includes the right: for internal use by DATACENTRIC to
distribute and market the data to third-party companies (with the
exception of infomediary companies, the following examples are cited:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 30/204
Informa, Experian, Arvato, Equifax, Iberinform, Axesor, Ardan, etc.),
for the purpose of being used by the recipients for
internal use only, and never for subsequent distribution or sale.
ii. The information will contain, among other data, name or company name, NIF, full address, and telephone number.
iii. That the records comprising the files delivered to DATACENTRIC are those of individual entrepreneurs and are excluded from the applicable data protection regulations in accordance with Article 2 of Royal Decree 1720/2007.
b. The contract of May 24, 2018 states:
i. The purpose is to adapt the referenced contract to the GDPR. The referenced contract remains in force as long as it is not modified.
ii. "For these purposes, CAMERDATA declares that the data it provides
under the aforementioned Contract (hereinafter the FILE) contains
personal data of individuals (hereinafter, the
INTERESTED PARTIES or RECIPIENTS), considering that this is
personal data related to the user's commercial activity, not
their private sphere, and that this processing is lawful in the
terms of art. 6.1. f) of the GDPR, in such a way that it allows us to send you
advertising from the sectors included in the privacy policy of
DATACENTRIC […]”
iii. DATACENTRIC is the data controller and processor, and
CAMERDATA is the data controller.
iv. “[…] CAMERDATA, as the owner of the FILE and data controller,
authorizes DATACENTRIC to market the
file to CLIENTS who contract the execution of the campaigns
regulated in the corresponding contract with data processors who are not hosted in the EEA, provided
that the clients, in their capacity as DATA EXPORTER, have
the proper authorization from the Director of the Spanish Data Protection Agency to carry out the aforementioned international
transfer […]”
And annexed to the contract is a “CONTRACT FOR THE PROVISION OF
DATA PROCESSING SERVICES” which states that:
i. CAMERDATA is the data controller and DATACENTRIC
is the data processor.
ii. DATACENTRIC will provide the processing services necessary
for the execution of advertising campaigns.
c. The contract of July 19, 2019, states that in relation to the contract of
April 25, 2017, CAMERDATA authorizes DATACENTRIC to distribute and market
the self-employed database owned by the former, to the infomediary company
EQUIFAX IBÉRICA, S.L., and the companies belonging to its
group. The distribution of the file will be carried out for the purpose of "marketing services" limited to the business sphere and never private, enrichment
of NIF (Tax Identification Number), identification of whether the person is self-employed for the purpose of locating them.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 31/204
Provides a copy of the contract dated 23/08/2021 and signed between CAMERDATA and
CERVED GROUP S.p.A. (an entity located in Italy, hereinafter CERVED)
which states, in its unofficial English translation, that:
a. That CERVED is a company engaged in the exercise of commercial information activities.
b. CAMERDATA will transfer the database of companies and self-employed workers to CERVED for its business activity for its internal use and that of its subsidiaries. That CERVED will also use the information for
distribution and marketing to third-party companies, except for designated infomediary companies.
c. The information will contain, among other data, the name or company name, tax identification number,
full address, telephone number, and geographic coordinates.
d. That the records comprising the files delivered to CERVED
include information on self-employed workers and personal data related to their commercial activity, not their private sphere, and that this processing is lawful under Art. 6.1.f. GDPR.
Provides general clauses used in the signing of contracts with between 500 and 900 clients per year to whom data is transferred for their exclusive use. This clause states (underlined):
“GENERAL CONTRACTING CONDITIONS
First: Purpose
The purpose of these General Contracting Conditions is to regulate the
conditions of acquisition by the CLIENT and supply by CAMERDATA, relating to the company information contained in CAMERDATA's
Spanish Company File.
Second: Supply and Use of the File
CAMERDATA will provide the CLIENT with a file containing company information, according to the characteristics (search profile, information fields, format, and technical support) specified in the quote accepted by the CLIENT.
The CLIENT must use the information as provided, without manipulating the content of the information fields in the list provided.
The information provided by CAMERDATA may be used by the
CLIENT for twelve months from the date of delivery.
The information provided to the CLIENT is the property of CAMERDATA, and therefore, without the latter's consent, it may not be provided in whole or in part to a third party. The CLIENT will take the necessary measures to store, manipulate, and, where appropriate, destroy it, thereby eliminating the possibility of misuse by third parties.
The sale or transfer of part or all of the information provided to third parties by the
CLIENT is expressly prohibited.
Failure by the CLIENT to comply with the obligations contained in this clause may result in CAMERDATA taking the corresponding legal action and, in any case, in the CLIENT compensating it for any damages caused, which, by mutual agreement, both parties will set at a minimum amount consisting of five times the price of the information provided.
CAMERDATA uses the advertising exclusion service provided by the
Spanish Association of the Digital Economy (Adigital), also known as the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 32/204
Robinson list service. Therefore, the information covered by this contract
relating to individual entrepreneurs (if any) may be
used for personalized advertising within the time periods established by
the regulations. After this period has elapsed, the CLIENT must
exclude from the information provided any new Robinson lists that may have
appeared before using it for personalized advertising.
Third: Sources of Information
CAMERDATA certifies that this file only contains data from commercial companies
and individual entrepreneurs that carry out commercial activities.
CAMERDATA guarantees the legality of the sources used for the
creation of the file.
Likewise, they are protected by Royal Legislative Decree 1/1996, of April 12, as amended by Law 5/1998, of March 6, on the incorporation into Spanish law of European Community Directive 96/9 of March 11, 1996, on the legal protection of databases.
[…]
Sixth: Data Protection
The data covered by this contract may contain personal data that may constitute a personal data file. This data, in accordance with data protection regulations, has been collected and is distributed for the sole purpose of facilitating contact with the companies identified in relation to their business activity, in accordance with the restrictions established by European Regulation (EU) 2016/679, General Data Protection Regulation. If the CLIENT stores the data
contained in this file for future use, it will become the controller of
its processing under the terms set forth in the European Regulation (EU)
2016/679, General Data Protection Regulation (hereinafter GDPR), assuming
all the obligations that this regulation imposes on those responsible for the
processing of personal data.
To comply with the principle of transparency and the obligations
described in Articles 14.1 and 14.2 of the GDPR, the CLIENT must make
individual communications to data subjects when the data has not been
obtained directly from the data subject.
Since the data comes from publicly accessible sources, and in the event that
one of the legally established reasons exists, if the CLIENT does not make
individual communications to the data subjects, it will adopt the following appropriate measures
to protect the rights, freedoms, and legitimate interests of the data subjects:
The CLIENT must provide the information indicated in sections 1 and 2 of
Article 14 of the GDPR in clear and simple language, in a concise,
transparent, intelligible, and easily accessible manner, no later than the time of the
first communication made to the data subjects. This communication
may consist of the following text, incorporating it clearly
visibly in the advertising communications sent to the data subjects, or
through a voiceover if the communication is made by
telephone.
"The contact information used to send this communication
has been obtained by (the CLIENT) after being collected from
(CAMERDATA).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 33/204
The purpose of processing this data is to send you commercial and marketing communications, offering you various
goods or services that may be of interest to you.
If you wish to exercise your rights of access, rectification, deletion,
restriction of processing, or object to processing, as well as the right
to the portability of your contact information, you can send your request to the
following address: ________, or by sending an email to __________,
always attaching a copy of a document that proves your identity
(ID, passport, or similar)."
To learn all the information related to your data,
please visit our website: (Link to the CLIENT's website, where the rights related to the GDPR will be explained in detail)"
If the CLIENT is required to hire a Data Protection Officer, they must add:
"You can also contact the Data Protection Officer of the
Data Controller at the following address: ________, or by sending an
email to __________,"
In any case, the information must be maintained in all other communications after the first.
The CLIENT agrees not to conduct telemarketing campaigns without a human operator, including the information provided when it relates to
telephone data.
[…]"
Provide a copy of the contract dated 06/29/2020 and signed between CAMERDATA and
KOMPASS S.A. (hereinafter KOMPASS), which states that:
“[…]
l. That KOMPASS Spain is a company founded in the early 1960s and is part of Kompass International, a French company with more than 65 years of experience as a B2B business information provider.
ll. That CAMERDATA is a company created by the Chambers of Commerce for the purpose of creating a database, called the Spanish Business File (hereinafter FEE), of which it is the owner, containing the data
of all individuals and legal entities that carry out business activities, as well as to offer business information and advisory services to its members in relation to said database. All of this in accordance with the provisions of Basic Law 4/2014 of April 1, on Official Chambers of Commerce, Industry, and Navigation.
[…]
AGREEMENTS
First: Purpose
The purpose of this contract is to regulate the terms of collaboration between CAMERDATA and KOMPASS regarding the provision of the following services:
- The transfer of 107,897 CIFs from records contained in the database
Spanish Companies File (hereinafter FEE), for which CAMERDATA
does not have the generic email field reported and partially the URL field
reported, by CAMERDATA in favor of KOMPASS for the purpose of
allowing KOMPASS to perform "webcrawling" work.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 34/204
- The transfer of the URL field of the 107,897 CIFs in the event that KOMPASS
has been informed (55,576 records counted) and the records from which
the generic email address was obtained as a result of "webcrawling" work by
KOMPASS to CAMERDATA, in order to use it in its business activities.
The content of the services and products subject to transfer is regulated in the following sections.
Second: Data Supply Conditions
CAMERDATA will transfer to KOMPASS the 107,897 CIFs resulting from a preliminary study, for use in the aforementioned webcrawling work.
KOMPASS will transfer to CAMERDATA the URL field of the 55,576 records analyzed.
KOMPASS will transfer to CAMERDATA the generic email field of the records
resulting from the webcrawling work for which the generic email field has been obtained (as many as have been obtained per record), relating them to their corresponding CIFs.
Third: Webcrawling
KOMPASS will perform webcrawling work on the database using its own resources. Provided by CAMERDATA, this information consists of applying Internet search and pattern recognition algorithms to attempt to obtain generic email addresses associated with the URLs provided.
[…]
Fifth: Data Protection
KOMPASS and CAMERDATA undertake to comply with Spanish legislation
on data protection and personal privacy. If this legislation cannot be
complied with, you must refrain from receiving information or other
services related to it, in accordance with the provisions of national legislation
on the matter.
KOMPASS guarantees that the generic emails obtained do not contain personal
data and therefore may be used as such.
Please provide a copy of the contract dated March 20, 2023, signed by CAMERDATA and KOMPASS, which states:
“[…]
AGREEMENTS
First: Purpose
The purpose of this contract is to regulate the terms of collaboration between CAMERDATA and KOMPASS regarding the provision of the following services:
- The transfer of records contained in the Spanish Companies File (hereinafter FEE) database that do not contain the generic email field provided, by CAMERDATA to KOMPASS, so that KOMPASS can carry out web crawling work and subsequently use it in its business activities.
- The transfer of records in the KOMPASS database that contain
the reported generic email field and the records from which the generic email address and the URLs thereof were obtained
by KOMPASS to CAMERDATA, so that it can use them in its business activities.
The content of the services and products subject to transfer is regulated in the following
sections.
Second: Data Supply Conditions
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 35/204
CAMERDATA will transfer to KOMPASS the NIFs of the records contained in the FEE database for which Kompass has the URL field provided and for which CAMERDATA does not have the generic email field (145,101 records): KOMPASS will transfer to CAMERDATA the records resulting from the webcrawling work for which the generic email field has been obtained, the following fields:
NIF
URL used for the webcrawling (mainly the universe of the 145,101 records)
Generic email obtained (as many as obtained per record)
Third: Webcrawling
KOMPASS will carry out, using its own resources, some webcrawling work based on
the Data provided by CAMERDATA consisting of the application of Internet search and pattern recognition algorithms to attempt to obtain generic email addresses associated with said URLs from the available URLs.
[…]”
Provides a copy of the contract dated 02/03/2020 and signed between CAMERDATA and DMOVO ANALYTICS, S.L. (hereinafter DMOVO), which states:
“[…]
THEY STATE
l.- That Dmovo is an independent company dedicated to providing professional strategic, organizational, business, operational, and technological consulting services in the fields of Information Technology (ICT) and Marketing.
ll.- That THE CLIENT is interested in contracting Dmovo to provide technological development, information processing, and consulting services.
[…]
CLAUSES
FIRST.- PURPOSE OF THIS CONTRACT
This Contract The purpose of this Agreement is to establish a collaborative framework for the provision of technological development, information processing, and consulting services by Dmovo.
The services consist of a periodic process of processing and adapting the name and address data from the company and self-employed registries for which THE CLIENT is the data controller.
The specifications and technical requirements of the services to be provided are detailed in ANNEX I (SmartAddress Offer) to this Agreement. These details will consist of the specific services to be provided by Dmovo and accepted in all their terms by THE CLIENT, and will be incorporated into this document as an integral part thereof for all purposes.
[…]
FIFTH.- SERVICES INCLUDED
The specific services regulated by this agreement are the following:
Batch normalization process for Camerdata
Dmovo will perform the data normalization processes four times a year with an estimated volume of 10 million records.
In addition, an annual process will be carried out for records belonging to the Basque Country and Navarre. In this case, an approximate volume of 500,000 records is estimated.
Processes to be carried out.
Population Normalization (INE)
Road Normalization (INE)
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 36/204
Postal Code Assignment.
Census Section Assignment (INE)
Coordinate Assignment.
Grid Assignment (GRID 100>(100).
Name Normalization.
Delivery of the file in the format defined by THE CLIENT.
SIXTH.- CONFIDENTIALITY
Dmovo undertakes to accept Confidential Information within a framework of trust for the proper execution of the agreed services and not to provide it to any third party or use it for its own benefit. without obtaining the prior written consent of the other party.
[…]”>>
--The Inspection Action Report states:
<<On 16/11/2023, it was verified that:
1. The URL https://sede.agenciatributaria.gob.es/Sede/todas-
gestiones/procedimientos-notributarios/tratamiento-datos-personales/tratamiento-
datos-personales/informacioninteresado-sobre-proteccion-datos/5-registro-actividades-
tratamiento/5_1-censo.html contains no content.
2. The URL
https://sede.agenciatributaria.gob.es/Sede/procedimientoini/ZA02.shtml and Information on the "Economic Activities Tax File Registration Design for Chambers of Commerce for the Annual File Submission for the 2008 and Subsequent Fiscal Year" can be found at
https://sede.agenciatributaria.gob.es/static_files/Sede/Procedimiento_ayuda/ZA02/drIA
E_CamCom08.pdf. This contains a table describing the exchanged data, including, among others, the following data:
"NIF", "Surname and First name or company name", "current tax address", "tax address"
(which also includes the "telephone number").
3. The Official State Gazette (BOE) of December 20, 2019, which can be accessed through the
link, states […]: "AGREEMENT BETWEEN THE STATE TAX ADMINISTRATION AGENCY AND THE OFFICIAL CHAMBER OF COMMERCE, INDUSTRY, SERVICES AND NAVIGATION OF SPAIN FOR THE TRANSFER OF TAX INFORMATION TO OFFICIAL CHAMBERS FOR THE EXERCISE OF THEIR PUBLIC-ADMINISTRATIVE FUNCTIONS
[…]
First. Purpose of the Agreement.
1. The purpose of this Agreement is to establish a general framework for collaboration
on the conditions and procedures governing the transfer of
information from the State Tax Administration Agency (hereinafter, the Tax Agency) to the Official Chambers of Commerce, Industry, Services, and Navigation (hereinafter, the Chambers) and to the Official Chamber of Commerce, Industry, Services, and Navigation of Spain (hereinafter, the Chamber of Commerce of Spain), preserving in all cases the rights of the persons to whom it refers.
2.
[…]
Second. Purpose of the transfer of information.
The transfer of information from the Tax Agency will be for the exclusive purpose of collaboration. with the Spanish Chamber of Commerce and the Chambers
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 37/204
in the performance of the public functions assigned to them when, for the exercise of these functions, the regulatory regulations require the provision of a certification issued by the Tax Agency or the submission, in original, copy, or certification, of the tax returns of the interested parties or any other communication issued by the Tax Agency, particularly in the case of those not required to file a tax return. In these cases, the information that must be included in such documents will be requested directly from the Tax Agency, provided that it is necessary for the performance of such functions and relates to a large number of interested parties or affected parties.
The public functions to be performed by the Chambers are set out in Annex III of this Agreement.
The transfer of tax data The sole purpose of the Tax on Economic Activities and the company censuses
will be to compile the public company census, fulfill the public-administrative functions assigned to the Chambers by Law 4/2014
Basic Law of the Official Chambers of Commerce, Industry, Services and Navigation, as well as to compile the electoral census referred to in Article 17 of the same Law.
Third. Authorization of those interested in the information provided.
[…]
However, the transfer of data from the Tax on Economic Activities and the company censuses required by Article 8 of the aforementioned Law 4/2014 will not
require the prior authorization of the interested parties.
Fourth. Recipients of the information provided.
The information provided by the Tax Agency may only be addressed to the bodies of the Spanish Chamber of Commerce and the Chambers that have been assigned the public functions that justify the transfer, […]. Under no circumstances may the recipients
be bodies, agencies, or entities that perform functions other than those
described in the second clause of this Agreement.
All of this is without prejudice to the strict allocation of the information sent by the Tax Agency to the purposes that justify it and for which it is requested. In any case, the recipient may not transfer the information sent by the Tax Agency to third parties.
[…]
Seventh. Transfer of information.
1. To fulfill the purposes described in the second clause, the information provided in Annex I to this Agreement is established.
[…]
Eighth. Control and security of the data provided.
[…]
2. The following controls are established over the custody and use of the information provided under this Agreement:
a) Internal control by the entity transferring the information.
The Chambers will carry out controls on the custody and use of the data received by the authorities, officials, or other personnel reporting to them, reporting to the Joint Coordination and Monitoring Committee provided for in
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 38/204
Clause thirteen of this Agreement on the results obtained from said monitoring.
They will have an information security policy, risk analysis and management, and an explicit assignment of security responsibilities appropriate to their mission, objectives, and size, and must apply these security mechanisms to the information provided by the Tax Agency. They will prevent access to the information provided by unauthorized personnel, establishing traceability of access to the information provided, and conducting audits of data access using random and risk-based criteria.
They will adopt specific measures to avoid the risk of the information being
used, even inadvertently, for other purposes, or by personnel with a
conflict of interest. They will also adopt measures to ensure compliance with the conditions underlying each transfer.
[…]
Ninth. Processing of personal data.
In the event that the information includes personal data of the interested parties, both
the transferor, the Tax Agency, the transferee, the Spanish Chamber of Commerce, and the Chambers will process the data in accordance with Regulation (EU) 2016/679
of the European Parliament and of the Council of April 27, 2016, and Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights.
The data processed in this Agreement is categorized as tax information.
In the case of the data transferor, the Tax Agency, the Data Controller for the purposes of the General Data Protection Regulation is the owner of the General Directorate.
In the case of the data transferors, the Spanish Chamber of Commerce and the Chambers of Commerce, the Data Controller for the purposes of the General Data Protection Regulation will be the person designated by each Chamber.
Tenth. Obligation of confidentiality.
1. All authorities, officials, and other personnel who have knowledge of the data or information provided under this Agreement shall be bound to the strictest and complete confidentiality regarding them. Violation of this obligation will entail incurring the criminal, administrative, and civil liabilities that may arise, as well as submission to the exercise of the powers that correspond to the Data Protection Agency.
[…]
ANNEX I TO THE AGREEMENT BETWEEN THE STATE TAX ADMINISTRATION AGENCY AND THE OFFICIAL CHAMBER OF COMMERCE, INDUSTRY, SERVICES AND NAVIGATION OF SPAIN FOR THE TRANSFER OF TAX INFORMATION TO THE OFFICIAL CHAMBERS FOR THE EXERCISE OF THEIR PUBLIC-ADMINISTRATIVE FUNCTIONS
[…]
ANNEX III
The budget for the conclusion and execution of this Agreement is the condition
of public administration, both of the Official Chamber of Commerce, Industry, Services and Navigation of Spain and of the Official Chambers themselves, with the provision of information by the State Tax Administration Agency being, in all cases, intended for the exercise of public functions.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 39/204
The public functions to be performed by the Official Chamber of Commerce, Industry, Services, and Navigation are listed directly and indirectly in letters d) to i) of Article 21.1 of Law 4/2014, of April 1, Basic Law of the Official Chambers of Commerce, Industry, Services, and Navigation:
[…]
Article 5 of Law 4/2014, Basic Law of the Official Chambers of Commerce, Industry, Services, and Navigation:
«1. The Official Chambers of Commerce, Industry, Services, and Navigation shall have the
following public-administrative functions:
[…]
g) Manage, pursuant to Article 8 of this Law, a public census of
all companies, as well as their establishments, branches, and
agencies located within their district.
[…]”
4. That the URL
https://sede.agenciatributaria.gob.es/static_files/Sede/Procedimiento_ayuda/ZA02/pInt
ercambioIAE2006.pdf contains the “PROTOCOL FOR THE EXCHANGE OF INFORMATION ON THE E.A.I. BETWEEN THE STATE TAX ADMINISTRATION AGENCY AND LOCAL ENTITIES / CHAMBERS OF COMMERCE” where it states:
“[…]”
5. REQUEST FOR E.A.I. FILES
Although the Tax Agency is obliged to provide E.A.I. information to all local entities with management and/or collection powers in this tax and to the Chambers of Commerce for the management and collection of the levies included in the Chamber Resource, this procedure is based on a prior request for the desired information, which Although it may seem like an
obstacle, it offers several important advantages, such as:
• Local authorities and Chambers of Commerce can request the type of information they wish, at any time, and as many times as they deem appropriate. Requests made in this way are automatically recorded in the AEAT Data Entry Registry, allowing for subsequent follow-up.
[…]
ANNEX II. Authorization form for the electronic exchange of information on the Economic Activity Tax.
[…]
The information requested will be used exclusively for the purposes conferred
by the regulations on the economic activities tax on this
municipality/agency, and may not be used to the detriment of the interested party
or affected party, nor transferred to third parties, except in cases expressly provided for
by law."
[…]>>
--The Inspection Action Report states:
<<On 11/21/2023, it was verified that:
1. That the Royal Decree 1065/2007, of July 27, approving the
General Regulations for management and inspection actions and procedures
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 40/204
tax and development of the common rules for tax application procedures, in its Article 5, states that "In the Census of Business Owners, Professionals, and Withholders, in addition to the data mentioned in Article 4 of this regulation,
the following information shall be included for each person or entity" and in Article 5. 4, the following data appears:
“Article 4. Contents of the Census of Taxpayers.
[…].”>>
--As a result of the actions carried out before the CHAMBER OF SPAIN
(CHAMBER), the inspector in charge states the following in his report:
<<As a result of the request for information made by the inspection,
on 11/21/2023, the CHAMBER sent the following information and statements to this agency (underlined):
1. “The database of the public census of companies of the Chamber of Spain is comprised, in accordance with Article 8 of Law 4/2014, of April 1, Basic Law of the Official Chambers of Commerce, Industry, Services and Navigation (hereinafter, Law 4/2014),
of legal and natural persons, national or foreign, that carry out commercial, industrial, of services and shipping companies in national territory.
Only those economic activities of companies, individuals, and legal entities whose activity falls under one of the headings of Divisions numbers 1 to 9, both inclusive, of Section One of Annex I of Royal Legislative Decree 1174/1990, of September 28, approving the rates and instructions for the Tax on Economic Activities, and which have not been deregistered, are included.
The data comprising the public business census of the Spanish Chamber of Commerce are sourced from the Economic Activities Tax and the necessary company census data provided by the State Agency of the Tax Administration, pursuant to the Agreement of November 25, 2019, signed between the Tax Administration and the Spanish Chamber of Commerce for the transfer of tax information to the Official Chambers of Commerce, Industry, and Services. and
Spanish Navigation for the fulfillment of their purposes and the exercise of their public-administrative functions, which has been extended by an addendum dated
December 19, 2023. They also originate from the data on the
Economic Activities Tax provided by the Provincial Council of Navarre and
those provided by the Chambers of Commerce of the Basque Country. […]”
2. That the total number of self-employed or individual entrepreneurs or natural persons currently listed in the public business census is 1,459,498.
3. That the data contained in the CHAMBER'S public business census are:
NIF/CIF (Tax Identification Number)
Name, first surname, second surname.
Postal address of the economic activity.
Postal code of the economic activity.
Province of the economic activity.
Municipality of the economic activity.
Description of the economic activity.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 41/204
Provide an extract from the database containing this data, among others.
4. “[…]The fields listed above are provided solely to
CAMERDATA, S.A., as a commercial entity constituted by multiple Spanish Chambers of Commerce and the Chamber of Spain, for inclusion in its Spanish Business File, for the purpose of legitimately processing, completing, and enriching them and having a quality database of companies operating in Spanish territory so that it can be offered to interested companies and third parties.
[…]”
5. Regarding the obligation to provide information under Article 14 of the GDPR, it is not an obligation, pursuant to Article 14.5 c). Data collection is expressly established by Law 4/2014 and the public-administrative functions that it assigns to the Chamber.
States that Article Article 3 of Law 4/2014 establishes:
[…]"
Article 5.1 of Law 4/2014 establishes the public-administrative functions of the CHAMBER:
"g) Manage, in accordance with Article 8 of this Law, a public census of all companies, as well as their establishments, branches, and agencies located within its district.
j) Promote actions aimed at increasing the competitiveness of small and medium-sized enterprises, and encourage innovation and technology transfer to companies.
(...)"
And that Article 8 of Law 4/2014 establishes in relation to the aforementioned census:
"The Official Chambers of Commerce, Industry, Services, and Navigation
shall compile a public census of companies, which shall include
natural or legal persons, national or foreign, that carry out commercial, industrial, service, and shipping activities in national territory (...)."
That Article 21.1 of Law 4/2014 establishes the following functions:
"[…]
a) Promote the general interests of commerce, industry, services, and
navigation at the national level.
b) Represent all the Chambers before various national and international bodies.
c) Coordinate and promote actions that affect all the Spanish Chambers.
d) To exercise, at the state level and in coordination with the Chambers of Commerce, Industry, Services, and Navigation, the functions referred to in
section 1 of article 5 of this Law. […]”
6. That “the collection of the data comprising the public business census
(listed in the previous point) and its processing for the preparation of a public census of all companies, whether natural or legal persons, constitutes the
performance of a public-administrative function of the Spanish Chambers of Commerce, which the Spanish Chamber exercises, at the state level and in coordination
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 42/204
with the Chambers of Commerce, for the fulfillment of the chamber's purposes,
thus promoting the general interests of commerce, industry, services, and navigation, and, in particular, promoting actions aimed at increasing the
competitiveness of small and medium-sized businesses (largely self-employed).”
7. That the legitimacy for processing that entails a public business census is the legal obligation, according to Article 5.1.g and 8 of Law 4/2014. That it is also the public interest. And it states:
“[…]
Without prejudice to the exercise of its public-administrative function of preparing a
public business census, through its management the Spanish Chamber also
fulfills an objective or mission of public or general interest that (i), on the one hand, is
inherent to its own functions of Article 21.1.d) of Law 4/2014, in
relation to the chamber's purposes of Article 3 of the same Law, such as
the promotion of the general interests of commerce, industry, services
and navigation, and business and economic development, and the main function
of providing services to all companies that carry out these activities, including business information services, thus strengthening
its role in supporting small and medium-sized enterprises in the field of
increasing their competitiveness (paragraph 12, section l, of the Preamble to Law 4/2014), and that (ii), on the other hand, is implicit in the public-administrative function of promoting actions aimed at increasing the competitiveness of small and medium-sized enterprises (article 5.1.j) of Law 4/2014).
In this regard, the Preamble to Law 4/2014 (paragraph 6, section l) highlights
the public interest objective or mission of the purposes, functions, and
activities of the Chambers of Commerce:
"Aware of their importance and necessity as basic institutions
for the economic and business development of our country, their nature as public law corporations is
maintained,
guaranteeing the exercise of public-administrative functions that,
in the current economic context, are of particular relevance in terms
of the regeneration of the economic fabric and job creation, and
their purpose of representing, promoting, and defending the
general interests of commerce, industry, services, and
ship, as well as the provision of services to all businesses, is
established."
Law 4/2014 assigns to the Chamber of Spain the exercise and fulfillment of
functions of public or general interest—in that they are functions of a public-administrative nature—among which is the preparation and management of
a public census of companies, necessary for the fulfillment of its
purposes and the exercise of other public-administrative functions of the chamber.
Thus, Law 4/2014 determines the purpose of the processing and its necessity for the
fulfillment of a mission carried out in the public interest.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 43/204
Thus, both the necessity of the data processing carried out, as well as the
purposes of public interest, are imposed by a regulation with the rank of
Law.”
8. Regarding the purpose of the processing, it states:
"The purpose of the processing carried out by the Spanish Chamber of Commerce is to promote the general interests of commerce, industry, services, and navigation, as well as business and economic development, and its main function is to provide services to all companies that carry out these activities, including business information services, thus strengthening its role in supporting small and medium-sized enterprises and promoting actions aimed at increasing their competitiveness.
By managing the public business register, a business information system or service is offered to the general public and businesses in particular, with the aim of providing greater transparency and security to commercial legal transactions, aiding economic and business development, and thereby fulfilling a general public interest for the business and professional sector and job creation.
Purpose for which the interested parties themselves, the self-employed or individual entrepreneurs, are interested in being part of this database, both to be located by third parties interested in their products and services, and to access this database to offer them to
third parties."
9. Regarding the transfer of data to CAMERDATA, the following is stated:
"The Spanish Chamber of Commerce provides the data from the public business census to
Camerdata, S.A. to process, complete, and enrich them legitimately,
and to have a quality database of companies operating in
Spanish territory, so that it can be offered to companies and interested third parties.
The legitimate basis for processing data from the public business census by Camerdata is that the processing is necessary for the satisfaction of legitimate interests pursued by the data controller or a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject that require the protection of personal data (Article 6.1. f) of the GDPR).
In this sense, it contributes to the development and promotion of commercial and industrial relations, thus providing a quality business information system for stakeholders in the business community, promoting economic and business development and providing greater security in commercial transactions, thereby satisfying a general interest.
The processing of data from the public business census by Camerdata also underlies a legitimate interest of the business owners themselves,
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 44/204
who need to have this information either to learn about the services and
products of other business owners or to make their own known to third parties.
Fundamental rights and freedoms of data subjects:
The fundamental rights and freedoms of data subjects are the general ones
that require the protection of personal data, with none specifically highlighted in this particular situation.
In any case, they will not be violated by the processing of data from the
public business census, because:
1. The category of personal data processed is limited to those from the public business census
of the Chamber of Spain and for purposes consistent with the purposes
of its preparation.
2. The data processed is contained in the public business census, a database publicly accessible on the website of the Chamber of Spain.
3. The easy exercise of the rights of the Data Subjects regulated in Articles 15 to 22 of the EU GDPR is guaranteed at all times.
Weighting results:
1. The processing is considered lawful.
2. The data processed is public data, accessible to the general public on the corporate website of the Chamber of Spain.
3. The categories of data processed are minimally invasive of the data subject's right to privacy, as they are data limited to the performance of a business activity by the data subject.
At no time are there data from their family sphere, much less data from special categories of data (Article 9 GDPR).
4th - The principle of the free circulation of data, established and protected by
the European regulations on the subject (GDPR).
5th - The purposes intended by Camerdata for data processing are consistent and compatible with those of the Chambers of Commerce's public business census, as they seek to provide a
quality business information system for stakeholders in the business sector,
promoting economic and business development and providing greater security in commercial transactions, thereby satisfying a
general economic interest.
[…]”>>
(Emphasis added)
--The Inspection Action Report also states:
<<On 03/22/2024, it was verified, regarding a randomly selected self-employed person
from the lists provided by CAMARA and CAMERDATA, that:
1. A search was conducted on www.google.es for the first and last name of a self-employed person, yielding results from the website www.expansion.com.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 45/204
2. That the website www.expansion.com contains data exclusively on the first and last name, postal code, province, municipality, year of commencement of activity, activity, SIC, CNAE. It is stated that the data was obtained from public sources by AXESOR
CONOCER PARA DECIDIR S.A. It is also stated that For more information about the self-employed person, a link is provided to the website autonomos.axesor.es. Clicking
on this link will redirect you to the website autonomos.axesor.es, displaying
exclusively the details of their first and last name, postal code, municipality, province,
CNAE (National Electoral Code), SIC (National Tax Code), and information about their activity.
The website autonomos.axesor.es also includes the following text: "Our reports will provide you with the most complete information about the business activity of […]
such as the NIF (Tax Identification Number), telephone number, address in ***CITY.2 (***PROVINCE.2), credit score, probability of default, and maximum solvency capacity.
" Legal incidents…”
3. Searching the first and last name of that self-employed person using www.google.com and restricting the search results to the einforma.es domain, search results are provided that, when clicked, redirect to the einforma.com website, where information about the name, surname, city, and province of the individual is provided. More detailed information includes the name and surname, postal code, province, municipality, activity, SIC, and CNAE (National Tax Code).
Furthermore, the einforma.com website contains a link with “Access the extended report for this company.” It also includes the text “elnforma, a brand of INFORMA D&B S.A.U. (S.M.E.), is the Spanish market leader in business information and company reports. We have a business database with more than 500 million company records, where you can search for companies from around the world, more than 7 million national economic agents, and access Prospecta.
4. Searching the first and last name of that self-employed person using the search engine www.google.com and restricting the search results to the domain axesor.es, no search results are provided.
5. On the censo.camara.es website, performing a search using the name field
and entering the first and last name of the same self-employed person above, results are provided with the first and last name, postal address, postal code, province, municipality, and activity. A link is also provided to the Camerdata Online company file (www.camerdata.es) for more information.
--The Inspection Action Report also states:
<<On 03/22/2024, it was verified that:
1. In section 5.1. "census" of the AEAT's processing activity log located at https://sede.agenciatributaria.gob.es/Sede/todas-
gestiones/procedimientos-no-tributarios/tratamiento-datos-personales/tratamiento-
datos-personales/informacion-interesado-sobre-proteccion-datos/5-registro-actividades-tratamiento/5_1-censo.html states:
"Description of the activity
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 46/204
Management and collection of information on taxpayers, whether individuals or legal entities. To this end, most census data is processed, including their history.
Purpose:
Effective application of the state tax and customs system
Interested parties
Taxpayers and taxpayers
Any Spaniard or foreigner with a DNI, NIE (DGP), or NIF (AEAT)
Data.
DNI and associated information, name and surname, address,
telephone number, email address, fax number, mobile phone number, marital status and, if applicable,
spouse or ex-spouse, country of birth, province of birth, city of birth, date of birth,
nationality, passport, sex, type of administration to which the taxpayer is attached, tax identification number in a foreign tax administration, municipal identification number, electoral identification number, census number, father's name, mother's name.
Transactions involving goods and services.
Tax obligations.
[…]
Recipients.
Social Security Agencies
Regional Government Bodies
Regional Governments
Local Government Bodies
Provincial Councils
Navarre Regional Government
Tax Agency
Basque Regional Governments
Chamber of Commerce
[…]>>
(Emphasis added)
THIRD: Turnover.
Article 35 of Law 4/2014, of April 1, Basic Law of the Official Chambers of Commerce, Industry, Services, and Navigation (hereinafter, Law 4/2014 or Basic Law of Chambers), "Budget and Transparency," establishes in section 1, last paragraph:
"The annual accounts, together with the audit report, and the Annual Report on Corporate Governance, shall be filed in the commercial registry corresponding to the
locality where the Chamber has its headquarters and shall be published by the
Chambers." (Emphasis added)
As of April 5, 2024, the Annual Accounts and Audit Report for the fiscal years 2021 and 2022 were published on the CHAMBER OF SPAIN'S website. According to the Balance Sheet as of December 31, 2022, the "Net Revenue" in 2021 was €6,136,662 and in 2022 was €6,308,255.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 47/204
FOURTH: Agreement to initiate sanctioning proceedings.
On April 15, 2024, the Director of the Spanish Data Protection Agency
agreed to initiate sanctioning proceedings against the Spanish Chamber of Commerce, in accordance with the provisions of Articles 63 and 64 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), for the alleged violation of the following provisions of Regulation
(EU) 2016/679, of April 27, on the Protection of Natural Persons with regard to the processing of personal data and the free movement of such data, and
repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter GDPR):
-Article 6.1. GDPR, infringement classified in Article 83.5.a)
-Article 5.1.b) of the GDPR, infringement classified in Article 83.5.a)
-Article 5.1.f) of the GDPR, classified in Article 83.5.a)
-Article 5.1.a) of the GDPR, classified in Article 83.5.a)
FIFTH: Notification of the initiation agreement.
As evidenced by the documentation in the file, the
notification of the aforementioned initiation agreement was received by the Spanish Chamber of Commerce by
post on April 24, 2024 (folio 1,725). The electronic notification
was made available on the AEPD website on April 15, 2024,
by accessing the content on April 25, 2024 (folio 1,726).
Article 41.7 of the LPACAP, "General conditions for the practice of notifications," provides: "When the interested party is notified through different channels,
the date of notification will be taken as the date of the first one."
SIXTH: Extension of the deadline for objections.
By means of a document submitted on May 8, 2024, CDE requests, pursuant to Article 32 of the LPACAP (Administrative Administrative Procedure Act), that the deadline for submitting arguments and proposing evidence be extended, since, given the complexity of the matter in question, it is extremely difficult to submit them within the period initially granted (folios 1,808 and 1,823 to 1,824).
It provides a copy of the notarial deed granting power, dated September 2, 2020, which shows that the individual appearing as CDE's attorney is authorized to intervene on its behalf in this administrative sanctioning procedure in all its steps and instances with full authority (folio 1,822).
By means of a document dated May 10, 2024, notified and accepted on the same date (folios 1,825 to 1,826). 1,827) responds to the entity granting the requested extension.
SEVENTH: Objections to the initiation agreement.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 48/204
CDE presents its objections on May 21, 2024 (pages 1,829 to 1,854) in which it
requests that this sanctioning procedure be closed. In addition, in the event that the Agency finds any
infringement of the GDPR, it requests the application of Article 77 of the LOPDGDD and argues that
"it has acted at all times in its capacity as a Public Law Corporation."
Regardless of the preceding procedural claims, CDE requests that the
information contained in its objections "not be communicated to any third party."
In defense of its claims, it invokes the following arguments:
A. As "preliminary questions," it examines the following:
1. It asserts that it "does not transfer" the NIF (Tax Identification Number) of individual entrepreneurs to CAMERDATA.
In this regard, it maintains that during the validity of the GDPR, there has never been a transfer of the NIF (Tax Identification Number) of individuals to CAMERDATA. It states that the NIF data "is not transferred to Camerdata, but is delivered encrypted using a one-way, irreversible algorithm." That is, a "hash" is provided, the result of an encryption process, "so the truth is that Camerdata does not receive these NIFs from CDE."
It adds that "The "hash" is part of the Public Business Registry, since without it, this registry could not be managed, but it is not accessible on the Internet for company-by-company consultation because it is not necessary for that purpose." And that "The inclusion of the "hash" is necessary to distinguish between entrepreneurs with the same first and last names (who would otherwise be confused) or to operate with entrepreneurs who have changed their first name, the order of their last names, or the last names themselves: the hash remains unchanged, but the NIF is not used, thus minimizing the risk of error in the processing of personal data."
That, as CAMERDATA has stated, this entity obtains the NIFs by its own means. It provides as an attached document a certificate signed on 05/16/2024 by
***POSITION 1.
It also states: "Please note that, according to Clause I of the Contract, the "Transferred Database" is the entire "Basic Business Census," and that, as clarified in Exhibit V, the "Basic Business Census" is nothing other than the "Public Business Census" under a different name."
It also states that "prior to the GDPR's entry into force, the NIF (Tax Identification Number) data had not been processed" and states on this matter that, "despite including the NIF (Tax Identification Number) in a general sense,
Annex I [of the contract between CDE and Camerdata] made it clear that the NIF (Tax Identification Number) of individuals was not included in the Transferred Database, which contains "only" the data referred to in Clause 12.2."
The text of clause 12, “Processing of personal data,” point 2, of the
Contract signed between CDE and CAMERDATA states:
“The Transferor also declares that the Transferred Database and its
updates contain data relating to individual entrepreneurs and data of
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 49/204
individuals who provide services to legal entities, relating
solely to their first and last names, the functions or positions held, as well as their professional postal or email address, telephone number, and fax number,
all in accordance with the provisions of Article 2 of the RLOPD.”
CDE concludes: “Therefore, under no circumstances can CDE be held responsible for transferring the NIF data to Camerdata.”
2. No data subject has filed a complaint with the CDE, nor has it been proven that
the CDE has caused harm to potential data subjects.
The Court states that, while it is aware that the AEPD may act ex officio, the GDPR has established the right to file a complaint with the supervisory authority as a right of data subjects, and the Institute for Democratic Culture in the
Digital Age has not proven that it acts on behalf of any self-employed person. In this regard, it emphasizes that the GDPR has brought about a substantial reform in the position of data subjects and complainants and invokes the Supreme Court ruling of 05/06/2021, ECLI:ES:TS:
2021:1584.
B. The first allegation concerns a violation of the principle of lawfulness, Article 6.1 of the GDPR.
It begins by recalling that the opening agreement attributed to CDE "a violation of the principle of lawfulness (Article 6.1 of the GDPR), materialized by having transferred to the company Camerdata, S.A. (hereinafter CAMERDATA) data of individual entrepreneurs that were lawfully in its possession, received from the tax authorities in compliance with the provisions of Article 8 of Law 4/2014."
1. It explains that CDE is a Public Law Corporation that pursues purposes of public interest, Article 20.1 of Law 4/2014, of April 1, Basic Law of Official Chambers of Commerce, Industry, Services, and Navigation (Law 4/2014)
“The Official Chamber of Commerce, Industry, Services, and Navigation of Spain
is a public law corporation, with its own legal personality and
full capacity to act in the fulfillment of its purposes, which is configured
as an advisory and collaborative body with the General Administration of the
State.”
It devotes a section to examining “The legal-public function of preparing and
publishing a public census of companies” and makes a specific
interpretation of Article 5.1.g) of Law 4/2014, a provision that establishes: “g)
Manage, in accordance with Article 8 of this Law, a public census of all companies, as well as their establishments, delegations, and agencies located in their district."
Thus, CDE maintains that the management of the public census includes: the preparation
(regulated in Article 8 of Law 4/2014) and its "effective publication," such that
this provision attributes to it the public legal function of "preparation and publication of a public census of companies."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 50/204
Regarding the publication of the Public Census of Companies, it states that there is no regulation that explains (i) how it should be verified, (ii) what the precise content of the information to be included in the public census is.
And then it states that, therefore, it is up to the CDE, in the exercise of its assigned legal-public function, to determine which fields are included in the public business register and what means are used to publicize the register. In this regard, it states:
"The Law merely states that not all information provided by the Tax Administration will be included in the Public Business Register."
It maintains that the AEPD, in the exercise of its powers, must respect the
exercise of the legal-public functions assigned to the CDE. The AEPD may verify that the CDE acts within the limits established by the GDPR, but only the CDE is competent to determine whether or not a particular field should be included
in the public business register and how the public business register should be publicized.
2. Regarding the duty of confidentiality established in Article 8 of Law 4/2014, which is
mentioned in the initiation agreement, it states that any information that CDE has received from the tax authorities and that has not been
included in the Public Business Census is subject to the duty of confidentiality. Therefore, it maintains that the duty of confidentiality does not apply to the information that makes up the Public Business Census that "CDE has the legal mandate to publish."
3. Regarding the legitimate grounds for its data processing, it states that the
transfer to Camerdata of the personal data from the Basic Business Census
is covered by two processing bases: (i) compliance with a legal obligation,
Article 6.1.c) GDPR, and (ii) the necessity of the processing to fulfill a mission carried out in the public interest,
Article 6.1.e) GDPR.
(i) Article 6.1.c): compliance with a legal obligation imposed on the data controller.
It alleges that Article 5.1.g), in conjunction with Article 8, both of Law 4/2014,
"obliges CDE to maintain a public census of all companies, as well as their establishments, branches, and agencies located within its jurisdiction."
It states that, although this provision "does not explain how the Public Census of Companies should be made public, the legislative mandate is clear: it is a public legal function within the jurisdiction—in this case—of CDE."
Based on the preceding statement, it states that:
It makes the Public Business Census public in two ways:
(i) by opening it to public consultation on the Internet, which can be done on the website available at https://censo.camara.es/ and
(ii) "by transferring the Basic Business Census to Camerdata so that it can use it […] as a reliable source in the preparation and updating of its
Spanish Business File."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 51/204
The first way (i) only allows consultation on a company-by-company basis, "and is therefore not useful for automated processing."
The second way (ii) makes the entire Public Business Census susceptible to computer processing, "thus fulfilling the legislator's mandate in the best possible way."
It warns that “CDE could have devised more ways to fulfill its
legal obligation to publish the Public Business Register, given that the
Law neither identifies nor restricts the ways in which said register must be made public:
it only requires that it be published and entrusts CDE with such publication.”
It states: “And, as seen above, CDE under no circumstances incorporates the NIF (Tax Identification Number) of individuals who are entrepreneurs or
professionals into the Public Business Register, but rather replaces it with a “hash” produced using a
one-way and irreversible algorithm.”
(ii) Processing necessary to fulfill a task carried out in the public interest (Article
6.1.e, GDPR)
- The domestic law on which the processing is based is Law 4/2014, which requires it to “publish the Public Business Register.”
-The various actions carried out by CDE in relation to the Public Registry of Companies derive from the public function attributed to it by Article 5.1.g) of Law 4/2014, under which CDE is entrusted with the task of "managing, in accordance with Article 8 of this Law, a public registry of all companies."
- The scope of the public interest is broad. It cites Legal Report 2018/175, page 10:
"Section e) "public interest mission" must be interpreted broadly,
in such a way as to allow public authorities, including within the scope of private law, to process personal data necessary for the legitimate purposes granted or permitted by law."
- It states that in order to assess whether or not there is a public interest in the transfer of the
Public Business Registry to Camerdata, in exercising the powers legally
attributed to it, it has taken into account the following considerations:
As has been seen, CDE, in the exercise of its legal-public functions, has
decided not to include the NIF of individuals in the Public Business Registry,
but only a "hash" resulting from one-way and irreversible encryption.
It adds that "the hash is necessary for the management of the Public Business Registry,
because, as explained above, the inclusion of the hash is necessary to
discriminate between business owners with identical first and last names (who would otherwise be confused) or to operate with business owners who have changed their name (including
in the case of a gender change), the order of their last names, or the last names themselves: the hash remains unchanged, but the NIF is not used, thus minimizing the risk
of error in the processing of personal data."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 52/204
"The hash is necessary to comply with the legal obligation established in Article
5.1.d) of the GDPR to ensure that personal data is accurate and up-to-date."
"With respect to all data included in the Public Business Registry
subject to transfer, except for the "hash," the circumstance exists that this data
for which a legitimate basis is presumed to exist under
Article 19.1 of the LOPDGDD. The two requirements established
in the regulation are met, since the data transferred is only that
necessary for professional identification, and the purpose is to allow
any third party to maintain relations with the company (individual or not)."
All data included in the Public Business Registry subject to transfer,
except for the "hash," is data that could be found, if searched,
by a simple company-by-company search of the Public Business Registry
available on the Internet openly to anyone.
There is a public interest in identifying entrepreneurs and professionals who
participate in legal transactions. It states that this public interest is satisfied in several ways, "including the Commercial Registry itself (which, however, does not list all individual entrepreneurs or professionals) and the obligation
established in Article 10 of Law 34/2002, of July 11, on Information Society Services, for any entrepreneur (individual or not) who
offers services on the Internet (in practice, almost all of them),
expressly including the NIF (Tax Identification Number), etc. However, only the Public Business Registry
allows access to the identifying data of entrepreneurs and professionals
(except for the NIF, as stated) in a complete and reliable manner." "It is important
for legal transactions to have this database, and to have it not only in the company-to-company search format (which is what the online application allows) but also in a format that can be processed electronically by companies. This is possible by transferring the
Basic Business Census to Camerdata."
The price of the Contract does not constitute the interest that CDE seeks for the transfer
of the Public Business Census, but rather is a means of recovering a portion
of the costs that CDE incurs in the computer processing of said Census in order to make it accessible (publish it) in full and not just on a query-by-query basis. Obviously, CDE's interest does not lie in the
€50,259.65 plus VAT that, according to Annex 2 of the Contract, constitutes
the price of the Contract, as this sum is insufficient to cover the IT costs
involved in making the Basic Business Census available, which total €53,358.
“For the 2024 fiscal year, CDE has a budget for the development of
public-administrative functions amounting to 1,973,480 euros (available
at the URL https://www.camara.es/sites/default/files/2024%20PRESUPUESTO
%20ORDINARIO%20PORTAL%20DE%20TRANSPARENCIA.pdf), which
includes the budget for the preparation and dissemination of the public census of
companies under the terms provided for in Law 4/2014. Pointing out, as the
AEPD does, that the “real” interest sought to be satisfied with the processing is the
commercial interests of both entities does not reflect reality, and is nothing more than—with all due respect—a statement of The AEPD is not
based on any data or assessment. Rather, as we say,
the CDE acts based on a public interest, which is none other than providing a
better public service to businesses and the community.
C. The second allegation concerns a violation of the purpose limitation principle (5.1.b)
- CDE states that the initiation agreement has attributed a violation of this
provision to it "by considering, [...], that the transfer of data to CAMERDATA "is
different from the processing that Article 8 of Law 4/2014 empowers it to carry out
with the data of self-employed entrepreneurs obtained from the tax authorities."
- It maintains that there has been no further processing of the data from the tax authorities "since the sole and exclusive purpose of the processing is
to comply with the legal obligation to prepare and manage the Public Business Registry
under the terms provided for in Law 4/2014. What has been done is precisely to make
the Public Business Registry public, the transfer being an instrument to achieve
this end."
-It denies that there has been any subsequent data processing for any purpose other than the initial one, so it would not have incurred a violation of the principle of purpose limitation, since "the processing carried out by CDE, including the transfer of the data to CAMERDATA, has the sole and exclusive purpose of complying with the
legal obligation to publicize the Public Business Census established in Law 4/2014 and thus pursuing a public interest, […]"
-It insists that the purpose for which the data received from the Tax Authorities are processed is to make the census public, and for that same purpose,
they are transferred to Camerdata: "The data is processed to make the Public Business Census public, and is transferred to Camerdata (an entity wholly owned by CDE and
various Chambers) for the same purpose. Once transferred, Camerdata may use them
for its own purposes, which must always be compatible with the purpose of making the data public. In any case, the transfer agreement includes a
clause that obliges the Transferee to "strictly observe and comply at all times
with the rights and obligations of each party regarding access, processing,
and transfer of data."
D. The third allegation concerns a violation of the confidentiality principle (Article 5.1.f GDPR).
The Court denies the alleged violation. It states that "CDE has taken measures to process personal data, specifically personal data relating to the NIF (Tax ID Number) of individual entrepreneurs, in a manner that guarantees adequate security" "both with respect to company-to-company consultations via the website and with respect to the Public Business Register provided (Basic Business Register)."
It states: "In the former, the NIF (Tax ID Number) is not recorded." In the latter, "the NIF (Tax ID Number) of individual entrepreneurs is not transferred to Camerdata, nor does Camerdata receive it from the Court."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 54/204
- Regarding the first point (consulting the company-by-company online), it says:
“As the AEPD itself points out in its Initiation Agreement, ‘[i]n the public census accessed from the CDE website, information is provided for individual entrepreneurs: name and surname, address (street, number, and sometimes apartment), town, province, and postal code. Also included is the IAE (Tax Identification Number) section and a description of the activity. However, the NIF (Tax Identification Number) is not included.’” This demonstrates that CDE has taken measures to process personal data,
specifically, personal data relating to the NIF (Tax Identification Number) of individual entrepreneurs, in a way that guarantees adequate security.
The public business census can be accessed online (https://www.camara.es/funcion-consultiva/consulta-del-censo-publico-de-empresas), and the CDE offers
the following information: As can be seen, in the section regarding the description
of the public business census at this URL, the data relating
to: Name, Address, Postal Code, Municipality, Activity are mentioned. "There is no reference
to the NIF (Tax Identification Number) of individual entrepreneurs, as it is not included in the public business census. Nor is it a search criterion to be used if you wish
to consult the census through https://censo.camara.es/, this link being
available at the URL indicated above."
-Regarding the second point (publication of the Public Business Census through its transfer to Camerdata), it states:
"CDE adopted another relevant security measure to protect the confidentiality of data relating to the NIF of individual entrepreneurs, consisting of the irreversible encryption of the NIF of individual entrepreneurs, achieved through the application of an irreversible encryption algorithm.
Neither CDE transfers the NIF data of individual entrepreneurs to Camerdata, nor does Camerdata receive it from Camerdata.
CDE applies the MD5 hash algorithm (short for Message-Digest Algorithm 5), which is unidirectional and irreversible.
It adds: “As the AEPD Legal Department has explained, “the hash algorithm should always allow the same digital fingerprint to be generated, starting from the same data or microdata, but starting from a specific digital fingerprint, we could never obtain the original data; that is, it guarantees the confidentiality of microdata since it is a one-way mathematical operation.” (Legal Report 0364/2015, consulted at https://www.aepd.es/documento/2015-0364.pdf, pp. 13 and 14).”
The GDPR mentions encryption in Recital 83, stating that “In order to maintain security and prevent processing from infringing the provisions of this Regulation, the controller or processor must assess the risks inherent in the processing and implement measures to mitigate them, such as encryption.”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 55/204
This is one of the appropriate technical and organizational security measures included in Article 32.1.a) of the GDPR.
It states: "Regarding encryption, the AEPD itself states that "The characteristic aspect of encryption is that, without access to the appropriate key, it should be impossible to access the content of the encrypted information or alter it without the changes being detected." (Guidelines for the validation of cryptographic systems in data protection, May 2023, consulted at the URL
https://www.aepd.es/guias/orientaciones-criptografia-aepd-isms-apep.pdf).
E. The fourth allegation concerns the violation of the principle of loyalty and transparency
(Article 5.1.a, GDPR)
CDE claims that the initiation agreement accuses it of a triple violation of the principle of transparency:
(i) Failure to notify the tax authorities of the transfer made to Camerdata;
(ii) Failure to notify the data subjects whose personal data have been transferred of the fact of the transfer;
(iii) “As a contracting party with Camerdata,” failure to “ensure that data subjects are provided with truthful information about the origin of the data.”
Regarding point (i), it argues that it “failed to inform the data subjects of the subsequent processing of the data.” the
Tax Authorities”:
That, “in the terms set out above, the transfer to
CAMERDATA is part of the processing carried out by CDE for the purpose of
publicizing the Public Business Census without any
subsequent processing for a purpose other than the original one and, therefore, is
inherent to the provisions of Law 4/2014 and the second clause of the
Agreement between the State Tax Administration Agency and CDE for the
exercise of the latter's public-administrative functions, […] The transfer
of the Public Business Census to Camerdata is part of the
purpose of making public the information contained in the aforementioned
Public Business Census, a purpose expressly contemplated in the Agreement.”
The manner in which the Public Business Registry must be made public is not limited by the Convention or the Law. CDE is entrusted with the public-legal function of establishing it.
Regarding section (ii), “having deprived individual entrepreneurs of information about the transfer of their data to third parties and the purposes for which it is communicated,” it rejects this statement for three reasons:
Exception to Article 14.5.a) of the GDPR: “First, the publication of the Public Business Registry is provided for in Law 4/2014, so it is a process known to the data subjects and falls within the exception contemplated in Article 14.5.a) of the GDPR, which provides that “[t]he provisions of sections 1 to 4 shall not apply when and to the extent that the data subject already has the information” (emphasis added).”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 56/204
Exception to Article 14.5.b) GDPR: Secondly, "notifying each and every Spanish individual entrepreneur of the transfer would be disproportionate (Article 14.5.b) GDPR), taking into account that the transfer is not the NIF but the hash, that the hash is part of the Public Business Registry, and that the rest of the data is accessible on the Internet. There are 1,459,498 individual entrepreneurs. The GDPR explains in Recital 62 that “it is not necessary to impose an obligation to provide information when the data subject already possesses the information, when recording or communicating the personal data is expressly required by law, or when providing the information to the data subject is impossible or requires a disproportionate effort” (emphasis added).”
Exception to Article 14.5.c) GDPR: Third, “since the mandate to make the Public Business Register public is established by law, Article 14.5.c) GDPR also applies, since it is the law that mandates the publication of the Public Business Register.”
Regarding point (iii), that “CDE, as a contracting party with CAMERDATA, has not ensured that data subjects are provided with truthful information about the origin of the data,” it argues:
This information is not provided for in Article 14 of the GDPR and,
even if it were, it would only be required of the data controller who
receives the data from another data controller, CDE being the ultimate controller in this case.
That the AEPD introduces here an “additional guarantee” that is not provided for in the
GDPR; which in the present case would already be covered by the provision that “The Parties undertake to observe and comply, strictly and at all times, with each other's rights and obligations regarding access,
processing, and transfer of data” (Clause 12.1 of the data transfer agreement),
which again means that the transferee must inform
about the origin of the data when it is necessary to comply with Article 14 of the GDPR, without the need for the transferor to impose an obligation that is provided for in the applicable data protection legislation and that is included within the provisions of the contract under the terms already indicated.
F. Fifth allegation, regarding the imposition of sanctions.
Alternatively, in the event that the AEPD finds that any violation of the GDPR has been committed, it requests that the legal regime described in Article 77 of the LOPDGDD be applied, maintaining that it has acted at all times as a
public law corporation.
It indicates that Law 4/2014 contemplates the action of CDE as a Public Law Corporation in the fulfillment of the public-administrative functions assigned to it, in particular those "relating to the management and publicity of the public business register." And therefore, if any violation of the GDPR is found, it would be appropriate
to apply Article 77 LOPDGDD, according to which the AEPD "shall issue a resolution
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 57/204
declaring the violation and establishing, where appropriate, the measures to be adopted
to cease the conduct or correct the effects of the violation that may have been committed" (Article 77.2 LOPDGDD).
Furthermore, it proposes as evidence the documentary evidence already in the file,
including the prior actions, and the evidence it provides with its allegations: a single
document, a certificate issued by ***POST.1.
EIGHTH: Evidence Phase. Opening and list of evidence to be taken.
On September 16, 2024, the investigating body agreed, in accordance with the provisions of Article 77.2 of the LPACAP (Spanish Criminal Procedure Law), to open a thirty-day trial period.
This is stated in the Diligence signed on that date (September 16, 2024), which details the
evidence it agrees to conduct (pages 1,864 and 1,865), in particular the following:
1. To reproduce for evidentiary purposes:
1.1. The complaint filed by the association Institut per a la Cultura Democratica a L'era Digital (Institute for Democratic Culture in the Digital Age) on December 27, 2022.
1.2. The internal note from the Agency Director, dated April 13, 2023, in which, in view of the complaint received, she urges the Subdirectorate General of Inspection to initiate preliminary investigations in accordance with Article 67 of the LOPDGDD (Spanish Data Protection Act).
1.3. All documentation generated and received during the preliminary investigations carried out, as well as the Investigation Report signed by the acting inspector.
1.4. The allegations of the respondent party regarding the agreement to initiate the sanctioning procedure and its accompanying documentation, consisting of a single "confidential" document: A certificate signed on May 16, 2024, by ***POST.1, with NIF A78035896.
2. Incorporate into this file (EXP202301678):
2.1. The following documents are part of the sanctioning file with
reference EXP202404641, which is being processed against CAMERDATA, S.A., with
NIF A78035896: Your allegations regarding the initiation agreement and the documents attached to allegations numbers 5 and 6.
2.2. The screenshots obtained from the census of Spanish companies accessible
from the CDE website.
2.3. The AEPD Legal Department Report number 089/2020.
3. Request:
3.1. CDE to send certain information and documentation to the AEPD.
3.2. CAMERDATA, S.A., with NIF A78035896, to send certain information and documentation to the AEPD.
3.3. To the State Tax Administration Agency (AEAT) and the tax agencies of the Provincial Council of Navarre and the Autonomous Community of the Basque Country to submit certain information and documentation to the AEPD.
(Pages 1864 and 1865)
NINTH: Evidence Phase. Document Incorporation Procedures.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 58/204
1. By means of a diligence signed by the investigating body on 09/16/2024, it is hereby recorded
that the following documents have been incorporated into the file of this sanctioning procedure on that date (page 1866):
-Written allegations regarding the agreement to initiate EXP202404641 submitted to this
Agency by the company Camerdata, S.A. (Incorporated as Annex 1 to the diligence, folios 1,867 to 1,923)
-The documents attached to the written statement of allegations submitted by Camerdata, S.A. in
EXP202404641, identified by numbers 5 and 6. They are, respectively, a document signed by the CEO of Kompass Spain on 05/10/2024 (incorporated as Annex 2 to the diligence, folio 1924) and the Confidentiality Agreement signed between
Camerdata, S.A., and Dmovo Analytics, S.L., on 12/18/2019 (incorporated as Annex 3 to the diligence, folios 1925 to 1932).
2. Through a diligence signed by the investigating body on 09/16/2024, the incorporation of the Legal Office Report number 089/2020 of the Spanish Data Protection Agency into this disciplinary proceeding is recorded. (Page 1,931, document incorporated on pages 1932 to 2,105).
3. By means of a document signed by the investigating body on September 17, 2024,
it is noted that four screenshots obtained on September 16, 2024, from the CDE website, specifically from the Public Business Census, are incorporated into this file.
Accessible at https://www.camara.es/funcionconsultiva/consulta-del-censo-publico-de-empresas.
The formal notice states that the screenshots included show
the following details (folio 2,106, corresponding to the formal notice, and screenshots 2,107 to 2,111 included):
1. That CDE, on its website, under the heading "Public Business Census", "DESCRIPTION", provides the following information:
"We provide you with the data included in the Public Census containing all the legal and physical entities of the Official Chambers of Commerce, Industry,
Services, and, where applicable, Navigation of Spain."
That the file "contains one record per activity (it does not accumulate several activities at the same address) and compiles the following data per record: Name,
Address, Postal Code, Municipality, Activity."
Therefore, the NIF (Tax Identification Number) is not included among the data provided.
2. That, in relation to individual entrepreneurs, after a query is made to the public business census, the data provided is: first and last name, postal address (street name and number), postal code, name of the province and municipality, IAE code, and description of the activity.
3. That, after a query is made by an individual entrepreneur to the public business census, below the information indicated in point 2 above,
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 59/204
the following legend is included with a direct link to CAMERDATA: "If you wish to obtain
more information, consult the Camerdata Online Business File."
TENTH: Testing Phase. 1. Tests carried out before the CDE. 2. Response
1. Evidence presented before the CDE:
By means of a document signed by the investigating body on 09/16/2024, the notification of which was accepted by the CDE on 09/17/2024 (folio 1,862), the opening of an evidentiary phase in this proceeding is communicated for a maximum period of thirty days and the evidence that has been agreed to be presented.
In this document, the CDE is informed (i) of the documents that are deemed reproduced for evidence purposes—which are the same as those listed in point 1 of the eighth
Factual Background, to which we refer to avoid unnecessary repetition—and (ii) of the documents that it is agreed to incorporate into this proceeding—which are the same as those listed in point 2 of the eighth
Factual Background, to which we refer—(folios 1,855 to 1,860).
CDE is requested to provide the Agency with the information and documentation detailed below:
1. Article 31.2 of the LOPDGDD provides that the subjects listed in Article 77.1 thereof shall make public an "inventory of their processing activities accessible by electronic means," which shall include the information established in Article 30
of the GDPR and its legal basis. To this end, it is requested to submit:
(i) Information about the space on its website where CDE's inventory of processing activities is published and a screenshot certifying such publication.
(ii) A copy of CDE's record of processing activities related to the public census of entrepreneurs.
2. In relation to the Agreement that CDE signed with the AEAT in 2019 for the transfer of tax information "for the exercise of its public-administrative functions," extended and amended in December 2023, you are requested to provide the following documents, which were required to be prepared during the processing prior to the signing of the aforementioned Agreement, and, where applicable, its amendment, in accordance with the provisions of Article 50 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector (LRJSP):
(i) The "explanatory memorandum" referred to in Article 50.1 of the LRJSP.
(ii) The "Report of its legal department" referred to in Article 50.2.a) of the LRJSP.
3. You are requested to explain the reasons why you decided not to include the NIF data of individual entrepreneurs in the public census accessible from your website. You are also requested to explain the reasons why you have decided—as stated in your allegations—not to include the NIF data of self-employed individuals in plain text in the database you provide to CAMERDATA and instead replace it with a hash algorithm.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 60/204
4. Please explain the reasons why you have chosen not to allow the
global download of information on individual entrepreneurs included in
the Census of Spanish Companies accessible from its website.
5. CDE has stated (objectives to the initiation agreement) that the transmission of data
to CAMERDATA is an instrument to achieve the purpose, it says, imposed by Law 4/2014, of "making the Public Census of Companies public." Please explain whether
the purpose for which you receive the data of self-employed entrepreneurs from the
Tax Authorities under Law 4/2014 is the same as that served
when you transfer your database to CAMERDATA, knowing that the latter has
signed contracts with third-party entities whose business activity is to market
the database and in which CAMERDATA has agreed with these third-party entities,
in order to guarantee its business, the confidential treatment of the information contained
in said database.
6. In your written submission to the initiation agreement, you stated that "the hash is
part of the Public Business Registry [...] but is not accessible on the Internet through
company-to-company consultations because it is not necessary for that purpose" (page 4); that
"CDE under no circumstances incorporates the NIF (Tax Identification Number) of individuals, entrepreneurs, or professionals into the Public Business Registry, but rather replaces it with a hash" (page 10 of your letter); that "the Transferred Database" is the entire "Basic Business Registry," and that, "as clarified in Exhibit V of the Contract," the "Basic Business Registry" is nothing other than the "Public Business Registry" under a different name" (page 3 of your letter).
In light of these statements, you are required to explain:
(i) What is the purpose of using three terms in the contract signed with Camerdata—Public Business Registry, Basic Business Registry, and Transferred Database—if, as inferred from your statements, the three files have the same content?
(ii) If each of the three terms used designates a file that
presents any difference(s) in content or of any other nature in relation to the others, you must specify it, provide the structure of the file, identifying the type of data it contains, and provide documentary evidence of your response.
7. In light of your statements—set forth in the preceding section, point 6—you are
required to inform and provide documentary evidence of which file—"Public Business Census," "Basic Business Census," or "Transferred Database"—the extract of 500 records that you sent to this Agency during the preliminary investigation ("Document_4.xlsx" provided by that party) belongs to, which you then stated came from the Public Census, and which does include the NIF (Tax Identification Number) of the aforementioned 500 self-employed workers.
8. In your allegations regarding the initiation agreement, you have stated (page 10) that "CDE in no case incorporates The Public Business Registry does not include the NIF (Tax Identification Number) of individuals, entrepreneurs, or professionals, but instead replaces it with a hash. The registry has stated that "The inclusion of the hash is necessary to discriminate between entrepreneurs with the same first and last names (which would otherwise be confused) or to operate with entrepreneurs who have changed their first name, the order of their last names, or the last names themselves: the hash remains unchanged, but the NIF is not used, thus minimizing the risk of error in the processing of personal data."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 61/204
It also adds that "The hash is part of the Public Business Registry, since without it, this registry could not be managed, but it is not accessible online for company-by-company consultation because it is not necessary for that purpose."
(i) Does this mean that, with respect to self-employed entrepreneurs, CDE has in its systems, in addition to the plain text of the NIF data for those entrepreneurs, the hash resulting from applying this algorithm to their NIF?
(ii) It has stated that the hash of the NIF for individual entrepreneurs is part of the Public Business Registry, even though it is not accessible through its website, and queries can only be made on a company-by-company basis. Does the NIF hash serve any purpose in the Public Business Registry query process through its website, for example, to help differentiate between entrepreneurs?
(iii) In addition to applying the hash function to the NIF data for individual entrepreneurs, does CDE also apply the hash function to the rest or part of the data for self-employed entrepreneurs in its database?
(iv) If so, does CDE provide CAMERDATA, in addition to the plain text data, the "hash" resulting from applying this function to the remainder or part of the data collected in the records of each self-employed entrepreneur?
9. Please explain the purpose or function of the "registration indicator" and how it is generated: a number included in the "ID" field in each of the records of self-employed entrepreneurs included in the list of 500 self-employed entrepreneurs that CDE provided to this Agency, at the request of the acting inspector, during the investigation.
10. In its submissions to the opening agreement, it has insisted that it does not provide CAMERDATA with the NIFs of self-employed entrepreneurs, "but rather a "hash" resulting from an encryption process (using a one-way algorithm), so the truth is that Camerdata does not receive these NIFs from CDE." You added that including the
NIF hash in the database you are providing is necessary to address various
purposes, including "discriminating between entrepreneurs with the same first and last name (who would otherwise be confused)."
Explain the reason for providing CAMERDATA with the NIF hash when, to address the needs you mention, an identification code could be used (such as the "registration indicator" in the "ID" field) and, in any case, a unique number linked to each record could be used.
11. Regarding the technical procedures that CDE carries out in relation to the information received from the Tax Authorities.
In order to incorporate into its database the information related to each individual entrepreneur
received from the Tax Authorities, of which the list of 500 records provided during the course of the Investigation Actions is representative,
CDE is required to carry out various technical procedures.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 62/204
Please report whether the necessary technical procedures performed by the entity have been
carried out, from 2020 to the present, through: (A) CDE's own IT services or (B) through third-party companies with which it has signed
the appropriate contracts.
Depending on the nature of your response, you must provide the following documents:
If the procedures are performed by CDE's own IT services (assumption A):
(i) Documentary evidence of the number of CDE employees who,
since 2020, have performed these technical procedures, indicating their qualification level.
(ii) Internal service instructions or orders (since 2020) with which CDE's IT department has worked to carry out technical procedures related to the information they
receive from the Tax Authorities.
If the services are provided by a third-party company (assumption B):
(i) Identification data of all companies with which the CDE IT department has contracted the provision of these services from 2020 to the present.
(ii) A copy of all contracts signed since 2020 with the companies you
mentioned in your response to point 1. You must include all annexes that are part of the contracts, where applicable, particularly those in force in 2023 and 2024.
12. Description of the "system" that CDE has been using to transmit data
to CAMERDATA. You are required to report and certify whether and since when the data transmission has been carried out, either through online access or physical media.
13. In the case of an online data transmission, you are required to:
(i) Provide documentation proving CAMERDATA access during 2023 and 2024 and access to updates for the fourth quarter of 2024.
(ii) Provide the full content accessed by CAMERDATA in 2023 regarding the same 500 self-employed entrepreneurs whose CDE records were submitted to this Agency on December 21, 2023, under the name "Document_4.xlsx".
14. In the case of data output on physical media (DVD, USB, etc.), you are required to provide:
(i) Proof of the physical media output, in accordance with the model (or equivalent) entitled "Authorization for the Output of Computer Media" appearing on page 28 of the PDF document submitted to this Agency in its response dated December 21, 2023, entitled "Documents 1 and 5.pdf", relating to the submissions made by CDE to CAMERDATA during 2023 and 2024 and the submission relating to the updates for the fourth quarter of 2024.
(ii) A complete copy of the data contained on the physical media, DVD/USB, sent in 2023, limited to the 500 self-employed entrepreneurs whose records CDE provided to this Agency on December 21, 2023. with the name “Document_4.xlsx”.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 63/204
15. If the NIF hashes are not transferred through the operations mentioned in the previous points, provide a copy of the records in the CDE Assigned Database, where the NIF hashes, calculated by CDE, are stored and transferred to CAMERDATA associated with the data of the 500 business owners provided by CDE to this Agency on December 21, 2023, under the name "Document_4.xlsx".
2. CDE's Response to the Requested Evidence:
In a letter dated September 24, 2024, CDE requested, pursuant to Article 32.1 of the LPACAP (Spanish Accords of Public Prosecution), that the initially granted period of ten business days be extended by the maximum legally permitted period (pages 2112 to 2130). The
investigating body agreed to grant the extension requested in a letter signed on September 26, 2024, the notification of which was accepted by CDE on the same date (pages 2131 to 2134).
On October 9, 2024, CDE responded to the requested evidence (pages 2135 to 2256):
- To the question regarding the inventory of processing activities, CDE responded that it was published in the "Transparency" section of the Spanish Chamber of Commerce website.
Attached in Annex I is a screenshot certifying the publication of the inventory of CDE processing activities on its website and informs that it can be accessed via the link https://www.camara.es/registro-de-actividades-del-tratamiento.
As Attached in Annex II is a copy of the aforementioned record of processing activities from the Spanish Chamber of Deputies (pages 2,139 and following). Section 10. “Company Census” (pages 2,144 and 2,145) contains the following information:
“Description—Compilation of a public census of companies that carry out commercial activities in Spain.
Purposes—Compilation of a public census of national or foreign companies that carry out commercial and industrial service and shipping activities in Spain.
Categories of interested parties—Contact persons, Applicants.
Retention criteria—Retained for NO LONGER THAN NECESSARY to achieve the purposes.
Processing system—Partially automated.
Categories of data.
Types of data—First and last name, Postal or email address, Telephone.
Categories of special or criminal data.
Other types of data—Employment details.
Categories of recipients—Transfers: Organizations or individuals directly related to the controller, Public registries.”
-Responding to the request to provide the Report of your Legal Department and the explanatory memorandum referred to in Articles 50.1 and 50.2.1 of Law 40/2015, the following responds:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 64/204
“The processing and approval of the agreements signed by the Spanish Chamber of Commerce is carried out in accordance with the provisions of Article 21.2 of Law 4/2014, of April 1, Basic Law of the Official Chambers of Commerce, Industry, Services, and Navigation, and Article 10.u) of the Internal Regulations of the Spanish Chamber of Commerce, approved by Order ECC/953/2015, of May 14.
In compliance with the foregoing, the Agreement […] and the Amendment Addendum and
the extension of the aforementioned Agreement—signed on December 19, 2023—were submitted
for approval to the Executive Committee of the Spanish Chamber, at its sessions
held on October 2, 2019, and November 23, 2023,
respectively. The supporting reports that accompanied the aforementioned Agreement are attached as Annex III and Annex IV.
CDE provides (pages 2,151 et seq.) as Annex III the "Report on the agreement between
the State Tax Administration Agency and the Official Chamber of Commerce,
Industry, Services, and Navigation of Spain for the transfer of tax information to the Official Chambers for the exercise of their public-administrative functions," signed on September 27, 2019. The CDE states that it was issued by the Director of
the CDE's Legal Services and that it was submitted to the Chamber's Executive Committee
along with the Agreement submitted for approval (the document provided does not indicate the signatory's
position in the organization).
The report, in the second paragraph of the "Actions to be Taken" section, emphasizes that the
transfer of data from Tax Administrations to the CDE has a sole and exclusive purpose: the preparation of the public census. And it adds that this information may not be used for any other purpose than the bodies of the Spanish Chamber of Commerce or the Chambers that have been assigned functions that justify the transfer of data:
"The transfer of IAE data and company census data will be for the exclusive purpose of compiling the public company census, fulfilling the public-administrative functions that Basic Law 4/2014 of the Official Chambers of Commerce, Industry, Services, and Navigation assigns to the Chambers, as well as compiling the electoral census referred to in Article 17 of the same Law.
The information transferred by the Tax Agency may only be used for the
bodies of the Spanish Chamber of Commerce and the Chambers that have been assigned the public functions that justify the transfer."
- To the question of whether the purpose for which the data of self-employed entrepreneurs is received by the Tax Authorities under Law 4/2014 is the same as that served when it provides its database to CAMERDATA, knowing that the latter has signed contracts with third-party entities whose business activity is to market the database and in which CAMERDATA has agreed with these third-party entities, in order to guarantee its business, to treat the information contained in said database confidentially, CDE responds:
"The answer is negative. The purpose for which the data of self-employed entrepreneurs is received by the Tax Authorities is the
rigorous preparation and updating of the Public Business Registry, which contains less data than that received from said Tax Authorities, as well as to fulfill the other purposes of the CDE.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 65/204
The purpose for which the Public Business Registry thus compiled is transferred to CAMERDATA is exclusively to comply with the legal mandate to publicize the Public Business Registry.
CAMERDATA is a commercial company that has its own management bodies and is responsible for its own decisions. Regarding the contracts that CAMERDATA has entered into with third parties, of which CDE is unaware, only CAMERDATA is responsible.
-The CDE does not respond to the question requesting it to explain the "reasons for deciding not to include the NIF data of individual entrepreneurs in the public registry accessible from its website" (question 6.3, first paragraph).
-In response to the question posed (6.3, second paragraph) asking for an explanation of why it decided not to include the self-employed persons' NIF (Tax Identification Number) in plain text in the database it transfers to CAMERDATA and instead replace it with a hash algorithm, the following response is given:
"The inclusion of the NIF hash in the transferred database is intended to
guarantee the communication of a unique identifier for each individual entrepreneur that is invariable over time, given that applying the same hash algorithm to the NIF data always yields the same result. Providing a unique identifier for each individual entrepreneur is necessary to distinguish between entrepreneurs
with the same first and last name, to operate with entrepreneurs who have changed their name (with or without a change of gender), the order of their last names, or the last names themselves, as well as to accurately monitor the additions, deletions, and
modifications that the file undergoes over time."
-With regard to self-employed entrepreneurs, does CDE have in its systems, in addition to
the plain text of these entrepreneurs' NIF data, the "hash" resulting from applying
this algorithm to the NIF? The CDE responds:
"Yes, the Spanish Chamber of Commerce generates the hash of the NIF of self-employed entrepreneurs in its systems.
Regarding the NIF of these individual entrepreneurs, CDE has it
because it was submitted by the Tax Authorities, but it is not part of the Public Business Registry."
-You are requested to provide information and provide documentary evidence of which file—"Public Business Census," "Basic Business Census," or "Provided Database"—the extract of 500 records you sent to this Agency during the preliminary investigation ("Document_4.xlsx" provided by this party) belongs to, which you then stated came from the Public Census, and which does include the NIF (Tax Identification Number) of the aforementioned 500 self-employed individuals.
The CDE does not respond to the question posed, as its answer has nothing to do with the question. Thus, it states:
"The NIF information was extracted neither from the Public Business Census nor from the Basic Business Census nor from the Transferred Database (any statement to this effect would have been due to an error).
The NIF information was extracted from the tax information received, which is the basis from which the public business census file is obtained for publication on www.camara.es, and the basic business census file is obtained for transfer to Camerdata.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 66/204
The tax information received is the database that consolidates the information from the state AEAT, Álava, Bilbao, Guipúzcoa, and Navarra, and contains all the information provided by these transferors, which is why it includes the NIF (Tax Identification Number)
for self-employed entrepreneurs. […]”
- Given that it stated in the allegations to the initiation agreement that the “hash”
of the NIF (Tax Identification Number) of individual entrepreneurs is part of the Public Business Registry despite
not being accessible through its website, the question arises (6.8.2.) whether the NIF hash
plays any role in the Public Business Registry consultation process through its
website, for example, helping to discriminate between entrepreneurs. CDE responds in
these terms:
“No, in the consultation In the online public business census, the hash does not
serve any function. Online consultation of the public business census enabled by
the Spanish Chamber of Commerce through its website www.camara.es is very basic.
However, the hash is an essential component of the Public Business Census,
since without it, the Public Business Census itself would be impossible for the CDE to manage, taking into account changes in names, surnames, addresses, etc., as
explained in the response to question 6.3 of this document.
- To the question of the reason for providing CAMERDATA with the NIF hash when, in order to meet the purposes mentioned—among them "to discriminate between entrepreneurs with the same first and last name (who would otherwise be confused)"—an identification code could be used (such as the "registration indicator" appearing in the ID field) and, in any case, a unique number linked to each record, the company responds:
"The hash identifier is invariable over time, and its calculation is not subject to error, as it is performed by applying known algorithms to data specific to the registry (individual entrepreneur), such as the NIF.
[…]
CAMERDATA needs the NIF hash so that the provided database can be used rationally and ensure the quality of the data on self-employed entrepreneurs in the update processes (registrations, deregistrations, and modifications)."
-In addition to applying the hash function to the NIF data of individual entrepreneurs,
does the CDE also apply the hash function to the rest or part of the data
of the self-employed entrepreneurs in its database? The CDE responds:
"No, the hash is only calculated on the NIF data of individual entrepreneurs
in order to have identifying data for each individual entrepreneur that remains unchanged over time."
- You have stated that the hash of the NIF (Tax Identification Number) of individual entrepreneurs is part of the Public Business Census, even though it is not accessible through its website, whose queries can only be made on a company-by-company basis. Does the NIF hash serve any purpose in the Public Business Census query process through its website, for example, helping to discriminate between entrepreneurs? The CDE responds:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 67/204
"No, the hash does not serve any purpose in the online query of the public business census. The online query of the public census enabled by the Chamber of Commerce of Spain through its website www.camara.es is very basic. […]
However, the hash is an essential part of the Public Business Registry,
since without it, the Public Registry itself would be impossible for the CDE to manage, taking into account changes in names, surnames, addresses, etc., as explained in the response to question 6.3 of this document."
--Please explain the purpose or function of the "registration indicator" and how it is generated: a number included in the "ID" field in each of the records of self-employed entrepreneurs included in the list of 500 self-employed individuals
that the CDE provided to this Agency, at the request of the inspector, during the investigation.
The CDE responds:
"It is a numerical identifier that follows a sequential order and is used to uniquely identify each record in the source table (source from which the information is extracted). This numeric identifier allows for single actions to be performed on
each record, such as deleting it with a delete statement, updating it with an update statement, or others, without affecting other records in the table. It is common practice for every database record to have a unique record identifier so that single operations can be performed on it. This unique record identifier does not identify the business owner, since a business owner can have multiple
records in the table depending on the number of economic activities and locations they have, each of which (the records) has a different number in the "ID" field.
--A description of the "system" that the CDE has been using to transmit the data to CAMERDATA is requested. You are required to report and verify whether and since when the data transmission has been carried out through online access or physical media. The CDE responds in these terms:
"The information is transmitted to Camerdata through Microsoft OneDrive, using the following procedure:
• The Chamber of Spain generates a CSV file with the established record design and compresses it with a password.
• The Chamber of Spain generates a CSV file that includes the list of hashes corresponding to the NIFs of the self-employed entrepreneurs.
• The Chamber of Spain uploads both files to a folder in your corporate OneDrive.
• The Chamber of Spain shares access to the CSV files with Camerdata. This sharing is also protected by a password (required for downloading).
• The Spanish Chamber of Commerce informs Camerdata by email of the availability of the information, as well as the password required for its download. Once Camerdata downloads the information, it confirms this to the Spanish Chamber of Commerce.
• The Spanish Chamber of Commerce deletes the folder from the corporate OneDrive. Emails exchanged with Camerdata regarding data transfers made from 2023 to the present are provided as documentary evidence.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 68/204
-- In the case of an online data transmission, the following is requested:
(i) That you provide documentation proving access to CAMERDATA during 2023 and 2024 and access to the updates for the fourth quarter of 2024.
The CDE responds in these terms:
“A document is attached as Annex VIII containing evidence of the information transfers made to Camerdata during 2023 and 2024. The updates for the fourth quarter of 2024 are not available at this time.
The latest information provided by the Spanish AEAT corresponds to the second quarter of 2024 and has not yet been processed.”
A copy of the emails exchanged is provided (pages 2,189 to 2,206).
Some of the emails provided are described below:
1. Under the heading "Send: State data update Quarter 3-2022."
These messages are provided:
1. "Email with the download link." The email was sent on
12/01/2023 at 1:16 PM from a corporate address of the CDE to the A.A.A.
1.2. "Email with passwords." Identical sender and recipient as in 1. Sent
on the same date at 12/01/2023 at 4:12 PM.
2. Under the heading "Email from Camerdata confirming the download," two new emails are provided, dated 13/03/2023:
2.1. From the corporate address of Camerdata belonging to the A.A.A., which
states: "I have observed that in this census there has been a decrease of 85,000 records compared to the previous ones. Can you confirm that the file is correct?"
2.2. Response from a CDE corporate email address:
"We did not modify or correct any records received from the AEAT. The only thing I detected was the increase in the number of deregistration records submitted in the quarterly updates for the 22nd quarter.
That's why I imagine this difference in records exists; according to the data we have, they would be correct."
3.- Under the heading "Submission: State data update Q4-2022." A copy of these emails is provided:
3.1. “Email with the download link.” Sent on March 21, 2023, at 9:50 a.m.
Same sender and recipient.
3.2. “Email with the passwords.” Sent on March 21, 2023, at 11:55 a.m.
Same sender and recipient.
4. Under the heading “Sending: Update of State Data as of December 2022
(Version 1 of the AEAT),” these messages are sent:
4.1. “Email with the download link,” dated June 27, 2023, at 9:50 a.m. Sent
from the CDE to Camerdata.
4.2. “Email with the download password,” dated June 27, 2023, at 9:51 a.m. Sent
from the CDE to Camerdata.
4.3. "Email from Camerdata confirming the download," dated June 27, 2023, at
11:51 a.m. Sent by Camerdata to the CDE.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 69/204
4.4. "Email with decompression password," dated June 27, 2023, at 12:25 p.m.
sent from the CDE to Camerdata.
5. Under the heading "Send: State Data Update Quarter 1-2023," a copy of the following emails is provided:
5.1. "Email with the download link," dated July 28, 2023, at 12:44 p.m.,
sent from the CDE to Camerdata.
5.2. "Email from Camerdata confirming the download," sent on August 1, 2023, at 5:31 a.m.
to the CDE.
5.3. "Email with the download and decompression password," sent on August 1, 2023, at 9:00 a.m.
from the CDE to Camerdata.
-You are requested to provide (ii) "the full content accessed by CAMERDATA in 2023
regarding the same 500 self-employed entrepreneurs whose records CDE provided to this
Agency on 12/21/2023 under the name "Document_4.xlsx."
The CDE responds in these terms:
"Attached as Annex IX is File ***FILE.1, which
contains the first 500 records corresponding to self-employed entrepreneurs from the
sample provided by the CDE. Since these are self-employed entrepreneurs, the first
9 characters of each record do not correspond to the NIF (Tax Identification Number), but rather to a sequential number (numeric record identifier) assigned during the file generation process, which allows each record of each individual entrepreneur to be linked to the hash of their NIF (Tax Identification Number) provided in the file ***FILE.2.”
After examining the aforementioned document, Annex IX, (pages 2,207 to 2,212), it is observed that the
first information field is a nine-digit list presented without separation next to the individual's first surname. These records are reproduced
from the list provided: The first and the tenth.
The first record is:
(…)
The tenth record provided is:
(…)
--The CDE is requested to provide a copy of the records from the Database if the NIF hashes are not transferred through the
operations mentioned in the previous points. Provided by CDE, where the NIF hashes are stored,
calculated by CDE, and transferred to CAMERDATA associated with the data of the 500 entrepreneurs provided by CDE to this Agency on 12/21/2023 under the name
"Documento_4.xlsx"
The CDE responds in these terms:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 70/204
"File ***FICHERO.2 is attached as Annex X, containing the hashes of
the first 500 records corresponding to the NIFs of the self-employed entrepreneurs
in the sample provided by CDE."
Upon examining the aforementioned document, Annex X (folios 2,225 to 2,256), it is observed that the
relationship provided includes, for each line (equivalent to each of the records),
a double piece of information separated by a vertical line: the first is composed
exclusively of digits, nine in total. The second is alphanumeric information (thirty-two elements) that corresponds to the hash.
The first record on the list provided is:
(...).
The tenth record on the list provided is:
(...)
ELEVENTH: Evidence Phase: Evidence presented before the AEAT. Response
1. You are requested to provide:
1.1. A copy of the "sign and send" screen of forms 36 and 37, showing the
information paragraph that you reproduced in your response to the Data Inspection request.
1.2. Documentary evidence that the link to which the taxpayer is referred
(https://sede.agenciatributaria.gob.es/Sede/condiciones-uso-sedeelectronica/datos-
personales.html) provides information on the transfers of IAE and census data that the AEAT plans to carry out.
1.3. If, starting in October 2023, the means through which the AEAT provides taxpayers with information on the transfer of their data has changed –
the link reproduced in point 1.2, as stated in its response to the Data Inspection request – the taxpayer must: (i) indicate the means through which it currently informs taxpayers about this matter; (ii) provide the content of the information provided; and (iii) provide documentary evidence of its response. Furthermore, (iv) the date on which this change occurred must be documented.
2. In its response to the Inspection request, the AEAT stated (page 3, end of point 1): <<In addition, the record of information provided is available on the Electronic Office.
https://sede.agenciatributaria.gob.es/Sede/procedimientoini/ZA02.shtml
https://sede.agenciatributaria.gob.es/static_files/Sede/Procedimiento_ayuda/ZA02/drIA
E_CamCom08.pdf >>
The first link leads to the "Exchange of Information on the Tax on Economic Activities" page. A list of links is included under the "i" symbol (circled). The second to last on the list is entitled: "Design of
Economic Activities Tax File Registration for Chambers of Commerce for the submission of the Annual File for the 2008 fiscal year and subsequent years (24 KB - pdf)".
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 71/204
Please provide information on whether this document is currently valid and, therefore, whether the information that the AEAT provides annually to the Chambers of Commerce regarding the IAE (Tax Income Tax) conforms, in terms of content and format, to the standard of this document.
The AEAT DPO responds to the questions raised:
-Regarding the information provided to data subjects pursuant to Article 13 of the GDPR, he states:
The processing of Census data is included in the Tax Agency's RAT (Registered Tax Registry), on the Electronic Office. Specifically, in section 5.1 Census, which
reports, among other points, the description of the activity, purpose, data, and
recipients, including the "Chamber of Commerce" among them.
It adds that, when completing forms 36 and 37
(https://sede.agenciatributaria.gob.es/Sede/procedimientoini/G322.shtml?faqId=f90c
bf61ed5d5710VgnVCM100000dc381e0aRCRD), the following text appears on the "sign and send" screen:
"In accordance with Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, and Article 11 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights, you are hereby informed that the personal data you provide will be processed by the State Tax Administration Agency for the purpose of the effective application of the state tax system and Customs. You can find more information on the
possible processing, transfers, and the procedure for exercising the rights established in Articles 15 to 22 of the regulation at the following link (https://sede.agenciatributaria.gob.es/Sede/condiciones-uso-sedeelectronica/ datos-personales.html).
Furthermore, the record of the information provided is available on the Electronic Office:
https://sede.agenciatributaria.gob.es/Sede/procedimientoini/ZA02.shtml
https://sede.agenciatributaria.gob.es/static_files/Sede/Procedimiento_ayuda/ZA02/drI
AE_CamCom08.pdf
-Regarding the data subject to transfer, please refer to Annex I of the Agreement signed
between the AEAT and the CDE. In your response, please provide a table with the information being transferred, the procedure under which the transfer takes place, and the frequency.
It is noted that with respect to the "Information" "Company census data according to Article 14,"
the procedures for which it is intended are (i) Preparation of the public company census, (ii) Preparation of the electoral census, and (iii) Other public administrative functions assigned by Law 4/2014. The "Frequency" is annual.
Regarding the "Information" "Data on the Tax on Economic Activities according to
Article 8 of Law 4/2014", the "Procedures" for which it is intended are
(i) Preparation of the public business census, (ii) Preparation of the electoral census, (iii)
Other public administrative functions assigned by Law 4/2014." The
"Periodicity" is annual with quarterly updates.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 72/204
- Regarding the basis of legitimacy and the purpose of the data transfers by the AEAT to the Chambers of Commerce, the Court responds that they are based on the existence of a legal obligation (Article 6.1.c) in relation, on the one hand, to the obligation imposed by
Article 8 of the Law 4/2014, which is developed in Article 22.3 of Royal Decree 669/2015,
of July 17, according to which:
3. The State Tax Administration Agency, as well as the other territorial administrations competent in tax matters, will collaborate with the governing bodies of the Chambers to provide them with the necessary information for the preparation and creation of the censuses, ensuring that only the employees of each Chamber determined by the plenary session will have access to said information, with the mandatory duty of confidentiality regarding said data. To this end, the State Tax Administration Agency will provide the information derived from the Economic Activities Tax census, along with the necessary company data included in other censuses it prepares and manages, in particular the Census of Entrepreneurs, Professionals, and Withholding Taxpayers.
It states that, "Aside from this obligation Legally, for the performance of the rest of the public functions performed by the Chambers, the Tax Agency has the obligation derived from the duty of inter-administrative collaboration under Article 141 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector, which includes, according to Article 142.a […] and Article 28 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, applicable in accordance with Article 141.
2.2 to the public-administrative procedures of the Official Chambers of Commerce, Industry, Services, and Navigation, when it recognizes the interested party's right to "not provide documents that are already in the possession of the acting Administration or have been prepared by any other Administration," imposing on the Administrations the duty to "collect documents electronically through their corporate networks or by consulting data intermediation platforms or other electronic systems enabled for this purpose."
In order to regulate the provision of information to the Chambers in both cases,
an agreement was signed with the Chamber of Commerce.
Reference is made to the Second Clause of said agreement, which specifies the purpose
of the transfer (Second. Purpose of the transfer of information).
"The transfer of information from the Tax Agency will be for the exclusive purpose of collaborating with the Spanish Chamber of Commerce and the Chambers
in the performance of the public functions assigned to them when, in order
to exercise these functions, the regulatory regulations require the provision of a
certification issued by the Tax Agency or the submission, in original, copy, or
certification, of the interested parties' tax returns or any other communication issued by the Tax Agency, particularly in the case of those not
required to file a tax return. In these cases, the information required to be included in such documents will be requested directly from the Tax Agency, provided that it is necessary for the exercise of such functions and relates to a large number of interested parties or affected parties.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 73/204
Annex III of this Agreement sets out the public functions to be performed by the Chambers.
The transfer of data from the Tax on Economic Activities and the company censuses will be for the exclusive purpose of preparing the public company census, fulfilling the public-administrative functions assigned to the Chambers by Law 4/2014, the Basic Law on Official Chambers of Commerce, Industry, Services and Navigation, as well as preparing the electoral census referred to in Article 17 of the same Law.
TWELFTH: Evidence Phase: Evidence presented to the Treasury of the Foral Community of Navarre. Response
By means of a document signed on 10/29/2024, the notification of which was made and accepted on the same date, the autonomous agency, the Foral Treasury of the Provincial Council of Navarre (hereinafter, HFN) is requested to report on the following matters (pages 2,276 to 2,279):
-What personal data of IAE taxpayers and the census data of individual entrepreneurs are communicated by the Foral Community Treasury to the CDE in compliance with the provisions of Article 8 of Law 4/2014 and with what regularity it communicates this information to the CDE.
-To report whether the taxpayer data communicated to the CDE by that Tax Authority has been solely related to entrepreneurs or whether it has been Additionally, those of taxpayers who carry out professional and artistic activities have been transferred.
The HFN responded on 11/08/2024 and explained that, pursuant to Article 156.2 of the Navarrese Local Tax Law, the data contained in the Registry of Economic Activities it manages are public (pages 2,304 and 2,305).
Article 156 of Regional Law 2/1995, which regulates Local Tax Authorities,
establishes:
“1. The tax will be managed by the Municipalities based on the Registry of Economic Activities.
This Registry will be compiled annually for each municipality and will consist of censuses containing the identification data and tax domicile of all taxpayers who carry out economic activities, including their domicile and heading or subheading of the activity, as well as the national, territorial, or minimum municipal tax on which they pay taxes.
[…]
2. The aforementioned annual Registry, with the exception of the tax domicile data, will be available to the public throughout the calendar year on the website of the Navarre Tax Authority.
Without prejudice to the provisions of the previous paragraph, access will also be permitted,
through the same means, to the following data appearing in the Registry of Economic Activities at the time of the query: the identification details of taxpayers who carry out economic activities, as well as their address and the heading or subheading of the activity.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 74/204
It is compiled annually for each municipality and will consist of censuses
including the identification details and tax address of all taxpayers who carry out economic activities, including their address, heading, subheading of the activity, and tax rate. (Emphasis added)
THIRTEENTH: Assessment of the results of the tests performed
Based on the results of the tests performed, it is deemed proven:
-That, without prejudice to the scope of the authorization granted by Law 4/2014 to CDE to compile a public business census (Articles 8 and 21.1 in relation to 5.1.g), the agreement signed with the AEAT expressly states that the information that the AEAT sends to CDE is related to the purposes that justify it and for which it is requested, and expressly prohibits the transfer of the information to third parties: "In any case, the
recipient may not transfer the information sent by the Tax Agency to third parties."
-That CDE publishes the public business register on its corporate website—understood
with the scope derived from the legal authorization granted by Law 4/2014—and that the public business register does not include the NIF (Tax ID Number).
-That on its corporate website, CDE clearly states that what it publishes is the
"Public Business Register" in the sense indicated above. This is without prejudice
to the confusion of concepts and terms incurred in its responses to the Inspection, allegations to the initiation agreement, responses to the evidence, and,
particularly in the database transfer contract signed with CAMERDATA.
-That, according to the contract signed between CDE and CAMERDATA, it is clearly evident
that the NIF (Tax ID Number) of self-employed workers is stipulated as the subject of the transfer.
-That the contract between CDE and CAMERDATA clearly states that the purposes for which the transfer is intended are: that
CAMERDATA will process the data related to marketing and that once
incorporated into its own database (Spanish Companies File), it may
transfer it to third parties. The purpose of the processing is derived from the information that
CAMERDATA provides in the "Legal Notice on the Use of the Portal and Services," which was
incorporated into the file by diligence of the acting inspector dated
10/18/2023, also incorporated for evidentiary purposes by diligence of the investigating body.
-That from the responses to the tests carried out in the evidentiary phase before the CDE and the documentation provided with them, it is clear:
1. That "The information is transmitted to Camerdata through Microsoft OneDrive,
using the following procedure:
• The Spanish Chamber generates a CSV file with the established record design and
compresses it with a password.
• The Spanish Chamber generates a CSV file that includes the list of hashes
corresponding to the NIFs of Self-employed entrepreneurs
• The Chamber of Spain uploads both files to a folder in its corporate OneDrive
• The Chamber of Spain shares access to the CSV files with Camerdata. This sharing is also protected with a password (required for download)
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 75/204
• The Chamber of Spain informs Camerdata by email of the availability of the information as well as the password required for its download. Once Camerdata downloads the information, it confirms this to the Chamber of Spain
• The Chamber of Spain deletes the folder from the corporate OneDrive. Emails exchanged with Camerdata regarding data transfers made from 2023 to the present are provided as documentary evidence.
2. When the CDE is asked to provide a copy of the records in the Provided Database where the NIF hashes are stored, calculated by the CDE, and
transferred to CAMERDATA associated with the data of the 500 entrepreneurs provided
by the CDE to this Agency on December 21, 2023, under the name "Document_4.xlsx," it responds:
"File ***FILE.2 is attached as Annex X, containing the hashes of
the first 500 records corresponding to the NIFs of the self-employed entrepreneurs
in the sample provided by the CDE."
And upon examining the aforementioned document, Annex X (folios 2,225 to 2,256), it is observed that the
relationship provided includes, for each line (equivalent to each of the records),
a double piece of information separated by a vertical line: the first is composed
exclusively of digits, nine in total. The second is alphanumeric information (thirty-two elements) that corresponds to the hash. Records 1 and 10 of the list provided are transcribed:
The first record of the list provided is:
(...).
The tenth record on the provided list is:
(...)
3. That in the document provided with its full content, accessed by CAMERDATA
in 2023, regarding the same 500 self-employed entrepreneurs whose records CDE
provided to the Agency on December 21, 2023, under the name "Document_4.xlsx," CDE states
that "since these are self-employed entrepreneurs, the first 9 characters of each record
do not correspond to the NIF (Tax Identification Number), but rather to a sequential number (numeric record identifier) assigned during the file generation process that allows
each record of each individual entrepreneur to be linked to the HASH of their NIF
provided in file ***FILE.2." (Emphasis added).
Upon examining the document, Annex IX, provided in connection with your response (folios 2,207 to 2,212), it is observed that the first information field is a nine-digit list presented without separation next to the individual's first surname.
Records 1 and 10 of the provided document are reproduced.
The first record is:
(...)
The tenth record is:
(...)
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 76/204
4. Upon examining the Excel document that CDE provided to the Agency during the
inspection with the records corresponding to 500 self-employed individuals within a defined range, it is verified that:
The information linked to (...) appears in the Excel table under record number 256.
The "ID" field shows "2".
The information linked to (...) appears in the Excel table under registration number 165. The "ID" field contains "7387".
FOURTEENTH: Proposed resolution.
The proposed resolution, signed by the investigating body on March 5, 2025, is formulated
in these terms:
"FIRST: That, by the Presidency of the Spanish Data Protection Agency,
the CHAMBER OF COMMERCE, INDUSTRY, SERVICES AND NAVIGATION OF SPAIN, with NIF Q2802216H, be sanctioned for a violation of Article 6.1 of the GDPR,
as defined in Article 83.5.a) of the GDPR, with an administrative fine (Article 58.2.i, GDPR) in the amount of €100,000 (one hundred thousand euros).
SECOND: That, by the Presidency of the Spanish Data Protection Agency,
the CHAMBER OF COMMERCE, INDUSTRY, SERVICES AND NAVIGATION OF SPAIN, with NIF Q2802216H, for a violation of Article 5.1.b) of the GDPR, classified in Article 83.5.a) of the GDPR, with an administrative fine (Article 58.2.i, GDPR) in the amount of €100,000 (one hundred thousand euros).
THIRD: That, by the Presidency of the Spanish Data Protection Agency,
the Spanish Chamber of Commerce, Industry, Services and Navigation, with Tax Identification Number (NIF) Q2802216H, be sanctioned for a violation of Article 5.1.f) of the GDPR, classified in Article 83.5.a) of the GDPR, with an administrative fine (Article 58.2.i, GDPR) in the amount of €100,000 (one hundred thousand euros).
FOURTH: That, by the The Presidency of the Spanish Data Protection Agency, hereby orders the CHAMBER OF COMMERCE, INDUSTRY, SERVICES AND NAVIGATION OF SPAIN, with NIF Q2802216H, to be sanctioned for a violation of Article 5.1.a) of the GDPR, as defined in Article 83.5.a) of the GDPR, with an administrative fine (Article 58.2.i, GDPR) in the amount of €100,000 (one hundred thousand euros).
FIFTH: That the Presidency of the Spanish Data Protection Agency, hereby orders the CHAMBER OF COMMERCE, INDUSTRY, SERVICES AND NAVIGATION OF SPAIN, with NIF Q2802216H, to be sanctioned for a violation of Article 14 of the GDPR, as defined in Article 83.5.b) of the GDPR, with a fine of an administrative fine (Article
58.2. i, GDPR) in the amount of €100,000 (one hundred thousand euros).
SIXTH: That the Presidency of the Spanish Data Protection Agency order the CHAMBER OF COMMERCE, INDUSTRY, SERVICES AND NAVIGATION OF
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 77/204
SPANISH, with NIF Q2802216H, pursuant to Article 58.2.d) of the GDPR, within one month of the sanctioning resolution being issued, to terminate the transfer to CAMERDATA of personal data of individual entrepreneurs that it receives from the tax authorities pursuant to Article 8 of Basic Law 4/2014 on the Official Chambers of Commerce, Services, Industry, and Navigation.”
The proposal will be notified electronically, with the date of availability and acceptance of the notification being March 5, 2025.
FIFTEENTH: Objections to the proposed resolution.
1. CDE, in a letter submitted on May 13, 2023, requests that the period for objections be extended by the maximum legally permitted amount. A response was issued on the same date, granting a two-day extension. The notification of the extension letter was made available on March 14, 2025, and accepted by CDE on March 17, 2025.
2. On March 21, 2025, CDE submitted its written submissions to the proposed resolution, requesting that the proceedings be dismissed and, as a subsidiary, requesting:
"(i) to assess the existence of medial competition and, where appropriate, the need not to sanction the same conduct twice when the legal interest protected is the same" and
"(ii) to understand that Article 77.2 of the LOPDGDD is applicable, as it is a public law corporation
acting "for the purposes of processing [related] to the exercise of public law powers," even in the event that the
Agency considers that such action was erroneous." (Emphasis added)
In defense of these claims, it invokes the following arguments:
2.1. Prior to this, it reiterates and reproduces the allegations made to the
initiation resolution.
2.2. In its first argument - "Summary of the controversy" - it sets out its arguments on the central issues under debate. To this end, it states:
- "The Spanish Data Protection Agency considers that the Chamber of Spain, a Public Law Corporation that is entrusted with legal and administrative functions for the "regeneration of the economic fabric and job creation" (Statement of Reasons for Law 4/2014), including that of "managing (...) a public census of all companies," is mistaken when, in the exercise of its legal and public functions, it considers that these functions include publishing this census and providing access to it to interested parties. Curiously, the Agency believes that publication on the Internet through an online database is included, but that publication by transferring it to entities that request it is not included."
(Emphasis added)
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 78/204
The CDE then asks what distinction exists “between one form of publication and another” and adds that the fact that it charges a fee that does not cover the cost of computer processing of the information does not distort the purpose of the publication or make it profitable.
It states that, in its understanding, the legal mandate to “manage the Public Census includes the obligation to make it public by both means”; that the “Law does not establish any distinction” and that the AEPD would be supplanting it in determining which is the appropriate medium for publication.
2.3. In the third allegation, “Procedural defects,” it invokes “two serious defects”
which, it claims, have left it defenseless.
1. It alleges that "one of the three required hearing procedures has been omitted, the one immediately preceding the proposed resolution"; the "hearing procedure required by Article 82 of Law 39/2015."
The explanation offered is as follows: in the administrative sanctioning procedure, a hearing is mandatory at three different times: (i) in the agreement to initiate the procedure (Article 64.2.f) of Law 39/2015), before processing the instruction of the procedure (and consequently the evidence), (ii) once the procedures have been instructed, and immediately before drafting the proposed resolution (i.e., after the evidence has been presented but before drafting the proposed resolution) (Article 82.1 of Law 39/2015, which does not establish any exception for the sanctioning procedure), and (iii) after drafting the proposed resolution of the investigating judge, therefore outside the scope of the latter's jurisdiction, but before the sanctioning resolution is issued (Article 89.2 of Law 39/2015).
Surprisingly, in this procedure, has omitted the second, causing
defensibility."
In support of his argument, he invokes the Supreme Court of Justice of the Valencian Community 231/2020, of May 12, FD 4 (Rec. 37/2018) and the Supreme Court of Justice of 11/11/2024 (Rec. 2960/2023),
ECLI:ES:TS:2024:5358.
He explains what he understands to be the purpose or reason for the procedure in Article 82 of the LPACAP that this Agency allegedly omitted: to ensure that the investigating judge knows the interested party's point of view on the outcome of the examination "before and not after the proposed resolution so that the written statement of allegations is taken into account in the preparation of the proposed resolution." And he adds: "If the procedure had been made clear to him before issuing the proposed resolution, he could have requested new evidence [...] which is no longer possible once the investigation and, therefore, the evidence process included therein have been closed—without hearing him."
He already anticipates his decision to assert in administrative litigation the lack of defense created by "the Agency's lack of sensitivity regarding this point."
2. He alleges that in the proposed resolution, "the types of offenses charged to this party have been modified, preventing this party from requesting the corresponding exculpatory evidence during the evidence phase."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 79/204
investigating evidence." He states: "It is not true that the facts are
different from those stated in the initial agreement, since the hearing given to
Camerdata, S.A. and the incorporation of its written allegations have given rise
to new facts."
CDE says: "It is hard to believe that the Investigating Officer, after reading the certificate from Camerdata, S.A.
signed on May 16, 2024, stating that Camerdata, S.A. "obtains the NIFs by its own means" (transcribed on page 85/152 of the draft resolution)
given that it only receives data encrypted "with the MD5 algorithm," and after receiving from both
the Spanish Chamber of Commerce and Camerdata, S.A. lists of information provided by the former to the latter regarding 500 self-employed entrepreneurs each, from which
it is clear that this information does not contain the NIFs of those self-employed entrepreneurs, it continues to state that there are no new facts (which is why the types of infringements charged can be
modified) and that Camerdata, S.A. receives the NIFs from the
Spanish Chamber of Commerce, given that, in its opinion, the NIFs are included in the Basic Business Census (folio 100/152), which is not true (only the "hash" is, which is also included in the Public Business Census, although not in the limited part of it that is displayed online for individual consultation—because it is not necessary for this purpose)."
2.4. In its fourth allegation, under the heading "Absence of harm caused to the
allegedly affected parties," CDE makes the following statements:
It maintains that "Article 65 of the LOPDGDD emphasizes the idea that violations are committed when harm is caused to the affected party." (Page 8 of his brief).
He states in a similar vein: “Both the General Data Protection Regulation and
the Organic Law on Data Protection and Guarantee of Digital Rights require
that, in order to exercise the sanctioning powers of the
Data Protection authorities, there must be proof of harm to the fundamental rights of at least one data subject […].” (Page 9 of his brief).
He also states that: “The AEPD's sanctioning action can only be taken if there is
certain harm to the rights of those affected, not otherwise. And in
the case at hand, no harm has been proven to anyone, so the
AEPD should never have initiated this sanctioning procedure.” (Page 10 of his brief)
In line with these statements, he emphasizes that "in the present case, it has not been proven at all that any harm has been caused to the interested parties" (page 8); that "the Agency does not at all prove the possible harm that may have been caused to the hypothetical affected parties" and that CAMERDATA processes data on a total of 1,665,049 self-employed workers. "That is, the number of hypothetical affected parties is very high, and none of them has ever filed a claim."
Furthermore, it mentions the SAN of 12/23/2022 (Rec. 104/2021), regarding which it comments that
the National Court annulled the AEPD resolution of 11/18/2020 (PS/000070/2019)
"considering that it was unacceptable that the Agency, after receiving five complaints from
an equal number of interested parties, "uses them to open a kind of general case against the privacy policy" of the accused entity." And immediately
it reminds us that the aforementioned SAN was revoked by the STS, Third Chamber, of
11/11/2024 (Rec. 2960/2023) ECLI:ES:TS:2024:5358, all of which In order to introduce the
following explanatory commentary on the reasons why the ruling issued by the National Assembly was revoked, reasons that, CDE warns us, do not apply in the case at hand:
"However, this ruling overturns that of the National Court because the procedure initiated by the AEPD was 'a sanctioning procedure that arose from five
complaints filed by different clients of the sanctioned entity,' such that there was a direct relationship between the complainants (however small their number) and the actions of the sanctioned controller. However, in our case, we are faced with a complaint from an association that seeks to carry out a crusade in favor of data protection, but that has nothing to do with the
defense of the affected data subjects. We reiterate that no interested party has filed any complaint throughout all the years that the company census advertising system at issue in this procedure has been in operation."
In this third allegation, CDE states twice that it is aware that "the
AEPD may act ex officio" but accompanies this statement of awareness with various comments regarding the Association whose complaint was the vehicle for transmitting facts that this Agency, in the exercise of its mandated functions, agreed to investigate. It states that the Agency has not established whether the
Association that filed a complaint about facts that led it to agree to open an ex officio investigation "represents the interests of affected parties, whether or not it is a consumer and user protection association, and whether, ultimately, its complaint means that someone has considered their right to data protection to have been violated."
2.5. In its fourth allegation, under the heading "The NIF (Tax Identification Number) has not been transferred, but rather the "Hash," and the infringing type requires voluntary transfer," it states:
That "The proposal repeatedly confuses the information published on the Internet
for individual consultation with the Public Business Census, and incorrectly differentiates between the Public Business Census and the Basic Business Census
and the transferred Database."
"The Public Business Census is the one prepared by the Spanish Chamber of Commerce, and includes the "hash" but not the NIF (which the Spanish Chamber of Commerce has, because it received it from the tax authorities, but does not use it directly in the Public Business Census,
but only its "hash"). Exactly the same thing happens with the Basic Business Census (also called the Transferred Database, which in both cases is a date-specific version of the Public Business Census, for transfer to Camerdata, S.A.): it only differs from the Public Business Census in that the latter is constantly updated, and the former are created only once in a while, when it is necessary to transfer the data to Camerdata, S.A.). The three documents (actually, two, since the last two are identical) dispense with the NIF and exclusively use the "hash," as confirmed by the test carried out by the Agency (which consulted 500 records of individual entrepreneurs from the Chamber of Spain and another 500 from Camerdata. S.A., without finding a single NIF, but only "hashes"). This
was clearly explained in the document submitted by this party as a response to the Instructor's request of September 16, 2024. Therefore,
what is stated on page 100 of the draft resolution is not true: it has been
demonstrated that Cámara de España does not transfer NIFs to Camerdata, S.A., but only "hashes."
The response given to the Inspector at the time, according to which the NIFs were transferred, was
clearly
incorrect, and was later corrected, and this was demonstrated during the inspection
(during which, as stated, what was actually transferred was verified). And the
contract prior to the GDPR understandably mentioned NIFs, but it is irrelevant
because the practice changed after the GDPR came into force, and it is proven that
what actually happens (which is the only thing subject to sanction) is not what was foreseen
in that old contract prior to the GDPR.
That the "hash" is part of the Public Business Registry is a fact. The
Investigating Judge seeks to prove the contrary by claiming that the "hash" does not appear in the information published
on the Internet individually. But "Public Business Registry" and "information published individually on the website of the
Chamber of Spain" are not the same. This is due to a reason: the "hash" is only
necessary when thousands or millions of data are processed, not when an individual query is made, and it is work data for mass data management, not data
of interest to citizens. Indeed, as has been stated several times (including in the written submission to the opening agreement), without the hash or the NIF, the Public Business Registry is unmanageable and would violate the data protection rights of many individual entrepreneurs. If neither the hash nor the NIF is available, it would confuse entrepreneurs with the same first and last names, entrepreneurs who have changed their surnames, entrepreneurs who have changed their name and/or gender, etc. The quality of the Public Business Registry would be very poor, and the number of errors very high, if it did not include the hash or the NIF. Given the choice, it is better to include the hash than the NIF.
And in the event of a mass transfer of data included in the Public Business Registry,
for the same reason, it is essential to transfer the complete Public Business Registry,
including the hashes, so that whoever receives it can avoid these same
errors.
This being the case, the Investigating Judge considers the hash to be a pseudonymized, not
anonymized, NIF, because he believes it is possible to obtain the NIF from the hash through
a complex operation (consisting of applying the same encryption to all
possible NIFs of Spanish citizens, handling tens of millions of data points, and searching
for the equivalence between a given hash and a NIF). This is a
"brute force" attack procedure, undoubtedly ingenious, previously unknown to the Spanish Chamber of
Republics, and surprising to the latter. The purpose of using the hash was not to pseudonymize the data, but to anonymize it, so that no one
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 82/204
could obtain the NIF from the hash. If this has not been fully achieved, this is certainly not the intention of the Spanish Chamber of Commerce.
In this party's opinion, regardless of whether the processing merits the qualification
of "anonymization" or merely "pseudonymization," what is certain is that
the Chamber of Spain, by using irreversible encryption (which is indeed what it is: the "hash" cannot be decrypted individually), sought to anonymize, not pseudonymize, the data and did not wish to transfer it (considering the transfer of the "hash" included for this purpose in the Public Business Registry to be sufficient). This intention is
relevant in a sanctioning procedure for transferring data without a legitimate basis,
because there is no transfer when there is "hacking" through a brute-force attack system.
There is not the slightest evidence (nor can there be, because it is false) that the Chamber of
Spain wanted to transfer the NIFs of individual entrepreneurs to Camerdata, S.A. And the alleged violations (illegal transfer, disloyalty, processing contrary to the established purpose, failure to communicate the transfer to the interested parties) all presuppose a voluntary transfer, which has not occurred.
The only thing the Spanish Chamber of Commerce did want to transfer is the remaining data, other than the NIF, included in the Public Business Registry. It is striking that the Investigating Judge believes that the "management" of the Public Business Registry includes the publication of data (other than the NIF) individually on the website, but not the publication of this same information (apart from the hashes and the NIFs, which have been discussed previously) in a joint and machine-readable form. Which leads us to the next section: "Was there a legitimate basis?"
2.6. In its fifth allegation, under the heading "There was a legitimate basis for transferring the information (excluding hashes and NIFS). The alleged violations have not been committed," CDE declares that it "has not committed any of the violations attributed to it in the Resolution Proposal" and, in this section (whose title mentions the absence of a legal basis for the transfer), it includes the following considerations regarding all the alleged violations:
a) "CDE does not transfer to Camerdata, S.A. the NIF of the natural persons"
CDE does not transfer the NIF of the natural persons to Camerdata, S.A., so it does not violate data protection regulations.
Regarding this matter, it is worth emphasizing the following points, which have already been
highlighted:
• In the certificate signed by B.B.B., ***POST.1, on May 16, 2024
("the Certificate"), said entity indicates that "The algorithm used is of the HASH or unique fingerprint type, and its main characteristic is that it is not possible
to obtain the input value (NIF) corresponding to an output value (HASH or MD5 fingerprint). Consequently, Camerdata, S.A. obtains the NIF by its own means" (emphasis added). This is a resounding and essential statement, since Camerdata, S.A. acknowledges and affirms that CDE does not transfer the NIF of the individuals.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 83/204
• The contract signed between CDE and Camerdata, S.A. on February 15, 2016 (hereinafter, "the Contract"), made it clear that the NIF of the individuals was not included in the Transferred Database, which contains "only" the data referred to in clause 12.2:
"The Transferor also declares that the Transferred Database and its updates contain data relating to individual entrepreneurs and data of individuals who provide services to legal entities, relating only to their first and last names, functions, or positions held, as well as
the professional postal or email address, telephone number, and fax number,
all in accordance with the provisions of Article 2 of the GDPR."
Camerdata, S.A. is the company that, through its own means, obtained the NIF data.
b) "In relation to the alleged violation of the principle of lawfulness of processing (Art.
6.1 of the GDPR)"
It declares that it has not violated the precept since it has a legitimate basis
for processing "which is related to the public interest (Art. 6.1.e) of the GDPR), and by virtue of this, it prepares and publishes, as part of the management of the Public Census of Companies, entrusted to it by Law 4/2014.
The processing carried out by CDE is based on the corresponding legal basis, since (i) Article 5.1.g) (in conjunction with Article 8) of Law 4/2014
requires (imposes a legal obligation that is enforceable) CDE to maintain
"a public census of all companies, as well as their establishments,
branches, and agencies located within its district," and (ii) Camerdata, S.A. is used to publish
said census, which constitutes acting in the public interest.
It should be noted that CDE does not transfer the NIF (Tax Identification Number) of individuals to Camerdata, S.A., so the alleged infringement cannot be committed.
c) Regarding the alleged violation of the principle of purpose limitation (Article 5.1.b) of the GDPR)
It states that it "has not violated the principle of purpose limitation (Article 5.1.b) of the GDPR), since, if applicable, the violation would have been committed by Camerdata, S.A. and not by CDE.
CDE provides Camerdata, S.A. with the Transferred Database to comply with the legal obligation to publicize the Public Registry of Companies established in Law 4/2014, as already indicated. Whether Camerdata, S.A., as an independent data controller, decides on the processing of personal data for other purposes, its own purposes, is beyond CDE's control.
It should be noted once again that in the Contract, clause 12.1 obliges
Camerdata, S.A., in its capacity as Assignee, to "strictly observe and comply
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 84/204
at all times with the rights and obligations of each party regarding
data access, processing, and transfer" (emphasis added).
Attributing to CDE an infringement it has not committed would violate the principle of
personal liability, which prevents anyone from being sanctioned for
the actions of others (STC 219/1988, of November 22, Legal Basis 3)."
d) Regarding the alleged violation of the principle of data confidentiality (Article 5.1.f) of the GDPR)
It states that "it has not violated the principle of data confidentiality either, since, on the one hand, the public business register does not include the NIF data,
as the AEPD itself points out in its Initiation Agreement, and, on the other hand, as already
stated, Camerdata, S.A. has stated that CDE uses an algorithm from
which "it is not possible to obtain the input value (NIF) corresponding to an output value (HASH or MD5 fingerprint)."
Neither does CDE transfer the NIF data of individual entrepreneurs to Camerdata, S.A., nor does Camerdata, S.A. receive it from Camerdata, S.A., so CDE has not violated the principle of data confidentiality.
CDE complies with its data security obligations, both with Law 4/2014 by guaranteeing the confidentiality of the data provided to it by the tax authorities and with the General Data Protection Regulation (GDPR), by applying irreversible encryption of the NIF of individual entrepreneurs when transferring the information to Camerdata, S.A.
Attributing to CDE the violation of Article 5.1.f) of the GDPR once again ignores the principle of personal liability, since CDE adopted measures to comply with the principle of confidentiality, as has been repeatedly and insistently explained.
e) Regarding the alleged violation of the principle of fair processing
(Article 5.1.a) of the GDPR)
CDE asserts that it has not violated this principle either. It states that "One of the
changes in legal classification in the resolution proposal phase is the
assessment that there has been a violation of the principle of fair processing (p. 107
of the proposal). Without prejudice to the allegations made in this
document regarding the lack of defense caused to this party by not having
agreed to a hearing prior to the resolution proposal, we must
point out with all due respect, but also with enormous force, that the Chamber
of Spain has in no way violated this principle.
Firstly, the Chamber of Spain has in no case concealed from the AEAT the
transfer of data to CAMERDATA. The Tax Agency's processing of data (which, as far as CDE is concerned, should not have included the NIF data, since the Chamber of Spain did not provide this data to CAMERDATA) was well known to the Tax Agency.
CDE has never acted deceptively or dishonestly.
The Tax Agency was aware of the data transfer. Proof of this is that
on December 19, 2023, the Tax Agency signed the renewal of the
Agreement with the Chamber of Spain (published in the Official State Gazette of February 16, 2024). That is, on a date after the request received from the AEPD in October 2023 and also after November 2, 2023, the day on which the AEAT data protection officer responded to the AEPD (p. 6
of the proposed resolution).
Secondly, as already noted, the transfer of the
Public Business Census to CAMERDATA, S.A. is inherent to the purpose of making public the
information contained in the aforementioned Public Business Census, a purpose
expressly contemplated in the Agreement with the AEAT, published in the
Official State Gazette. Therefore, there is no breach of loyalty, as the data owners for the purposes of compliance with data protection regulations are the
individual entrepreneurs and not the tax authorities.
Thirdly, since CDE has received the transfer of data from the tax authorities
and taking into account the significant number of interested parties, it is clear that providing information to the interested party is impossible or requires disproportionate efforts.
And fourthly, Law 4/2014 requires CDE to publish the Public Business Census
of Companies, which it has complied with, and therefore it is not possible to attribute to it an
infringement it has not committed.
Considering the above, it is clear that the AEAT and those affected
were aware of the existence of the public business census, since it was a
census that has been published for years.
And they are also aware of the transfer of the data to CAMERDATA, S.A. Neither the
AEAT has at any time required CDE or CAMERDATA to cease
advertising the Census in the manner it was structured based on the Agreement of February 15, 2016, nor has any hypothetical affected party filed
any claim against CDE for such advertising over all these years. To claim, without
any proof or evidence, that CDE has acted unfairly in relation to
the group whose interests it is supposed to defend is completely unfounded.
f) Regarding the alleged violation of the principle of information to interested parties (Article 14 of the GDPR)
CDE has not committed any violation, so the violation of Article 14 of the GDPR is not attributable to it, nor is the principle of culpability applicable in administrative sanctioning law.
Although the AEPD indicates that CDE has not proven that it has carried out and documented an evaluation of the effort involved in informing interested parties, the effort is clearly disproportionate, with the number of affected parties highlighted by the AEPD itself in its Proposal for a Resolution (almost one and a half million).
CDE cannot be held responsible for this violation when Law 4/2014
requires it to prepare the public business register, which is what it has done. And
also, when CDE has not transferred the NIF of the individuals to Camerdata, S.A., so it was not appropriate to report a process that is not being carried out."
2.7. The sixth allegation is titled "A sanction is being issued five times for a single violation. The investigator is forgetting the medial competition."
Alternatively, should the previous arguments be rejected, the Court argues the following:
a) That the same conduct is being sanctioned multiple times, with the same subjects, facts, and grounds or protected legal asset.
It indicates that the proposed resolution charged CDE with committing the
following GDPR violations:
“— A violation of Article 6.1 of the GDPR (“principle of lawfulness”), for transferring to CAMERDATA data of individual entrepreneurs that are lawfully in its possession, having received them from tax authorities without an adequate basis for legitimacy under the GDPR.
— A violation of Article 5.1.b) of the GDPR (“principle of limitation of the purpose of processing”), because, according to the Draft Resolution, “the purpose
of the original processing by the Chamber of Spain of the data obtained from the Tax Authorities and the purpose of the subsequent processing, the transfer to CAMERDATA, are clearly different and incompatible.”
— A violation of Article 5.1.f) of the GDPR (“principle of confidentiality”), for “failing to comply with the obligation to guarantee the confidentiality of the NIF data of self-employed persons that it lawfully receives from the Tax Authorities under Article 8 of Law 4/2014.”
— A violation of Article 5.1.a) of the GDPR (“principle of loyalty”), because “the CDE’s transfer of the self-employed workers’ data to CAMERDATA constitutes,
from the perspective of its data subjects, deceptive processing” and “the transfer is carried out without any reasonable expectation that such processing could actually take place; there has been a complete lack of information about the existence of this processing; and the CDE has ignored the adverse effects that the processing may have on data subjects.”
— A violation of Article 14 of the GDPR (“information to be provided where the personal data has not been obtained from the data subject”), for failing to inform data subjects of the transfer of their personal data to CAMERDATA.”
CDE considers that in "all these cases" "the triple identity of subject, fact, and protected legal asset is present, which would be the transfer by the latter to CAMERDATA of the personal data of self-employed entrepreneurs, and especially the NIF. “
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 87/204
It states that “There are several names applied to the same reality: if there is a transfer without a legitimate basis because it is carried out, according to the proposed resolution, for a purpose other than the legal and administrative purposes attributed to the Spanish Chamber of Commerce, and for that reason, data has been improperly transferred (that is, it should have been kept confidential instead of being transferred), and all of this is considered unfair because the interested party was not informed (because the Spanish Chamber of Commerce believed there was a legitimate basis for the transfer that made it unnecessary to inform the interested party), and therefore contrary to the duty to inform the interested party, all of this would be (if it were) one and the same violation: transferring personal data (particularly NIFs) without a legitimate basis. If the legitimate basis invoked for such processing, consisting of the transfer (Articles 6.1.c) and 6.1.e)), existed, neither would the duty to respect the purpose of the processing have been breached, nor would any duty of confidentiality have been violated, nor would the conduct be unfair, nor would the interested parties have to be informed.
It indicates that, “for this hypothesis, it would therefore be appropriate to sanction only once, for a violation of Article 6.1 of the GDPR, as it is the most serious of the five violations alleged and because the accusation of the other four is included in the first violation.”
As the European Data Protection Board has pointed out in this regard regarding the concurrence of violations,
3.1.1. Concurrent violations
The principle of concurrent violations (also called "apparent concurrence" or "false concurrence") applies whenever the application of one provision prevents or overrides the applicability of the other. In other words, the concurrence already occurs at the abstract level of the legal provisions. This could be based on the principles of speciality, subsidiarity, or consumption, which are usually applied when the provisions protect the same legal interest.
In such cases, it would be unlawful to sanction the offender twice for the same violation.
In the case of concurrence violations, the amount of the fine must be calculated
solely on the basis of the violation selected in accordance with the previous rules
(prevalent violation)"1 (emphasis added).
The proper application of the ne bis in idem principle, as a general principle of
law,
implies that the imposition of multiple administrative sanctions is prohibited
when, as in this case, the identity of the offender, the fact,
and the basis for the violations attributed to the Spanish Chamber of Deputies are present.
Failure to apply this principle would also entail a violation of the principle of
proportionality in the imposition of administrative sanctions, since, as the
Constitutional Court has stated, "once a specific sanction has been applied to a
specific violation, the punitive reaction has been exhausted" (emphasis added)
(STC 154/1990, of October 15, Legal Basis 3).
b) There is media competition
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 88/204
The CDE maintains that several of the alleged violations are related to each other,
and are related to media competition, regulated in Article 29.5 of the LPACAP (Spanish Civil Code), which the
Investigating Officer has ignored. This provision states that "when the commission of one
violation necessarily leads to the commission of another or others, only the sanction corresponding to the most serious violation committed should be imposed."
And he explains: "Such is the present case: a transfer without a legitimate basis (because the
existing legitimate basis does not cover—in the Agency's opinion—the purpose of the
processing pursued by the transfer) necessarily entails a new
purpose of processing different from that of the transferor, and necessarily entails
a violation of the principle of confidentiality (how can one carry out
an unlawful transfer of confidential information without violating the
principle of confidentiality?), and also a lack of loyalty (since, by
definition, the data subjects have no reasonable expectation that an
illegal transfer will occur), and of course a lack of information (the illegal
transfer is not reported because the transferor believes it does not exist—regardless of
the fact that this violation is not applicable because, if there were someone obliged to report,
it would be Camerdata, S.A. and not the Chamber of Spain—as has been said, they are two
different entities that the Instructor too often confuses). There is
medial concurrence in all of this."
2.8. The seventh allegation is titled "A fine is being imposed on a
public corporation for the (allegedly) improper performance of its
public functions."
The company argues that Article 77.2 of the LOPDGDD (Spanish Organic Law on the Protection of Personal Data) prevents CDE, a public-law corporation, from being subject to financial penalties "for acting in the (allegedly) improper exercise of its public functions."
It considers that CDE "has carried out the processing that the AEPD censures based on the provisions of Law 4/2014. In any case, it is motivated by its obligation to make the business census public, without it being possible to determine that it was carrying out a mere private-law activity."
It reiterates that what CDE has done "is to sign an agreement with CAMERDATA to, with all the necessary guarantees, facilitate greater access to data from the public business census, without, in any case, transferring the NIF."
It indicates that "the Agency's interpretation directly conflicts with the reality of the facts." And it explains that “any Public Administration may
contract the provision of a service without implying that such a contract
converts it into a private law entity to which Article
77 of the LOPDGDD would not apply.”
It states that “there is no doubt that the Spanish Chamber intended to fulfill its
public function of publicizing the Public Business Registry, a public law power.
The Agency may disagree on whether it did so correctly or not, but it should not question that the intended purpose was “related” (to
use the wording of the Law) to that public law power to manage the
Public Business Registry (which, as stated, is included in “hash”).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 89/204
It indicates that “when the AEPD indicates, to deny the application of art. 77 of the
LOPDGDD, which states that the Spanish Chamber of Deputies was not acting "in the exercise of public administrative functions" (p. 104 of the proposal), is ignoring the fact that Article
77.1.g) actually provides that this provision applies to "public law corporations when the purposes of the processing are related to the exercise of public law powers." And this is precisely the situation we find ourselves in.
The Chamber of Deputies adds that "the Spanish Chamber of Deputies had no profit motive in this transaction."
From the actions carried out in this procedure and the documentation in the file, the following have been established:
PROVEN FACTS
FIRST: The Registry of Processing Activities (RAT) of the AEAT - as of
February 25, 2025 https://sede.agenciatributaria.gob.es/Sede/todas-
gestiones/procedimientos-no-tributarios/tratamiento-datos-personales/tratamiento-
datos-personales/informacion-interesado-sobre-proteccion-datos/5-registro-
actividades-tratamiento.html - when referring to the "Census," includes the "Chamber of Commerce" among the recipients of the processed data.
Section 5.1. The Tax Administration Service (RAT) of the AEAT (Spanish Tax Agency) "Census" describes this processing activity as "Management and collection of information on taxpayers, whether individuals or legal entities. To this end, most census data is processed, including historical data." It indicates that the "Purpose" is "the application of the state tax and customs system" and that it processes the following "Data":
"DNI and associated data, NIE (National Identification Number), NIF (Tax Identification Number), company name, first and last name,
address, telephone number, email address, fax, mobile phone number, marital status and, where applicable, spouse or ex-spouse, country of birth, province of birth, city of birth, date of birth, nationality, passport, sex, type of administration to which the taxpayer is assigned, tax identification number in a foreign tax administration, municipal identification number, electoral identification number, census number, father's name, mother's name.
. Transactions of goods and services.
. Tax obligations."
The "Recipients" section lists eleven entities, including the "Chamber of Commerce."
SECOND: The CDE states in its response of 12/20/2023 to the request from the
Data Inspectorate:
"The public business census is published openly and free of charge within the "Spanish Companies" section of the Chamber of Spain's corporate website." (Page 1,452)
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 90/204
THIRD: It is stated that the public business census is published openly through the CDE's website, www.camara.es, under the name "National Business Census" and that the information it provides regarding individual entrepreneurs relates exclusively to the following data: name, surname, address, postal code, municipality, and activity.
This is confirmed by the screenshots obtained from the CDE website on September 16, 2024, incorporated into the file through a Diligence dated September 17, 2024
(folios 2,106 to 2,111), which allow the following points to be verified:
a. That on the website www.camara.es (www.camara.es/funcion-consultiva/consulta-
del-censo-publico-de-empresas) under the heading "Public Business Census,"
a list of options appears, and the first, "Description," offers the following
information regarding the "Public Business Census":
"We provide you with the data included in the Public Census, which contains all the
legal and physical entities of the Official Chambers of Commerce, Industry,
Services, and, where applicable, Navigation of Spain."
That the file "contains one record per activity (it does not accumulate multiple activities
at the same address) and compiles the following data per record: Name,
Address, Postal Code, Municipality, Activity." The NIF (Tax Identification Number) is not included.
b. That, when a query is made about an individual entrepreneur in the public business census
– from the "Public Business Census," "Database" option (which says
"access our database from here"), which redirects to the "Consult
National Business Census" screen – the query result offers exclusively
the following data: first and last name, postal address (street name and number),
postal code, name of the province and municipality, IAE (Tax Identification Number) code, and description of
the activity (pages 2106, 2110, and 2111). The NIF (Tax Identification Number) is not included.
FOURTH: The file confirms that when a query is made regarding an individual entrepreneur in the "public business census" through the CDE corporate website - from the "Public Business Census," "Database" option (which says "access our database from here"), which redirects to the screen
"Consult the National Business Census" - the information provided includes a link to the CAMERDATA website preceded by the following legend: "If you wish to obtain more information, consult the Camerdata Online Business File."
The file contains a screenshot obtained during the test phase (folio 2,111), incorporated into the file through a Diligence (folio 2,106), which confirms this.
FIFTH: The Agreement between the AEAT and the CDE "for the transfer of tax information to the Official Chambers for the exercise of their public-administrative functions," signed on November 25, 2019 (Official State Gazette, December 20, 2019), extended for four years, and amended by an "Addendum" signed on December 19, 2023 (Official State Gazette, February 16, 2024), stipulates:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 91/204
- Regarding the purpose of the transfer (second clause): The "exclusive purpose" of the communication of the data to the CDE and the Chambers is "to collaborate in the development of the public functions assigned to them," which are specified in that clause. Clause
second by means of an express reference to Annex III of the Agreement, which, in turn,
reproduces Articles 5.1, 5.2, and 21.1, letters d) to i) of Law 4/2014.
It adds that "The transfer of data from the Tax on Economic Activities and the company censuses will have the exclusive purpose of preparing the public company census, fulfilling the public-administrative functions that
Basic Law 4/2014 on the Official Chambers of Commerce, Industry, Services, and Navigation attributes to the Chambers, as well as preparing the electoral census referred to in Article 17 of the same Law."
- Regarding recipients (Clause Four): The information transferred by the AEAT
can only be addressed to "the bodies of the Spanish Chamber of Commerce
and the Chambers that have been assigned the public functions that justify the transfer."
“Under no circumstances may the recipients be bodies, agencies, or entities that perform functions other than those described in the second clause of this Agreement.”
“All of this without prejudice to the strict allocation of the information sent by the Tax Agency to the purposes that justify it and for which it is requested.
In any case, the recipient may not transfer the information sent by the Tax Agency to third parties.” (Page 1,013) (Emphasis added)
SIXTH: It is proven that CDE, in its response dated 12/20/2023 to the request from the Data Inspection (page 646), stated (pages 1,450 and following):
i. Asked about the origin of the data it processes:
“The data comprising the Chamber of Spain's public business census are the data from the Economic Activities Tax and the necessary company censuses provided by the State Agency of the Tax Administration.” And that “they also originate from the Economic Activities Tax data provided by the Provincial Council of Navarre and from those provided by the Chambers of Commerce of the Basque Country.” (1451)
ii. Asked about the data on self-employed entrepreneurs it processes:
“All the data contained in the Chamber of Spain's public business census regarding self-employed individuals or individual entrepreneurs are detailed here:” and it mentions
the following: “NIF field,” “Name field,” “Address field,” “Postal Code field,” “Province Code field,” “Province field,” “Municipality Code field,” and “State Code field.”
“Municipality field”; “Heading field”; “Description field”; and “ID field.” (Page 1452)
Indicates that “there is one record for each combination of the IAE heading and postal address.”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 92/204
iii. When asked about the transfer of data from the public business census to third-party entities, including CAMERDATA, she states:
“The fields listed above are provided solely to CAMERDATA, S.A., as a commercial entity established by multiple Spanish Chambers of Commerce and the Chamber of Spain, for inclusion in its Spanish Business File, for the purpose of legitimately processing, completing, and enriching them, and to have a quality database of companies operating in Spanish territory that can be offered to interested companies and third parties.
[…]” (Pages 1,452 and 1,453)
iv. When asked about the obligation to inform data subjects pursuant to Article 14 of the GDPR about the data processing carried out, the Court denies that such an obligation exists, as Article 14, paragraph 5, letter c) of the GDPR is applicable. It states that "The collection of data is expressly established by Union or Member State law, which applies to the data controller in response to the public-administrative purposes and functions that Law 4/2014 attributes to the Spanish Chambers of Commerce and the Chamber of Spain." (Page 1453)
v. When asked about the legal basis for processing “the public business census for self-employed workers,” she states (pages 1457 to 1459):
“The legal basis for processing the business databases of the Spanish Chamber of Commerce, which includes self-employed workers […], is based on two legal grounds:
1. Article 6.1.c) of the GDPR, since “in accordance with Articles 5.1.g and 8 of Law 4/2014,
the Chambers of Commerce have, among other public-administrative functions, the task of
preparing and managing a public business census.”
2. Article 6.1.e) of the GDPR, “processing is necessary for the fulfillment of a mission carried out in the public interest,” which CDE links in this case to the preparation of a public business census and to the management that “is inherent to their functions under the article.” 21.1.d) of Law 4/2014, in relation to the purposes of the Chamber of Deputies (Article 3 of the same Law) and the public interest objective that “is implicit in the public-administrative function of promoting actions aimed at increasing the competitiveness of small and medium-sized enterprises (Article 5.1.j) of Law 4/2014).” (Pages 1457 to 1459)
vi. When asked about the legitimacy of the “processing that involves the transfer
of data from the public business census to third parties, including CAMERDATA, in the case of self-employed workers,” she states:
“The Spanish Chamber of Deputies provides the data from the public business census to
Camerdata, S.A. to process, complete, and enrich them legitimately and
have a quality database of companies operating in Spanish territory to be able to offer it to interested companies and third parties."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 93/204
The basis for legitimacy invoked is Article 6.1.f) of the GDPR. (Pages 1,460 and 1,461)
SEVENTH: The file contains an Excel document provided by CDE
in response to the Inspection's request to submit "an extract of its database [...] containing all the data available regarding the
first 500 self-employed workers corresponding to consecutive records of the result of the alphabetical ordering of the same by first surname starting with the letter "P", then by second surname, then by first name, or simply by Name
beginning with the letter "P" if the "surname" field does not exist.
The receipt of the document at the Agency is registered with the reference
"REGAGE23e00086547926" with the "Name: Document_4.xlsx" and "Type: Attached Document" (Page 1,448).
In view of this document, it is confirmed that the CDE database for self-employed entrepreneurs contains, for each record, the following fields, in this order: NIF (Tax Identification Number), Name (which includes the first name and both surnames), Address (which includes the street type, name, number, and in some records, the floor); Postal Code;
Province Code; Municipality Code: Province; Municipality; Title; Description; ID.
EIGHTH: "Business database transfer agreement." Regulates the transfer of data from CDE (transferor) to CAMERDATA (assignee), signed on February 15, 2016,
tacitly renewable for successive periods of one year (agreement 6.2) and in force
on the date it is submitted, December 20, 2023 (pages 1,477 and following).
Relevant to the explanatory part of the contract and its stipulations ("agreements") are:
1.- Explanatory V: states that, in consideration of "the data from the Economic Activities Tax and the necessary company censuses"
(Explanatory IV) "received from the collaborating public administrations," "the Spanish Chamber of Commerce will prepare the public company census under the name "Basic Company Census," guaranteeing confidentiality in the processing and
the exclusive use of the information received."
And from the second paragraph of Exhibit V of the contract, it follows that the Basic Business Census contains only data on individual entrepreneurs.
Exhibit VIII: which indicates that CAMERDATA "has been developing and commercially exploiting a business information system called the "Spanish Business File," which is a separate database from the "Basic Business Census" prepared by CDE, "although for the development of its activity it is interested in obtaining a copy of the business information from the "Basic Business Census."
2. First Agreement, Purpose:
"1.1. By this Contract, the Assignor assigns and transfers to the Assignee, who, in turn, receives and acquires for itself a copy of all the business data contained in the Basic Business Census referred to in the previous Exhibit V (hereinafter the Assigned Database), updated as of
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 94/204
January 2016, which contains the information fields indicated in
Annex 1 of 3,160,984 Company Registries.”
“[…]the Company Registry is understood to mean all the information fields in
Annex 1 relating to each of the companies contained in the Assigned Database,
with the company's NIF (Tax Identification Number) being used as the identifier for said registry.”
“1.2. The Company Registries that make up the Transferred Database refer solely and exclusively to those indicated in the second paragraph of
Exhibit V above."
3. Annex I, to which Agreement 1.1 refers to determine the information fields relating to each of the companies contained in the Transferred Database, states:
"In accordance with the provisions of the First Agreement of the Contract, the Database and its updates will contain the following information fields
for each company listed therein (hereinafter, Company Registry).
Data for each Company Registry
1. Tax Identification Number (NIF)
2. Company name or corporate name
3. Main address
4. Business address
5. IAE activity section
6. IAE activity"
4. Second Agreement. "Purpose.
The assignee will include the business data from the Transferred Database and any periodic updates thereof in the Spanish Business File owned by it, and will process, complete, and enhance them under the terms of this Agreement for the purpose of commercially offering it to interested companies and third parties as a database of information on companies operating in Spanish territory.
5. Seventh Agreement: "Assignment of the Agreement.
7.1. The assignee may not assign, in whole or in part, to a third party the rights and obligations that correspond to it under this agreement, nor the Transferred Database, nor any of its updates, without the prior express written authorization of the assignor.
This prohibition excludes the assignment of the data from the Transferred Database incorporated in the Spanish Business File owned by the assignee, in accordance with the provisions of the Second and Third Agreements of the Agreement."
6. Third Agreement. “Effectiveness of the transfer.
The transfer of the Transferred Database and its updates will be carried out
under the terms and conditions agreed upon by the Parties in Annex 2, attached to the
Contract and forming part thereof for all purposes.”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 95/204
7. Annex 2 to the “Business Database Transfer” Agreement dated February 15, 2016, entitled “Conditions of the Transfer of the Transferred Database” (pages 1,492 to 1,497) establishes:
“For the transfer of the Transferred Database and its updates, the Parties agree to the following:
A) Obligations of the Transferor:
a.1) The Transferor guarantees to the Transferee:
(i) […]
(ii) That the data included in the Transferred Database and its updates
are obtained from the public business census regulated by Law 4/2014
prepared by the Transferor under the name of the Basic Business Census.
a.2) The transfer of the Assigned Database and its updates:
(i) Will cover all the information fields indicated in Annex 1
of the Business Database Assignment Agreement of February 15, 2016 (hereinafter the agreement) that the Assignor has at the time of its preparation.
A) Obligations of the Assignee:
b.1) The Assignee undertakes to incorporate the information from the Assigned Database into the Spanish Business File and to process and market it
under the terms agreed in the Agreement and its Annexes.
b.2) The Assignee undertakes to always keep the business data in the Spanish Business File updated and, to this end, undertakes to:
(i) Obtain from the Assignor all updates to the Assigned Database that the Assignor periodically makes within the following fifteen (15) business days [...].
(ii) Not to transfer or market the Transferred Database or any updates
and not to make any copies other than backup copies.
(iii) Incorporate into the Spanish Company File the information from the Company Registries of the updated Transferred Database within thirty (30) business days following the date it receives it from the Transferor […]”
(iv) Carry out said update by overwriting the Spanish Company File with the information from the Transferred Database updated for each Administration Code submitted. Consequently, the Transferee will be obliged to delete from the Spanish Company File the information from the Transferred Database previously submitted regarding said Administration Codes, which will be completely replaced and without effect, and the Transferee will not be able to use said information for the purpose of the Contract or for any other purpose; it may only keep it blocked and available to public authorities, judges, and courts […]”
b.3) The Transferee may only inform interested third parties that the source of the information in the Spanish Company File Regarding
the fields in Annex 1 of the Contract correspond to those of the Basic Business Census when said file has incorporated information
from the Transferor's latest updated Transferred Database. Otherwise,
it will not be able to report this source.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 96/204
b.4) Upon receipt of the Transferred Database or its update, the
Transferee will proceed to:
(i) Standardize names and addresses […]
(ii) Incorporate the information from the Transferred Database or its
updates processed in this way into the Spanish Business File
owned by the Transferee.
b.5) The Spanish Company File that the Assignee develops and
markets will have the following characteristics:
(i) The company record and its fields in the Assigned Database
indicated in Annex 1 of the Contract. The remaining fields in
said File will not modify, alter, or contradict the fields in the Assigned Database and its updates.
(ii) Fields developed by the Assignee based on algorithms created
by it.
(iii) Fields provided by the Assignee: such as Legal Form, main activity, registered office, branches, business activity.
(iv) Fields provided by other legitimate and up-to-date sources: Business name, telephone number, fax number, National Tax Code (CNAE), website, date of incorporation, number of employees, turnover, imports/exports, positions (up to 5 positions with first and last names), company type (to distinguish between self-employed workers not classified as Section 2 or 3), geodetic coordinates (in three universal systems), or others.
b.6) The Assignee undertakes to provide the Assignor, in a format […], with the necessary data and information from the Spanish Company File […] for the sole purpose of enabling the Assignor to verify compliance with the terms agreed in the Contract and its Annexes. […]”
B) Price of the Assigned Database
[…]
C) D) Price of the Assigned Database for subsequent updates.
[…]”.
NINTH: CAMERDATA responded on November 13, 2023, to the information request from the Agency's Data Inspection (folio 650) requesting details of all the data processed, the precise meaning of each piece of data, the origin of each piece of data and the procedure for obtaining it, to whom it is transferred, and the identification of said recipients.
It also requested the total number of self-employed individuals listed in said database (folios 703 to 707):
“All the data contained in the CAMERDATA company database regarding self-employed individuals is listed and detailed below:
NIF (Tax Identification Number), Company Name, Business Name, Generic Email, Address, Postal Code, Municipality, Province, District, Census Section, Telephone, Telephone 2, Company Type, Main Activity of the IAE, All IAE Activities, Address Type, Number of Branches, Website, Year of Incorporation, Employees, Import/Export,
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 97/204
Company Type, Activity CNAE, Latitude wgs84, Longitude wgs84, Coor Type wgs84, Camerdata ID.
The total number of self-employed workers currently in the database is
1,665,049. Please note that not all records have all the data listed above.
The NIF data is the Tax Identification Number. The data source is the public business census published by the Spanish Chamber of Commerce in accordance
with the provisions of Law 4/2014 (hereinafter, the Public Business Census), and is
obtained each time a new business census is uploaded. The NIF data is
provided to clients who request the business information services offered by Camerdata, including, on the one hand, entities in the sector known as
infomediary or information reusing companies (Axesor, Cerved,
Datacentric, Equifax, Informa, Iberinform, and Moody's) and, on the other hand, end-user clients who request it for their exclusive internal use."
TENTH: CDE states—in its objections to the start-up agreement—that it does not provide CAMERDATA with the NIF data of self-employed entrepreneurs, but rather provides a "hash," the result of an encryption process, "so the truth is that
Camerdata does not receive these NIFs from CDE."
It adds that "The "hash" is part of the Public Business Registry, since without it, this registry
could not be managed, but it is not accessible on the Internet through company-by-company consultation because it is not necessary for that purpose."
ELEVENTH: The file, provided by the CDE, contains a document signed on
05/16/2024 by ***POSITION 1, which states the confidential nature of its content and certifies the following:
“1. CAMERDATA (…). Consequently, CAMERDATA obtains the NIF (Tax Identification Number) through its own means.
2. The CDE, […] in the exercise of the public-administrative functions attributed to it, prepares, manages, and publishes (Article 5.1.g) in relation to Article 8 of Law 4/2014) the public census of companies in Spain.
This public census of companies is, as its name indicates, public, and is available
to any interested party on the Internet at https://www.camara.es/funcion-
consultiva/consulta-del-censo-publico-de-empresas. However, the availability of the public business census on the Internet is limited.
3. That CDE sends the public business census to CAMERDATA in a format that allows for more complete fulfillment of this purpose established in the Law (making the census public), through means other than simply making it available for consultation, company by company, on the Internet.
4. That CAMERDATA processes the information received from CDE as the data controller, without following instructions from CDE.
TWELFTH: Regarding the information that the CDE transfers to CAMERDATA, it is hereby confirmed:
1. The CDE states that:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 98/204
“The information is transmitted to Camerdata via Microsoft OneDrive, using the following procedure:
• The Chamber of Spain generates a CSV file with the established record design and compresses it with a password.
• The Chamber of Spain generates a CSV file that includes the list of hashes corresponding to the NIFs of the self-employed entrepreneurs.
• The Chamber of Spain uploads both files to a folder in its corporate OneDrive.
• The Chamber of Spain shares access to the CSV files with Camerdata. This sharing is also protected with a password (required for downloading).
• The Spanish Chamber of Deputies informs Camerdata by email of the availability of the information as well as the password required for its download. Once Camerdata downloads the information, it confirms this to the Spanish Chamber of Deputies.
• The Spanish Chamber of Deputies deletes the folder from the corporate OneDrive. Emails exchanged with Camerdata regarding data transfers made from 2023 to the present are provided as
documentary evidence.
2. That the CDE has provided as Annex X File ***FILE.2, which contains the hashes of the first 500 records corresponding to the NIFs of the self-employed entrepreneurs in the sample provided by the CDE.
That, upon examining the aforementioned document, Annex X, (folios 2,225 to 2,256), it is observed that
the list provided includes, for each line (equivalent to each of the records),
a double piece of information separated by a vertical line: the first is composed
exclusively of digits, nine in total. The second is alphanumeric information (thirty-two elements) that corresponds to the hash.
That records 1 and 10 of the list provided are as follows:
The first record: (...).
The tenth: (...)
3. That in the document provided with the full content, accessed by CAMERDATA
in 2023 regarding the same 500 self-employed entrepreneurs whose records CDE
provided to the Agency on December 21, 2023, under the name "Document_4.xlsx," the CDE
states that:
"since these are self-employed entrepreneurs, the first 9 characters of each record do not
correspond to the NIF (Tax Identification Number), but rather to a sequential number (numeric record identifier) assigned during the file generation process that allows linking
each record of each individual entrepreneur with the HASH of their NIF (Tax Identification Number) provided in
file ***FILE.2."
That upon examining document Annex IX (pages 2,207 to 2,212), it is observed that the
first information field is a nine-digit list presented without separation next to the individual's first surname. Records 1 and 10 of the provided document are reproduced.
The first record is:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 99/204
(...)
The tenth record is:
(...)
THIRTEENTH: Regarding the purpose for which CAMERDATA processes the data of self-employed workers obtained from CDE and who its recipients are.
The file includes, incorporated by diligence of the acting inspector dated 10/18/2023, a screenshot obtained on 10/17/2023 of the “Legal Notice of the Use of the Portal and Services” of CAMERADATA, from which the following paragraphs are reproduced:
“6. Information on the processing of data (FEE and marketed products) not obtained from the interested party, related to marketing and advertising
6.1. Basic information
The records processed by Cameradata from the Spanish Company Files database that contain personal data have been obtained by
CAMERDATA after having been collected legitimately, as the data has been
obtained from an Official Census prepared by a public body, and the
person subject to the data (the interested party) either carries out an activity listed in Royal Decree of 2007 (RD 457/2007) or holds a position of responsibility that appears Published in the commercial register.
The purpose of processing these data is to send commercial and marketing communications, offering various goods or services that may be of interest to you.
[…]
6.2.3. Legitimacy of the processing:
This processing is carried out on data obtained from an Official Census
prepared by a public body, […] without the need to obtain your prior consent, based on the legitimate interest in knowing this information
required by CAMERDATA Clients, as set forth in Article 6.1.f of the
GDPR, and in Recital 47 of the GDPR, given that the intended purpose of
our clients is to conduct commercial and marketing communications campaigns, offering various goods or services that may be of interest to you.
In other cases, the legitimacy of the processing of these data by CAMERDATA Clients may correspond to the situations provided for in
letters b) or c) of Article 6.1 of the GDPR.
[…]
6.2.5. Purpose of processing
The purpose of processing is to conduct commercial and marketing communications campaigns to offer products or services
our own or those of third-party companies that may be of interest to you, for marketing purposes, within the business sphere and never within the private sphere.
6.2.6. Recipients of personal data
Only our clients who have requested the creation of a custom database to be delivered or
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 100/204
third-party companies that, in turn, provide services to end users for the same marketing purposes and those companies with which they have signed data processor agreements or contracts may access the personal data for which CAMERDATA is the data controller. (Pages 84 to 86)
FOURTEENTH: Regarding the purpose for which CAMERDATA processes the data obtained from CDE.
CAMERDATA declares that it has published this announcement on the websites of seven Chambers of Commerce in order to inform interested parties of the processing of their personal data, given that it considers that the exception provided for in Article 14.5.b) of the GDPR applies to it:
“Information for self-employed workers regarding the protection of personal data
This communication informs all self-employed persons of the processing of their personal data by Camerdata and the ASEDIE member companies that are subject to its code of conduct for the data protection intermediary sector, which are listed below: Axesor, Datacentric, Iberinform, Informa, and Equifax.
The data processed by CAMERDATA and related companies has been
legitimately collected by CAMERDATA and obtained from an official Census
prepared by a public body, corresponding to the person subject to the data (the self-employed worker) in the exercise of an activity listed in the Royal Decree of 2007 (RD 475/2007).
The purpose of processing this data is to send commercial and marketing communications, offering various goods or services that
may be of interest to you, as well as commercial information about the business activity carried out by the self-employed worker.
If you wish to exercise your rights of access [...]
FIFTEENTH: The data comprising the Registry of Economic Activities managed by the Regional Treasury of Navarre are public pursuant to Article 156.2 of Regional Law 2/1995, of March 10, on Local Treasuries of Navarre.
LEGAL BASIS
I
Jurisdiction
In accordance with the powers granted to each supervisory authority by Article 58.2 of the GDPR and as established in Articles 47, 48.1, 64.2, and 68.1 of the LOPDGDD,
the President of the Spanish Data Protection Agency is competent to resolve this procedure.
Likewise, Article 63.2 of the LOPDGDD establishes: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the regulations issued in its development, and, insofar as they do not contradict them, by the general rules on administrative procedures."
II
Preliminary Questions
1. Purpose of the procedure. Article 19 of the LOPDGDD.
1.1. Based on the definition of "processing" provided in Article 4.2 of the GDPR, CDE's conduct, which is the subject of this sanctioning procedure, materializes in the transfer to the company CAMERDATA, without an adequate legal basis, of personal data of the individual entrepreneurs to which CDE has lawfully accessed; this transfer has been carried out in execution of a private contract between CDE and CAMERDATA called the "Business Database Transfer Agreement," signed on February 15, 2016, and in force when CDE responded to the Data Inspectorate's request, that is, on December 20, 2023, since it was sent in response to the Inspector's request to provide a copy of the signed and "current" contracts entered into with CAMERDATA. CDE's conduct, the subject of this procedure, also includes processing the personal data of self-employed entrepreneurs for a purpose incompatible with the specific purpose (provided for in Article 8 of Law 4/2014) for which CDE lawfully accesses them. It violated, with respect to the self-employed entrepreneurs' tax identification number (NIF), the obligation imposed by the GDPR to guarantee the confidentiality of the data it processes. In violating the principle of fair processing in relation to self-employed entrepreneurs, who provided their data to the tax authorities in the confidence that, except in cases expressly provided for by law, it could not be transferred to third parties without their consent, having intentionally, premeditatedly, and systematically violated the express prohibition imposed in the Agreement signed with the AEAT (Spanish Tax Agency) on transferring to third parties data relating to the IAE (Tax Income Tax) and company census records provided by the Tax Authority. And in failing to comply with the obligation to inform interested parties about the processing—in this case, the transfer to CAMERDATA—of the data concerning them.
Thus, the sanctioning procedure before us focuses exclusively on
the processing of personal data of individual entrepreneurs; of
natural person entrepreneurs.
“Personal data” (Article 4.1 of the GDPR) means “any information relating to an
identified or identifiable natural person ("data subject"); an identifiable natural person is any person whose
identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name,
an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental,
economic, cultural or social identity of that natural person.”
According to Article 1, the GDPR aims to protect the fundamental rights and
freedoms of natural persons, in particular their right to the
protection of personal data. Recital 1 of the GDPR proclaims that “The
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 102/204
protection of natural persons with regard to the processing of personal data
is a fundamental right” recognized in Article 8(1) of the Charter of Fundamental Rights of the European Union ("the Charter") and in Article 16(1)
of the Treaty on the Functioning of the European Union (TFEU), which establish that “everyone has the right to the protection of personal data concerning him or her.”
Recital 14 reiterates the scope of the protection provided by the GDPR to
all natural persons. It states that "The protection granted by this
Regulation should apply to natural persons, regardless of their
nationality or place of residence, with regard to the processing of their personal data.
This Regulation does not regulate the processing of personal data relating to legal persons, and in particular to undertakings incorporated as legal persons,
including the name and form of the legal person and its contact details."
Article 2 of the GDPR, "Material Scope," determines in paragraph 2 the processing of personal data to which Regulation (EU) 679/2016 does not apply. None of the four cases mentioned in the provision expressly refers to the processing of personal data of natural person entrepreneurs.
It is evident from the foregoing that the protection provided by the GDPR, insofar as it extends to all natural persons, includes the processing of personal data of self-employed entrepreneurs. And there is also evidence of the absence of
reasons that could justify, in light of the GDPR, a possible exclusion from its scope
of application of personal data concerning individuals
who carry out business activities as self-employed persons, in line with Article
2.3 of
Royal Decree 1720/2007, of December 21.
Directive 95/46/EC—expressly repealed by the GDPR—was transposed into Spanish domestic law through Organic Law 15/1999 on the Protection of Personal Data (LOPD). The implementing regulations, approved by Royal Decree 1720/2007 of December 21 (RLOPOD), established in Article 2, "Objective Scope of Application," Section 3:
"3. Likewise, data relating to individual entrepreneurs, when referring to them in their capacity as merchants, industrialists, or shipowners, shall also be deemed to be excluded from the applicable personal data protection regime."
(Emphasis added)
The GDPR has represented a substantial advance in the effective protection of the right
relating to the protection of the personal data of individuals in relation to Directive
95/46/EC. This is despite the fact that a different conclusion could be reached if the assessment of both regulations is superficial and consists of little more than comparing the literal meaning of Article 1 of the GDPR and the Directive. On this aspect, the ECJ ruling of 27/02/2025, Case
C-203/22, states:
"51 Finally, with regard to the purposes of the GDPR, it is necessary to recall that the objective of this Regulation is, in particular, to ensure a high level of protection of the fundamental rights and freedoms of individuals, in particular their right to the protection of personal data, enshrined in Article 16 TFEU and guaranteed as a fundamental right in Article 8 of the Charter, which complements the right to privacy guaranteed in Article 7 of the latter [see, in this regard, the judgment of 4 October 2024, Schrems (Disclosure of Data to the General Public), C 446/21, EU:C:2024:834, paragraph 45
and the case law cited].
52 Thus, as also stated in recital 11, the GDPR aims to strengthen and specify the rights of data subjects (judgment of 4 May 2023, Austrian Data Protection Act and CRIF, C 487/21, EU:C:2023:369,
paragraph 33 and the case law cited).
1.2. Article 19 of the LOPDGDD.
To the extent that Article 19 of the LOPDGDD is sought to be used to support the legitimacy of data processing, it is important to remember some grounds to be taken into account.
Thus, the GDPR in particular and the LOPDGDD are the general regulation that, for constitutional purposes, permits data processing without consent. One avenue for legitimization without consent is the legitimate interest protected by the GDPR (Article 6.1 f). It should be noted that our legislator, in the LOPDGDD (General Data Protection Act), has created some cases of
presumption of legitimate interest, in which there is greater certainty if these conditions are met. In any case, the avenue for legitimizing processing without consent
based on legitimate interest does not require a "regulatory presumption." Legitimate interest
constitutes an autonomous legal basis, which does not depend on the existence of a national law that presumes it. This is expressly recognized by the EDPB in its recent
guidelines. The absence of a presumption established by law (as in our case, Article 19.2 of the LOPDGDD) in no way excludes the possibility of legitimacy based on legitimate interest. Thus, "legitimate interest" can validly operate even in contexts not expressly regulated by national legislation, such as in cases where the presumption of legitimacy is present. However, its evaluation requires a more intensive analysis, and in these cases, its application requires a more restrictive and guarantee-based approach. There is no presumption, so the data controller based on legitimate interest must justify, based on the principle of proactive responsibility, the suitability, necessity, and proportionality of the processing, as well as the effective prevalence of its interest over the rights and freedoms of the data subject. The absence of a legal presumption increases the argumentative and documentary burden of the data controller.
Cases must be considered in which there is a regulation of legitimate interest that is similar or close to the one being supported. (such as Article 19.2, the provisions of which are not given here). Likewise, specific regulations must be taken into account (such as the Chamber of Commerce Act). Legal regulations may contain express prohibitions that will undoubtedly
not allow data processing, and regulations may also be established that
determine or guide the purpose of data use. In these cases, and on a case-by-case basis, it will be necessary to analyze whether or not the deviation from the purpose of the data is compatible and, if applicable, whether this new purpose can be legitimized by a new basis for legitimation,
such as a specific regulation or, where appropriate, legitimate interest. In these cases,
the admissibility of legitimation will undoubtedly depend on compliance with
a whole series of requirements, requisites, and guarantees. These requirements will become more
intense due to the nature of the data, the impact on the affected groups,
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 104/204
and various rights, in addition to data protection and the purposes of the processing itself.
On these grounds, it is now appropriate to rule out the existence of the prerequisites of Article
19 of the LOPDGDD. This article regulates a rebuttable presumption of the lawfulness of the processing that concerns, among other subjects, individual entrepreneurs.
Article 19 of the LOPDGDD, "Processing of contact data, of individual entrepreneurs, and of independent professionals," states:
"1. Unless proven otherwise, the processing of contact data and, where applicable, data relating to the function or position held by natural persons who provide services to a legal entity shall be presumed to be covered by the provisions of Article
6.1.f) of Regulation (EU) 2016/679, provided that the following requirements are met:
a) That The processing relates solely to the data necessary for their professional location.
b) The purpose of the processing is solely to maintain relations of any kind with the legal entity for which the data subject provides their services.
2. The same presumption shall apply to the processing of data relating to sole proprietors and independent professionals when the data relates to them solely in that capacity and is not processed to establish a relationship with them as natural persons.
3. The data controllers or processors referred to in Article 77.1 of this Organic Law may also process the data mentioned in the two
previous sections when this arises from a legal obligation or is necessary for the exercise of their powers. (Emphasis added)
This Agency cannot dispute, for the reasons explained below, that Article 19.2 of the GDPR has no other scope than to establish a
presumption of lawfulness that applies exclusively to the contact information of individual entrepreneurs.
According to its literal meaning, Article 19.1 of the LOPDGDD establishes a
iuris tantum presumption of lawfulness that is defined through two elements: its
foundation and its purpose. It is based on Article 6.1.f) and concerns contact information or, possibly, the function or position held. The presumption thus
defined in Article 19.1 applies to natural persons who provide services to a legal entity. When Article 19.2 of the LOPDGDD refers to the
application of "the same presumption," it must be taken as defined
in Section 1: for the aforementioned elements, its basis, and its purpose.
Thus, Article 19.2 merely states that the rebuttable presumption based on
Article 6.1.f) whose purpose is contact data will apply to the processing of data of self-employed entrepreneurs.
Furthermore, such an interpretation of the text of the law is supported by Opinion 757/2017, of October 26,
of the Council of State on the draft Organic Law on Data Protection (currently LOPDGDD), which, when commenting on what was Article 20 (currently Article 19) in the draft Organic Law, states:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 105/204
“Article 20 of the Draft Law regulates the processing of contact data of natural persons who provide services for a legal entity (paragraph 1) and for individual entrepreneurs (paragraph 2), in both cases invoking the provisions of Article 6.1.f) of the Regulation as legal protection. In the first case, in order to understand that there is legality under this article, the provision requires that the processing relates solely to the data necessary to locate the data subject's professional location and that the purpose of the processing is solely to maintain relations of any kind with the legal entity for which the data subject provides his or her services; In the second, the processing relates
solely to the data of entrepreneurs in that capacity and is not processed
to establish a relationship with them as natural persons." (Emphasis added)
The commentary included in Opinion 757/2017 of the Council of State on
Article 20 of the Draft Organic Law (currently Article 19 of the LOPDGDD) confirms that the presumption established therein operates,
exclusively, on the contact data of self-employed entrepreneurs. This is because it indicates that Article 20 of the Draft Law "regulates the processing of contact data" and immediately specifies who; who are the persons to whom such data pertain: natural persons who provide services for a legal entity (section 1) "and" individual entrepreneurs (section 2). If what the opinion had intended In other words, Article 20 of the Draft Regulation regulates the
processing of contact data only for natural persons who provide services to a legal entity, and for sole proprietors, all their data; the copulative conjunction "and" would not exist. Furthermore, the commentary adds that "in both cases," that is, in the processing of contact data in paragraphs 1 and 2 of Article 20 of the Draft Regulation, the basis for lawfulness is found in Article 6.1.f) of the Regulation. And, from there, the commentary examines what the requirements are, respectively, of paragraphs 1 and 2, based on Article 6.1.f) of the GDPR, for the processing—clearly, of contact data—to be lawful.
"The rules must be interpreted taking into account not only the proper meaning of the words, but also their context, the social reality of the time in which they are to be applied, and the spirit and purposes pursued by the regulations." of which it forms part”
(Article 3.1 of the Civil Code)
Article 19 of the LOPD cannot be separated from the GDPR. It is not permissible to interpret it separately or without regard to the GDPR, but only and exclusively within the context of the Regulation. In this regard, the objective guiding the drafting of the GDPR, to ensure effective and uniform protection of the right to the protection of personal data in the Member States of the Union, is once again underlined. Recital
(11) states that “The effective protection of personal data in the Union requires that the rights of data subjects and the obligations of those who process and determine the processing of personal data be strengthened and specified, and that equivalent powers be recognized in the Member States to supervise and ensure compliance with the rules relating to the protection of personal data, and that violations be punished with equivalent sanctions.”
For this purpose, the GDPR has articulated mechanisms that the Directive did not foresee, through which it reinforces the effectiveness of the fundamental right and which cannot be ignored when interpreting a regulation in light of the GDPR. Worth mentioning, among others, is the principle of proactive accountability (Article 5.2), which is applied to all the principles of Article 5.1 of the GDPR and which shifts the burden of proof of compliance to the data controller. The approach focuses on the risk that the fundamental rights and freedoms of individuals may pose as a result of the processing of personal data concerning them, so that the potential impact on fundamental rights and freedoms of a violation of the right to data protection gives this fundamental right an instrumental character. in the protection of all fundamental rights and
freedoms of the individual. Or protection by design, which obliges the
controller to implement appropriate technical and organizational measures to ensure
and be able to demonstrate that the processing complies with this Regulation.
The first name, surname, and NIF are personal data that accompany the individual
outside their business activity and do not lose their nature due to the fact that
they carry out a business activity. An interpretation of Article 19.2 of the
LOPDGDD that advocates that the processing of any data of a self-employed
businessperson when "referring to them solely in that capacity" enjoys a
presumption of lawfulness, de facto nullifies for this group of individuals the principle of
proactive accountability (Article 5.2) regarding the lawfulness of the processing
of their personal data. This, we insist, is when the personal data processed does not
lose its nature because its processing refers to the business person
in that capacity; expression, for The rest is very difficult to determine in practice and leads to a permanent situation of legal uncertainty regarding the protection of the personal data of more than one and a half million individuals.
The argument that all data of individual entrepreneurs fall within the rebuttable presumption of Article 19.2 of the LOPDGDD is contrary to the spirit of the GDPR and lacks support in its provisions. It would also constitute an unjustified restriction of the fundamental right to data protection due to the disproportionate nature of the fact that, in order to protect the security of commercial transactions, as invoked by CDE, the processing of all personal data of a self-employed entrepreneur is presumed to be lawful unless the entrepreneur proves that the processing in question is not.
This Agency understands that the processing of data of an individual entrepreneur other than contact information does not enjoy the presumption of lawfulness based on Article 6.1.f). of the GDPR. This applies even if the processing relates to data belonging to the individual
in their capacity as an entrepreneur and even if the processing is not intended to establish a personal relationship. The consequence is, in accordance with the principle of proactive accountability (Article 5.2 of the GDPR), that the controller of personal data of individual entrepreneurs other than contact information has the burden of proving that the processing carried out is supported by a lawful basis under the GDPR.
Having established the above, it is worth referring to the specific factual situation at hand:
the transfer by CDE of the data of individual entrepreneurs that it
lawfully obtained from the tax authorities for the fulfillment of certain public-administrative functions attributed to it by Law 4/2014.
The meaning that, in this Agency's opinion, Article 19.2 of the LOPDGDD has
only excluded the presumption of lawfulness Contact information, so CDE,
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 107/204
as the controller, would be required to demonstrate (under Article 5.2 GDPR) that the processing of the remaining data was lawful due to a legal basis under the GDPR.
However, without prejudice to the provisions set forth in the preceding paragraphs, it is
stated that, after weighing the legitimate interests of CDE or the third parties to whom it provides the data, on the one hand, and the interests, fundamental rights and freedoms of the self-employed entrepreneurs who own the affected personal data, on the other, the result is that CDE's processing of the self-employed workers' data cannot be covered by the circumstance of
Article 6.1.f) of the GDPR. In this regard, we refer to the discussion in
Ground VII, Violation of the principle of lawfulness.
It should also be added—without prejudice to returning to this issue later—that the provision in the tenth additional provision of the LOPDGDD, according to which public administrations may transfer, based on Article 6.1.f) of the GDPR, the data requested by them to private law subjects when they determine that the applicant has a legitimate interest that prevails over the rights and interests of the data subjects, is not applicable to CDE in the present case.
In this case, CAMERDATA, as a private law subject, has not requested a transfer to CDE. Nor has CDE made a corresponding prior weighing of the balance between, on the one hand, its legitimate interests or those of a third party, and, on the other, the rights, fundamental freedoms, and
interests of the data subjects. We are dealing with a private contract signed by a
commercial company and the CDE in the exercise of purely private activities.
Furthermore, the CDE has the status of a public administration to the extent that it acts in the exercise of the public-administrative functions entrusted to it by Law 4/2014.
For the aforementioned tenth additional provision to be applicable, the CDE would have to
carry out the transfer in the exercise of the entrusted public-legal functions,
since any treatment outside of such functions strips it of its status as a public administration. However, a transfer that neither relates to the "public census" (which we will refer to later) nor entails making it public (the publicity referred to in Article 8 of Law 4/2014, by its very nature, must allow free and general access to the information, and in this case only those who contract with CAMERDATA can access the transferred information) would fall outside the public legal functions entrusted to it, and in this case, CDE would not act as a public authority, which is the essential requirement for applying the aforementioned tenth additional provision.
2. Regarding the data controller. Non-application of Article 77 of the LOPDGDD.
2.1. Article 4.7 of the GDPR defines the controller as "the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing; where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law." (Emphasis added)
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 108/204
When CDE processes the data of individual entrepreneurs in compliance with a legal obligation (formerly Article 8 of Law 4/2014) or in compliance with a mission of public interest (formerly Article 21 in conjunction with Article 5.1 of Law 4/2014), it is
this Law that identifies it as the controller of the specific data processing carried out to fulfill the obligation imposed on it or to perform the public mission assigned to it.
It is worth mentioning at this point that the Agreement "for the transfer of tax information to Official Chambers for the exercise of their public-administrative functions," signed between the AEAT and the Spanish Chamber of Commerce on November 25, 2019, amended and extended by an Addendum signed in December 2023, establishes in its ninth clause, point 5: "At the Tax Agency, the Data Controller for the purposes of the General Data Protection Regulation is the head of the General Directorate, and at the Spanish Chamber of Commerce and the Chambers, the Data Controller will be the person designated by each Chamber." (Emphasis added)
However, with regard to the receipt of data from the AEAT, the provisions of the ninth clause of the Agreement signed with the AEAT, according to which the person designated by the CDE will be the data controller, are not applicable. CDE is the
controller for the processing carried out upon receipt of data from the IAE (Tax Income Tax) and the census of self-employed entrepreneurs transmitted to it by the AEAT (Spanish Tax Agency) and the other tax authorities, and is also responsible for the processing of data it carries out when preparing the public census and for other public-administrative functions entrusted to it by Law 4/2014.
This conclusion seems necessary in light of the criteria of Guidelines 07/2020 regarding
the functional nature of the concept of controller and taking into consideration the
presumption established therein that the processing carried out within an organization by its employees has been carried out by that organization.
Guidelines 7/2020 on the concept of controller and processor in the GDPR, version 2.0, approved by the European Data Protection Board (hereinafter EDPB) on July 7, 2021, indicate that the concept of controller is a functional concept, as its objective is to assign responsibilities based on the actual role played by each party in the processing carried out.
They also indicate (section 12) that “the legal status of a ‘controller’ […] should, in principle, be established by virtue of its specific activities in a given situation and not based on the formal designation of a participant as a ‘controller’ […] This implies that the assignment of the role of controller […] should normally derive from an analysis of the facts or circumstances of the case and, consequently, is non-negotiable.”
They also indicate (section 13) that the concept of data controller is an "autonomous" concept since it must be interpreted primarily in accordance with EU data protection law and "should not be affected by other concepts—with which it sometimes conflicts or overlaps—from other areas of law."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 109/204
And in section 18 they state: “Sometimes, companies and public bodies appoint a specific person who is responsible for processing activities. Even when a specific natural person is appointed to ensure compliance with data protection regulations, they will not be the data controller, but will act on behalf of the legal entity (company or public body), which, as the data controller, will ultimately be liable for any potential violations of the regulations […] In principle, all processing of personal data carried out by employees within the scope of an organization's activities will be presumed to be carried out under the control of that organization.” (Emphasis added)
Different from the data processing we have referred to—the lawful processing that CDE carries out in compliance with the provisions of Law 4/2014—is the data processing that constitutes the subject of this sanctioning procedure,
and in which CDE acts as the controller. This processing is specified in the transfer to CAMERDATA, in execution of a private contract signed between the two, of the data of self-employed entrepreneurs. This data is lawfully obtained from tax authorities for the sole purpose of fulfilling a legal obligation established in Article 8 of Law 4/2014, and this provision also authorizes it to process it for other public administrative functions provided for therein.
2.2. Article 77 of the LOPDGDD, "Regime applicable to certain categories of controllers or processors," incorporates a specific regime, essentially described in section 2, applicable to the subjects listed in section 1. According to this, the resolution issued by the data protection authority when such subjects commit any of the violations referred to in Articles 72 to 74 of the aforementioned Organic Law will declare the violation, establishing, where appropriate, the measures to be adopted to cease the conduct or correct the effects of the violation committed, with the exception of that provided for in Article 58.2.i of the GDPR (administrative fine).
Article 77.1 of the LOPDGDD provides that "The regime established in this article shall apply to processing for which the following parties are responsible or in charge," among which it mentions, letter g), "Public law corporations when the purposes of the processing are related to the exercise of public law powers." (Emphasis added)
Letter g of Article 77.1 of the LOPDGDD requires, in order to apply the regime described in section 2 of Article 77: (i) that the data subject be a public law corporation and (ii) that the data processing has a purpose related "to the exercise of public law powers."
Law 4/2014 grants the CHAMBER OF SPAIN the status of a Public Law corporation and stipulates that it may act in the exercise of public-administrative functions (Article 21 in relation to Article 5.1) or in the exercise of purely private activities (Article 21 in relation to Article 5.3).
The data processing in question, the transfer by CDE to CAMERDATA of the data of self-employed entrepreneurs, is not intended to fulfill a public-administrative function assigned by Law 4/2014. In relation to this processing, CDE
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 110/204
has freely chosen the purposes and means and, in this regard, has signed a contract with CAMERDATA under which it transfers personal data of self-employed entrepreneurs that it lawfully obtains for other purposes.
Therefore, assuming that the processing of data of self-employed entrepreneurs carried out by CDE and which is the subject of this procedure—the transfer of such data to CAMERDATA in execution of a private contract—does not meet the conditions that constitute the factual situation described in letter g) of Article 77.1 of the LOPDGDD, since the processing is not related to the exercise of public powers, we conclude that the legal regime provided for in Article 77 of the LOPDGDD is not applicable to CDE, as the data controller. III
Context and characteristics of the data processing subject to this procedure
1. Law 4/2014, of April 1, Basic Law of the Official Chambers of Commerce, Industry, Services, and Navigation (hereinafter, Law 4/2014 or Basic Law of Chambers), enacted—with the exception of its Article 5.2—under Article 149.1, sections 6, 13, and 18, of the Spanish Constitution (EC), establishes the basic regulations of the
Official Chambers of Commerce, Industry, Services, and, where applicable, Navigation (hereinafter, the Chambers) and the specific regime of the Official Chamber of Commerce, Industry, Services, and Navigation of Spain (hereinafter, the Chamber of Spain or CDE).
The CDE is a public law corporation and has legal personality and full capacity to act in the fulfillment of its purposes. This is established in Article 20.1 of Law 4/2014, which also adds, "that it is configured as an advisory and collaborative body with the General State Administration, without prejudice to any private interests it may pursue."
Law 4/2014 introduces into our legal system a chamber system of "universal membership" without any financial obligation on its members, so that their membership in the respective Chamber occurs "ex officio" (Article 7). With this, Law 4/2014 departs from the approach followed by the previous law, Law 3/1993, which had established a model of mandatory membership and compulsory payment of dues, and from the approach subsequently introduced through the reform of Law 3/1993 by Royal Decree-Law 13/2010, which changed it to a chamber system of "voluntary membership."
Article 8 of Law 4/2014, under the heading "Public Census," provides:
"The Official Chambers of Commerce, Industry, Services, and Navigation shall compile a public census of companies, which shall include natural or legal persons, national or foreign, that carry out commercial, industrial, service, and shipping activities in national territory. For the purpose of this compilation, they shall have the collaboration of the competent tax authority as well as other authorities that provide the necessary information, guaranteeing, in all cases, confidentiality in the processing and exclusive use of said information.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 111/204
For the compilation of the public census of companies, the tax authorities shall provide the Official Chamber of Commerce, Industry, Services, and Navigation of Spain and the Official Chambers of Commerce, Industry, Services, and Navigation of Spain. Browsing the data on the Economic Activities Tax and
the necessary company censuses. Only the employees of each Chamber determined by the plenary session will have access
to the information provided by the tax administration.
This information will be used to compile the public company census, to fulfill the public-administrative functions that this Law
assigns to the Chambers, as well as to compile the electoral census
referred to in Article 17 thereof.
These personnel shall have, with regard to the aforementioned data, the same duty of confidentiality as tax administration officials. Failure to comply
with this duty shall, in any case, constitute a very serious infraction in accordance with
their disciplinary regime. (Emphasis added)
The law imposes on the CDE and the Chambers the obligation to prepare ("shall prepare") a public business census, and to fulfill this obligation, it stipulates that they will rely on the collaboration of the tax authorities.
The provision obliges the tax authorities to communicate—"shall provide," the law states—both to the CDE and the Chambers "the data" on the tax on economic activities (hereinafter, IAE) and the company censuses that are "necessary" for the fulfillment of the purposes it determines.
Furthermore, the CDE and the Chambers are authorized to process the information received for the preparation of the public census in order to fulfill "the public-administrative functions that this Law attributes to the Chambers" and the preparation of the electoral census referred to in Article 17 of Law 4/2014.
The obligation that The Law requires tax authorities to
communicate to the CDE and the other Chambers the IAE data and company census data necessary for the purposes established in Article 8. It is accompanied by the
establishment of measures intended to guarantee the right of individuals
to the protection of their data: it determines the specific purposes
for which the CDE and the Chambers may process the data provided to them by the tax authorities; it determines what data may be provided by the
tax authorities—"those necessary" to meet said purposes—and
it imposes on the data transferees (the CDE and the Chambers) the obligation to
guarantee their "confidentiality" in the processing and "the exclusive use" of the information thus obtained. The Preamble to Law 4/2014 states in Section II:
"The Official Chambers of Commerce, Industry, Services and Navigation shall prepare
a public census of companies, for the preparation of which they will have the collaboration of the competent tax authorities, guaranteeing, in all cases, the confidentiality of the processing and exclusive use of the information for the purposes established by law.”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 112/204
Chapter V of Law 4/2014 is dedicated to the Spanish Chamber of Commerce and regulates in
Article 21 the “Functions” entrusted to it:
“1. The Official Chamber of Commerce, Industry, Services and Navigation of Spain
shall perform the following functions:
a) Promote the general interests of commerce, industry, services and navigation at the state level.
b) Represent all the Chambers of Commerce before various state
and international bodies.
c) Coordinate and promote actions that affect all the Spanish Chambers of Commerce.
d) Exercise at the state level and, in coordination with the Chambers of Commerce,
Industry, Services, and Navigation, the functions referred to in section 1
of Article 5 of this Law.
e) Report, with the nature and scope provided for in current legislation, on
draft laws or state provisions of any rank that directly affect
commerce, industry, services, and navigation.
f) Advise the General State Administration, under the terms it
establishes, on matters related to commerce, industry, services, and
navigation.
g) Perform the public-administrative functions assigned to it,
when they affect the State as a whole.
h) Manage, under the terms provided for in the agreements with the Ministry of
Economy and Competitiveness, the actions planned in the Chamber of
Internationalization Plan and the Chamber of Competitiveness Plan.
i) Perform national and international commercial mediation and arbitration functions, in accordance with current legislation.” (Emphasis added)
Article 5.1 of Law 4/2014, to which Article 21.1.g refers, addresses functions of a public-administrative nature. Article 5 distinguishes, by virtue of their nature, between the functions "of a public-administrative nature," set forth in Article 5.1; the "public-administrative functions [...], in the manner and to the extent determined, where appropriate, by the Autonomous Communities," set forth in Article 5.2; and "other activities, which shall be private in nature and shall be provided under a free competition regime, which contribute to the defense, support, or promotion of commerce, industry, services, and navigation, or which are useful for the development of the aforementioned purposes and, in particular, the establishment of business information and advisory services," set forth in Article 5.3.
Article 5.1. Law 14/2014 provides:
“1. The Official Chambers of Commerce, Industry, Services, and Navigation
shall have the following public-administrative functions:
a) Issue certificates of origin and other certifications related to national and international commercial traffic, in the cases provided for in current regulations.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 113/204
b) Compile commercial customs and practices, as well as business practices and customs, and issue certifications regarding their existence.
c) Act as an advisory body to Public Administrations, under the terms established by them, for the development of commerce, industry, services, and navigation.
d) Develop activities to support and encourage foreign trade.
e) Participate with the competent administrations in organizing practical training in workplaces included in the Vocational Training courses and Dual Vocational Training actions and initiatives, especially in the selection and validation of workplaces and companies, in the appointment and training of student tutors, and in the monitoring and evaluation of program compliance, without prejudice to the functions that may be assigned to business organizations in this area.
f) Process, when required by the General State Administration, public aid programs for companies in the terms established in each case, as well as manage public services related to them when their management falls under the responsibility of the State Administration.
g) Manage, in accordance with Article 8 of this Law, a public census of all companies, as well as their establishments, branches, and agencies located within their district.
h) Act as one-stop business centers when required to do so by the competent Public Administrations.
i) Collaborate with the Administrations Public administrations in the administrative simplification
of procedures for starting and developing economic and business activities, as well as in improving economic and business regulation.
j) Promote actions aimed at increasing the competitiveness of small and medium-sized enterprises, and encourage innovation and technology transfer to companies.
k) Promote and collaborate with public administrations in the implementation of the digital economy in companies.
l) If the managing authority of the European Union Funds deems it appropriate, the Chambers may participate in the management of European Union Funds aimed at improving competitiveness in companies.
2. Communication of data by tax authorities to the CDE and the Chambers
The legal basis for the communication by tax authorities of the data of individual entrepreneurs obtained through the IAE and the
census of entrepreneurs, professionals, and withholding agents to the CDE and the Chambers for the purposes set forth in Article 8 of Law 4/2014 is that established in letter c) of Article 6.1. of the GDPR: “The processing is necessary for compliance with a legal obligation imposed on the controller. All this, without prejudice to the fact that the transferring tax authority must always be able to prove that the processing carried out has complied with the other principles that, pursuant to Article 5 of the GDPR, govern the processing of data.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 114/204
Tax authorities are not required to inform data subjects of the transfer pursuant to Article 13(4) of the GDPR, which states: “The provisions of paragraphs 1, 2, and 3 shall not apply when and to the extent that the data subject already has the information.”
This provision must be interpreted in light of Recital 62 of the GDPR, which states:
“It is not necessary to impose the obligation to provide information when the interested party already has the information, when the registration or communication of personal data is expressly established by law."
With regard to the AEAT, it should be noted that its DPO has informed this Agency that it does inform interested parties, in accordance with Article 13, paragraphs 1, 2, and 3, of the GDPR, of the transfer of personal data to CDE. It indicates that the information is provided in layers and that when the census forms 036 and 037 are completed, a legend appears on the "sign and send" screen that reads: "You can find more information about possible processing, transfers, and the procedure for exercising the rights established in Articles 15 to 22 of the regulation in the following
link (https://sede.aqenciatributaria.qob.es/Sede/condiciones-uso-sede-electronica/datos-personales.html).
Likewise, the AEAT includes in its Registry of Processing Activities (RAT) the processing that consists of communicating to the CDE and the Chambers the data provided to the "census of entrepreneurs, professionals, and withholding agents (forms 036 and 037)."
3. Agreement between the CDE and the AEAT
On November 25, 2019, the CDE and the AEAT signed an Agreement "for the transfer of tax information to the Official Chambers for the exercise of their public-administrative functions," published in the Official State Gazette (BOE) on December 20, 2019.
The four-year Agreement has been extended for another four years through an amendment and extension addendum signed on December 19, 2023, published in the Official State Gazette (BOE) on February 16, 2024, with clauses eight ("Control and security of the data provided") and nine ("Data protection") affected by the amendment.
The Explanatory Memorandum of Understanding of the Agreement states: CDE "performs public functions, especially those directly and indirectly related to letters d) to i) of Article 21.1 of Law 4/2014.
The Official Chambers of Commerce, Industry, Services, and Navigation are
Public Law Corporations with legal personality and full capacity to act in the fulfillment of their purposes and, when acting in the exercise of the administrative or public-administrative functions entrusted to them by law, are considered public administrations.
The purpose of the State Tax Administration Agency's provision of information will, in all cases, be the exercise of public functions, both by […] and by the Official Chamber of Commerce, Industry, Services and Navigation of Spain, in its capacity as public administration.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 115/204
The purpose of the Agreement is to establish the conditions and procedure governing the transfer of information from the AEAT to the Chambers and the CDE, "while preserving in all cases the rights of the persons to whom it refers" and, in summary, has the following content:
i. Regarding the "Purpose of the transfer of information," the second clause of the Agreement distinguishes between (i) the "transfer of information from the Tax Agency" and (ii) the "transfer of data from the Tax on Economic Activities and company census data."
In the first case (i), the purpose of the transfer will be "collaboration with the Chamber of Commerce of Spain and the Chambers in the performance of the public functions assigned to them when, in the exercise of these functions, the Regulations
require the provision of a certification issued by the Tax Agency or
the submission, in original, copy, or certification, of the interested parties' tax returns or any other communication issued by the Tax Agency, particularly in the case of those not required to file a return. In these cases, the information that must be included in such documents will be requested directly from the Tax Agency, provided that it is necessary for the exercise of such functions and
relates to a large number of interested parties or affected parties."
In the second case (ii), the transfer has "the exclusive purpose of preparing the public business register, fulfilling the public-administrative functions that Basic Law 4/2014 on Official Chambers of Commerce, Industry, Services, and Navigation attributes to the Chambers, as well as preparing the electoral register referred to in Article 17 of the same Law."
Annex III of the Agreement addresses public functions and separately describes the public functions to be performed by the CDE and the Chambers. It states that:
“The basis for the execution and implementation of this Agreement is the status of public administration, […] of the Official Chamber of Commerce, Industry, Services, and Navigation of Spain and of the […], with the provision of information to be provided by the State Tax Administration Agency, in all cases, being intended for the exercise of public functions.”
“The public functions to be performed by the Official Chamber of Commerce, Industry, Services, and Navigation are listed directly and indirectly in
letters d) to i) of Article 21.1 of Law 4/2014, of April 1, Basic Law of the Official Chambers of Commerce, Industry, Services, and Navigation.”
iii. When referring to the authorization of those interested in the information provided
(clause three), the Agreement is based on the previous distinction:
In the case (i) of transfer of tax information, the express and prior authorization of the interested party is required: "the express prior authorization of the interested parties must be obtained, as established in article 95.1.k) of the General Tax Law, under the terms and with the guarantees established in article 2.4 of the Order of the Ministry of Economy and Finance of November 18, 1999."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 116/204
In the case (ii) of the transfer of IAE data and company census data, the authorization of the interested parties is not required: "However, the transfer of data from the
Tax on Economic Activities and company census data imposed by
Article 8 of the aforementioned Law 4/2014 will not require the prior authorization of the interested parties."
iv. The data provided by the AEAT are those declared by taxpayers and
other parties obliged to provide information (clause six).
v. Regarding the recipients of the information, the Agreement states (clause four)
that the information transferred by the AEAT may only be received by the bodies
of the CDE and the Chambers "that have been assigned the public functions that justify the transfer." "Under no circumstances may the recipients be bodies, agencies, or
entities that perform functions other than those described in the second clause of this
Agreement."
It also adds: "All of this without prejudice to the strict allocation of the information
sent by the Tax Agency to the purposes that justify it and for which it is requested."
"In any case, the recipient may not transfer the information sent
by the Tax Agency to third parties."
vi. When the information provided includes personal data of the interested parties,
both the transferor, the AEAT (Tax Agency), the transferee, the Spanish Chamber of Commerce, and the
Chambers will process the data in accordance with the GDPR (clause nine).
vii. Regarding the data controller (clause nine, section 5), it establishes:
“At the Tax Agency, the Data Controller for the purposes of the General Data Protection Regulation is the head of the General Directorate, and at the Spanish Chamber of Commerce and the Chambers of Commerce, the Data Controller will be the person designated by each Chamber.”
vii. Provision of information (clause seven). This is detailed in Annex I to the Agreement,
according to which, when the information comes from business census data and
is intended for the preparation of the “public business census” (article 8 of Law 4/2014) and for the preparation of the electoral census (article 17), it will be provided annually. And the information regarding IAE data for the preparation of the public business census (Article 8 of Law 4/2014) and the electoral census (Article 17) will be updated annually, with semiannual updates.
viii. Regarding the control and security of the data provided, clause eight states that it will be governed by the provisions of the regulations in force at any given time regarding data protection and information security, and in particular by Regulation (EU) 2016/679 […], Organic Law 3/2018, […] the regulatory provisions of internal regulations regarding the protection of personal data, Royal Decree 3/2010, of January 8, which regulates the National Security Framework in the field of Electronic Administration […], and
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 117/204
the Information Security Policy of the Tax Agency and the Chambers that adhere to this Agreement.”
It provides for the existence of "controls over the custody and use of the information provided under this Agreement" adopted by both the entity transferring the information and the entity holding the information transferred. Regarding the former, it establishes that the Chambers "shall adopt specific measures to avoid the risk that the information may be used, even inadvertently, for other purposes, or by personnel with a conflict of interest. Measures shall also be taken to ensure compliance with the conditions underlying each of the transfers."
ix. An obligation of confidentiality is imposed on authorities, officials, and other personnel who have knowledge of the data or information provided under this Agreement. It states that "Violation of this obligation will entail incurring the appropriate criminal, administrative, and civil liabilities, as well as subjection to the exercise of the powers of the Data Protection Agency." (Clause Ten)
4. The “Public Business Register”
It is necessary to refer to the “public business register”—a term used in Article 8
of Law 4/2014—in order to clarify its concept and content.
The CDE is required to compile a public business register that includes all
companies, whether legal entities or individuals, national or foreign, that carry out commercial, industrial, service, and shipping activities in the national territory.
The public business register, regulated in Article 8 of this Law, is an institutional registry whose main purpose is to identify and keep up-to-date all
natural or legal entities, national or foreign, that carry out economic activities—commercial, industrial, service, or shipping—in the national territory.
Its compilation—and management—is the responsibility of the Chambers of Commerce and is
based on data provided by tax authorities, as well as other public authorities. that can provide necessary information. It should be noted that, as can be deduced from the law, the purpose of this census is not commercial, but strictly public-administrative. On the one hand, it serves as a basis for fulfilling the functions that the law attributes to the Chambers of Commerce in their capacity as public-law corporations, as bodies of representation, promotion, and advisory services to the business community. It also has the specific additional purpose of compiling the electoral register that determines who can participate in the election processes for the representative bodies of the Chambers themselves. The same limitation on specific personnel regarding access to tax data used to compile the census reflects that the census has an institutional nature, linked to the functioning of the chamber system and the public management of the business community, and cannot be understood as a general source of economic publicity nor be confused with private databases used for informational or commercial purposes. The regulation of the Public Business Census is what it is. Despite the The functional and economic relevance that a business information ecosystem can represent, the truth is that the legislator, although he could have expressly chosen to establish a legal regime for the disclosure or generalized access to this data—accompanied by appropriate guarantees—has not done so. The current legislation in Spain—possibly unlike other European Union countries—has not articulated a regulatory framework that provides openly, and with express legal backing, for the availability of these databases with information on individual entrepreneurs, even when such access could serve legitimate public or private interests and is mediated by obligations of transparency, oversight, and accountability. Thus, the only option available is to resort to the possibilities offered by the legal system, where appropriate, to individualized or granular access management, which is not the current practice. The legitimacy, opportunity, or the usefulness of other purposes or interests,
other than those determined by the legislator for the business census. The business census has not been designed by the legislator to cover an
instrument for purposes that can be pursued through the processing of data of individual entrepreneurs by infomediary entities, such as the interest
of such entities in structuring and offering information on business or professional activities carried out by individuals, in response to a
continuous demand from multiple sectors. This purpose, where appropriate, could support
a legitimate interest that would allow the creation of information products that support decision-making in commercial, contractual, or professional environments.
Consequently, several purposes that could be considered legitimate in other
contexts do not fit within the legal framework of this census. Thus, it is not
contemplated that the census serves as a business verification tool available to third parties, nor that it provides companies, public administrations, or
professionals with access to data for Assess the existence, continuity, or economic capacity of a business before entering into contracts or establishing legal relationships.
Although this purpose may be useful for mitigating risks or strengthening security in commercial transactions, it is not provided for in the law as a function of the chamber's census.
Nor is it included among its objectives to allow verification of the professional or business status of a natural person in compliance with specific regulations, such as those related to public procurement, anti-money laundering, or financing, even though these needs exist in other areas.
Furthermore, the law does not attribute to the census the purpose of individual promotion of the entrepreneur, nor does it grant it a publicity-related purpose in the sense of increasing the visibility or competitive positioning of the subject in the market. Access to census data is also subject to strict confidentiality conditions, which reinforces its restricted nature and is for internal use by the Chambers.
Finally, although Article 19 of the LOPDGDD, and under its conditions, allows the processing of professional location data of individual entrepreneurs to facilitate economic and legal relations, it is not linked to the public census. Therefore,
it should be understood that the Chamber of Deputies' census does not cover or enable uses aimed at
processing data for informational, commercial, or analytical purposes by third parties, which must be based on other sources and different legal mechanisms.
If these purposes are pursued through data processing tools and processes,
there must be a legitimacy that does not facilitate the regulation of the business census.
And, in any case, data processing that is appropriate and relevant to the business census according to its legal design must comply with the provisions of the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 119/204
GDPR, so the provisions of Law 4/2014 regarding the public census that concern or are related to the processing of personal data of individual entrepreneurs can only be interpreted in light of the GDPR and the
LOPDGDD.
CDE has maintained in its arguments throughout this procedure that Law
4/2014 does not determine which data are part of the public census, nor does it determine
the means by which it must be made public. In its opinion, the Agency, having
found a violation of the GDPR in the transfer of the database to CAMERDATA, is supplanting CDE in a decision (the content and form of publicity of the public census) that is solely within the jurisdiction of that corporation.
The obligation that Law 4/2014 imposes on CDE to "prepare" (ex. Article 8) and the
authorization it grants (ex. Article 8) to process IAE and census data, which it obtains from the tax authorities to fulfill the public function of "managing" (ex. Article 21.1.d, in conjunction with Article 5.1.g) relates to a specific purpose: "the public business census."
The dictionary of the Royal Spanish Academy (RAE) indicates "registration" or "registration" as synonyms for census. The term "registry" is defined (second
meaning) as "a place from which something can be registered or viewed." We are, therefore,
referring to a "public" business registry. In short, Article 8 of Law 4/2014
refers to a public business registry.
The registry function is a function of the State manifested in the existence of
registries that refer to various aspects and sectors of life. It is a public function.
The public nature of the registry is an essential aspect of the ultimate purpose
of the registry function, which is to ensure legal certainty.
When Article 8 of the Law entrusts the CDE with preparing a public census, it
imposes the obligation to prepare a public registry. And by entrusting Article
5.1.g) with the public administrative function of "managing" a public business census, in the terms of
Article 8, it is entrusting CDE with the
performance of the registry function in relation to the aforementioned public business census.
Thus, the purpose of the preparation and management assigned to CDE is a public registry.
A business file or database created from the information to which CDE has access in the performance of the entrusted public administrative function (formerly Article 5.1.g) is unrelated to the registry function. That purpose would be something else, not
the "public business census" mentioned in Law 4/2014, and, therefore, its processing could in no case be protected by the legal bases derived from
the provisions of the aforementioned legal text. The "management" of the public census may undoubtedly involve data processing. If appropriate, and depending on the specific form of access to the registry deemed appropriate, it could involve providing individualized access or access to specific sectors or areas for the purposes of the public census, but not the subject of the contract being considered here.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 120/204
With regard to (obviously in relation to self-employed entrepreneurs) the content of the "public business register," and what data it contains, in contrast to CDE's assertion that Law 4/2014 does not determine what these are—which leads it to conclude that it is its sole responsibility to specify its content—it is important to remember that the determination of the register must be made by the data controllers according to their specific legal framework, but subject to the limitations of the GDPR and the LOPDGDD. At this point, the general principles of law must be taken into account, particularly that of proportionality, to which any restriction of a fundamental right such as the one at hand must adhere. The GDPR and the LOPDGDD can determine which personal data should not be included in the public business registry because they are inadequate, unnecessary, or disproportionate. In this regard, Article 5.1.c) of the GDPR proclaims the principle of data minimization, according to which the data processed must be "adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed."
Having said this, it is essential to highlight that it is confirmed in the file that the public business registry is currently accessible from CDE's corporate website, a fact also reported on its own website.
Thus, the screenshots obtained from www.camara.es included in the
file (Third Proven Fact) confirm that on the website www.camara.es/funcion-
consultiva/consulta-del-censo-publico-de-empresas, under the heading "Public Business Census," a list of drop-down menus appears, and the first, "Description," offers this information regarding the "Public Business Census":
"We provide you with the data included in the Public Census, which contains all the legal and physical entities of the Official Chambers of Commerce, Industry,
Services, and, where applicable, Navigation of Spain."
It also states that:
"it compiles one record per activity (it does not accumulate multiple activities under the same address) and compiles the following data per record: Name, Address, Postal Code, Municipality, Activity."
Access to the Public Business Registry from the CDE website is, as required by its
nature, accessible to all.
Regarding its content, it is observed that the public business registry accessible
through the CDE corporate website includes the following personal data of individual entrepreneurs: first and last name, postal address (street
name and number, sometimes the floor), postal code, name of the province and municipality, IAE (Tax Identification Number), and a description of the activity. It does not include the NIF (Tax Identification Number). This demonstrates that the data controller, CDE, has fully applied
the minimization principle (ex Article 5.1.c GDPR) in its preparation. Therefore, the criteria regarding which data may or may not be included in the public business registry
exist and are established by the GDPR and the LOPDGDD (General Data Protection Act).
It should be added—given that the CDE has maintained that it is responsible for determining what data is included in the public business register and has stated that
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 121/204
it could have perfectly well decided to also include the NIF data of individual entrepreneurs—that the controversy over whether the NIF of individual entrepreneurs should or should not be included in the public business register would be resolved negatively after a proportionality assessment, applying the constitutional doctrine contained, among others, in STC 39/2016, of March 31.
The Supreme Court echoed this in the Supreme Court ruling of 11/02/2016 (appeal 2538/2015)
in which it states that "having raised the debate on proportionality between the rights invoked in conflict, it should be remembered that the Constitutional Court
has been outlining this judgment of proportionality, declaring that it requires
the concurrence of three requirements or conditions. On the one hand, a judgment of suitability,
referring to determining whether the measure adopted is likely to achieve the proposed objective.
Secondly, a judgment of necessity, understood in the sense that the
purpose pursued by the measure is essential for its legitimate purpose and cannot be
obtained by other means that avoid the infringement of other rights or are less intensely affected. And thirdly, a judgment of proportionality in the
strict sense, insofar as the measure adopted is weighted and balanced, insofar as it
derives more benefits for the purpose pursued than harm in the affected area. of
the rights also protected.”
In this regard, a relevant element in this assessment would be that the NIF information for self-employed entrepreneurs is not necessary for the purpose of the public business census
referred to in Article 8 of the Basic Law on Chambers of Commerce:
to provide a list of companies operating in Spanish territory, indicating their sector and identification. Contrary to the arguments of the CDE, incorporating NIF information in the public business census would not contribute
to increasing the legal certainty of commercial transactions, which, for self-employed entrepreneurs, is amply guaranteed when they provide their NIF information to the person
with whom they contract or enter into negotiations. Nor is the NIF (Tax Identification Number) required—a particularly sensitive piece of information as it unequivocally identifies the natural person—to identify a company that is not a legal entity. For the identification of the company as such, the relevant information is already included: the IAE (Tax Identification Number) heading and a description of the activity, as well as the owner's first and last name and, where applicable, the trade name. We must add that our commercial regulations do not, in general, require formal disclosure for individual entrepreneurs, unlike those that do exist for commercial companies, which would justify the disclosure of information such as the NIF (Tax Identification Number) that fully identifies the individual.
Article 19 of the Spanish Commercial Code provides: "1. Registration in the Commercial Registry shall be optional for individual entrepreneurs, with the exception of shipowners." All of this, regardless of whether the legislator has deemed it necessary for the protection of the general interest to publicize the NIF (Tax Identification Number)—regardless of whether the business owner is a natural person or a legal entity—so it has been provided. This occurs, for example, in Law 34/2002 on Information Society Services and Electronic Commerce.
A matter that would have been different is the inclusion and, where appropriate, publicity of the NIF (Tax Identification Number) if
it were a publicity tool other than the business census regulated by law.
It is also noted that there is a general belief that the public business census prepared by CDE in compliance with the obligation imposed by
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 122/204
Article 8 of Law 4/2014 is the one currently accessible from its corporate website. CDE and CAMERDATA have even admitted this on occasion, despite the confusion they have persistently tried to generate on this issue. We
refer to their response to the Inspection request dated 12/20/2023, in which CDE states:
"The public business census is published openly and free of charge in the "Companies of Spain" section of the Chamber of Spain's corporate website."
(Second proven fact)
In the certificate issued by ***POST.1, which CDE submitted as an annex to its allegations regarding the initiation agreement, it states in point 2:
“The CDE, […] in the exercise of the public-administrative functions assigned to it, prepares, manages, and publishes (Article 5.1.g) in relation to Article 8 of Law 4/2014) the public business census in Spain.
This public business census is, as its name indicates, public, and is available to any interested party online at https://www.camara.es/funcion-
consultiva/consulta-del-censo-publico-de-empresas. However, the availability of the public business census online is limited.” (Proven fact eleven)
In conclusion:
The legal obligation to "prepare" and the public administrative function of
"managing" that the Basic Law on Chambers imposes and attributes to CDE (formerly
Articles 8 and 21.1.d in connection with 5.1.g) falls upon a "public census of companies," a public company registry. The consequence of this is that
a company file or database that CDE
has generated with data obtained in the exercise of the function entrusted to it and intended for private use, such as its transmission to a
commercial company, CAMERDATA, is not subsumed within the provisions of Law 4/2014 mentioned above, nor can it, therefore, rely on the grounds of legality arising from the aforementioned
provisions of the legal text. This fact, the transmission (and the prior creation of the
file or database with information available to it as the entity
entrusted by law with the registration function of the business census) for
private use is unrelated to the "registration function," which the law
entrusts to CDE through Article 21.1d) in connection with 5.1.g)
to "manage" a public business census, in the terms of Article 8.
Regarding the content of the "public business census" prepared by CDE in
compliance with the provisions of Article 8 of Law 4/2014, the processing
of the personal data of self-employed entrepreneurs carried out through it must in all cases comply with the principles of personal data protection, in particular, for the purposes of this matter, that of data minimization (ex Article 5.1.c, GDPR). The consequence is that, unless otherwise provided by law, the NIF data of the individual entrepreneur should not be included, as it undoubtedly identifies the individual and its inclusion does not constitute a relevant contribution to the purpose of the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 123/204
"public business census" as defined in the context of Law
4/2014,
CDE has prepared and published on its corporate website the "public business census": it is freely accessible to all and complies with the principle of minimization, as it does not use all the data provided by the tax authorities, but only those "necessary".
5. The database provided by CDE to CAMERDATA and the supposed obligation conferred by Law 4/2014 to "publicize" the public census.
The foregoing discussion regarding the public business census, which at first glance
may seem unnecessary, is nevertheless necessary given the fact—easily
verifiable by reading any of the written allegations submitted
by CDE and even the contract signed with CAMERDATA—that CDE has been systematically creating deliberate
confusion between the "public business census" and the
database that is being transferred to the company CAMERDATA, which contains
information that CDE has obtained from tax authorities for the
compilation of the public census and for the public administrative functions entrusted to it by Law 4/2014. Likewise, confusion has been created regarding the
development and management of the public business census mentioned in the aforementioned Law.
CDE attempts to make it appear that the database it transfers to CAMERDATA and the public business census are the same. This implies that the legal basis for both is the same, and therefore, the transfer of data to CAMERDATA is legally binding. To such an extent that it has even maintained that the only difference between the two is the method of publication: through the corporate website, the public business census in the strict sense, and through a contract with CAMERDATA, by virtue of a decision adopted, supposedly, in the exercise of public legal functions, the database. Some paragraphs of their arguments regarding the proposed resolution are transcribed:
“The Spanish Data Protection Agency considers that the Chamber of Spain,
[…] is mistaken when, in the exercise of its legal and public functions, it considers
that these functions include publishing this census and providing access
to it to interested parties. Curiously, the Agency understands that publication on the Internet through an online database is included, but publication by transferring it to entities that request it is not included.”
“The Chamber of Spain understands that the legal mandate to manage the Public Census
includes the obligation to make it public by both means.”
"CDE provides Camerdata, S.A. with the Assigned Database to comply with the
legal obligation to publicize the Public Business Registry established in
Law 4/2014, as already indicated. If Camerdata, S.A., as an independent data controller,
decides whether to process personal data for other purposes, its own purposes, this is beyond CDE's control."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 124/204
The "Business Database Transfer Agreement," signed between CDE and CAMERDATA on February 15, 2016, in force on the date it was provided at the request of the Inspection, December 20, 2023, coined two expressions to refer to the database that constitutes its object: "Basic Business Census" and "Transferred Database" (Proven Fact Eight).
To understand the scope of the data processing that is the subject of this procedure, it is important not to lose sight of the two fundamental differences between
the lawful processing that CDE performs on the data of self-employed entrepreneurs when
it prepares and manages the "public business census" (formerly Article 8 and Article 5.1.g of Law 4/2014), which CDE refers to on its corporate website as the Public Business Census, and the processing of personal data that materializes in the transfer to CAMERDATA of a file containing data on self-employed entrepreneurs
(referred to by CDE, as the case may be, as the "Basic Business Census" and "Transferred Database" and even also as the Public Business Census):
The first difference lies in the fact that the file containing data on self-employed entrepreneurs
that is the subject of the transfer—we insist, referred to by CDE, as the case may be, as the "Basic Business Census" or "Database" "Cedida" and even "Public Business Registry" - are unrelated to the registry function entrusted to CDE (formerly Article 5.1.g) and are
merely a private database that CDE has compiled with information obtained
during the exercise of the entrusted public-administrative functions.
The consequence is that the data processing related to the database
that CDE transfers to CAMERDATA cannot be covered by the legal bases of
Article 6.1(c) or 6.1(e), as both must be connected to a law, in this case Law 4/2014, which refers to the "public business register."
The second difference relates to the alleged obligation that Law 4/2014
assigns to CDE to "publicize" or "publish" the "public business register."
CDE has maintained throughout the proceedings that Law 4/2014 assigns to it the
function of "publicizing" the "public business register." It states, for example:
"The Spanish Chamber of Deputies understands that the legal mandate to manage the Public Registry
includes the obligation to make it public by both means" (means it has
identified as "publishing this registry and providing access to it to interested parties").
Such an obligation is nonexistent. Publicity is what is offered by the public registry
that the Law mandates to be compiled. The public nature of the registry is an essential aspect of the ultimate purpose
of the registry function, which is to ensure legal certainty. The specific form of this registry publicity and its admissibility from the perspective of data protection could, where appropriate, be assessed, but the publicity of the registry does not include the mass transfer
of data to carry out or enable access to data for purposes other than those specific to the public registry of companies, however interesting they may be, but which the legislator has not covered.
Furthermore, the processing that consists of
transferring to CAMERDATA a database containing information on self-employed entrepreneurs
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 125/204
—unlawful processing carried out outside the public business registry and
the registry function entrusted to CDE—is intended for a company that
will use it (since this activity is part of its corporate purpose) for commercial or
marketing purposes.
Thus, in response to what CDE has been alleging throughout this procedure—that, given that Law 4/2014 imposes the obligation to publicize the public business register, but does not specify the means for doing so, it is up to the corporation to decide the means by which to do so—this Agency indicates that, indeed, Law 4/2014 does not detail the means of publicity because the obligation that the Law imposes on CDE is not to publicize it, but rather to prepare a business register, a public business register, and entrusts it with a public administrative function in relation to it, which is the development of the registration function.
Regarding the terminological confusion mentioned at the beginning of this section, we now refer to paragraphs IV and V, and to some of the clauses of the contract (agreements) signed between CDE and CAMERDATA.
The contract states that CDE will prepare the "public business census" under the name "Basic Business Census." Thus, paragraphs IV and V state that, in consideration of "the data from the Economic Activities Tax and the necessary business censuses" (paragraph IV) "received from the collaborating public authorities," "the Spanish Chamber of Commerce will prepare the public business census under the name "Basic Business Census," guaranteeing confidentiality in the processing and the exclusive use of the information received."
The first agreement of the contract between CDE and CAMERDATA, Object, introduces the term
“Transferred Database.” It stipulates in point 1.1:
“By this Agreement, the Transferor transfers to the Transferee, who, in turn, receives and acquires for itself a copy of all the business data
contained in the Basic Business Census referred to in the previous Exhibit V (hereinafter the Transferred Database), updated as of January 2016, which contains the information fields indicated in
Annex 1 of 3,160,984 Business Registries.”
“[…]the Business Registry is understood to mean all the information fields in
Annex 1 relating to each of the companies contained in the Transferred Database, with the company's Tax Identification Number (NIF) being used as the identifier of said registry.”
Also significant are the CDE's allegations regarding the proposed resolution, which reflect an attempt to confuse the data handled by the public business census, on the one hand, and, on the other, between the public business census (formerly Article 8 of Law 4/2014) and the basic business census:
"The Agency wrongly reasons that if the hash is not in the information
published in detail on the Chamber of Spain website, then it does not belong to the Public Business Census. But this inference is false.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 126/204
[...] the Chamber of Spain believes that a database without hashes is
impossible to manage. The unique hash to identify each business owner is
absolutely essential for managing the Public Business Census, since
without it, the census It would produce false information […] Without the NIF, at least without the unique hash for each individual entrepreneur, it is not possible to manage the Public Business Registry […] by virtue of the principle of data minimization.
The Spanish Chamber of Commerce has preferred to incorporate the hash instead of the NIF. “But the hash must exist, it must be part of the Public Business Registry (without it, it is unmanageable), and if it is part of it [the Public Business Registry], it must be able to be delivered to companies that request it as part of the obligation to make the Public Business Registry public.”
"That the "hash" is part of the Public Business Census is a fact.
The instructor attempts to prove the contrary by claiming that it is the information that is
published on the internet individually; the "hash" does not appear. But "Public Business Census" and "information published individually on the
website of the Spanish Chamber of Commerce are not the same thing." (Emphasis added)
Thus, setting aside any deliberate confusion, we conclude:
That the "Basic Business Census" or "Transferred Database" (which constitutes
the object of the "Transfer of Business Databases" contract that CDE and
CAMERDATA signed in February 2016) is not, and cannot be, the "public business census" referred to in Article 8 of Law 4/2014 (a
public registry), but rather its nature is different despite the data origin being the same. Furthermore, The "public business register," on the one hand, and
the Basic Business Register or Transferred Database, on the other, are, in their
essence, different, regardless of whether the personal data that forms part of them are identical or not (whether or not the NIF (Tax Identification Number) or NIF hash is included).
That publicity in relation to the public business register is,
exclusively, that which is carried out through it. There is no further publicity
within the provisions of the Law other than that which the "public register" itself
grants. Law 4/2014 does not impose on CDE any obligation to "publicize"
the public register.
IV
Change of legal classification made at the resolution proposal stage
1. The agreement to initiate this sanctioning procedure attributed to CDE, among other
infractions, the alleged violation of the "principles of loyalty and transparency"
established in article 5.1.a) of the GDPR, a violation classified in Article 8.3.5.a) of the GDPR and considered by the LOPDGDD, for the purposes of the statute of limitations, as very serious (Article 72.1.a).
In the resolution proposal phase, taking into consideration the same facts that the initiation agreement had assessed and classified as an alleged violation of the principles of loyalty and transparency (Article 5.1.a of the GDPR), the investigating body proceeded to change its legal classification and, based on the principle of specialty, found two distinct violations: i. a violation of the principle of loyalty, established
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 127/204
in Article 5.1.a) of the GDPR and classified in Article 83.5.a), and ii. a violation of Article 14 of the GDPR. GDPR, as defined in Article 83.5.b).
Let us recall in this regard that Section IX of the initiation agreement, entitled "On the alleged violation of the principle of legality and transparency, Article 5.1.a) GDPR," stated in its point 2:
"2. In the present case, the information gaps in terms of transparency that are observed are, in summary, the following:
- The processing operation that is the subject of analysis in this opening agreement (the transfer by CDE to CAMERDATA of a database that includes the personal data of self-employed entrepreneurs) begins from the moment that CDE anticipates that it will carry out this transfer with respect to data that it has lawfully obtained related to specific purposes of a public nature attributed to it by Law 4/2014.
CDE's forecast—based on the information available—has been at least since
2016, the date of the contract with CAMERDATA. Fair processing would require CDE to have informed the tax authorities that
provide it with the data, in compliance with Article 8 of the Basic Law on Chambers of
this subsequent processing. Especially given the safeguards contained in
the aforementioned Article 8 and the provisions of the agreement it signed with
the AEAT. There is no evidence that CDE has provided this information in a timely manner.
-It is not planned nor is there any record that it has provided any information to the
interested parties whose personal data are being transferred to
CAMERDATA. This is particularly serious given that they have been deprived of the
information that this data will, in turn, be transferred to third parties.
-CDE, as a contracting party with CAMERDATA, has failed to ensure that it compels
CAMERDATA and the third parties to whom it transfers the database to
provide truthful information about the origin of the data.”
Regarding the appropriateness of changing, in the proposed resolution phase, the legal classification of the facts that the Initiation Agreement classified as a violation of Article 5.1.a) of the GDPR and the impact that such a change could have on CDE's right to defense, the proposed resolution stated that there was no legal impediment to such a change, provided that, as was the case in this case, the facts on which the new charge was based remained unchanged.
The first of the rights granted to the alleged responsible party by Article 53.2 of the LPACAP is the right to be notified of the facts with which they are charged, the violations that such facts may constitute, and the sanctions that, if applicable, may be imposed.
The Constitutional Court has clarified that "the essential content of the constitutional right to be informed of the accusation refers to the acts considered punishable and which are attributed to the accused." accused” (STC 95/1995).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 128/204
Unlike what happens with the information about the facts that constitute the infraction, the Constitutional Court (CC), in Judgment 145/1993, warns that the communication to the alleged offender of the legal classification and the possible sanction to be imposed is not part of the essential content of the right to be informed of the accusation.
The disclosure of the facts constituting the administrative infraction is so important that the CC has declared that the requirements of Article 24.2 of the Spanish Constitution are fundamentally satisfied by the sole communication of the alleged facts, in order to be able to defend oneself against them (STC 2/1987 and 190/1987). Along these lines The Supreme Court, in its ruling of March 3, 2004, affirms that "the primary purpose of the initiation agreement is to provide information on the alleged facts and not on their legal qualification, which will be addressed by the proposed resolution."
In this regard, we can mention the SAN of March 12, 2016 (appeal 312/2014), whose Second Legal Basis addresses, in the following terms, the question raised by the plaintiff that "the proposed resolution altered the legal qualification of the initiation agreement":
"Based on the arguments raised by the plaintiff, it is appropriate to reflect on the constitutional doctrine and jurisprudence regarding the scope of the right of those sanctioned to be informed of the accusation during the processing of the administrative sanctioning procedure and the limits that the sanctioning body must respect in the exercise of its sanctioning power to safeguard the plaintiff's right to defense.
The principles inspiring the criminal system are applicable, with certain nuances, to administrative sanctioning law, given that both are manifestations of the State's punitive system, as reflected in the Constitution itself, the consistent jurisprudence of our Supreme Court, and the doctrine of the Constitutional Court (in this regard, Supreme Court rulings of April 28, 2014 - Appeal No. 364/2013 - and April 9, 2014 - Appeal No. 212/2013 -, among others)"
[...]
For its part, the Supreme Court has also established that one of the guarantees applicable to the administrative sanctioning procedure derived from the right to defense recognized in Article 24 of the Constitution is the right to be informed of the accusation in order to adequately defend oneself, as established by the Supreme Court ruling of November 3, 2003 - Appeal No. 4.896/2000 -, whose doctrine is reiterated in the Judgments of said Court of May 21, 2014 - Appeal No. 492/2013 -, and of October 30, 2013 - Appeal No. 2.184/2012 -, in the following terms: "Well, from the doctrine of the Constitutional Court and the jurisprudence of this Chamber, the following principles should be highlighted:
a) [...] In relation to this operation of transferring the guarantees of Article 24 of the Spanish Constitution to the administrative sanctioning procedure [...], a consolidated constitutional doctrine has been progressively developed in numerous resolutions, in which the following are cited as applicable, without being exhaustive: the right to defense, which prohibits any defenselessness; the right to be informed of the accusation, with the unavoidable consequence of the immutability of the facts. defendants; the right to the presumption of innocence, [...]
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 129/204
b) Among the guarantees applicable to the administrative sanctioning procedure is, of course, the right to be informed of the accusation in order to be able to adequately defend oneself; and such information includes the facts attributed, their legal classification, and the proposed sanction. However, the strict correlation between accusation and decision refers to the facts and not so much to the legal classification, since, while the facts being charged remain unchanged, the proposed resolution and, ultimately, the sanctioning decision, another sentence may be used with two limitations: the impossibility of including in said resolution of the procedure a legal classification of greater severity than that reflected in the communication of charges addressed to the person subject to the sanctioning procedure, and the impossibility of including in the resolution a classification different from the one reported if there is
heterogeneity in the protected legal rights or if the infringement
definitively considered incorporates an element of a type that does not
correspond to the one that was notified and for which the sanctioned party has not, consequently,
had an opportunity to defend itself. And there is no variation in the
facts between the statement of charges, the proposed resolution, and the sanctioning decision when, although the terms used are not exactly
the same, they are similar, and what exists is a different technical-legal assessment
of them (Cf. STC 98/1989 and 145/1993).
This same criterion has been maintained by the AN after the LPACAP came into force;
we refer to the SAN of 02/07/2020 (appeal 915/2018).
Based on the foregoing, the proposed resolution considered the change in legal classification made in this procedure to be fully legally compliant, given that the facts included in the two violations attributed to CDE in the proposed resolution—Articles 14 and 5.1.a) of the GDPR—were included in the initial agreement, although subsumed under a single violation, of Article 5.1.a) of the GDPR. Therefore, the new legal classification did not imply a change in the facts initially assessed, but rather, they remained unchanged.
2. Regarding the serious procedural defect allegedly committed by the change in legal classification.
In its arguments to the proposed resolution, CDE asserts that the change in legal classification is not legally compliant. It considers that the Agency has committed a serious procedural defect that has left it defenseless, and states the following: That in the proposed resolution, "the types of offenses attributed to this party have been modified, preventing this party from requesting the corresponding exculpatory evidence during the trial phase."
It states that "It is not true that the facts are different from those stated in the initiation agreement, since the hearing given to Camerdata, S.A. and the incorporation of its written allegations have given rise to new facts."
And he adds: "It is hard to believe that the Investigating Officer, after reading the certificate from Camerdata, S.A.
signed on May 16, 2024, stating that Camerdata, S.A. "obtains the NIFs
through its own means" (transcribed on page 85/152 of the draft resolution)
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 130/204
given that it only receives data encrypted "with the MD5 algorithm," and after receiving from both
the Spanish Chamber of Commerce and Camerdata, S.A. lists with the information provided by the former to the latter regarding 500 self-employed entrepreneurs each, from which
it is clear that this information does not contain the NIFs of those self-employed entrepreneurs, continues to maintain that there are no new facts (which is why the types of offenses can be modified). defendants) and that Camerdata, S.A. receives the NIFs from the Spanish Chamber of Commerce, given that, in its opinion, the NIFs are included in the Basic Business Census (folio 100/152), which is not true (only the "hash" is, which is also included in the Public Business Census, although not in the limited part of it that is displayed online for individual consultation—because it is not necessary for this purpose)." (Emphasis added)
We must emphasize that the grounds for defenselessness invoked by the opposing party—the modification
of "the types of offenses attributed to this party," in the plural—do not correspond to the truth of the
facts. In order to substantiate this point, we refer to the written draft resolution, which corroborates what has been stated in point 1 of this Ground: that the change in legal classification only affected the initially alleged violation of the principles of loyalty and transparency, and that the facts assessed when making the change in classification were those considered when drafting the initiation agreement.
In light of the arguments CDE puts forward, it is clear that it has no interest in recalling that the change in legal classification at the proposal stage dealt exclusively with one of the four violations alleged against it in the initiation agreement, specifically the one relating to the principles of loyalty and transparency in Article 5.1.a) of the GDPR. It is also clear that it has no interest in recalling that the "new facts," which it claims would have become apparent as a result of the evidence produced and the certificate from ***POST.1 that CDE itself attached to its allegations to the initiation agreement, bear absolutely no relation to the facts that, after the change in legal classification, are subsumed under the violations of the principle of loyalty (Article 5.1.a GDPR) and Article 14 of the GDPR.
V
Regarding the CHAMBER OF SPAIN's allegations regarding the initiation agreement
The allegations regarding the initiation agreement made by the CDE (folios 1829 to 1854 of the file) are detailed in the seventh Factual Background of this resolution. In them, CDE requests that the proceedings be closed and, as a subsidiary measure, in the event that the Agency were to find any violation of the GDPR, requests the application of Article 77 of the LOPDGDD, stating that it "has acted at all times in its capacity as a Public Law Corporation."
The most relevant issues raised in its allegations regarding the initiation agreement—issues that are examined and answered in the corresponding legal grounds for this resolution—are, in summary, the following:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 131/204
1. CDE categorically states that it “does not transfer” the NIFs of individual entrepreneurs to CAMERDATA; that what it provides is a “hash,” the result of an encryption process, “so the truth is that Camerdata does not receive these NIFs from
CDE.” It adds that, as CAMERDATA has stated (referring to the certificate signed
on 05/16/2024 by ***POST.1), this entity “obtains the NIFs by its own means.”
It further states that "The hash is part of the Public Business Registry, since without it
this registry could not be managed, but it is not accessible online for consultation on a company-by-company basis, because it is not necessary for that purpose."
Regarding these statements, it is important to clarify:
First, as explained in detail below in the Grounds regarding
the violation of Article 6.1 of the GDPR, the hash of the NIF of self-employed entrepreneurs
that CDE acknowledges it does provide to CAMERDATA—and not the plain text of the NIF, which is
what it declared in the Investigation Action phase that it was providing to CAMERDATA—is personal data. What CDE provides to CAMERDATA is the NIF data
pseudonymized through a technique called the hash algorithm. In order for CAMERDATA
to be able to "obtain the NIFs by its own means," as the CDE alleges, it must first provide the CDE with the hash result of those NIFs.
Second: Regarding CDE's claim that "The hash is part of the Public Business Registry," it is necessary to reiterate the confusion of concepts and terms that it systematically incurs.
The term "public business registry" is used by Law 4/2014 to refer to the registry
for which CDE is authorized (and, in their respective areas, the various Chambers of Commerce). It is proven in the Proven Facts that the public business registry—in the strict sense, as used by Law 4/2014—is
publicly accessible through CDE's corporate website. Consequently, it is necessary to reject the CDE's statement in its written submission to the initiation agreement, stating that "The hash is part of the Public Business Registry, since without it, this registry could not be managed, but it is not accessible online through company-by-company consultations because it is not necessary for that purpose." This is because the (very extensive) information that the tax authorities provide to the CDE and the Chambers of Commerce for the purposes specified in Law 4/2014 cannot be confused with the public registry.
The hash, therefore, is not part of the public business registry. However, it is transmitted to CAMERDATA, which can use the NIF hash to associate all the activities that a given business has declared in the IAE (Tax Identification Number), additional information that is not provided in the public business registry.
2. Regarding the alleged violation of Article 6.1 of the GDPR, two interconnected aspects are worth highlighting.
On the one hand, CDE invokes two legitimate grounds for its processing:
(i) compliance with a legal obligation, Article 6.1.c) GDPR, and (ii) the necessity of the processing to fulfill a task carried out in the public interest, Article 6.1.e) GDPR.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 132/204
It does not invoke as a legal basis the one it cited in its response to the Data Inspectorate: Article 6.1.f) GDPR. Furthermore, it only refers to this basis of legality now
to point out that it is the only one that the Agency—erroneously—has considered
to be applicable in relation to the processing under review.
Furthermore, the CDE makes a particular interpretation of Article 5.1.g) of Law
4/2014 and considers that this provision attributes to it the public legal function of
"preparation" and "publication" "of a public business census." The management of the
public census includes: the preparation (which, it says, is regulated in Article 8 of
Law 4/2014) and its "effective publication." And with regard to the latter, it states that
there is no regulation that explains (i) how such publication should be verified, (ii)
nor what the precise content of the information to be included in the public census is.
From this, it concludes that it is up to the CDE, in the "exercise of its assigned legal-public function," to determine which fields are included in the public business census and what means are used to publicize it.
3. Regarding the violation of the principle of purpose limitation (Article 5.1.b) that is alleged against it, the CDE rejects such a violation, given that it denies having processed the data of self-employed workers for any purpose other than the initial one "since the sole and exclusive purpose of the processing is to comply with the legal obligation to prepare and manage the Public Business Census under the terms provided for in Law 4/2014. What has been done is precisely to make the Public Business Census public, with the transfer being an instrument to achieve this end."
4. Regarding the violation of the confidentiality principle (Article 5.1.f GDPR), which
concerns the NIF (Tax Identification Number) data, CDE denies its existence and argues that it has processed this data of self-employed entrepreneurs, ensuring adequate security, both
with respect to the query made through its website—where, as CDE acknowledges in these allegations, the NIF (Tax Identification Number) is not included—and with respect to the transfer
of data it makes to CAMERDATA (which it refers to as: "Transferred Public Business Census (Basic Business Census)"). Regarding this second case,
in line with the previous statement that it does not transfer the NIF but rather the resulting hash,
it states that "the NIF of individual entrepreneurs is not transferred to
Camerdata, nor does Camerdata receive it from CAMERDATA."
5. Regarding the violation of the principles of loyalty and transparency (Article 5.1.a
GDPR), your allegations do not make any express mention of the violation of the principle of loyalty for which you are held responsible. You maintain that the initiation agreement accuses you of "a triple violation of the principle of transparency," which is specified in the following terms:
(i) Failure to notify the tax authorities of the transfer to Camerdata;
(ii) Failure to notify the data subjects whose personal data have been transferred of the fact of the transfer;
(iii) "As a contracting party with Camerdata," failure to "ensure that data subjects are provided with truthful information about the origin of the data."
6. In the alternative, it requests that the legal regime described in
Article 77 of the LOPDGDD be applied, having acted at all times as a
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 133/204
public law corporation. This request has been answered in the preceding
Ground II, point 2.2, to which we refer.
VI
Regarding the allegations of the Spanish Chamber of Commerce regarding the proposed resolution
The allegations regarding the proposed resolution made by CDE are detailed in
the last Factual Background of this resolution. In them, CDE requests
that the proceedings be closed and, alternatively, in the event
that the Agency were to detect any violation of the GDPR, requests the application
of Article 77 of the LOPDGDD, stating that it "has acted at all times in its capacity as a Public Law Corporation."
It invokes the existence of two serious procedural flaws that have caused it to be defenseless.
(i) That in the proposed resolution, "the types of infringement attributed to this party have been modified, preventing this party from requesting
the corresponding exculpatory evidence during the evidentiary phase." It states that "It is not true that the facts
are different from those stated in the initiation agreement, since the hearing
given to Camerdata, S.A. and the incorporation of its written allegations have
given rise to new facts."
The alleged procedural defect is addressed by referring to the change
in legal classification, Grounds IV, point 2.
(ii) That the procedure has invoked one of the three required hearing procedures,
the one immediately preceding the proposed resolution.
It alleges the absence of harm caused to the alleged affected parties.
The examination of the five alleged violations is carried out in a single ground entitled "There was a legitimate basis for the transfer (...) The alleged violations have not been committed. In relation to these, the Court reiterates the arguments invoked in the previous procedure.
Alternatively, it invokes the existence of a medial concurrence of violations or the appropriateness of applying the principle of non bis in idem due to the existence of an apparent concurrence of violations. This question is answered in Ground XVII when examining the sanctions imposed.
We refer below, since it has not been mentioned in any Ground, to the procedural defect allegedly causing defenselessness related to the omission of "one of the three necessary hearing procedures, the one immediately preceding the proposed resolution." In its allegations, CDE maintains that in the administrative sanctioning procedure, "a hearing procedure is mandatory at three different times: (i) in the agreement to initiate the procedure (Article 64.2.f) of Law 39/2015), before processing the instruction of the procedure (and consequently the evidence), (ii) once "the procedures have been instructed, and immediately before drafting the proposed resolution" (i.e., after the evidence has been presented but before drafting the proposed resolution) (Article 82.1 of Law 39/2015, which does not establish any exception for the sanctioning procedure), and (iii) after drafting the proposed resolution of the investigating judge, therefore outside the scope of the latter's jurisdiction, but before the sanctioning resolution is issued (Article 89.2 of Law 39/2015). Surprisingly, the second has been omitted in this procedure, causing a lack of defense.”
However, there is no defect in the procedure conducted, much less any that would cause a lack of defense for the accused, as all the procedures have been scrupulously observed.
It is sufficient to note in this regard that, according to the LPACAP, Article 76 establishes
the first of the regulated procedures for allegation and submission of documents available to interested parties throughout the common administrative sanctioning procedure: “Interested parties may, at any time during the procedure prior to the hearing, present allegations and submit documents or other evidence. Both will be taken into account by the competent body when drafting the corresponding proposed resolution."
In the area of the administrative sanctioning procedure, the second stage of the presentation of allegations is provided for in Article 89 of the LPACAP. In this case, due to the requirements of the accused's right to defense, the proposed resolution must be drafted before the hearing of the interested parties and not afterward, as provided for the rest of the administrative procedures in Article 82 of the LPACAP. Thus, this provision is entitled "Hearing Procedure," and Article 89 of the LPACAP is entitled "Proposed Resolution in Sanctioning Procedures." It provides:
"2. In the case of sanctioning procedures, once the investigation of the procedure has concluded, the investigating body shall formulate a proposed resolution, which must be notified to the interested parties. The proposed resolution
must indicate the disclosure of the procedure and the deadline for submitting
allegations and submitting documents and information deemed relevant."
It is unknown whether the omission of an unknown evidentiary procedure is also being invoked, since
CDE argues that "if the procedure had been disclosed to him before
issuing the proposed resolution, he could have requested new evidence
[…] which is no longer possible once the investigation and, therefore,
also the evidentiary procedure included therein have been closed—without hearing him." The only procedure available to the accused to propose the evidence he considers necessary for his defense is the pleadings procedure provided for in Article 76.1 of the LPAC (Spanish Civil Procedure Act).
The pleading specifying the alleged first procedural defect, which allegedly caused defenselessness, does not merit further comment.
VII
Violation of the principle of lawfulness (Article 6.1 GDPR)
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 135/204
1. This resolution accuses CDE of violating Article 6.1 of the GDPR (principle of lawfulness), specifically the transfer to CAMERDATA without an adequate legal basis in accordance with the GDPR, in execution of a contract signed between the two parties
in force on the date on which it was provided to this Agency. December 20, 2023, personal data of individual entrepreneurs to which CDE lawfully accesses in accordance with the provisions of Article 8 of Law 4/2014.
All processing of personal data must be based on one of the legal grounds specifically established in Article 6 of the GDPR, which provides:
"Lawfulness of processing:
"1. Processing will only be lawful if at least one of the following conditions is met:
a) the data subject has given consent to the processing of their personal data for one or more specific purposes;
b) processing is necessary for the performance of a contract to which the data subject is a party or for the implementation, at the request of the data subject, of pre-contractual measures;
c) processing is necessary for compliance with a legal obligation applicable to the data controller;
d) processing is necessary to protect the vital interests of the data subject or another natural person;
e) processing is necessary for compliance with a a task carried out in the public interest or in the exercise of official authority vested in the controller;
(f) processing is necessary for the purposes of the legitimate interests pursued
by the controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
Point (f) of the first subparagraph shall not apply to processing
carried out by public authorities in the exercise of their tasks.
2. Member States may maintain or introduce more specific provisions
in order to adapt the application of the rules of this Regulation with regard
to processing pursuant to points (c) and (e) of paragraph 1 by setting out more
precisely specific processing requirements and other measures ensuring lawful and fair processing, including other specific processing situations pursuant to Chapter IX.
3. The basis for the processing referred to in paragraph 1, Letters c) and e) must be established by:
a) Union law, or
b) the law of the Member States to which the controller is subject.
The purpose of the processing must be determined in that legal basis or, in relation to the processing referred to in paragraph 1(e), it must be necessary for the
performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. That legal basis may contain specific provisions to adapt the application of rules in this Regulation, including: the general conditions governing the lawfulness of processing by the controller; the types of data subject to processing; the data subjects concerned; the entities to which personal data may be disclosed and the purposes of such disclosure; the purpose limitation; the retention periods. the
data, as well as the processing operations and procedures, including measures to ensure lawful and fair processing, such as those relating to other specific processing situations pursuant to Chapter IX. Union or Member State law shall fulfil a public interest objective and be proportionate to the legitimate purpose pursued.
4. Where processing for a purpose other than that for which the personal data were collected is not based on the data subject's consent or on Union or Member State law that constitutes a necessary and proportionate measure in a democratic society to safeguard the objectives set out in Article 23(1), the controller, in order to determine
whether processing for another purpose is compatible with the purpose for which the personal data were initially collected, shall take into account, inter alia:
a) any relationship between the purposes for which the personal data were collected and the purposes of any envisaged further processing;
b) the context in which the personal data were collected Personal data, in particular with regard to the relationship between data subjects and the controller;
c) the nature of the personal data, in particular where special categories of personal data are processed, in accordance with Article 9, or personal data relating to criminal convictions and offences, in accordance with Article 10;
d) the possible consequences for data subjects of the planned further processing;
e) the existence of appropriate safeguards, which may include encryption or pseudonymization.
Recital 40 of the GDPR states:
“For processing to be lawful, personal data must be processed with the consent of the data subject or on another legitimate ground established by law, whether by this Regulation or by other Union or Member State law to which this Regulation refers, including the
necessity for compliance with a legal obligation applicable to the controller or the
necessity for the performance of a contract to which the data subject is party or in order to
take steps at the request of the data subject prior to entering into a contract.”
The lawfulness of processing personal data may be based on any of the
six circumstances or processing grounds set out in Article 6.1 of the GDPR.
For specific personal data processing, the appropriate legal basis under the GDPR does not necessarily have to be the data subject's consent
for one or more specific purposes. The five other circumstances mentioned in Article 6.1 of the GDPR are also valid legal grounds, and have the same value as consent: the contract or pre-contractual relationship; a legal obligation; the protection of the vital interests of the data subject or a third party; the processing being
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 137/204
carried out in the public interest or in the exercise of official authority vested in the controller, or the prevalence of the legitimate interest of the controller or a third party overrides the interests, fundamental rights and freedoms of the data subjects.
Article 6.1.f) of the GDPR (prevalence of the legitimate interest of the controller or a third party over the interests, fundamental rights, and freedoms of the data subjects) is one of the possible legal bases for data processing.
Furthermore, for this circumstance to take effect, in no case is a specific regulatory provision required, nor is a legal provision establishing a rebuttable presumption of lawfulness, as is the case, for example, with Articles 19 and 20 of the LOPDGDD.
Therefore, processing based on Article 6.1.f) of the GDPR may take place
—prevalence of the legitimate interest of the controller or a third party—apart from
those other cases in which a law establishes a presumption of lawfulness based
on legitimate interest. And this circumstance may even operate as a basis for legality when, having established a rebuttable presumption of legality, a law does not meet the requirements that the law requires for its application. It should also be added that, since the legal basis for processing is Article 6.1.f) of the GDPR, the only distinct legal effect between the cases in which this ground for legality applies based on a presumption and those in which it does not is that, in this second case, the data controller bears the burden of proving the legality of the processing in accordance with Article 5.2 of the GDPR.
The Preamble to the LOPDGDD, Section V, clearly states this:
“Title IV contains ‘Provisions applicable to specific processing operations,’ incorporating a series of assumptions that should in no case be considered exhaustive of all lawful processing operations. Among these, it is worth highlighting, first of all,
those for which the legislator establishes a presumption "iuris tantum" of the prevalence of the legitimate interest of the controller when they are carried out
with a series of requirements. This does not exclude the lawfulness of this type of processing
when the conditions provided for in the text are not strictly met, although in
this case the controller must carry out the legally required weighing, as
its legitimate interest is not presumed to prevail.”
In this regard, with regard to Article 19.2 of the LOPDGDD, as set out in Section 1 of Ground II, "Preliminary Issues," (to which we refer), this Agency considers that it establishes a rebuttable presumption of lawfulness, based on the circumstance of Article 6.1.f), which applies exclusively to the contact information of individual entrepreneurs.
2. Data processing that constitutes a violation of Article 6.1 of the GDPR and the data processed.
CDE and CAMERDATA signed a "Business Database Transfer" contract on February 15, 2016, which is tacitly renewable for successive periods of one year (agreement 6.2) and is effective as of the date it is submitted, December 20, 2023.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 138/204
The first agreement of the contract addresses its purpose and establishes:
“By this Contract, the Assignor assigns and transfers to the Assignee, who, in turn,
receives and acquires for itself a copy of all the business data contained in the Basic Business Census referred to in Exhibit V above (hereinafter the Assigned Database), updated as of January 2016, which
contains the information fields indicated in Annex 1 of 3,160,984
Business Registries.”
“[…]the Company Registry is understood to mean all the information fields in Annex 1 relating to each of the companies contained in the Transferred Database, with the company's Tax Identification Number (NIF) being used as the identifier for said registry.”
Point 2 of the first agreement states: “The Company Registries that make up the Transferred Database refer solely and exclusively to those indicated in the second paragraph of Exhibit V above.”
As indicated, the transfer agreement signed between CDE and CAMERDATA uses two terms to refer to the database that constitutes its purpose: “Basic Company Census” and “Transferred Database.” CDE sometimes also refers to its database as the Public Company Census.
Regarding the personal data of the self-employed entrepreneurs who are the subject of the transfer, the provisions of Annex I of the Contract, to which their agreement 1.1 refers, must be followed to determine the information fields relating to each of the companies contained in the Transferred Database. It states:
"In accordance with the provisions of the First Agreement of the Contract, the Database
and its updates will contain the following information fields for each company listed therein (hereinafter, the Company Registry).
Data for each Company Registry
1. NIF (Tax Identification Number)
2. Company name or business name
3. Main address
4. Business address
5. IAE activity section
6. IAE activity"
As indicated, the transfer agreement signed between CDE and CAMERDATA uses two terms to refer to the database that constitutes its subject: "Basic Company Census" and "Transferred Database." CDE sometimes also refers to its database as the Public Business Census.
Regarding the content of the CDE database, which is the subject of the transfer agreement to CAMERDATA, according to its stipulations, it includes the NIF (Tax Identification Number) among the personal
data of the individual entrepreneurs included in it. Annex I of the contract, transcribed above, details the information fields that the database and its updates will contain for each company listed therein: Number 1 indicates the "Company Tax Identification Number."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 139/204
Meanwhile, regarding the public business register accessible through CDE's corporate website, it is confirmed that it includes the following personal data
of individual entrepreneurs: first and last name, postal address (street name and number, sometimes the floor), postal code, name of the province and municipality, IAE code, and description of the activity. It does not include the NIF (Tax Identification Number). This demonstrates that the data controller, CDE, has fully applied the minimization principle (ex Article 5.1.c GDPR) in its preparation.
Therefore, the criteria regarding which data may or may not be included in the public business register
exist and are established by the GDPR and the LOPDGDD (General Data Protection Act).
In its allegations regarding the start-up agreement, CDE ignores the content of the contract that binds it to CAMERDATA and asserts that it does not transfer the NIF data to CAMERDATA and that it does provide the hash of the NIF of the individual entrepreneurs. Thus, it states: the
NIF data "is not transferred to Camerdata, but is delivered encrypted using a one-way and irreversible algorithm." A "hash" is provided, the result of an encryption process, "so the truth is that Camerdata does not receive these NIFs from CDE." It also states that, "as Camerdata has stated, that entity obtains the NIFs through its own means."
The only document provided by CDE as an annex to its allegations regarding the start-up agreement is a certificate signed on 05/16/2024 by ***POSITION 1.
Based on CDE's statements in its allegations regarding the start-up agreement, in which it expressly states that it does not provide CAMERDATA with the NIF data and that what it does provide within the framework of the contract signed with it is the hash of the self-employed workers' NIFs, with CAMERDATA obtaining the NIFs through its own means, it should be noted that what CDE is providing to CAMERDATA is the self-employed workers' NIF data, albeit pseudonymized.
In this case, the result of applying the hash function to the self-employed workers' NIF data does not result in anonymized information, therefore excluded from the scope of the GDPR. Instead, it results in pseudonymized personal data that CAMERDATA can reverse-reverse. This is evident from the statements made by CAMERDATA in response to this Agency's request for information, in which it states that the NIF data of the individual entrepreneurs is obtained from what it calls a "public business file" from CDE. Thus, CDE is acknowledging in its allegations to the initial agreement that it transfers to CAMERDATA the NIF data of the self-employed workers listed in its database (all of them, in application of the principle of universal registration), albeit pseudonymized.
Article 4.5 of the GDPR defines pseudonymization as “the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.”
Recital 26 of the GDPR indicates that anonymized data is outside the scope of the GDPR:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 140/204
“Therefore, the principles of data protection should not apply to anonymized information.” And that pseudonymised data and information linked to that dataset are included in the protection provided by the GDPR: “The principles of data protection should apply to all information relating to an identified or identifiable natural person. Pseudonymised personal data, which could be attributed to a natural person by the use of additional information, should be considered information about an identifiable natural person. In determining whether a natural person is identifiable, all means, such as identification, that the controller or any other person can reasonably use to directly or indirectly identify the natural person should be taken into account. In determining whether there is a reasonable likelihood that means will be used to identify a natural person, all objective factors, such as the costs and time required for identification, should be taken into account, taking into account both the technology available at the time of the processing and technological developments.”
The pseudonymized nature of personal data, which in this case results from applying the hash function to specific input information, is evident in light of Opinion 05/2014 on anonymization techniques, WP216,
adopted by the Article 29 Working Party (WP29) on April 10, 2014. This explanation is even clearer when the information to which the technique is applied is, as is the case here, the NIF (Tax Identification Number), and this circumstance is known to CAMERDATA.
Opinion 05/2014 of the WP29 devotes a specific section to pseudonymization,
regarding which it states:
"Pseudonymization consists of replacing one attribute (usually a
single attribute) with another in a record. Consequently, there remains a
high probability of indirectly identifying the natural person; in other
words, the exclusive use of pseudonymization does not guarantee an anonymized
data set. However, this opinion examines this method due
to the numerous misconceptions and errors surrounding it.
Pseudonymization reduces the linkability of a data set to the
identity of the data subject; it is therefore a useful security measure,
but it is not an anonymization method.
The result of pseudonymization may be independent of the initial value (such
as a random number generated by the controller or a surname chosen by the data subject) or may be derived from the
original values. of an attribute or set of attributes, such as in the
case of hash functions or encryption systems.”
It refers to the most commonly used pseudonymization techniques and mentions the hash function:
"Hash function: This is a function that returns a fixed-size result from an input value of any size (this input can be made up of a single attribute or a set of attributes). This function is not reversible, that is, there is no risk of reversing the result, as in the case of encryption. However, if the range of input values for the hash function is known, these values can be passed through the function to obtain the actual value of a given record. For example, if the hash function is applied to the national identification number to pseudonymize a data set, this attribute can be obtained simply by running the function with all possible input values and comparing the results with the values in the data set. Hash functions are typically designed to be able to execute relatively quickly, making them subject to brute-force attacks.16 Pre-computed tables can also be created to achieve bulk reversal of a large number of hash values.
Using a "salted" hash function (in which a random value, known as "salt," is added to the attribute being hashed) can reduce the probability of obtaining the input value. However, using reasonable means, it is still possible to calculate the original value of the attribute hidden behind the result of a salted hash function.17
Consequently, the fact that CDE did not provide CAMERDATA with the self-employed persons' NIF data in plain text—as stipulated in the contract signed between the two parties—but rather, as stated, provided CAMERDATA with the resulting hash, implies that the transfer is of the individual entrepreneurs' NIF personal data, albeit pseudonymized. As the WP29 Opinion makes clear, the hashing technique can constitute a security measure, but it may not imply the anonymization of the data. The example provided by the aforementioned Opinion is particularly significant: the application of the hash function to national identification data (the equivalent of our NIF).
Recently, on January 16, 2025, the EDPB approved Guidelines 01/2025 on pseudonymization. Section 88 states the following:
“88. Within the scope of pseudonymization, it should not be possible to attribute pseudonymized data relating to a data subject whose identifiers are known. This could be done by applying the pseudonymization transformation to such identifiers, obtaining the pseudonym, and locating the pseudonymized data attached to that pseudonym. (For example, if you know that the transformation is simply a SHA256 hash of a name, you could apply this to all the names you have elsewhere and then see which hashes match in the dataset.) Therefore, the transformation must include information that the pseudonymized controller keeps secret and that an unauthorized person cannot use. Only possession of the secret information should allow the calculation of the pseudonym given the identifier. In order to limit the likelihood of a successful guess or brute-force search, the secrets must have sufficient entropy. Entropy refers here to the randomness of the secret parameter. For example: If the
controller selects the date the pseudonymization transformation was applied
as a parameter, the entropy of this parameter will be very low. However, if the
controller selects a randomly generated string of 20 alphanumeric characters
as a secret parameter, the entropy is high.) For the first class, cryptographic algorithms, this information takes the form of secret parameters or keys. For the second class, lookup tables, the controllers keep the tables secret. (Our translation)
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 142/204
In its arguments to the proposed resolution, the CDE argues that the NIF is indeed part of the public business register, although this data is not publicly accessible.
The explanation it offers is as follows:
“Public Business Register” and "Information published individually on the
Spanish Chamber of Commerce website" is not the same. This is due to one reason: the "hash" is only necessary when processing thousands or millions of data items, not when performing an individual query, and it is a working piece of data for mass data management, not data of interest to citizens. Indeed, as has been stated several times (including in the written statement of objections to the opening agreement), without the "hash" or the NIF, the
Public Business Registry is unmanageable and would violate the right to data protection of many individual entrepreneurs. Without the "hash" or the NIF, entrepreneurs with the same first and last names, entrepreneurs
who have changed their last names, entrepreneurs who have changed their name and/or gender, etc., would be confused. The quality of the Public Business Registry would be very poor, and the number of errors very high, if it did not include the "hash" or the NIF. NIF (Tax ID Number). Given the choice, it is
better to include the hash than the NIF.
“The proposal repeatedly confuses the information published on the Internet for individual
consultation with the Public Business Census, and incorrectly
differentiates between the Public Business Census and the Basic Business Census and the
transferred Database.” "The Public Business Census is the one prepared by the Chamber of Spain, and it includes the hash but not the NIF (which the Chamber of Spain has, because it has received it from the tax authorities, but does not use it directly in the Public Business Census, but only its hash)."
Regarding this allegation, it is one thing that the NIF may be necessary for the "management" of the public census due to the huge volume of data processed or for other reasons, and another thing is the information that can be accessed through the public census, the public business registry, in short. And the information accessible through the public registry does not include the NIF data.
CDE also alleges that clause twelfth of the contract entered into with CAMERDATA, Processing of Personal Data, establishes (12.2.) “The transferor also states that the Transferred Database and its updates contain data relating to individual entrepreneurs and data of natural persons who provide services to legal entities, relating solely to their first and last names, the functions or positions held, as well as their professional postal or email address, telephone number, and fax number, all in accordance with the provisions of Article 2 of the RLOPD.”
While it is true that the clause exists, it is also true that the first agreement of the contract clearly states that the Company Registry includes all the information fields in Annex 1 relating to each of the companies listed in the Transferred Database, with their NIF being taken as the identifier of said registry.” This means that the database is organized based on the NIF data and that without the NIF
The database is not operational for its recipient, CAMERDATA. Furthermore, the
references to the NIF are continuous in the contractual stipulations of which its annexes are included.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 143/204
3. Legal bases for the processing invoked by CDE during the procedure and
during the Preliminary Investigation.
In its allegations to the initiation agreement, CDE invokes, against the alleged infringement of Article 6.1 of the GDPR, two legitimate bases for the processing:
(i) compliance with a legal obligation, Article 6.1.c) GDPR, and (ii) the necessity of the processing to fulfill a task carried out in the public interest, Article 6.1.e) GDPR.
(i) Compliance with a legal obligation, Article 6.1.c) GDPR. In defense of the application of this legal basis, the Court argued:
“Article 5.1.g) (in conjunction with Article 8) of Law 4/2014 obliges CDE
to maintain “a public census of all companies, as well as their
establishments, branches, and agencies located within its jurisdiction.”
“Although this provision does not explain how the Public Census of Companies should be made “public,” the legislative mandate is clear: it is a public-legal function within the jurisdiction—in this case—of CDE.”
"CDE makes the Public Business Census public in two ways: (i) first, by opening it to public consultation on the Internet, which can be done on the website available at https://censo.camara.es/, and (ii) second, by transferring the Basic Business Census to Camerdata so that it can use it (along with other information) as a reliable source in the preparation and updating of its Spanish Business File. The first method only allows consultation on a company-by-company basis and is therefore not useful for computer processing. The second method allows for greater availability by making the entire Public Business Census available for computer processing, thus fulfilling the legislator's mandate in the best possible way."
It stated that “CDE could have devised more ways to fulfill its
legal obligation to publish the Public Business Register, given that the
Law neither identifies nor restricts the ways in which said register must be made public:
it only requires that it be published and entrusts CDE with such publication.”
It added that “as seen above, CDE under no circumstances incorporates the NIF (Tax Identification Number) of individuals who are entrepreneurs or professionals into the
Public Business Register, but rather replaces it with a “hash” produced using a
one-way and irreversible algorithm.” (Emphasis added)
(ii) The necessity of processing to fulfill a mission carried out in the public interest,
Article 6.1.e) GDPR: It argued in defense of the application of this legal basis:
That the domestic law on which it is based, Law 4/2014, requires it to “publish the Public Business Register.”
That the various actions carried out in relation to the Public Business Registry derive from the public function attributed to it by Article 5.1.g) of
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 144/204
Law 4/2014, by virtue of which the CDE is entrusted with the function of “managing, in accordance with Article 8 of this Law, a public registry of all companies.” That
“the scope of the public interest is broad,” and to this end, Legal Report
2018/175, page 10, mentions: “Section e) “public interest mission” must be interpreted broadly so as to allow public authorities, including within the scope of private law, to process personal data necessary for the legitimate purposes granted or permitted by law.”
In its allegations to the proposed resolution, it argues the following:
“CDE has a legitimate basis for processing the data, which is related to the public interest (Article 6.1.e) of the GDPR), and by virtue of this, it prepares and publishes, as part of the management of the Public Business Registry entrusted to it by Law 4/2014.
The processing carried out by CDE is based on the corresponding legitimate basis, since (i) Article 5.1.g) (in conjunction with Article 8) of Law 4/2014 obliges (imposes a legal obligation that is enforceable) CDE to manage “a public registry of all companies, as well as their establishments, branches, and agencies located in its district,” and (ii) for the publication of said registry, it uses Camerdata, S.A., which entails acting as a by virtue of the public interest.
It should be remembered that CDE does not transfer the NIF of individuals to Camerdata, S.A., so the alleged violation cannot be committed either. (Emphasis added)
During the Preliminary Investigation, when asked by the Agency's Data Inspectorate about the legitimate basis for transferring data of self-employed entrepreneurs to third parties, in particular to CAMERDATA, the agency responded that it was protected by Article 6.1.f) of the GDPR.
Before examining the possible application of the various legal bases invoked to the data processing that is the subject of this procedure, we must mention the ECJ ruling of 04/10/2024, Case C-200/23, which, in relation to the grounds that may legitimize the processing of personal data under Article 6 of the GDPR, indicates that those not based on the data subject's consent must be subject to a restrictive interpretation (Section 96).
The legal basis of Article 6.1.c) of the GDPR requires, as a prerequisite for its application, that the processing carried out be "necessary" to comply with the legal obligation that the law imposes on the data controller. The term "necessity" has its own independent meaning in EU law. The Court of Justice of the European Union considers it to be an “autonomous concept of Community law” (ECJEU of 16/12/2008, case C-524/2006, paragraph 52), and the European Court of Human Rights states that the “adjective necessary is not synonymous with “indispensable” nor does it have the flexibility of the expressions “admissible,” “ordinary,” “useful,” “reasonable,” or “desirable”” (paragraph 97 of the ECHR of 25/03/1983).
The purpose of the processing must be determined in said legal basis, that is, in a law (Article 6.3 of the GDPR).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 145/204
The grounds for the lawfulness of the article 6.1.c) of the GDPR that CDE has invoked, in connection
with Article 8 of Law 4/2014, consists of the alleged obligation that this legal provision imposes on it to prepare ("shall prepare," the law states) a "public census of companies."
In arguing this rationale, CDE also mentions (combining both) what is not a legal obligation but rather a public-administrative function attributed to it by
Article 21.1.d), which, in turn, makes a general reference to the public functions of
Article 5.1., whose section g) mentions "Manage, in the terms of Article 8 of
this Law, a public census of all companies, as well as their establishments,
delegations, and agencies located within its district."
What is relevant is that the object of the legal obligation to "prepare"
imposed on CDE and the public administrative function of "managing" entrusted to it
is "the public business census."
As indicated, the registry function is a function of the State manifested in the
existence of registries that refer to various aspects and sectors of life. It is a
public function. The public nature of the registry is an essential aspect of the ultimate
purpose of the registry function, which is to ensure legal certainty.
When Article 8 of the Law entrusts CDE with preparing a public census, it
imposes the obligation to prepare a public registry. And when Article 5.1.g) entrusts
CDE with the public administrative function of "managing" a public business census, in the terms of Article 8, it is entrusting CDE with the development of the registry function in relation to the aforementioned public business census.
A database that is not a public business registry—as is the case with the database that is the subject of the contract that CDE signed with CAMERDATA—has nothing to do with the purpose of Articles 8 and 5.1.g) of that Law. Therefore, the processing of personal data included in a file or database that is not a public registry or related to the exercise of entrusted public-administrative functions could never be legally based on Law 4/2014.
Regarding the alleged obligation that Law 4/2014 attributes to CDE to "publicize" or "publish" the "public business registry," as explained in Section III, paragraph 5, such an obligation does not exist. The only obligation imposed on CDE by Law 4/2014
is to "prepare" a public business register, and it assigns it the public-administrative function of "managing," "in accordance with Article 8 of this Law, a public register of all companies, as well as their establishments, branches, and
agencies located within its district."
The act of "preparing" ends with the creation of the public register. From then on,
CDE assumes the management function, which is none other than the development of the registry function. "Publicity" is granted by the public register itself, whose
nature is inherent to it, as it is accessible to all.
Thus, the Basic Law has not provided, since it is unnecessary, for a specific action on the part of CDE aimed at publicizing the public register, that is, a public register.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 146/204
Disclosure is carried out through the public census, due to the externalization that implies freely accessible data.
At this point, it is recalled that the contract signed between CDE and CAMERDATA for the Transfer of Business Databases establishes that CAMERDATA will use the database transferred by CDE for commercial purposes.
The second clause of the contract, "Purpose," states that the "transferee will include the business data from the Transferred Database and its periodic updates in the Spanish Company File it owns, and will process, complete, and enrich them under the terms of this Contract for the purpose of offering it commercially to companies and interested third parties as a database of information on companies operating in Spanish territory."
The database that is the subject of the contract is intended for the limited group
of people who will access the processed data (for the purposes of this document, the personal data of self-employed entrepreneurs) under the conditions, presumably onerous, that CAMERDATA establishes.
It should also be emphasized that the database covered by the Database Transfer contract that binds CDE and CAMERDATA is, by its very nature, distinct from the "public business census," the public registry referred to in
Article 8 of the Law. This distinction remains valid regardless of the personal data it collects, even if they have identical content. Whether or not they include the
NIF (Tax Identification Number) or the corresponding hash.
Regarding the recipients of the database that CDE transfers to CAMERDATA, the information provided by this company in the "Legal Notice on the Use of the Portal and Services" (contained in the thirteenth Proven Fact) is very illuminating. Thus, in point 6.1. Basic information states:
“The records processed by Camerdata from the Spanish Company Files database that contain personal data have been obtained by CAMERDATA after being legitimately collected, as the data has been obtained from an Official Census prepared by a public body, […] The processing of this data is for the purpose of sending commercial and marketing communications, offering various goods or services that may be of interest to you.
Section 6.2.5. “Purpose of the processing” states:
“The purpose of the processing is to conduct commercial and marketing communications campaigns, offering products or services, either our own or those of third-party companies, that may be of interest to you, for marketing purposes, within the business sphere and never within the private sphere.”
Even more illuminating is point 6.2.6. “Recipients of personal data”:
“Only our clients who have requested the creation of the custom database to be delivered, or third-party companies that, in turn, provide services to end users for the same marketing purposes, and those companies with which they have signed data processor agreements or contracts, may access the personal data for which CAMERDATA is the data controller.”
Therefore, the file or database that is the subject of the contract cannot be, as intended, the public business census, which is merely a public registry.
The database provided is not intended for general knowledge, open to all and without restrictions, but rather for CAMERDATA's clients. It is a "private" file.
Having explained the reasons why the processing that constitutes the infringement cannot be protected under Article 6.1.c) of the GDPR in connection with the legal obligation imposed by Article 8 of Law 4/2014, even connecting this provision with the public-administrative function set forth in Article 5.1.g) of the aforementioned Law, it is appropriate to examine, in light of the foregoing considerations, the
arguments put forward by CDE in the process of submitting objections to the proposal. Thus, CDE has stated:
-That the Agency "considers that the Chamber of Commerce of Spain [...] It is mistaken when, in the exercise of its legal and public functions, it considers that these functions include publishing this census and providing access to it to interested parties.
Curiously, the Agency understands that publication on the Internet through an online database is included, but publication through transfer to entities that request it is not included. (Emphasis added)
- That it questions what distinction exists “between one form of publication and another”; that
the fact that it charges a fee that does not cover the cost of computer processing
the information does not distort the purpose of the publication nor make it profitable; and that, in its understanding, the legal mandate to “manage the Public Census
includes the obligation to make it public by both means.” That the “Law does not establish
any distinction” and that the AEPD would be supplanting it in determining which is
the ideal medium for its publication.
CDE's arguments reveal that it is attempting to present the “public census” and the database
transferred to CAMERDATA as if the latter were also the “public census”
referred to in Article 8 of the Basic Law, that is, a public business registry.
However, as explained, the “Basic Business Census” or “Database Data
Transferred” (which constitutes the object of the “Transfer of business databases” contract that CDE and CAMERDATA entered into in February 2016) is not, and cannot be, the “public business register” referred to in Article 8 of Law 4/2014 (a public registry), but its nature is different despite the data origin being the same. Furthermore, the “public business register,” on the one hand, and the
Basic Business Register or Transferred Database, on the other, are, in essence, different, regardless of whether the personal data contained therein is identical or not (whether or not the NIF or NIF hash is included).
It should be added that publicity in relation to the public business register is, exclusively, that which is carried out through it. There is no other publicity falling within the provisions of the Law other than that which the register itself provides. “public census” grants.
Law 4/2014 does not impose on CDE any obligation to “publicize” the public census.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 148/204
The legal basis of Article 6.1.e) of the GDPR: Processing is necessary for the
fulfillment of a task carried out in the public interest or in the exercise of public powers conferred on the data controller.
The processing of personal data may only be considered based on the
fulfillment of a task carried out in the public interest or in the exercise of public powers conferred on the data controller when it derives from a power conferred by
a law (Article 8.2 of the LOPDGDD). The purpose of the processing
must be necessary for the fulfillment of a task carried out in the public interest or
in the exercise of public powers conferred on the data controller.
For the reasons In no case is it necessary for the CDE to exercise the
public administrative functions entrusted to it, with regard to the public census,
and the performance of the registry function (formerly Article 5.1.g), to transfer to CAMERDATA a database created with the information obtained in connection with the performance of the functions entrusted to it by law.
The arguments presented require the conclusion that the circumstance of Article 6.1.e)
of the GDPR invoked by CDE cannot serve as a basis for the data processing under consideration.
In its allegations regarding the initiation agreement, CDE used the same arguments to defend this basis for legitimacy that it invoked to support the circumstance of Article 6.1.c): "the obligation to publish the Public Business Registry imposed on it by the Basic Law on Chambers" and the various actions it carries out in relation to the "Public Business Registry" that derive from the public function attributed to it by Article 5.1.g): "to manage, in accordance with Article 8 of this Law, a public registry of all companies."
We reiterate what was stated in the preceding section, to the effect that Article 8 of Law 4/2014 refers to a public registry, the nature of which is different from the database transferred to CAMERDATA, despite the fact that the data originates from the same source. Furthermore, the "public business census," on the one hand, and the Basic Business Census or Transferred Database, on the other, are distinct by nature, regardless of whether the personal data included in them are identical (whether or not the NIF (Tax Identification Number) or NIF hash is included). Law 4/2014 does not impose on CDE any obligation to "publicize" the public census. There is no further publicity within the provisions of the Law other than that granted by the "public census" itself.
CDE also invoked, under this basis of legitimacy, the public interest it pursues. In this regard, and without prejudice to the considerations made, it is further indicated that Article 5.1 of Law 4/2014 lists public-administrative functions, including a reference to the public business census in its oft-cited section g). And that function,
as indicated, consists of managing the public business census or registry.
Without prejudice to the considerations regarding the fact that the purpose of the transfer of CDE to CAMERDATA is not a "public census" within the meaning of Article 8 of Law 4/2014,
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 149/204
The processing of the data under evaluation in this procedure cannot pursue a public or general interest. On the contrary, it is clear that what it seeks is to provide CAMERDATA with a personal database of individual entrepreneurs to process for marketing purposes and to provide them for that purpose to third parties. Clearly, the interests promoted by this treatment are not the "general" interests of commerce, industry, or services, but rather the specific interests of an entity or, at most, a specific sector: the infomediary.
The criteria that CDE, as stated in its allegations to the initiation agreement, takes into consideration to determine whether or not there is a public interest in the processing carried out—which it refers to as the "transfer of the "Public Business Registry"—are reproduced below, as well as the response to these arguments:
a. CDE stated that, in the exercise of its legal-public functions, it has decided not to include in the "Public Business Registry" (a term that is not equivalent to the public registry referred to in Article 8 of the Law but rather to the database it transfers to CAMERDATA, whose content is also broader), the NIF of natural persons, but only a "hash" resulting from one-way and irreversible encryption.
This allegation is responded to by indicating that—as is evident upon examining this question—CDE does transfer the NIF data of individuals to CAMERDATA. entrepreneurs
natural persons, albeit pseudonymized. If CAMERDATA did not receive the NIF hash,
under no circumstances would it be able to obtain the NIF data "on its own."
b. CDE maintains that "the hash is necessary for managing the Public Business Registry, since the inclusion of the hash is necessary to discriminate between entrepreneurs with the same first and last name. And that "The hash is necessary to comply with the legal obligation established in Article 5.1.d) of the GDPR that personal data be accurate and up-to-date."
The response to this argument is that it is not necessary to process the NIF hash to fulfill the public administrative function entrusted to it by Article 21.1.d) of Law 4/2014, in conjunction with Article 5.1g), "managing the public registry." The entrusted legal-public function is fulfilled and exhausted in the preparation and management of the "public" census.
Necessity should not be confused with convenience; transmitting the hash data is not necessary to comply with the obligations imposed by Law 4/2014.
v. CDE maintains that, "with respect to all data included in the "Public Registry of Companies subject to transfer" except the "hash," "the circumstance exists that they are data for which a legitimate basis is presumed to exist pursuant to Article 19.1 of the LOPDGDD." It states that "the two requirements established in the law are met, since the data transferred are only those necessary for professional identification, and the purpose is to allow any third party to maintain relations with the company (individual or not)."
The response to this argument is that the iuris tantum presumption of lawfulness of the processing provided for in Article 19.2 of the GDPR—which is limited to contact data—does not apply to the processing that CDE carries out when it transfers its Business Database or Transferred Database to CAMERATA. This file contains more data than merely contact data, and therefore does not benefit from the presumption of lawfulness invoked.
d. CDE maintains that all data included in the "Public Business Registry" that is the subject of transfer, except for the "hash," "are data that could be found, if searched for, by simply searching the "Public Business Registry" (a term that in this case does coincide with the public registry that Law 4/2014 authorizes it to compile), "available on the Internet and open to anyone."
The response is that the fact that personal data that is publicly available may be obtained does not mean that this circumstance constitutes a grounds for the lawfulness of the processing. In any case, the processing must be covered by one of the six legal bases detailed in Article 6.1 of the GDPR. The only consequence that may arise from the data being publicly available is the lesser impact that the processing could have on the data subject's rights, as it could have an impact on the data subject's interests. in the reasonable expectations of the data subject, which, where appropriate, should be assessed at its fair value in weighing the legitimate interest pursued by the data controller or by third parties for the purposes of applying the legal basis of Article 6.1f) GDPR (according to the Court of Justice of the European Union of
November 24, 2011).
e. CDE maintains that there is a public interest in identifying entrepreneurs and professionals involved in legal transactions. This public interest is satisfied in several ways, "including the Commercial Registry itself (which, however, does not list all individual entrepreneurs or professionals) and the obligation established in Article 10 of Law 34/2002, of July 11, on Information Society Services, for any entrepreneur (individual or not) who offers services on the Internet (in practice, almost all of them), expressly including the NIF, etc.
" But only the Public Business Registry provides complete and reliable access to the identifying data of business owners and professionals (except for the NIF, as mentioned above).
"It is important for legal transactions to have this database, and to have it available not only in a company-by-company search format (which is what the online application allows) but also in a format that companies can process electronically. This is possible by transferring the Basic Business Registry to Camerdata."
The response is that the public interest that the legislator has deemed worthy of protection is specified in Article 8 of Law 4/2014, the preparation of a public business census. This legal mandate has been fully understood by the CDE and has complied with through the public census currently accessible through its corporate website, which respects the data protection principles relating to the lawfulness of processing, purpose limitation, and data minimization.
In its submissions to the proposed resolution, the CDE states that it "has a legitimate basis for processing the data, which is related to the public interest (Article 6.1.e) of the GDPR), and pursuant to this, it prepares and publishes, as part of the management of the Public Business Census entrusted to it by law." 4/2014.”
Neither in this paragraph nor in the following two—the only three paragraphs devoted to the
violation of Article 6.1 of the GDPR alleged in its allegations regarding the proposal—does it offer further information about the public interest it supposedly defends with the processing carried out. It states that it is "by virtue" of this public interest that it "prepares" and "publishes," integrated into the function of "managing," the public census (provided for in Article 5.1.g, to which Article 21.1.d of the Basic Law refers).
In the second paragraph, it alludes, in a rather unclear way, to two bases of legitimacy: the
legal obligation that is required of CDE, mentions Article 8 of the Law in connection
with Article 5.1.g. It adds that "(ii) for the publication of said census, Camerdata, S.A. is used, which implies acting in the public interest."
In short, the argument put forward during the hearing is nothing more than a
reiteration of those put forward during the submission of objections to the initial agreement, which have been undermined by the preceding discussion.
The legal basis of Article 6.1.f) of the GDPR is the prevalence of the legitimate interest of CDE or CAMERDATA over the rights, fundamental freedoms, and interests of data subjects.
There are several reasons why it is necessary to analyze whether the processing of personal data
of self-employed entrepreneurs carried out by CDE, which is the subject of this procedure, can be based on this legal basis: In addition to having invoked it during the Preliminary Investigation, in response to the Data Inspectorate's question about the legal basis for transferring data of self-employed entrepreneurs to third parties, in particular CAMERDATA, CDE has
continued to invoke it throughout the procedure, insofar as it maintains that
Article 19.2 of the LOPDGDD establishes a rebuttable presumption of lawfulness for the processing of "all" data of self-employed entrepreneurs.
In its response to the Data Inspectorate regarding the legal basis for the transfer to CAMERDATA, it then made the following assessment of the data processing carried out
from the perspective of the fundamental rights and freedoms of individual entrepreneurs:
"1. The categories of personal data processed are limited to those contained in the public business census of the Chamber of Spain"; "2. The data processed are those contained in the public business census, a database publicly accessible on the website of the Chamber of Spain"; and "3. The easy exercise of the rights of data subjects regulated in Articles 15 to 22 of the GDPR is guaranteed at all times."
And without further ado, he concluded by saying:
“Result of the assessment:
1. The processing is considered lawful.
2. The data being processed is public data, accessible to the general public on the corporate website of the Chamber of Commerce of Spain.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 152/204
3. The categories of data processed are minimally invasive of the data subject's right to privacy, as they are data related to the data subject's performance of a business activity […].
4. The principle of the free movement of data, established and protected by the relevant European regulations (GDPR).
5. The purposes intended by Camerdata's processing of the data are consistent and compatible with those of the public business register of the Chambers of Commerce […]”
Article 6.1.f) The GDPR establishes that processing will be lawful if it is "necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child."
Recital 47 of Regulation (EU) 2016/679 contributes to the task of clarifying the content and scope of the legitimizing circumstance of Article 6.1.f) of the GDPR.
Opinion 1/2024 of the European Data Protection Board (EDPB) on the processing of personal data based on Article 6.1.f) (Version 1.0), adopted on
October 8, 2024, facilitates the interpretation of Article 6.1.f) of the GDPR and offers guidelines for the appropriate weighing of competing interests and rights.
The application of Article 6.1.f) GDPR requires the existence of a legitimate interest of the data controller or a third party; that the processing is necessary for the pursuit of the legitimate interest; and that, in weighing the legitimate interest of the controller or third party, on the one hand, and the impact on the interests, fundamental rights and freedoms of the data subject of the intended processing, on the other, the former prevails.
The Opinion distinguishes—in Section 14—between the concepts of "interest" and "purpose," which are closely related, although distinct (mentioned, for example, in Article 5(1)(b) GDPR).
It states that “A ‘purpose’ is the specific reason for which the data is processed: the
purpose or intention of the data processing. On the other hand, an ‘interest’ is the broader interest or benefit that a data controller or third party may have in
performing a specific processing activity. For example, a data controller may have an interest in promoting its products, while this interest may be furthered by processing personal data for direct
marketing purposes.”
It also indicates (15) that “Not all interests allow a controller to invoke Article 6(1)(f) of the GDPR as a legal basis. The CJEU has made it clear that the first step to be taken when assessing whether Article 6(1)(f) can be invoked as a valid legal basis is to verify whether the interest pursued by the controller can be considered “legitimate.”17 In other words, the controller must conclude that the interest pursued is “legitimate” before moving on to the second step of the three-step assessment process that must be carried out under Article 6(1)(f) (i.e., before assessing whether the processing of personal data is necessary to pursue the legitimate interest in question).
However, in order to conclude that a particular processing of personal data is based on prevalence of the legitimate interest of the controller or third parties versus
the interests or fundamental rights of data subjects, the analysis must begin by examining whether the legitimate interest invoked meets certain requirements, which, following the guidelines of Opinion 6/2014, would be the following:
(i) It must be lawful, that is, in accordance with applicable national and EU legislation;
(ii) it must be sufficiently specific, that is, articulated with sufficient clarity to
allow the balancing test to be carried out against the interests and fundamental rights of the data subject; and (iii) it must represent a real and present interest, not speculative.
CDE has not specified in its response to the Inspection request, in which it
invoked Article 6.1 f) of the GDPR as the legal basis for the processing, nor in the
arguments made during the procedure what the legitimate interest it sought to satisfy is. It has stated during the procedure that the processing of The
personal data of self-employed entrepreneurs is necessary for the
development of commercial activity with legal certainty and, by providing certainty to relationships, contributes to their development. Previously, in responding to the Data Inspectorate, the Court stated that the processing of data of sole proprietors: (i)
contributes to the development and promotion of commercial and industrial relations; (ii)
provides a quality business information system; (iii) promotes economic and business development; (iv) provides greater security in commercial transactions; (v) satisfies the particular interests of data subjects who benefit from the publicity of their activity and access to information from other companies. However, this statement does not reveal the existence of a specific interest, nor is it formulated with sufficient clarity to allow proof of its weighing against the rights, freedoms, or interests of those affected.
However, it is evident from the contract signed between CAMERDATA and CDE What
may be the "real" interest that is sought to be satisfied with the processing: to promote the
activity of the company CAMERDATA, a holding company established by CDE and
other Chambers of Commerce, by providing it with the raw material (data) that it uses to develop its business. At this point, it is appropriate to bring up the
STS of 20/06/2020 (Cassation Ruling 1074/2019), which clearly states this issue when, in its sixth legal ground, it states, regarding one of the
questions of cassation interest raised in the Order admitting the appeal, that
"The commercial interests of a company responsible for a data file must give way to the legitimate interest of the data subject in protecting the data."
The first element to be examined is the legality of the legitimate interest invoked; that is, whether
it complies with national and EU legislation. Opinion 6/2014 of the WP29 states that
an interest can be considered legitimate "as long as the data controller can pursue this interest in accordance with data protection laws and other legislation," which implies that the processing in which it is expressed is in accordance with the legal system.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 154/204
As previously noted, the purposes and social interests that data processing may have are very diverse, but they are not those established by the legislator for the business census. The interest, or the processing into which it results, will be legitimate if it is "lawful," that is, compliant with applicable national and EU legislation. The data processing carried out by CDE—the transmission to CAMERDATA of the data it has accessed, obtained from The
Tax Administrations, pursuant to Article 8 of Law 4/2014, are incompatible with compliance with the regulations that govern and guarantee the fundamental right to the protection of personal data, in particular, as will be explained below, with the principles of purpose limitation and confidentiality.
It is further added that the processing that defines the interest that CDE has sought to satisfy with its actions, the transfer to CAMERDATA of personal data of self-employed entrepreneurs lawfully obtained for other purposes established in the Basic Law, violates that law, Law 4/2014, which in its Article 8 authorizes CDE to process data related to the IAE (Tax Income Tax) and company census data exclusively for the preparation of the public census, the electoral register, and the public functions entrusted to it by that Law. As indicated and duly accredited, the processing that is the subject of this procedure does not correspond to any of the data for which CDE is authorized by law.
The conclusion is, therefore, that, as long as the interest or the processing in which it is expressed is contrary to our legal system and that of the EU, since it is contrary to the aforementioned Basic Law on Chambers of Commerce and the GDPR, it is not lawful. Opinion 6/2014 of the 29th Working Party (WG29) states very clearly: "[...] the data controller [...] may pursue any interest, provided it is not illegitimate."
As explained in detail, there is no protection in Article 19.2 of the LOPDDD, nor is there any compatibility with the purposes of Law 4/2014 on Chambers of Commerce. Even if a whole
series of potentially legitimate interests are identified, a balancing test would have to be carried out between the interest invoked by CDE and the impact that the processing has on the fundamental rights of the data subjects, for the simple
reason that the first condition for applying the legal basis of Article 6.1.f) GDPR is not met: the existence of a legitimate interest on the part of the data controller or a third party. Furthermore, since the interest pursued has not been clearly expressed, the balancing would be carried out with what we intuit is the real interest of the processing carried out.
The result of the balancing, if carried out, would also not be favorable to the prevailing interest that CDE/CAMERDATA seek to satisfy through the
transmission of data that constitutes the subject of the contract that binds them.
In this regard, first, Article 6.1.f) requires that the processing be "necessary." The term "necessity" used in Article 6.1 of the GDPR has, in the opinion of the
CJEU, its own and independent meaning in Community law. It is, the Court states, an "autonomous concept of Community law" (ECJ of
16/12/2008, Case C-524/2006, paragraph 52). Furthermore, the European Court of Human Rights (ECtHR) has also offered guidelines for interpreting the
concept of necessity. In paragraph 97 of its Judgment of March 25, 1983, it states that
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 155/204
The adjective "necessary" is not synonymous with "indispensable," nor does it have the flexibility of the expressions "admissible," "ordinary," "useful," "reasonable," or "desirable."
It is evident that the processing carried out—the creation of a database with
information obtained in the exercise of entrusted public administrative functions
(the registry function, pursuant to Article 5.1.g of Law 4/2014) and its transfer to CAMERDATA—is not only unnecessary, but is contrary to the law.
Focusing on the weighing of conflicting interests and rights, we must turn to the criterion repeatedly followed by the Constitutional Court on the constitutionality of a measure restricting a fundamental right (Judgments of the Constitutional Court
66/1995, of May 8, FJ 5; 55/1996, of March 28, FJJ 6, 7, 8, and 9; 207/1996, of December 16, FJ 4 e); and 37/1998, of February 17, FJ 8).
To verify whether a measure that limits or restricts a fundamental right—such as
in this case the right to the protection of personal data—passes the proportionality test, it will be necessary to verify that it meets the following three requirements or conditions: whether the measure is likely to achieve the proposed objective (judgment of moderateness for achieving that purpose with equal effectiveness) (judgment of necessity); and, finally, whether the It is weighted or balanced, as it results in more benefits or advantages for the general interest than harm to other goods or values in conflict (a judgment of proportionality in the strict sense).
And even considering that the interests pursued could be of sufficient intensity and scope, in a case of legitimacy based on legitimate interest without a particular legal basis or presumption, they would have to be accompanied by a strict weighing and evaluation of whether the processing is strictly proportional. This is always accompanied by evidence by those who do not enjoy a legal presumption of legitimate interest. Thus, where appropriate, for legitimate interest to be accepted as a valid basis for legitimacy in the processing of personal data, especially the more impactful and widespread the processing is, as would be the case here, it would be necessary to effectively apply a series of compensatory guarantees to ensure the protection of the rights and freedoms of the affected persons. The processing must be strictly proportional, which requires that does not exceed the data processed or the purposes pursued. Furthermore, transparency must be guaranteed for the data subject, providing clear and accessible information about the legal basis invoked and the interests pursued. It is essential that the exercise of the right to object is genuinely guaranteed in practice, including simple, effective, and accessible channels for its exercise. Likewise, technical and organizational measures must be adopted to reduce the impact of the processing on the rights of data subjects, which may include the anonymization or pseudonymization of data when possible. The entity responsible for the processing must have carried out a prior data protection impact assessment in cases required by law or when the processing is particularly sensitive, and assess, where appropriate, the need for prior consultation with the supervisory authority. It must also be able to demonstrate that it has taken into account the data subject's reasonable expectations based on the context in which the data were collected.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 156/204
Furthermore, it is advisable to have internal controls and periodic audits that verify compliance with these guarantees, as well as to establish additional protection mechanisms, such as codes of conduct or certification schemes.
All of this can be complemented with a periodic review of the processing and its effects on the rights of those affected, in order to assess whether the conditions of legitimate interest and compensatory measures remain adequate and proportionate over time.
This means that no more information should be processed than necessary, nor should it be retained for longer than necessary. Data minimization and purpose limitation thus become essential conditions for validating the judgment of necessity.
In the present case, moreover, the data subjects would have no expectation that their data could be subject to processing. The tax authorities to whom the data subjects have provided their data in the confidence that it will not be transferred to third parties without your consent, except in cases expressly provided for by law, which does not include the data processing assessed here. In short,
It must therefore be concluded that the file or database that CDE transfers to CAMERDATA, created with information lawfully received from the tax authorities in accordance with the provisions of Law 4/2014, cannot be legally based on the circumstances described in Article 6.1.f) of the GDPR.
As indicated, the processing that CDE has carried out in the present case cannot be legally based on the legal basis of Article 6.1.f) of the GDPR. And
it is also important to emphasize that, in relation to the processing at hand, CDE
had not adopted any measure to counterbalance the effective restriction
of the fundamental right to data protection entailed by its processing of the data of self-employed entrepreneurs.
In light of the foregoing, it is clear that there is no
legal basis pursuant to Article 6.1 of the GDPR to support the lawfulness of the processing of data of self-employed entrepreneurs that CDE has carried out and on which
the present procedure is based.
Having established the above, it is important to note that public administrations could carry out data processing for purposes that are not incompatible with the purpose of the original lawful processing.
4. Subjective element of the alleged administrative offense.
Regarding the violation of Article 6.1 of the GDPR alleged against CDE in this proceeding, it is noted that the element of culpability is present, without which it is not possible in our legal system to impose punitive liability (Article 28 of Law 40/2015). Culpability here is not manifested in the failure to perform the necessary due diligence to constitute this element of the violation, but, in this case, it is of extraordinary relevance because it takes the form of intent.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 157/204
We are dealing with data processing carried out consciously and
premeditatedly with the intention of using information that CDE can access lawfully
for the purposes entrusted to it by Law 4/2014, for another purpose for which the Law does not authorize it.
The intention to carry out the transfer is reflected in the contract signed between the two parties in 2016, valid at least until December 20, 2023. Regarding the intellectual or cognitive element—transferring the data to CAMERDATA, knowing that it is unlawful and that it violates the GDPR—there is undeniable evidence of this, such as the deliberately confusing wording used in the Business Database Transfer contract to create the belief that the purpose of said contract is the "public business census," thus extending the legal grounds for the "public census" in Law 4/2014 to this processing. Exhibit V of the aforementioned contract is worth mentioning as a clear example of the intention to mask the processing actually carried out. It is also proven that CDE is fully aware of data protection regulations, as demonstrated by its correct application of these regulations in preparing and managing the "public business census." It has clearly not included the NIF data of self-employed entrepreneurs, applying the principle of data minimization and ensuring its confidentiality. The census is "public," that is, accessible to all and is configured for consultation, not for downloading information that would allow its use for other purposes. CDE
correctly complies with the legal obligation to compile the "public business census" and, at the same time, deliberately ignores all legal limits with a processing procedure—the transfer to CAMERDATA—designated in the contract signed with CAMERDATA.
Under this contract, information relating to individual entrepreneurs that CDE holds for other purposes established in its regulatory law is transferred to CAMERDATA for inclusion in its own data file, thus helping this company develop its corporate purpose.
It is worth mentioning regarding CAMERDATA's corporate purpose that, as stated in the
Audit Report for fiscal year 2022 ("Report", section
"1. Company Activity"), "The Company is primarily engaged in the marketing and sale throughout Spain of databases of companies, businesses,
official organizations, and other economic actors and agents, to individuals or companies through the implementation of the necessary IT tools:
websites, search programs, databases, etc., (page 868 of the
file).
Finally, the direct connection between CDE and CAMERDATA cannot be ignored, despite the fact that, as CDE claims, they are two different legal entities.
We note that the same Audit Report for fiscal year 2022 states that "The Company is governed by a Board of Directors composed of 5 members, including 4 members from Chambers of Commerce." It also indicates that "as of December 31, 2022, the Company's shareholder structure is as follows:
Shareholder % of capital; Barcelona Chamber of Commerce 27.14%; Valencia Chamber of Commerce 27.14%; Spanish Chamber of Commerce 18.10%; Madrid Chamber of Commerce 16.89%; Other minority chambers 10.73%."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 158/204
The processing of personal data that is the subject of this sanctioning procedure,
specifically, the transfer by CDE to CAMERDATA of the personal data of self-employed entrepreneurs that it has lawfully obtained from the tax authorities
for compliance with the legal obligation to compile a public business census, to compile a voter census under the terms of Article 17 of Law 4/2014, and for the performance of the public administrative functions assigned to it by the aforementioned Law, is not covered by any of the grounds for lawfulness specifically established in Article 6.1 of the GDPR. Consequently, this resolution
considers that the data processing examined, for which CDE is held responsible,
violates Article 6.1 of the GDPR.
VIII
Classification and limitation period for the violation of Article 6.1 of the GDPR
The violation of Article 6.1 of the GDPR for which CDE is held responsible in this resolution is classified in Article 83.5.a) of the GDPR, which states:
“5. Violations of the following provisions shall be punishable, in accordance with
paragraph 2, by administrative fines of up to EUR 20,000,000 or, in the case of an undertaking, by an amount equivalent to a maximum of 4% of the total annual global turnover of the preceding financial year, whichever is higher:
a) the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9;
[…]”
For the sole purpose of determining the statute of limitations for the infringement, the
LOPDGDD provides in Article 72, under the heading “Infringements considered very serious”:
“1. Pursuant to the provisions of Article 83.5 of Regulation (EU) 2016/679, infringements that constitute a substantial violation of the articles mentioned therein, and in particular the following, are considered very serious and will be subject to a three-year statute of limitations:
a) […]
b) The processing of personal data without any of the conditions for the lawfulness of the processing established in Article 6 of Regulation (EU) 2016/679 being met.”
IX
Violation of Article 5.1.b) of the GDPR
1. This resolution attributes to the CDE a violation of the principle of purpose limitation of processing. Article 5 of the GDPR, “Principles relating to processing,”
establishes:
“1. Personal data shall be:
[…]
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 159/204
b) “collected for specific, explicit, and legitimate purposes, and shall not be further processed in a manner incompatible with those purposes; in accordance with Article 89,
paragraph 1, further processing of personal data for archiving purposes in the
public interest, scientific and historical research purposes, or statistical purposes shall not be considered incompatible with the initial purposes (<<purpose limitation>>).”
Recital 50 of the GDPR helps clarify the scope of this principle:
“(50) The processing of personal data for purposes other than those for which they were initially collected should only be permitted where it is compatible with the purposes for which they were initially collected. In such a case, no separate legal basis, other than that which allowed the personal data to be obtained, is required. If processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, the tasks and purposes for which further processing is to be considered compatible and lawful may be determined and specified in accordance with Union or Member State law. […]. The legal basis provided for in Union or Member State law for the processing of personal data may also serve as a legal basis for further processing. In order to determine whether the purpose of further processing is compatible with the purpose of the initial collection of the personal data, the Personal data, the controller, having met all requirements for the lawfulness of the original processing, must take into account, among other things, any relationship between these purposes and the purposes of the envisaged further processing, the context in which the data were collected, in particular the data subject's reasonable expectations based on his or her relationship with the controller regarding their further use, the nature of the personal data, the consequences for data subjects of the envisaged further processing, and the existence of appropriate safeguards both in the original processing operation and in the envisaged further processing operation.
Where the data subject has given consent or the processing is based on Union or Member State law that constitutes a necessary and proportionate measure in a democratic society to safeguard, in particular, important objectives of general public interest, the controller must be entitled to further process the personal data, regardless of the compatibility of the purposes. In any case, the application of the principles
established by this Regulation and, in particular, informing the data subject
about those other purposes and about their rights, including the right to object.
The
indication of possible criminal acts or threats to public security by the controller and the transmission to the competent authority of data concerning individual cases or multiple cases related to the same criminal act or threat to public security must be considered to be in the legitimate interest of the controller. However, such transmission in the legitimate interest of the controller or the further processing of personal data should be prohibited if the processing is not compatible with a legal, professional, or otherwise binding obligation of secrecy.
The principle of purpose limitation implies that the controller must process the data for one or more "specified," "explicit," and "legitimate" purposes. The
purpose of the processing must be clearly defined, allowing
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 160/204
to know what processing activities are included in it. The data controller must not
subsequently process the data collected for specific, explicit, and legitimate purposes in a manner incompatible with those purposes. The GDPR does not prohibit
processing for purposes other than those that justified the original processing,
but rather prohibits processing for incompatible purposes.
Article 6.4 of the GDPR offers some features or criteria for determining the compatibility of the further purposes of processing with the purpose of the initial processing:
“Where processing for a purpose other than that for which the personal data were collected is not based on the data subject’s consent or on Union or Member State law that constitutes a necessary and proportionate measure in a democratic society to safeguard the objectives set out in Article 23(1), the controller, in order to determine
whether processing for another purpose is compatible with the purpose for which the personal data were initially collected, shall take into account, inter alia:
a) any relationship between the purposes for which the personal data were collected and the purposes of the envisaged further processing;
b) the context in which the personal data were collected, in particular with regard
to the relationship between the data subjects and the controller;
c) the nature of the personal data, in particular when special categories of personal data are processed, in accordance with Article 9, or personal data relating to criminal convictions and offences, in accordance with Article 10;
d) the possible consequences for data subjects of the planned further processing;
e) the existence of appropriate safeguards, which may include encryption or pseudonymization.
2. CDE, like all other Chambers of Commerce, is a corporation governed by public law, with legal personality and full capacity to act in the fulfillment of its purposes "without prejudice to the private interests they pursue" (Article 2 of Law 4/2014).
Article 3 of the Basic Law on Chambers, "Purpose," provides that official Chambers, including CDE, "have the purpose of representing, promoting, and defending the general interests of commerce, industry, services, and navigation, as well as providing services to companies that carry out the aforementioned activities. They shall also exercise the public powers attributed to them by this Law and those that may be assigned to them by Public Administrations in accordance with the instruments established by law."
Pursuant to Article 8 of the Basic Law on Chambers of Commerce, "Public Census," the CDE is obliged to compile (shall compile, according to the provision) "a public census of companies, which will include individuals or legal entities, national or foreign, that carry out commercial, industrial, service, and shipping activities in national territory." The provision indicates that for its preparation, it will rely "on the collaboration of the competent tax administration, as well as other administrations that provide the necessary information, guaranteeing, in all cases, confidentiality in the processing and exclusive use of said information."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 161/204
Regarding the collaboration of tax authorities, Article 8 specifies that "For the purpose of compiling the public business census, the tax authorities shall provide the Official Chamber of Commerce, Industry, Services, and Navigation of Spain and the Official Chambers of Commerce, Industry, Services, and Navigation with the necessary data on the Tax on Economic Activities and the business censuses. Only the employees of each Chamber determined by the plenary session shall have access to the information provided by the tax authority."
Regarding the use that the Chambers may make of the information thus obtained, Article
8 provides: "This information shall be used to compile the public business census, to fulfill the public-administrative functions that this Law attributes to the Chambers, as well as to compile the electoral census
referred to in Article 17 of the same."
In order to establish the conditions and guarantees under which the transmission of tax information on self-employed entrepreneurs from the AEAT (Tax Agency) to the CDE (Department of Debt Collection and Debt Collection), both signed an agreement on November 25, 2019, "for the transfer of tax information to the Official Chambers for the exercise of their public-administrative functions" (Official State Gazette, December 20, 2019). This agreement was extended for four years and amended by an "Addendum" signed on December 19, 2023 (Official State Gazette, February 16, 2024).
The second clause of the Agreement addresses the purpose of the transfer and provides:
“The transfer of data from the Tax on Economic Activities and company censuses will be for the exclusive purpose of preparing the public company census, fulfilling the public-administrative functions assigned to the Chambers by Law 4/2014,
Basic Law of the Official Chambers of Commerce, Industry, Services, and Navigation,
as well as preparing the electoral census referred to in
Article 17 of the same Law.”
In line with the exclusive purpose for which the data is transferred, the Agreement states (clause four, recipients of the information provided) that “The information transferred by the Tax Agency may only be addressed to the bodies of the Spanish Chamber of Commerce and the Chambers that have been assigned the public functions that justify the transfer, including the competent audit bodies to the extent that, pursuant to their own regulations, they participate in the procedures referred to in the second clause of this Agreement.”
It specifies that “Under no circumstances may the recipients be bodies, agencies, or entities that perform functions other than those described in the second clause of this Agreement.” It also establishes “the strict allocation of the information sent by the Tax Agency to the purposes that justify it and for which it is requested” and that “the recipient may not transfer the information sent by the Tax Agency to third parties.”
Worthy of mention is the "Report on the agreement between the State Agency for Tax Administration and the Official Chamber of Commerce, Industry, Services and Navigation of Spain for the transfer of tax information to the Official Chambers for the exercise of their public-administrative functions," signed on September 27, 2019, which CDE provided in response to the request made during the trial phase to provide the report of its legal department and the supporting memorandum referred to in Articles 50.1 and 50.2.1 of Law 40/2015 in relation to the agreements.
The report provided (which does not state the position held in the organization by the signatory) under the second paragraph of "Actions to be carried out" emphasizes that the transfer of data from the Tax Administrations to the CDE has a single and exclusive purpose: the preparation of the public census. And it adds that this information may not be used for any other purpose than the bodies of the Spanish Chamber of Commerce or the Chambers that have been assigned functions that justify the data transfer:
"The transfer of the IAE data and the company census data will be
for the exclusive purpose of preparing the public company census, fulfilling
the public-administrative functions that Law 4/2014, Basic Law of the Official Chambers of Commerce, Industry, Services, and Navigation, attributes to the Chambers,
as well as preparing the electoral register referred to in Article 17 of
the same Law.
The information transferred by the Tax Agency may only be used
for the bodies of the Spanish Chamber of Commerce and the Chambers that have been assigned the public functions that justify the transfer."
Likewise, it should be emphasized that the transfer of tax data (related to the IAE and company censuses) to the Official Chambers, and therefore also to the CDE,
which Article 8 of Law 4/2014 imposes on the tax authorities, represents
for individual entrepreneurs, who are assigned to a Chamber of Commerce ex officio, regardless of their will, a restriction of the fundamental right
to the protection of their personal data recognized in Article 18.4 of the Spanish Constitution.
This restriction is imposed by law and is justified in this case by the public interest it
seeks to satisfy.
The data that the tax authorities provide to the CDE to compile a
public company census is considered tax data. And, by virtue of the
legal obligation imposed by Article 8 of Law 4/2014 on tax authorities,
the confidential nature of the tax data obtained by tax authorities in the exercise of their functions, as well as the prohibition of transfer to third parties except in cases expressly provided for, granted by the General Tax Law in Article 95, is hereby lifted (in relation to the information referred to in this provision).
It is precisely the data of individual entrepreneurs that the
Tax Authorities provide to CDE, which it lawfully accesses
for the functions for which it is authorized by its regulatory law, that are
transferred by CDE to CAMERDATA, in execution of a private contract
signed between the two, for a purpose that, in addition to being different from the original
purpose that justified access to the data, is excluded from said original purpose given
how it is configured in the Basic Law on Chambers.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 163/204
On February 15, 2016, CDE and CAMERDATA signed a "Business Database Transfer Agreement," in force on the date of its submission to this Agency, December 20, 2023. It stipulates (first agreement, Object) section 1.1:
"By this Agreement, the Transferor transfers to the Transferee, who, in turn, receives and acquires for itself a copy of all the business data contained in the Basic Business Census referred to in the previous Exhibit V (hereinafter the Transferred Database), updated as of January 2016, which contains the information fields indicated in
Annex 1 of 3,160,984 Business Registries."
It is important to clarify, to avoid misinterpretations, that although the contract between CDE and CAMERDATA prohibits the assignee (CAMERDATA) from transferring to third parties "the Transferred Database or any of its updates without the prior express written authorization of the Transferor" (agreement 7.1), this does not imply that there is no transfer of data. This is because such prohibition (agreement 7.1, first paragraph) applies to the Transferred Database, but not to its content. In this regard, the second paragraph of agreement 7.1 states:
"Excluded from this prohibition is the transfer of data from the Transferred Database
incorporated in the Spanish Company File owned by the assignees in accordance with the provisions of the Second and Third Agreements of the Contract."
Agreement 7.1, second paragraph, which must be related to the obligation that the contract imposes on the transferee (CAMERDATA) to incorporate the information included in the Transferred Database into its database, the Spanish Business File. Thus, Annex 2 to the Business Database Transfer Agreement (which, according to said agreement, forms an inseparable part of it) states under the heading "B)
Obligations of the Transferee:
"b.1) The Transferee undertakes to incorporate the information from the Transferred Database into the Spanish Business File and to process and market it under the terms agreed in the Agreement and its Annexes.
" b.2) The Transferee undertakes to always keep the business data in the Spanish Company File up-to-date and, to this end, undertakes to:
(i) Obtain from the Transferor all updates to the Transferred Database that the Transferor periodically makes within 15 (15) business days following the date on which it receives written notification to this effect from the Transferor.
(ii) Not to transfer or market the Transferred Database or its updates, and not to make any copies other than backup copies.
(iii) Incorporate the information from the Company Registries of the updated Transferred Database into the Spanish Company File within thirty (30) business days following the date on which it receives it from the Transferor and process it under the terms indicated in the following paragraph b.4).”
3. CDE’s allegations regarding the initiation agreement and the proposed resolution.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 164/204
In its allegations regarding the initiation agreement, CDE denies having committed a violation of
Article 5.1.b) of the GDPR, as it denies having processed the data of the self-employed workers for any purpose other than the initial one. In this regard, it maintains:
“that the sole and exclusive purpose of the processing is to comply with the legal obligation to
prepare and manage the Public Company Registry under the terms set forth in the Law 4/2014. What has been done is precisely to make the Public Business Census public, with the transfer being an instrument to achieve this goal.
This argument is consistent with the thesis it defends, according to which Law 4/2014 assigns it the function of publicizing the public business register, and, given the lack of legal provisions in this regard, it transfers the data to CAMERDATA in compliance with a supposed legal obligation to make the public business register public.
In its allegations regarding the proposed resolution, CDE maintains the same argument—the transfer is made in compliance with a legal obligation to publicize the public register—and also adds that the violation of Article 5.1.b), if it existed, would be attributable to CAMERDATA.
In this regard, it states that it "has not violated the principle of limitation of processing (Article 5.1.b) of the GDPR), since, if applicable, the violation would have been committed by Camerdata, S.A. and not by CDE."
CDE provides Camerdata, S.A. with the Assigned Database to comply with the
legal obligation to publicize the Public Registry of Companies established in Law 4/2014, as previously indicated. Whether Camerdata, S.A., as an independent data controller, decides whether to process personal data for other purposes, its own purposes, is beyond CDE's control.
It should be noted once again that Clause 12.1 of the Agreement obliges Camerdata, S.A., in its capacity as Assignee, to "strictly observe and comply at all times with the rights and obligations of each party regarding access, processing, and transfer of data" (emphasis added).
"Charging CDE with an infraction it did not commit would violate the principle of personal responsibility, which prevents anyone from being sanctioned for the actions of others (Judgment of the Constitutional Court (STC) 219/1988, of November 22, Legal Basis 3)."
In response to CDE's allegations, two clarifications must be made that undermine its arguments:
First, as explained in detail in Grounds III, points 4 and 5 of this resolution, as well as when examining the violation of Article 6.1 of the GDPR for which it is responsible, it is made clear that Law 4/2014 does not impose any obligation on CDE to publicize the public business register. Publicity is provided by the public register that the law requires to be compiled.
The only obligation that the Basic Law imposes on CDE is to "prepare" a "public business register" and the function of managing it, which consists of carrying out the registry functions.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 165/204
domains. “publicity” is what, by its very nature, projects the “public record.”
The second is related to the allegation that the violation of Article 5.1.b) of the GDPR would be attributable to CAMERDATA, thus invoking the principle of personal responsibility.
Article 6.4 of the GDPR provides:
“Where processing for a purpose other than that for which the personal data were collected is not based […], the controller, in order to determine whether processing for another purpose is compatible with the purpose for which the personal data were initially collected, shall take into account.”
Similarly, Recital 50 states that: “In order to determine whether the purpose of the further processing is compatible with the purpose of the initial collection of the personal data, the controller, after having met all the requirements for the lawfulness of the original processing, must take into account, inter alia, […].”
In relation to the processing under consideration, CDE holds the status of the data controller, since it is the party that decides on its purposes and means and who signs with CAMERDATA a contract for the transfer of a database that, as CDE and CAMERDATA have acknowledged, and as is evident from the proven facts, its content comes from the information that CDE has accessed in the exercise of the functions entrusted to it by Law 4/2014. Therefore, there is no violation of the principle of personal responsibility, which prevents anyone from being sanctioned for the actions of others.
Thus, as the data controller, CDE should have assessed and ensured that the processing it intended to carry out complied with the principle of purpose limitation (Article 5.1.b). This is an obligation inherent to the proactive responsibility provided for in Article 5.2 of the GDPR. It should also be remembered that the principle deemed to have been violated must be complied with throughout the entire duration of the transaction. lifetime of the processing. It is therefore irrelevant that on the date the contract was signed (February 2016), the GDPR had not yet been approved, since, on the one hand, in light of Organic Law 15/1999 on the Protection of Personal Data (LOPD), the purpose of the subsequent processing carried out was also conduct classified as a sanctioning regulation, and, on the other hand, since the GDPR came into force, it was required to assess the adequacy of the processing carried out with the new regulations.
In light of the above and in regard to the comments made by CDE in its
allegations according to which the Agency is taking into consideration a contract
signed in 2016 that is outdated, we clarify that the Agency is taking into consideration the "current" contract with CAMERDATA; the one provided by CDE on
12/20/2023 In response to the Data Inspectorate's request. If the contract, as stated, has not been updated—whether due to a lack of diligence or a lack of will—this is an irrelevant issue for the purposes of this report.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 166/204
4. The principle of proactive accountability in Article 5.2 of the GDPR requires the data controller to be able to demonstrate compliance with the principles governing data processing, which is why the principle of purpose limitation is relevant. CDE has not provided any evidence to prove that the data processing carried out complied with the principle of Article 5.1.b) of the GDPR.
From the established facts, it is concluded that the purposes of CDE's original processing of the data obtained from the tax authorities and the subsequent processing—the transfer to CAMERDATA—are not only different but also incompatible:
- There is no relationship between the purpose for which CDE can access the data provided by the tax authorities (IAE and company census data) for the creation of the public census (a public registry) and for its management
(registry functions) and the processing operation consisting of creating a data phase with that information and negotiating with it, as this is the purpose of the contract signed with CAMERDATA.
There is no relationship between the purpose of data processing, which consists of
compiling a public business census, for which Article 8 of Law 4/2014
entitles the CDE, a public purpose, and the specific purpose for which CDE transfers the data to CAMERDATA: the sending of commercial and marketing communications, offering
various goods or services, as well as commercial information on the business activity carried out by the self-employed entrepreneur.
The public interest purpose sought to be addressed by Article 8 of Law 4/2014 is proportional to the restriction it imposes on the right to data protection of individual entrepreneurs, but it is in no way proportional to the purpose sought by the transfer to CAMERDATA.
The origin of the data of the self-employed entrepreneurs who are the subject of the transfer prevents them from having any reasonable expectation regarding the subsequent processing of their data by CAMERDATA. It cannot be ignored that the data that CDE
provides to CAMERDATA is the data that individual entrepreneurs provide to the tax authorities. It is confidential and cannot be provided to third parties except in the cases provided for by law or with the express consent of the data subject (formerly Article 95 of General Tax Law 58/2003).
- The nature of the tax data that the CDE receives from the AEAT makes its subsequent processing incompatible with the purpose for which CAMERDATA will use it.
- The obvious adverse consequences that may arise for the interested parties from the subsequent processing of the data, in addition to the fact that CAMERDATA transfers the NIF (Tax Identification Number) of self-employed workers to third-party companies to which it markets the database.
At this point, we refer to the considerations made in the corresponding Basis regarding the CDE transferring the data of the self-employed workers to CAMERDATA. Pseudonymized NIF (the hash) and CAMERDATA can obtain the NIF in plain text
thanks to the hash provided by CDE.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 167/204
It is important to add that, as stated in Recital 50, last paragraph, "However,
such transmission in the legitimate interest of the controller or the further processing of personal data must be prohibited if the processing is not compatible with an obligation of
legal, professional, or otherwise binding secrecy." In this regard, we recall
again the stipulations of the Agreement signed between the AEAT and the CDE in its
fourth clause: In any case, the recipient may not transfer to third parties the
information sent by the Tax Agency.
5. The violation of Article 5.1.b) of the GDPR attributed to CDE includes the
element of The culpability without which it is not possible in our legal system to demand punitive liability (Article 28 of Law 40/2015). Liability in this case is not attributed to negligence or negligence, but to intent.
CDE's intention to process the data of self-employed entrepreneurs for a commercial or marketing purpose that is not only different from, but also clearly incompatible with, the purpose for which Article 8 of Law 4/2014 authorizes CDE to access the IAE data and company census data provided by the tax authorities is evident in the Business Database Transfer Agreement signed between the two parties in February 2016, which has remained in force until at least December 20, 2023. The second clause of the contract, "Purpose,"
establishes that "The transferee will include the business data from the Transferred Database [...] for the purpose of offering it commercially to companies and interested third parties as a database of information on companies operating
in Spanish territory."
It also adds that the purpose of processing the transferred data coincides with
CAMERDATA's corporate purpose, a fact that CDE is aware of, as it is one
of the company's four majority shareholders and sits on its board of directors.
Furthermore, the documentation in the file shows that CDE
has been fully aware that the data processing it carries out, the
transmission of a database to CAMERDATA, is not consistent with the
purpose for which it obtained the data. We must again refer to the safeguards
established by Article 8 of Law 4/2014 to guarantee the right of individuals
to the protection of their data: Data transferees (CDE and
the other Official Chambers) are required to "exclusively use" the information obtained.
Particularly relevant are the stipulations of the Agreement signed with the AEAT,
particularly its fourth clause, "Recipients of the information," which stipulates, among
other things, that the information sent by the Tax Agency must be strictly assigned to
the purposes that justify it and for which it is requested, or that the recipient may not transfer
the information sent by the Tax Agency to third parties. Likewise, we again
refer to the report from the CDE Legal Department, which coincides with the
fourth clause of the Agreement.
The reasons set forth lead to the conclusion that CDE should be held liable for the violation of Article 5.1.b) of the GDPR on the grounds of willful misconduct.
6. CDE's violation of the purpose limitation principle, specifically its processing of the data it lawfully accessed for a specific purpose
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 168/204
provided for in its Regulatory Law for a different purpose that is incompatible with the original purpose, is of extraordinary relevance in the case presented here.
The party responsible for the administrative offense is a public law corporation that, acting as a public administration in the exercise of the functions assigned to it by its Regulatory Law, is authorized to access data that business owners and individuals have provided to the tax authorities in the exercise of their functions. Access to tax information is justified only by the public interest sought—having a public business census that faithfully reflects reality—which is compiled by CDE. The legal obligation that Article 8 of Law 4/2014 imposes on tax authorities to collaborate and allow CDE access to the IAE data and business censuses necessary for the purpose justifying access exempts the tax authority from obtaining the consent of the interested parties for the transfer.
The information obtained in its capacity as a public authority (since it accesses it in compliance with a legal obligation and to perform a public function) is used for a purpose not contemplated by law: a database is created with information that has been accessed thanks to the authorization it has by virtue of performing a public administrative function. CDE does not have the authority to use this information to generate a database that is being transferred.
Furthermore, it is incompatible with the commercial and marketing purposes pursued by the subsequent processing, which is channeled through a contract signed with CAMERDATA, through which the data is transferred to CAMERDATA for processing for this purpose. It should be emphasized that there is large-scale data processing, as the number of individuals whose personal data is processed by CDE exceeds one and a half million. It is also relevant that the data transferred concerning them is extensive, including their NIF (Tax Identification Number), in plain text or pseudonymized.
For the reasons stated, it is clear that the violation of the principle of purpose limitation for processing for which CDE is responsible has, in this particular case,
its own entity, in the sense that the unlawfulness of the conduct contrary to the principle of Article 5.1.b) of the GDPR is neither subsumed nor exhausted by the violation of the principle of lawfulness, since we understand that the unfair element of the violation of Article 5.1.b) of the GDPR goes beyond the unlawfulness that falls within the violation of Article 6.1.a) of the GDPR.
For the reasons stated above, it is clear in this procedure that CDE has violated the principle of purpose limitation for processing under Article 5.1.b) of the GDPR.
X
Classification and limitation period for the violation of the principle of purpose limitation (Article 5.1.b) of the GDPR)
The violation of Article 5.1.b) of the GDPR for which the CDE is held liable is
defined in Article 83.5.a) of the GDPR, which establishes:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 169/204
“5. Violations of the following provisions shall be punished, in accordance with
section 2, with administrative fines of up to EUR 20,000,000 or, in the case of a company, an amount equivalent to up to 4% of the total annual global turnover of the preceding financial year, whichever is higher:
a) the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7 and 9; [...].”
Furthermore, for the sole purpose of determining the statute of limitations for the
infraction, the LOPDGDD classifies it as very serious and provides:
“1. Pursuant to the provisions of Article 83.5 of Regulation (EU) 2016/679,
infractions that constitute a substantial violation of the articles mentioned therein, and in particular, the
following, are considered very serious and will be subject to a three-year statute of limitations:
[…]
d) The use of data for a purpose that is incompatible with the purpose
for which it was collected, without the consent of the data subject or a
legal basis for doing so.”
XI
Breach of the confidentiality principle, Article 5.1.f) of the GDPR
1. This resolution attributes to the CDE a breach of the confidentiality principle established in Article 5.1.f) of the GDPR, under which the data controller is obliged to process personal data in a way that ensures adequate security, "including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, through the application of appropriate technical or organizational measures."
Recital 75 of the GDPR states: “Risks to the rights and freedoms of natural persons, of varying severity and likelihood, may arise from the processing of data that could cause physical, material, or immaterial harm, in particular where the processing may give rise to discrimination, identity theft or fraud, financial loss, reputational damage, loss of confidentiality of data subject to professional secrecy, unauthorized reversal of pseudonymization, or any other significant economic or social harm.” (Emphasis added)
Constitutional Court Judgment (STC) 292/2000, in its Legal Basis 7, regarding the content of the right to personal data protection,
states: "[…] the content of the fundamental right to data protection consists of a power of disposition and control over personal data that empowers the individual to decide which of those data to provide to a third party, be it the State or an individual, or which that third party may collect, and which also allows the individual to know who possesses that personal data and for what purpose, and to object to such possession or use."
Pursuant to Article 5.1.f), the data controller is obliged to process personal data in a manner that ensures adequate security, "including protection against unauthorized or unlawful processing" through the application of appropriate technical or organizational measures.
A breach of the confidentiality principle requires that unauthorized communication or access to such data by third parties has occurred, and that the unlawful communication or access has occurred as a result of the controller's failure to apply appropriate technical or organizational measures to ensure confidentiality in light of the existing risk.
Article 24 of the GDPR, “Controller Responsibility,” expands on Article 5.1.f) and provides:
“1. Taking into account the nature, scope, context, and purposes of processing, as well as the risks of varying likelihood and severity for the rights and
freedoms of natural persons, the controller shall implement appropriate technical and organizational measures to ensure and be able to demonstrate that the processing is in compliance with this Regulation. Such measures shall be reviewed and
updated where necessary.
2. Where proportionate to the processing activities, the measures referred to in paragraph 1 shall include the implementation by the controller of appropriate data protection policies.
3. Adherence to codes of conduct approved pursuant to Article 40 or to a certification mechanism approved pursuant to Article 42 may be used as elements to demonstrate compliance by the controller with its obligations.” of the data controller."
2. Law 4/2014 imposes on the CDE the obligation to compile a public business census and entrusts it with the public administrative function of managing it. Law 4/2014 expressly authorizes the CDE to process IAE data and company census data, to compile the public census, to compile the electoral register, and for the public-administrative functions conferred upon it. Of these, the only one related to the public census is that established in Article 5.1.g) to manage the public census.
It has also been indicated that when Article 8 of the Law obliges the CDE to compile a public census, it imposes on it the obligation to compile a public register. And by
assigning Article 5.1.g) the public administrative function of "managing" a public business census, in the
terms of Article 8, it is entrusting it with the
performance of the registry function in relation to the aforementioned public business census.
In the present case, it is clear that CDE has unlawfully transferred personal data of self-employed entrepreneurs. This data is lawfully obtained from the tax authorities
in accordance with the authorization granted by Law 4/2014. The unlawful transfer is
articulated through a contract signed with CAMERDATA, the purpose of which is a
database that CDE calls the Basic Business Census or the Transferred Database.
The content of the database that is the subject of the unlawful transfer relates to data that can be obtained through the public registry, the public census, and, in addition, other data that cannot be obtained by accessing the public business census, in particular, the NIF (Tax Identification Number).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 171/204
Thus, the public business census, which is accessed from the CDE website, only provides information on the first and last name, address (street, number, and
sometimes the floor), town, province, and postal code. It also includes the IAE (Tax Identification Number) heading and a description of the activity. It does not include the NIF (Tax Identification Number). The proven facts, to which we refer, confirm this point, particularly the third section b. The NIF (Tax Identification Number) is not included because it is unnecessary for compliance with the legal obligation imposed on CDE by Article 8 of Law 4/2014, and by not including it, it
respects the principle of personal data minimization provided for in Article 5.1.c) of the GDPR.
However, CDE receives the NIF (Tax Identification Number) from the tax authorities, as evidenced
by the Excel document that CDE sent to the Data Inspectorate with all the personal data it had in its possession related to a group of 500 self-employed workers,
and in which this information appears in the first field of each record.
In its response to the Inspection request, CAMERDATA stated that its file, called "Spanish Business File," which lists a total of 1,665,049 self-employed individuals, does include the NIF (Tax Identification Number) of self-employed entrepreneurs.
It stated that "The source of the data is the public business census published by the Spanish Chamber of Commerce in accordance with Law 4/2014 (hereinafter the Public Business Census) and is obtained each time a new business census is uploaded." (Proven fact nine)
However, CAMERDATA later corrected this information in its allegations regarding the start-up agreement and declared that it had been a factual error. Thus, in its allegations to the start-up agreement, it denies that CDE provided it with the NIF (Tax Identification Number) and states that it only provides the NIF hash, while CAMERDATA obtains the NIF (Tax Identification Number) of individual entrepreneurs through its own means.
CARMERDATA does not deny in any way that it processes the NIF data; this data is indeed part of the Spanish Business File that the entity markets.
Likewise, CDE, in its response to the Inspection request, states that it provides CAMERDATA with the NIF (Tax Identification Number) of self-employed entrepreneurs (Proven Fact Three
point iii) and subsequently rectifies it, explaining that it was an error and declaring that it only provides the resulting hash. As proof of the veracity of its statements, it provides a certificate issued by ***PUESTO.1 in which it so declares. The eleventh proven fact states that this document from the company's General Manager certifies that:
“1. CAMERDATA (…) is commonly used to securely store data.
The algorithm used is a HASH or unique fingerprint, and its main characteristic is that it is not possible to obtain the input value (NIF) corresponding to an output value (HASH or MD5 fingerprint). Therefore, CAMERDATA obtains the NIF
through its own means.”
CDE has argued that it does not transfer the NIF but rather the resulting hash. It states that “the NIF of individual entrepreneurs is not
transferred to Camerdata, nor does Camerdata receive it from the former.”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 172/204
When examining the violation of Article 6.1 of the GDPR, it is indicated that the result of applying the hash function to the self-employed persons' tax identification number (NIF) data does not
result in anonymized information, therefore excluded from the scope of the GDPR, but rather results in pseudonymized personal data. Thus, CDE is acknowledging in its allegations to the initiation agreement that it transfers to CAMERDATA the NIF data of the self-employed persons listed in its database (all of them, in application of the principle of universal affiliation), albeit pseudonymized.
In any case, it is relevant for the purposes of assessing the violation of Article 5.1.f) of the GDPR that CDE does provide the NIF hash to CAMERDATA. If CAMERDATA can obtain the NIF data of the self-employed workers by its own means, it is because it has the hash resulting from applying the algorithm in question. Without the hash, CAMERDATA could not have obtained the NIF data.
It is important to clarify that the transfer of the NIF data of the self-employed workers to CAMERDATA is not considered to be included in the processing contrary to the principle of confidentiality—the transfer by CDE of the NIF data of the self-employed workers that it would have received from the Regional Treasury of the Community of Navarre. The reason is that the data that
comprises the Registry of Economic Activities managed by the Navarre Regional Treasury are public pursuant to Article 156.2 of Regional Law 2/1995, of March 10, on Local Treasuries of Navarre, which provides: "The aforementioned annual Registry, with the exception of tax domicile data, will be available to the public throughout the calendar year on the Navarre Tax Authority website.
Notwithstanding the provisions of the previous paragraph, access will also be permitted,
via the same means, to the following data appearing in the Registry of Economic Activities at the time of the query: the identification details of taxpayers who carry out economic activities, as well as the address and heading or
subheading of the activity."
During the testing phase, CDE was asked to describe the system it is using to transmit the data to CAMERDATA. CDE responds that "The information is transmitted to Camerdata via Microsoft OneDrive, using the following procedure:
• The Chamber of Spain generates a CSV file with the established record layout and compresses it with a password.
• The Chamber of Spain generates a CSV file that includes the list of hashes corresponding to the NIFs of the self-employed entrepreneurs.
• The Chamber of Spain uploads both files to a folder in its corporate OneDrive.
• The Chamber of Spain shares access to the CSV files with Camerdata. This sharing is also protected with a password (required for download).
• The Chamber of Spain informs Camerdata by email of the availability of the information, as well as the password required for its download. Once Camerdata downloads the information, it confirms this to the Chamber of Spain.
• The Chamber of Spain deletes the folder from the corporate OneDrive. Emails exchanged with Camerdata regarding the
data transfers made from 2023 to the present."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 173/204
The request was made to provide documentation proving access to CAMERDATA during 2023 and 2024 and access to the updates for the fourth quarter of 2024.
CDE sent a document with what it calls "evidence of the information transfers made to Camerdata during 2023 and 2024," which are the emails exchanged between both entities for the management of these transfers. The procedure consists of sending an email with the download link; another email with the passwords; and an email confirming the download.
It was requested that the CDE provide "the full content accessed by CAMERDATA in 2023 regarding the same 500 self-employed entrepreneurs whose records were provided to this Agency on December 21, 2023, under the name "Document_4.xlsx."
CDE responded by providing document Annex IX (File ***FILE.1) which contains the first 500 records corresponding to self-employed entrepreneurs in the sample provided by CDE. It added that "since these are self-employed entrepreneurs, the first 9 characters of each record do not correspond to the NIF (Tax Identification Number), but rather to a sequential number (numerical record identifier) assigned during the file generation process (...) provided in file ***FILE.2."
Upon examination of Annex IX, it was found that the first information field is a nine-digit list presented without separation next to the individual's first surname. They reproduce records 1 and 10 of the provided list:
1st record:
(…)
10th record.
(…)
CDE provides a copy of the records associated with the data of the 500 business owners
provided by CDE to this Agency on December 21, 2023, under the name
"Document_4.xlsx", from the Provided Database where the hashes of the NIFs calculated by CDE and transferred to CAMERDATA are stored. Upon examination of the
aforementioned document, it is verified that it includes, for each record, two pieces of information separated by a vertical line: the nine-digit identifier and the alphanumeric data (thirty-two elements) corresponding to the hash. Records 1 and 10,
as can be seen, have the same identifier as in the file provided
as Annex IX.
However, upon examination of the Excel document provided by CDE in response At the request of the Data Inspection, in which one of the fields, "ID," was an identifier, it was found that for entrepreneurs with the same data (those listed in the first and tenth digits), the "ID" does not match the nine-digit reference that CDE now calls an identifier.
In short, when CDE provides the database to the company, it sends two files: one contains the records with the entrepreneurs' data, except for the NIF hash, and the other contains the hash. In both files, the information is
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 174/204
preceded by a numerical reference that is different for each entrepreneur, which, CDE explains, allows the NIF hash to be linked to the remaining data of the NIF holder.
However, the numerical reference that CDE calls an identifier does not match with
the registration identifier that was included for those same records in the document
provided to the Inspection (Excel table with the data CDE had for a defined range of 500 self-employed workers). The explanation offered by CDE, that the purpose of the
numeric identifier it now presents to us is to link the business owner's data
(except for the NIF) with the corresponding NIF hash, does not seem logical.
The numeric identifier in question could easily represent an additional
element ("the salt") that is included in the input information when applying the algorithm.
This would mean offering greater facilities to CAMERDATA, in addition to what is already
represented by providing the hash, to determine the corresponding NIF of the self-employed workers.
CDE has denied having violated Article 5.1.f) of the GDPR and argues that it has
processed the NIF of self-employed workers, guaranteeing adequate security, both with respect to the query made through its website - where, as
it acknowledges in In its allegations regarding the initial agreement, the NIF is not included - as with regard to the transfer of data to CAMERDATA (which it refers to with this expression: "Transferred Public Business Census (Basic Business Census)").
Article 5.2 of the GDPR, the principle of proactive accountability, imposes on the data controller the obligation to comply with and be able to prove compliance with the data protection principles, which is why the principle of confidentiality is of interest here.
CDE, as the data controller of the data obtained from the tax authorities for the purposes set forth in Law 4/2014, is obliged to guarantee their confidentiality. To this end, it is obliged to adopt appropriate technical and organizational measures taking into account the nature, scope, context, and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons.
It is evident that, as Here, CDE, in connection with the illicit processing it is carrying out, is providing the hash of the NIF of self-employed entrepreneurs that it has obtained using the MD5 algorithm. It is not adopting any security measures that are appropriate, taking into account the nature, scope, context, and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, as indicated in Article 24 of the GDPR. It is well known in the field of digital security that this algorithm is easily reversible and that when the type of incoming information is known, as is the case here, even more so given the type of data we are talking about (the NIF), reversing the information is a given.
In addition to the above, as indicated, the numerical identifier that CDE includes preceding the information it provides to CAMERDATA (a file with the data except for the hash and another with the hash) could easily represent a an
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 175/204
additional element ("the salt") that is included in the input information when applying the algorithm used.
3. The liability attributed to CDE for the violation of Article 5.1.f) is attributed to willful misconduct. This is not a reckless act, but rather an intentional one. Without the hash, CAMERDATA could not have obtained the self-employed person's NIF (Tax ID Number).
CDE intentionally transfers the NIF hash to CAMERDATA and encrypts it in an algorithm that, when applied to information such as the identification number, is easily reversible. The operation of the database that CDE transfers to CAMERDATA is subject to having the NIF hash (the transfer agreement clearly states in clause 1.1 that the NIF identifier Each record is the NIF. Furthermore, the purpose of CAMERDATA is to provide "additional" information beyond that provided by the public census. We cite the announcement that appears every time a query is made to the public census accessible from the CDE website. Below the result with the information obtained, a legend appears that says "more" information and a link to the CAMERDATA website.
Considering the foregoing—in any case, with the aforementioned exclusion of the self-employed persons' NIF (Tax ID Number) provided to CDE by the Tax Administration of the Autonomous Community of Navarre—it is proven that CDE, in the course of the unlawful transfer of a database to CAMERDATA, breached its obligation to guarantee the confidentiality of the self-employed persons' NIF (Tax ID Number).
XII
Classification and limitation period for breaches of the confidentiality principle,
Article 5.1.f) GDPR
The breach of the confidentiality principle, provided for in Article 5.1.f) of the GDPR,
for which CDE is held responsible in this resolution, is classified
in Article 83.5.a) of the GDPR, which establishes:
“5. Violations of the following provisions shall be punishable, in accordance with
paragraph 2, with administrative fines of up to EUR 20,000,000 or, in the case of a company, an amount equivalent to a maximum of 4% of the total global annual turnover of the preceding financial year, whichever is higher:
a) the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9; [...]”
To the For the sole purpose of determining the statute of limitations for a breach of the confidentiality principle set forth in Article 5.1.f) of the GDPR, the LOPDGDD classifies it as very serious and provides:
“1. Pursuant to the provisions of Article 83.5 of Regulation (EU) 2016/679, breaches that entail
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 176/204
a substantial violation of the articles mentioned therein and, in particular, the
following are considered very serious and will be subject to a three-year statute of limitations:
[…]
i) Breach of the duty of confidentiality established in Article 5 of this Organic Law.”
XIII
Breach of the principle of fair processing (Article 5.1.a GDPR)
Article 5 of the GDPR, under the heading "Principles relating to Processing", provides in
paragraph 1 a): "1. Personal data shall be: a) processed lawfully, fairly, and transparently with regard to the data subject ("lawfulness, fairness, and transparency")."
In this resolution, CDE is held liable for a breach of the principle of fair processing
with regard to data subjects regarding the transfer of their personal data to CAMERDATA. These data were lawfully received from tax authorities
for the performance of the functions entrusted to it by Law 4/2014.
Recitals 39 and 60 of the GDPR determine the following:
(39) All processing of personal data must be lawful and fair. For natural persons, it must be absolutely clear that personal data concerning them are being collected, used, accessed, or otherwise processed, as well as the extent to which such data are or will be processed. [...]
(60) The principles of fair and transparent processing require that the data subject be informed of the existence of the processing operation and its purposes. The controller must provide the data subject with all necessary additional information to ensure fair and transparent processing, taking into account the specific circumstances and context in which the personal data are processed.
It follows from the wording of the recitals transcribed that the principle of fair processing requires that data subjects be clearly aware—and therefore, with information that is neither misleading nor incomplete—that their data are being collected, used, accessed, or otherwise processed. The principle implies fair and honest conduct by the data controller in informing the data subject of any processing that concerns them that deviates from the one they have been informed of.
EDPB Guidelines 4/2019, relating to Article 25 of the GDPR, Data Protection by Design and by Default, adopted on 20/10/2020, state regarding the principle of fairness:
“69. Fairness is a general principle requiring that personal data shall not be processed
in a manner that is unjustifiably harmful, unlawfully discriminatory, unexpected, or
deceptive for the data subject.”
They also indicate that it is a manifestation of loyalty in the processing that “Interested parties must have the maximum possible degree of autonomy to determine the use made of their personal data, as well as the scope and conditions of such use or processing […] The processing must correspond to the reasonable expectations of the interested parties […] The data controller shall not abuse the needs or vulnerabilities of the interested parties. […] The controller must not “force” the choice of its users in an unfair manner […] Data controllers must not transfer the risks of the company to the interested parties. […] Information and options for the processing of personal data must be provided in an objective and neutral manner, avoiding any type of misleading or manipulative language or design […] The controller must assess the overall effects that the processing has on the rights and dignity of the data subjects. people. […] The
controller must make available to the data subject information regarding the manner in which
the personal data is processed, must act as it has stated it will, and must not mislead the data subject.”
The processing carried out by CDE—materialized in the transmission to CAMERDATA of self-employed workers' data obtained from tax authorities to fulfill an
obligation imposed by law and certain public functions—begins from the moment CDE anticipates that it will carry out this data transfer, which violates the
application of the information received for the intended purpose of processing.
CDE is aware of the origin and nature of the data it processes, and of the confidentiality obligation
that exists in relation to such data on the part of the tax authorities.
Despite this, it uses the information obtained for processing purposes that the data subjects are unaware of, which will deprive them of the possibility of knowing how their data came into the possession of the sales representatives who process it. The principle of loyalty required the CDE to refrain from processing the data, consult the tax authorities about its purpose, and inform them of any subsequent processing of the data for purposes incompatible with those for which it received it. This is because these authorities collect data from taxpayers, which the taxpayers provide with the confidence that the CDE will guarantee its confidentiality. It is clear that no communication has been made in this regard, given that the terms of the agreement signed with the Tax Agency (AEAT) confirm that they have agreed that the tax data the CDE receives cannot be transmitted to third parties.
Nor is it recorded on the CDE's website or by any other means that the CDE has informed the self-employed of any processing of their personal data other than that for which it receives it from the tax authorities: transfer to CAMERDATA. Furthermore, when CAMERDATA—a holding company established by the Chambers of Commerce in the 1980s—decided to place an announcement on the official Chambers' website to inform self-employed workers about the processing of their data, given that it does not comply with the obligation imposed by Article 14 of the GDPR, it did not include information regarding the origin of the data; that the data is obtained from the CDE, which in turn receives it from the tax authorities for the purposes established in Law 4/2014. On the contrary, the announcement simply states that the data comes from a census compiled by a "public body," and nothing more.
Considering the circumstances surrounding the data processing analyzed, it is concluded that the CDE's transfer of self-employed workers' data to CAMERDATA constitutes, from the perspective of its data subjects, deceptive processing, especially considering the institutions involved and the trust that citizens have in them; that the transfer is made without any reasonable expectation that such processing could actually take place; that there has been a complete lack of information about the existence of this processing; and that the CDE has ignored the adverse effects that the processing may have on data subjects.
For the reasons stated above, this resolution considers that CDE has violated the
principle of fair processing in relation to data subjects as provided for in
Article 5.1.a) of the GDPR.
XIV
Classification and limitation period for the violation of the principle of loyalty, Article 5.1.a) GDPR
The violation of the principle of loyalty, established in Article 5.1.a) of the GDPR, for which CDE is held responsible, is classified in Article 83.5.a) of the GDPR, which states:
“5. Violations of the following provisions shall be punishable, in accordance with paragraph 2, with administrative fines of up to EUR 20,000,000 or, in the case of an undertaking, an amount equivalent to a maximum of 4% of the total global annual turnover of the preceding financial year, whichever is higher:
a) The basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9; [...]”
For the sole purpose of determining the limitation period for The violation of the principle of fairness established in Article 5.1.a) of the GDPR is classified as very serious by the LOPDGDD and provides:
“1. Pursuant to the provisions of Article 83.5 of Regulation (EU) 2016/679, violations that constitute a substantial violation of the articles mentioned therein, and in particular, the following, are considered very serious and will be subject to a three-year statute of limitations:
a) The processing of personal data in violation of the principles and guarantees established in Article 5 of Regulation (EU) 2016/679.
[…]”.
XV
Violation of Article 14 of the GDPR
1. In this resolution, CDE is held liable for a violation of Article 14 of the
GDPR, which establishes:
“Information to be provided when the personal data has not been obtained
from the data subject
1. When the personal data has not been obtained from the data subject, the data controller shall provide the data subject with the following information:
a) the identity and contact details of the controller and, where applicable, of his or her representative;
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 179/204
b) the contact details of the data protection officer, where applicable;
c) the purposes for which the personal data are processed, as well as the legal basis for the processing;
d) the categories of personal data involved;
(e) the recipients or categories of recipients of the personal data, where applicable;
(f) where applicable, the controller's intention to transfer personal data to a recipient in a third country or international organization and the existence or absence of an adequacy decision by the Commission, or, in the case of transfers referred to in Articles 46 or 47 or the second subparagraph of Article 49(1), reference to the appropriate or suitable safeguards and the means of obtaining a copy of them or the fact that they have been provided.
2. In addition to the information referred to in paragraph 1, the controller shall provide the data subject with the following information necessary to ensure fair and transparent processing of data in relation to the data subject:
(a) the period for which the personal data will be stored, or, where that is not possible, the criteria used to determine that period;
(b) the period for which the personal data will be stored; (b) where processing is based on Article 6(1)(f), the legitimate interests of the controller or a third party;
(c) the existence of the right to request from the controller access to, rectification, erasure, or restriction of processing of personal data concerning the data subject, and to object to processing, as well as the right to data portability;
(d) where processing is based on Article 6(1)(a) or Article
9(2)(a), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
(e) the right to lodge a complaint with a supervisory authority;
(f) the source of the personal data and, where applicable, whether they originate from publicly available sources;
(g) the right to withdraw consent; (g) the existence of automated decision-making, including profiling, as referred to in Article 22(1) and (4), and, at least in those cases, meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject.
3. The controller shall provide the information referred to in paragraphs 1 and 2:
(a) within a reasonable period after obtaining the personal data, and at the latest within one month, taking into account the specific circumstances of which the personal data are processed;
(b) where the personal data are to be used for communication with the data subject, at the latest at the time of the first communication to that data subject; or
(c) where the personal data are planned to be communicated to another recipient, at the latest at the time when the personal data are communicated for the first time.
4. Where the controller plans to further process personal data for a purpose other than that for which they were obtained, it shall, prior to such further processing, provide the data subject with information about that other purpose and any other relevant information indicated in paragraph 2.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 180/204
5. The provisions of paragraphs 1 to 4 shall not apply where and to the extent that:
a) the data subject already has the information;
(b) communication of such information proves impossible or would entail a disproportionate effort, in particular for processing for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, subject to the conditions and safeguards referred to in Article 89(1) or to the extent that the obligation referred to in paragraph 1 of this Article would render impossible or seriously impair the achievement of the objectives of such processing. In such cases, the controller shall take appropriate measures to safeguard the rights, freedoms and legitimate interests of the data subject, including by making the information public; (c) the collection or disclosure is expressly provided for by Union or Member State law to which the controller is subject and which provides for appropriate measures to safeguard the legitimate interests of the data subject; or (d) where the personal data must remain confidential on the basis of an obligation of professional secrecy governed by Union or Member State law, including an obligation of professional secrecy governed by Union or Member State law, including a statutory obligation of secrecy.
2. In the agreement initiating the procedure, CDE was charged with a violation of the principles of "loyalty and transparency" set forth in Article 5.1.a) of the GDPR, a violation classified in Article 83.5.a) of the GDPR.
During the resolution proposal process, the investigating body agreed to change the legal classification of the aforementioned violation and charge CDE with two separate violations: one violation for breaching the principle of loyalty (Article 5.1.a) and a second for breaching the obligation imposed by Article 14 of the GDPR.
In its allegations to the initiation agreement, CDE stated, regarding the violation of the principles of loyalty and transparency (Article 5.1.a, GDPR), that it was charged with a triple violation of the principle of transparency, in particular the following:
(i) Failure to notify the tax authorities of the transfer made to Camerdata;
(ii) Failure to inform the data subjects whose personal data have been transferred of the fact of the transfer;
(iii) “As a contracting party with Camerdata,” failure to “ensure that the data subjects are provided with truthful information about the origin of the data.”
In its defense, it alleged, with respect to point (i), “failing to inform the tax authorities of the subsequent processing,” that “the transfer to CAMERDATA is part of the processing that CDE carries out for the purpose of publicizing the Public Business Census, without any further processing for a purpose other than the original and, therefore, is inherent to the provisions of Law 4/2014 and the second clause of the Agreement between the State Agency for Tax Administration and CDE for the exercise of the latter's public-administrative functions, […] The transfer of the Public Business Census to Camerdata is Integrated
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 181/204
within the purpose of making public the information contained in the aforementioned
Public Business Registry, a purpose expressly contemplated in the Agreement."
That the manner in which the Public Business Registry must be made public is not limited by the Convention or the Law. CDE is entrusted with the public-legal function of establishing it.
Regarding section (ii), “having deprived individual entrepreneurs of information about the transfer of their data to third parties and the purposes for which it is communicated,” the Court rejected this assertion for three reasons:
- The exception in Article 14.5.a) of the GDPR: “First, the publication of the Public Business Registry is provided for in Law 4/2014, so it is a processing procedure known to the data subjects and falls within the exception
contemplated in Article 14.5.a) of the GDPR, which provides that “[t]he provisions of paragraphs 1 to 4 shall not apply when and to the extent that the data subject already has the information” (emphasis added).”
-The exception in Article 14.5.b) GDPR: “Notifying each and every Spanish individual entrepreneur of the transfer would be disproportionate (Article 14.5.b GDPR), taking into account that the hash is not transferred but rather the NIF, that the hash is part of the Public Business Registry, and that the rest of the data is accessible on the Internet. There are 1,459,498 individual entrepreneurs. The GDPR explains in its Recital 62 that “it is not necessary to impose an obligation to provide information when the data subject already has the information, when registration or communication of personal data is expressly required by law, or when providing the information to the data subject is impossible or requires a disproportionate effort” (emphasis added).”
-Exception to Article 14.5.c) GDPR: Third, "given that the mandate to make the Public Business Register public is established by law, Article 14.5.c) GDPR also applies, since it is the law that mandates the publication of the Public Business Register."
Regarding point (iii), that "CDE, as a contracting party with CAMERDATA, has not ensured that data subjects are provided with truthful information
about the origin of the data," it argued that:
-This information is not provided for in Article 14 of the GDPR and, even if it were, it would only be required of the data controller who receives the data from another data controller, CDE being the ultimate data controller in this case.
-That the AEPD introduces an "additional guarantee" here that is not provided for in the GDPR; In the present case, this would already be covered by the provision that "The Parties undertake to observe and comply, strictly and at all times, with each other's rights and obligations regarding access, processing, and transfer of data" (Clause 12.1 of the data transfer agreement). This again means that the transferee is required to provide information about the origin of the data when complying with Article 14 of the GDPR, without the need for the transferor to impose an obligation that is provided for in the applicable data protection legislation and is included in the terms of the agreement under the terms already indicated."
In summary, CDE's arguments invoked in the allegations to the initiation agreement revolve around the purported purpose and the alleged legal obligation to publicize the public census and the consequences that arise from this approach: that the processing is known to all (exception of Article 14.5.a) or that the communication has been made in compliance with a legal obligation (exception of Article 14.5.c). It also mentions that the communication of such information involves a disproportionate effort (Article 14.5.b).
In its arguments to the proposed resolution, it rejects the existence of any violation of Article 14 of the GDPR. It invokes the disproportionate effort that would be required to inform and states that, although the Agency points out that CDE has not proven that it has carried out and documented an evaluation of the effort involved in informing the interested parties, the The effort is clearly disproportionate, with the number of affected individuals highlighted by the AEPD itself in its Resolution Proposal (almost one and a half million).
It states that "CDE cannot be held responsible for committing this violation when Law 4/2014 requires it to compile the public business register, which is what it has done. Furthermore, CDE has not transferred the NIFs of individuals to Camerdata, S.A., so it was not appropriate to report processing that is not being carried out."
The proposed resolution responded to CDE's allegations regarding the initiation agreement, in which it argued that there was no infringement with the following arguments:
- Regarding its claim that the exception set forth in Article 14.5.a) of the GDPR be applied to the obligation to inform established in Article 14 of the GDPR (the data subject already has the information), this would require, in order to be successful, that CDE had proven this, which it evidently has not done.
- Regarding the exception set forth in Article 14.5.b) of the GDPR, the criteria established by the Guidelines on transparency under Regulation 679/2016, of the Article 29 Working Party, revised and approved on April 11, 2018, were cited. Regarding the exception to the obligation to inform contemplated in Article 14.5.b) of the GDPR, the following are stated: (Section 64) the following:
“Given the emphasis in Recital 62 and Article 14.5(b) on archiving, research, and statistical purposes regarding the application of this exemption, the position of the WP29 is that this exception should not be routinely used by controllers that do not process personal data for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes. The WP29 emphasizes that, where these are the purposes pursued, the conditions set out in Article 89.1 must continue to be met, and the provision of the information must constitute a disproportionate effort.”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 183/204
Furthermore, it should be noted that, as Section 64 specifies, “When a data controller seeks to apply the exception in Article 14.5 (b) on the basis that providing the information would entail a disproportionate effort, it should carry out a balancing exercise to assess the effort that providing the information to the data subject would entail against the impact and effects on the data subject if the information were not provided. This assessment must be documented by the controller in accordance with its accountability obligations.”
In this regard, it was stated that CDE had not accredited to this Agency that it had
conducted and documented an assessment of the effort it entails
informing interested parties regarding the impact and effects that result
for individual entrepreneurs of not being informed of the processing of their data for purposes other than and incompatible with those for which it
receives it from the tax authorities. And, above all, and in the event of admitting the
disproportionate effort to inform all interested parties, it would have been
essential to accredit that it had adopted appropriate measures to protect
the rights, freedoms, and legitimate interests of self-employed workers, in particular that it had
made available to them the information it is required to provide in accordance with Article 14, paragraphs 1 and 2 of the GDPR.
Regarding the argument that "given that the mandate to make public the Public Business Registry is established by law, it is also Article 14.5.c) of the GDPR applies, since it is the Law that mandates the publication of the Public Business Registry.” It was stated that the processing that CDE
carries out of the data of self-employed entrepreneurs, which consists of the transfer of their data to CAMERDATA, does not take place in compliance with a legal obligation or in the
exercise of public-administrative functions. Therefore, this
exception to the obligation to inform provided for in Article 14 of the GDPR could not apply. Furthermore, the CDE has not adopted any measures—at least not of which it has informed us—to protect the legitimate interests of the data subjects.
This resolution reiterates that the alleged obligation to "publicize," which CDE has been invoking in the course of the procedure, as an additional action to
the preparation and management of the public census, is nonexistent. Publicity is provided by the public registry that the Law requires to be prepared. We insist that the transfer that
CDE makes of a database of self-employed entrepreneurs (a private file) does not, in this case, represent the exercise of No public administrative function. Nor does it constitute compliance with a supposed legal obligation to "publicize" the public census. Such an obligation does not exist. Publicity is provided by the public registry that the law mandates to be compiled. The public nature of the registry is an essential aspect of the ultimate purpose of the registry function, which is to ensure legal certainty.
Regarding the circumstance in Article 14.5.b) as an exception to the obligation to inform (the disproportionate effort of communication), the Transparency Guidelines state that a balancing exercise should be carried out to assess the effort that providing the information to the data subject would entail in relation to the impact and effects on the data subject if the information were not provided. In its statement of allegations to the proposed CDE, it directly concludes that no evaluation is needed and that the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 184/204
The disproportion is obvious given that more than one and a half million self-employed workers are affected. It makes no mention at all of the impact and effects that the processing it has carried out has on the data subjects.
The relevant information that CDE should have provided is regarding the origin or provenance of the data: that it was obtained using the authorization granted by Law 4/2014 for the performance of the public administrative functions entrusted to it.
It is established in this procedure that CDE has not fulfilled its obligation to inform self-employed entrepreneurs of the processing carried out. Nor do any of the exceptions provided for in Article 14.5 of the GDPR that would exempt it from this obligation apply.
Based on the foregoing, a violation of Article 14 of the GDPR has been established for which CDE is responsible.
XVI
Classification and limitation period for the violation of Article 14 14
GDPR
The violation of Article 14 of the GDPR for which CDE is held responsible in this resolution is defined in Article 83.5.b) of the GDPR, which establishes:
“5. Violations of the following provisions shall be punishable, in accordance with
paragraph 2, by administrative fines of up to EUR 20,000,000 or, in the case of a company, by an amount equivalent to a maximum of 4% of the total global annual turnover of the preceding financial year, whichever is greater:
a) […]
b) the rights of data subjects pursuant to Articles 12 to 22.”
For the sole purpose of determining the statute of limitations for the violation, the LOPDGDD classifies it as very serious and provides:
“1. Pursuant to Article 83.5 of Regulation (EU) 2016/679,
infractions that constitute a substantial violation of the articles mentioned therein, and in particular, the
following, are considered very serious and will be subject to a three-year statute of limitations:
[…]
h) Failure to inform the data subject about the processing of their personal data
in accordance with the provisions of Articles 13 and 14 of Regulation (EU) 2016/679 and 12 of this Organic Law."
XVII
Sanctions
1. The corrective powers conferred on the AEPD as the supervisory authority are listed in Article 58.2 of the GDPR, sections a) to j). The provision mentions, among them, section i), the power to impose an administrative fine in accordance with Article 83 of the GDPR.
In Section II of this resolution, it is indicated that Article 77 of the LOPDGDD is not applicable to CDE, in relation to the GDPR violations alleged against it. Article 77.1 of the LOPDGDD lists the subjects to whom the regime described in Article 77.2 of the LOPDGDD applies, which prevents the imposition of the corrective measure of Article 58.2.i (administrative fine) when they are found responsible for the violations provided for in Articles 72 to 74. Article 77.1 of the LOPDGGD
mentioned in letter g) "Public law corporations may be applied when the purposes of the processing are related to the exercise of public law powers."
As explained in Section II, Section 2.2, to which we refer, the provision of Article 77.2 of the LOPDGDD is not applicable even though CDE is a public law corporation, because the data processing carried out by CDE, which constitutes the subject of this procedure, was not carried out in the exercise of the public administrative functions that the Basic Law attributes to it in relation to the public business census, nor in the exercise of any other public administrative function. The transfer to CAMERDATA does not meet the conditions that constitute the factual situation described in letter g) of Article 77.1 of the LOPDGDD.
It is agreed that CDE will be imposed administrative fines (Article 58.2.i) for violations of Articles 6.1, 5.1.b), 5.1.f),
(5.1.a), and 14 of the GDPR, without prejudice to the corrective measures also agreed to be imposed in this resolution.
2. Article 83 of the GDPR, "General conditions for the imposition of administrative fines," states in paragraph 1 that the supervisory authority shall ensure that the imposition of fines for violations of this Regulation indicated in paragraphs 4, 5, and 6 comply in each individual case with the principles of effectiveness,
proportionality, and deterrence.
The principle of proportionality requires that there be a correlation between the violation and the penalty, with the prohibition of unnecessary or excessive measures, so that the penalty is appropriate to achieve the purposes that justify it. To ensure that the penalty is appropriate for the violation committed, Article 83.2 of the GDPR establishes a list of criteria that help determine the penalty. The provision establishes:
"Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or as a substitute for the measures contemplated in Article 58, paragraph 2, letters a) to h) and j). When deciding whether to impose an administrative fine and its amount in each individual case, due account shall be taken of:
a) the nature, severity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage suffered;
b) the intentionality or negligence in the infringement;
c) any measures taken by the controller or processor to mitigate the damage suffered by the data subjects;
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 186/204
d) the degree of responsibility of the controller or processor processor, taking into account the technical or organizational measures they have implemented pursuant to Articles 25 and 32;
e) any previous breaches committed by the controller or processor;
f) the degree of cooperation with the supervisory authority in order to remedy the breach and mitigate the potential adverse effects of the breach;
g) the categories of personal data affected by the breach;
h) how the supervisory authority became aware of the breach, in particular whether the controller or processor notified the breach and, if so, to what extent;
i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned in relation to the same matter, compliance with those measures;
j) adherence to codes of conduct pursuant to Article 40 or certification mechanisms approved pursuant to Article 42; and
k) any other applicable aggravating or mitigating factors to the circumstances of the case,
such as the financial benefits obtained or losses avoided, directly or indirectly, through the infringement."
The LOPDGDD, Article 76, "Sanctions and Corrective Measures," provides in relation to
Article 83.2.k) that the following may be taken into account:
"a) The ongoing nature of the violation.
b) The connection between the offender's activity and the processing of personal data.
c) The benefits obtained as a result of committing the violation.
d) The possibility that the affected party's conduct could have led to the commission of the violation.
e) The existence of a merger by absorption process subsequent to the commission of the violation, which cannot be attributed to the acquiring entity.
f) The impact on the rights of minors.
g) The availability, when not mandatory, of a data protection officer.
h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms, in cases where there are disputes between them and any interested party."
Furthermore, Article 83.5 of the GDPR provides that the maximum amount of the penalty
imposed will be the greater of the following two amounts: €20,000,000 or,
in the case of a company, an "amount equivalent to a maximum of 4% of the total annual global turnover of the previous financial year."
In this regard, as stated in the Third Facts of this
resolution, CDE's turnover during the 2021 and 2022 financial years was €6,136,662 and €6,308,255, respectively.
3. It should be noted that, in the present case, in relation to the data processing operation carried out by CDE that is the subject of assessment in this
proceeding, Article 83.3 of the GDPR is applicable, which provides:
“If a controller or processor intentionally or negligently fails to comply, for the same or related processing operations,
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 187/204
with various provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount provided for the most serious violations.”
3. Concurrent offenses.
CDE alleges that several of the violations alleged in this proceeding are interrelated in medial competition, regulated in Article 29.5 of the LPACAP, and maintains the following in support of this argument:
"Such is the case at hand: a transfer without a legitimate basis (because the existing legitimate basis does not cover—in the Agency's opinion—the purpose of the processing pursued by the transfer) necessarily entails a new purpose of processing different from that of the transferor, and necessarily entails a violation of the principle of confidentiality (how can a transfer of confidential information be made contrary to the law without violating the principle of confidentiality?), and also a lack of loyalty (since, by definition, the interested parties do not have a reasonable expectation that an illegal transfer will occur), and of course a lack of information (the illegal transfer is not reported, because the transferor believes it does not exist—regardless of whether this violation is admissible). Because here, if there were someone required to report, it would be Camerdata, S.A. and not the Chamber of Spain—as has been said, they are two different entities that the
Investigating Judge too often confuses). There is a medial concurrence in all of this."
However, the medial concurrence of infractions requires the existence of several
conducts, each constituting different infractions, one of which is a necessary means for the commission of the others. Ultimately, it requires a plurality of actions, a plurality of protected legal rights, and a necessary relationship
between one infraction and another, or a "necessary derivation of some infractions with respect
to the others and vice versa." In the words of the Supreme Court (Supreme Court of 02/08/1999, Rec 9/1996), when referring to this last element, "the application of medial concurrence requires a necessary derivation of some infractions from the others and vice versa, so it is essential that some cannot be committed without the execution of the others."
In the factual situation presented here, although there is a plurality of protected legal assets, there is no plurality of actions. Therefore, there is no medial concurrence between the infractions attributed to CDE.
CDE also alleges the existence of a triple identity of subject, fact, and protected legal asset among all the infractions attributed to it in this proceeding.
It defends the alleged triple identity (infringing party, fact, and grounds) with
these arguments:
“There are several names applied to the same reality: if there is a transfer without a legitimate basis because it is carried out, according to the proposed resolution, for a purpose other than the legal and administrative purposes attributed to the Spanish Chamber of Commerce, and for that reason, data has been improperly transferred (i.e., it should have been kept confidential instead of being transferred), and all of this is considered unfair because the interested party was not informed (because the Spanish Chamber of Commerce believed there was a legitimate basis for the transfer that
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 188/204
made the information to the interested party unnecessary), and therefore contrary to the duty to inform the interested party, all of this would be (if it were) one and the same violation: transferring personal data (particularly NIFs) without a legitimate basis. Because
if the legitimate basis invoked for this processing, consisting of the
transfer (Articles 6.1.c) and 6.1.e)) existed, neither the duty to respect the purpose of the processing would have been breached, nor any duty of confidentiality would have been violated, nor would the conduct
be disloyal, nor would the interested parties need to be informed." (Emphasis added)
It therefore considers that the principle of ne bis in idem is applicable and that it would be appropriate
to impose a single sanction, which it considers should be for the violation of Article
6.1 of the GDPR, since, it says, it is "the most serious of the five violations alleged and because
it considers that the accusation of the other four is included in that of the first."
It cites the European Data Protection Board (EDPB) Guidelines 04/2022,
on the calculation of fines under the GDPR, adopted on May 24, 2023, of which it reproduces sections 30 and 31: “3.1.1. Concurrent infringements
The principle of concurrent infringements (also called "apparent concurrent" or "false concurrent") applies whenever the application of one provision prevents or overrides the applicability of the other. In other words, the concurrent infringement already occurs at the abstract level of the legal provisions. This could be based on the principles of speciality, subsidiarity, or consumption, which are usually applied when the provisions protect the same legal interest. In such cases, it would be unlawful to sanction the offender twice for the same infringement. In the case of concurrent infringements, the amount of the fine should be calculated solely on the basis of the selected violation in accordance with the previous rules (prevailing violation).”
It adds that “Failure to apply the aforementioned principle would also entail a violation of the
principle of proportionality in the imposition of administrative sanctions.”
The apparent overlap of rules or improper overlap exists when a factual situation is subsumed, at the same time, by several provisions that protect the same legal interest. It is resolved by the principle of non bis in idem. Therefore, the principle of proportionality does not apply here, as claimed to the contrary, because the question raised by this hypothesis is which rule applies and not the determination of the sanction and its scope.
In the case at hand, the GDPR (5) violations attributed to CDE protect different legal interests: the lawfulness of the processing (Article 6.1); the purpose
for which the data are processed, which must be specific, explicit, and legitimate (Article 5.1.b); Confidentiality (Article 5.1.f); fair processing in relation to data subjects (Article 5.1.a); and transparency (Article 14).
Sections 34 and 35 of ECDP Guidelines 4/2022 are worth mentioning:
“34. Where, on the other hand, two provisions pursue autonomous objectives,
this constitutes a differentiating factor that justifies the imposition of separate fines. For
example, if a violation of one provision automatically results in a
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 189/204
violation of the other, but the reverse is not true, these violations pursue
autonomous objectives.
35. These principles of specialization can only be applied to the extent that
the objectives pursued by the violations in question are actually congruent
in the specific case. Since the data protection principles of Article 5 of the
GDPR are established as general concepts, there may be situations in which
other provisions are a specification of that principle, but do not circumscribe it. the
principle in its entirety. In other words, a provision does not always define the
full scope of the principle. Therefore, depending on the circumstances, in
some cases they overlap congruently and one violation may replace the
other, while in other cases, the overlap is only partial and, therefore, not
fully congruent. To the extent that they are not congruent, there is no concurrent
offenses. Instead, they can be applied side by side when calculating the fine.
Well, in the present case, the same behavior has given rise to several
violations. However, these violations are not congruent, so there would be no concurrent offenses. Thus, by transferring the criterion indicated - if a
violation of one provision automatically gives rise to a violation of the other,
but the reverse is not true, these violations pursue autonomous objectives -
it follows that the objectives of the violation of Article 6.1 and 5.1.b) of the GDPR are not congruent. Neither are those of Articles 6.1 and 14 of the GDPR, nor those of Articles 6.1 and 5.1.f) or 5.1.a). Therefore, as indicated, there would be no concurrent offenses.
The alleged offenses fall within what the EDPB calls in its
Guidelines 4/2020 "ideal concurrence" (the equivalent of ideal competition), to which Article 83.3 of the GDPR applies.
The principle of unity of action (also called "ideal concurrence") applies
in cases where a conduct falls under several legal provisions,
with the difference that one provision is not excluded or subsumed by the
applicability of the other, because they do not fall within the scope of the principles
of specialization, subsidiarity, or consumerism and primarily pursue different objectives.
In these cases, the Article 83.3 of the GDPR, which provides:
“If a controller or processor intentionally or negligently fails to comply with various provisions of this Regulation for the same or related processing operations, the total amount of the administrative fine shall not exceed the amount provided for the most serious infringements.”
4. In determining the amount of the administrative fine to be imposed on CDE in relation to each of the GDPR violations for which it is responsible, the following circumstances of Article 83.2 of the GDPR are observed:
4.1. Violation of Article 6.1 of the GDPR:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 190/204
These factors of Article 83.2 of the GDPR are considered aggravating factors, which reflect a greater unlawfulness of the conduct and/or the culpability of the controller:
-Article 83.2.a): “the nature, seriousness, and duration of the violation, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage and damages
they have suffered."
The nature, scope, and purpose of the processing operation are, in this
case, factors that demonstrate the extraordinary seriousness of the processing carried out.
In this regard, the origin of the data—related to the IAE (Tax Income Tax Act)
and the company census—must be taken into consideration. According to Law 4/2014, CDE is authorized to process the data for the exclusive purpose of compiling the public company census,
the electoral census, and the public-administrative functions granted to it by law, including those related to the public census and its management (ex Article 5.1.g). CDE, for its assigned function of managing the public census, has access to information from the tax authorities and has processed the data obtained by incorporating it into a
file that it transmits to CAMERDATA in execution of a private contract. The purpose
of using information obtained while acting as a public administration for a
private purpose, such as transferring it to CAMERDATA highlights the seriousness
of the processing under review, from the perspective of its unlawfulness.
CDE transfers the data of individual entrepreneurs obtained
from the tax authorities to CAMERDATA with full knowledge that
they will be used for commercial purposes (as provided for in the contract signed by CDE) and
therefore, with knowledge of the risks to the fundamental rights and freedoms
of the data subjects that such processing could entail. CDE is aware
of the purpose of the database it transfers. Not only because of the aforementioned contractual provision,
but also because CAMERDATA's processing of the data is in line
with its corporate purpose, an aspect that CDE is aware of, as it is
a company formed by several Official Chambers, including CDE, on whose
Board of Directors it sits.
Also relevant is the extremely high number of people who have been affected
by the unlawful processing of their data, around one and a half million. Individuals
who have the status of entrepreneurs. The seriousness of the conduct is amplified if one considers the null expectations that those affected could have had that the processing that materializes the violation of Article 6.1 could actually be carried out.
The continued unlawful processing of the data of self-employed entrepreneurs is also relevant. We note that the processing is maintained for one year and, unless the entrepreneur status is terminated, it continues until the next update. This processing operation began, at the latest, with the contract signed between CDE and CAMERDATA in 2016.
After the GDPR came into force on May 25, 2018, in 2019, the Agreement was signed with the AEAT, which regulates the conditions and procedure for accessing the information provided by this tax authority.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 191/204
-Article 83.2.b): “intentionality or negligence in the violation.”
Article 28.1 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector, provides: “Only natural or legal persons […] who are responsible for them due to intent or negligence may be sanctioned for acts constituting an administrative violation.” In this regard, the Supreme Court, in its Judgment of March 18, 2005 (Recital No. 7707/2000), states that “an administrative violation could not be deemed to have been committed if the subjective element of culpability were not present, or, in other words, if the conduct typically constituting an administrative violation was not attributable to intent or negligence.”
CDE knowingly transfers the data to CAMERDATA. The data of the self-employed individuals subject to the transfer comes from the tax authorities, and CDE
accesses them in the performance of public-administrative functions assigned by its regulatory law. The contract through which the transfer is established, directly or indirectly, identifies the subject of the transfer with the "public business register." The
purpose of the processing to be carried out by the transferee, as stated in the contract, is commercial purposes.
-Article 83.2.g) GDPR: "The categories of personal data affected by the infringement."
The personal data of the sole proprietors transferred to CAMERDATA includes their NIF (Tax Identification Number), either in plain text or as a hash of the NIF.
The NIF of natural persons is sensitive data due to the risk that its processing may pose to the fundamental rights and freedoms of its owner. Although the literal wording of Article 83.2.g) of the GDPR appears to link this criterion for scaling the fine exclusively with Article 9 of the GDPR (the
special categories of personal data), the GDPR nevertheless contains references to other data classifications that respond to the purpose pursued by Article 83.2 of the GDPR: to scale the fine in accordance with the principles of proportionality and effectiveness. Thus, recitals 51 and 75 of the GDPR distinguish a group of personal data that, by their nature, are particularly "sensitive" due to the significant risk that their processing may pose to fundamental rights and freedoms, as it may cause physical, material, or immaterial harm.
This group or category includes, in addition to the specially protected data regulated by Article 9 of the GDPR, many others. Recital 75 mentions
personal data whose processing may entail a risk of varying severity and
probability for the rights and freedoms of natural persons and
refers to data whose processing "may give rise to discrimination,
identity theft or fraud, financial loss, damage to reputation,
loss of confidentiality of data subject to professional secrecy, unauthorized
reversal of pseudonymization, or any other significant economic or social harm."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 192/204
The numerical identifier of the DNI, together with the verification character corresponding
to the tax identification number, unequivocally identifies a natural person.
This quality makes it particularly sensitive data, since if
its processing is not accompanied by the necessary technical and organizational measures
to ensure that the person identified with it is truly its owner, a third party can
easily impersonate a natural person, or, in other words,
can commit identity fraud, with the risks that this entails for the
privacy, honor, and assets of the person impersonated.
No factors are found that mitigate the culpability or unlawfulness
of the conduct that violates Article 6.1 of the GDPR.
In light of the factors identified, CDE is sanctioned for violating Article
6.1 of the GDPR with an administrative fine of €100,000 (one hundred thousand euros).
4.2. Violation of Article 5.1.b) of the GDPR:
In relation to this violation, the following factors listed in Article 83.2 of the GDPR are considered aggravating factors, reflecting a greater unlawfulness of CDE's conduct and/or culpability:
Article 83.2.a): "the nature, gravity, and duration of the violation, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage suffered."
The nature, scope, and purpose of the processing operation are, in this case, factors that demonstrate the extraordinary seriousness of the processing carried out.
In this regard, the origin of the data—related to the IAE (Tax Income Tax) and company censuses—must be taken into consideration. Pursuant to Law 4/2014, the CDE is authorized to process the data for the exclusive purpose of compiling the public business census, the electoral census, and the public-administrative functions granted to it by law, including, but not limited to, the management of the public census (formerly Article 5.1.g). For its assigned function of managing the public census, CDE has access to information from the tax authorities and has processed the data obtained by incorporating it into a file that it transmits to CAMERDATA in the execution of a private contract. The purpose of using information obtained while acting as a public authority for a private purpose, such as transferring it to CAMERDATA, highlights the seriousness of the processing in question, from the perspective of its unlawfulness.
The transfer of the data of individual entrepreneurs obtained from the tax authorities to CAMERDATA is carried out by CDE with full knowledge that they will be used for commercial purposes (as provided for in the contract signed by CDE) and, therefore, with knowledge of the risks to the fundamental rights and freedoms of the data subjects that such processing could entail. CDE is aware of the purpose of the database it transfers. Not only because of the aforementioned contractual provision, but also because the processing that CAMERDATA will carry out of the data is in accordance with its corporate purpose, a fact that CDE is aware of, as it is a company formed by several Official Chambers, including CDE, on whose Board of Directors it sits.
Also relevant is the extremely high number of people affected
by the unlawful processing of their data, around 1.5 million individuals
who are entrepreneurs. The seriousness of the conduct is amplified if one considers the low expectations that those affected may have had that the processing
that constitutes a violation of Article 6.1 could actually be carried out.
The continued unlawful processing of the data of self-employed entrepreneurs
is also significant. We note that the processing is maintained for
one year and, unless the entrepreneur's status is terminated, it continues
until the next update. This processing operation began, at the latest,
with the contract signed between CDE and CAMERDATA in 2016.
After the GDPR came into force on May 25, 2018, in 2019, the Agreement was signed with the AEAT (Tax Agency), which regulates the conditions and procedure for accessing the information provided by this tax authority.
-Article 83.2.b): "intentionality or negligence in the violation."
Article 28.1 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector, provides: "Only natural or legal persons […] who are responsible for them due to intent or negligence may be sanctioned for acts constituting an administrative violation." In this regard, the Supreme Court, in its Judgment
of March 18, 2005 (Recital No. 7707/2000), states that "an administrative offense could not be deemed to have been committed if the subjective element of culpability were not present, or, in other words, if the conduct typically constituting an administrative offense was not attributable to intent or negligence."
CDE transfers the data to CAMERDATA knowing that it is unlawful. The data of the self-employed workers subject to the transfer come from the tax authorities, and CDE accesses them in the performance of public-administrative functions assigned by its regulatory law. The contract through which the transfer is established, directly or indirectly, identifies the subject matter of the transfer with the "public business census." The purpose of the processing to be carried out by the transferee, as stated in the contract, is commercial purposes.
-Article 83.2.g) GDPR: "The categories of personal data affected by the breach."
The personal data of individual entrepreneurs transferred to CAMERDATA includes their tax identification number (TIN), either in plain text or as a hash.
The tax identification number of individuals is sensitive data due to the risk that its processing may pose to the fundamental rights and freedoms of its owner. Although the
literal wording of Article 83.2.g) of the GDPR appears to link this criterion for scaling the fine exclusively with Article 9 of the GDPR (the
special categories of personal data), the GDPR nevertheless contains references
to other data classifications that reflect the purpose pursued by
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 194/204
Article 83.2 of the GDPR, to scale the fine in accordance with the principles
of proportionality and effectiveness. Thus, recitals 51 and 75 of the GDPR distinguish
a group of personal data that, by their nature, are particularly "sensitive"
due to the significant risk that their processing may entail for fundamental rights and
freedoms, as it may cause physical, material, or immaterial harm.
In addition to the specially protected data regulated by Article 9 of the GDPR, this group or category includes many other data. Recital 75 mentions
personal data whose processing may entail a risk of varying severity and
probability for the rights and freedoms of natural persons and
refers to data whose processing "may give rise to discrimination,
identity theft or fraud, financial loss, damage to reputation,
loss of confidentiality of data subject to professional secrecy, unauthorized
reversal of pseudonymization, or any other significant economic or social harm."
The numerical identifier of the DNI, together with the verification character corresponding
to the tax identification number, unequivocally identifies a natural person.
This quality makes it particularly sensitive data, since if
its processing is not accompanied by the necessary technical and organizational measures
to ensure that the person identified with it is truly its owner, a third party can
easily impersonate a natural person, or, in other words,
can commit identity fraud, with the risks that this entails for the
privacy, honor, and assets of the person impersonated.
No factors are found that mitigate the culpability or unlawfulness
of the conduct that violates Article 5.1.b) of the GDPR.
In light of the factors identified, it is agreed to sanction CDE for violating
Article 5.1.b) of the GDPR with an administrative fine of €100,000 (one hundred thousand euros).
4.3. Violation of Article 5.1.f) of the GDPR:
In relation to this violation, the following factors listed in Article 83.2 of the GDPR are considered aggravating factors, reflecting a greater unlawfulness of CDE's conduct and/or culpability:
Article 83.2.a): "the nature, gravity, and duration of the violation, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage suffered."
The nature, scope, and purpose of the processing operation are, in this case, factors that demonstrate the extraordinary seriousness of the processing carried out.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 195/204
In this regard, the origin of the data—related to the IAE (Tax Income Tax) and company censuses—must be taken into consideration. Pursuant to Law 4/2014, the CDE is authorized to process the data for the exclusive purpose of compiling the public company census,
the electoral census, and the public-administrative functions granted to it by law, including those related to the public census and its management (ex Article 5.1.g). For its assigned function of managing the public census, CDE has access to information from the tax authorities and has processed the data obtained, incorporating it into a file that it transmits to CAMERDATA in execution of a private contract. The purpose
of using information obtained while acting as a public authority for a
private purpose, such as transferring it to CAMERDATA, highlights the seriousness
of the processing under consideration, from the perspective of its unlawfulness.
CDE transfers the data of individual entrepreneurs obtained
from tax authorities to CAMERDATA with full knowledge that
they will be used for commercial purposes (as provided for in the contract signed by CDE) and,
therefore, with knowledge of the risks to the fundamental rights and freedoms
of the data subjects that such processing could entail. CDE is aware
of the purpose of the database it transfers. Not only because of the aforementioned contractual provision,
but also because CAMERDATA's processing of the data is in line
with its corporate purpose, an aspect that CDE is aware of, as it is
a company formed by several Official Chambers, including CDE, on whose
Board of Directors it sits.
Also relevant is the extremely high number of individuals affected
by the unlawful processing of their data, around one and a half million individuals
who are business owners. The seriousness of the conduct is amplified if one considers the low expectations that those affected may have had that the processing
that constitutes a violation of Article 6.1 could actually be carried out.
The continued unlawful processing of data of self-employed business owners
is also significant. We note that the processing continues for
one year and, unless the status of business owner is terminated, it continues
until the next update. This processing operation began, at the latest, with the contract signed between CDE and CAMERDATA in 2016.
After the GDPR came into force on May 25, 2018, in 2019, the Agreement was signed with the AEAT (Tax Agency), which regulates the conditions and procedure for accessing the information provided by this tax authority.
Article 83.2.b): "intentionality or negligence in the violation."
Article 28.1 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector,
stipulates: "Only natural or legal persons […] who are responsible for such acts due to intent or negligence may be sanctioned for acts constituting an administrative violation." In this regard, the Supreme Court, in its ruling
of March 18, 2005 (Rec. 7707/2000), states that "an administrative offense could not be deemed to have been committed if the subjective element of culpability were not present, or, in other words, if the conduct typically constituting an administrative offense was not attributable to intent or negligence."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 196/204
CDE transfers the data to CAMERDATA, knowing that it is unlawful. The data of the self-employed workers subject to the transfer come from the tax authorities, and CDE accesses them in the performance of public-administrative functions assigned by its regulatory law. The contract through which the transfer is established, directly or indirectly, identifies the purpose of the transfer with the "public business register." The purpose of the processing to be carried out by the transferee, as stated in the contract, is commercial purposes.
Article 83.2.g) GDPR: "The categories of personal data affected by the infringement."
The personal data of individual entrepreneurs that are transferred to CAMERDATA includes their tax identification number (TIN), either in plain text or as a hash of the TIN.
The TIN of natural persons is sensitive data due to the risk that its processing may pose to the fundamental rights and freedoms of its owner. Although the literal wording of Article 83.2.g) of the GDPR appears to link this criterion for scaling the fine exclusively with Article 9 of the GDPR (the special categories of personal data), the GDPR nevertheless contains references to other data classifications that reflect the purpose of Article 83.2 of the GDPR: to scale the fine in accordance with the principles of proportionality and effectiveness. Thus, recitals 51 and 75 of the GDPR distinguish a group of personal data that, by their nature, are particularly "sensitive" due to the significant risk that their processing may entail for fundamental rights and freedoms, as it may cause physical, material, or immaterial harm.
This group or category includes, in addition to the specially protected data regulated by Article 9 of the GDPR, many others. Recital 75 mentions personal data whose processing may entail a risk of varying severity and
probability for the rights and freedoms of natural persons and refers to data whose processing "may give rise to discrimination,
identity theft or fraud, financial loss, damage to reputation,
loss of confidentiality of data subject to professional secrecy, unauthorized reversal of pseudonymization, or any other significant economic or social harm."
The numerical identifier of the national identity document, together with the verification character corresponding
to the tax identification number, unequivocally identifies a natural person.
This quality makes it particularly sensitive data, since if
its processing is not accompanied by the necessary technical and organizational measures
to ensure that the person identified with it is truly its owner, a third party can
easily impersonate a natural person, or, in other words,
can commit identity fraud, with the resulting risks to the
privacy, honor, and assets of the person impersonated.
There are no factors that mitigate the culpability or unlawfulness of the conduct that violates Article 5.1.f) of the GDPR.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 197/204
In light of the factors assessed, it is agreed to sanction CDE for the violation of
Article 5.1.f) of the GDPR with an administrative fine of €100,000 (one hundred thousand euros).
4.4. Violation of Article 5.1.a) of the GDPR:
These factors in Article 83.2 of the GDPR are considered aggravating factors, reflecting
a greater unlawfulness of the conduct and/or the culpability of the respondent:
-Article 83.2.a): "the nature, severity, and duration of the violation, taking into account
the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damages and losses suffered."
The nature, scope, and purpose of the processing operation are, in this case, factors that demonstrate the extraordinary seriousness of the processing carried out.
In this regard, the origin of the data—related to the IAE (Tax Income Tax)
and the company census—must be taken into consideration. Pursuant to Law 4/2014, the CDE is authorized to process the data for the exclusive purpose of compiling the public company census, the electoral census, and the public-administrative functions granted to it by law, including those related to the public census and its management (ex Article 5.1.g). For the purpose of managing the public census, CDE has access to information from the tax authorities and has processed the data obtained by incorporating it into a file that it transmits to CAMERDATA in execution of a private contract. The purpose
of using information obtained while acting as a public authority for a
private purpose, such as transferring it to CAMERDATA, highlights the seriousness
of the processing under consideration, from the perspective of its unlawfulness.
CDE transfers the data of individual entrepreneurs obtained
from tax authorities to CAMERDATA with full knowledge that they will be used for commercial purposes (as provided for in the contract signed by CDE) and,
therefore, with knowledge of the risks to the fundamental rights and freedoms of the data subjects that such processing could entail. CDE is aware
of the purpose of the database it transfers. Not only because of the aforementioned contractual provision,
but also because CAMERDATA's processing of the data is in line
with its corporate purpose, an aspect that CDE is aware of, as it is
a company formed by several Official Chambers, including CDE, on whose
Board of Directors it sits.
Also relevant is the extremely high number of people affected
by the unlawful processing of their data, around one and a half million individuals
who are entrepreneurs. The seriousness of the conduct is amplified if one considers the low expectations that those affected may have had that the processing
that materializes the violation of Article 6.1 could actually be carried out.
The continued unlawful processing of the data of self-employed entrepreneurs
is also significant. We note that the processing continues for
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 198/204
one year and, if the entrepreneur status is not terminated, it continues
until the next update. This processing operation began, at the latest, with the contract signed between CDE and CAMERDATA in 2016.
After the GDPR came into force on May 25, 2018, in 2019, the Agreement was signed with the AEAT (Tax Agency), which regulates the conditions and procedure for accessing the information provided by this tax authority.
Article 83.2.b): "intentionality or negligence in the violation."
Article 28.1 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector, provides: "Only natural or legal persons […] who are responsible for them due to intent or negligence may be sanctioned for acts constituting an administrative violation." In this regard, the Supreme Court, in its Ruling
of March 18, 2005 (Recital No. 7707/2000), states that "an administrative offense could not be deemed to have been committed if the subjective element of culpability were not present, or, in other words, if the conduct typically constituting an administrative offense was not attributable to intent or negligence."
CDE transfers the data to CAMERDATA knowing that it is unlawful. The data of the self-employed workers subject to the transfer come from the tax authorities, and CDE
accesses them in the performance of public-administrative functions assigned by its regulatory law. The contract through which the transfer is established, directly or indirectly, identifies the subject matter of the transfer with the "public business census." The
purpose of the processing to be carried out by the transferee, as stated in the contract, is for commercial purposes.
-Article 83.2.g) GDPR: "The categories of personal data affected by the infringement."
The personal data of individual entrepreneurs that are subject to transfer to CAMERDATA include their tax identification number (TIN), whether in plain text or as a hash.
The TIN of individuals is sensitive data due to the risk that its processing may pose to the fundamental rights and freedoms of its owner. Although the literal wording of Article 83.2.g) of the GDPR appears to link this criterion for scaling the fine exclusively with Article 9 of the GDPR (the special categories of personal data), the GDPR nevertheless contains references to other data classifications that serve the purpose of Article 83.2 of the GDPR: to scale the fine in accordance with the principles of proportionality and effectiveness. Thus, Recitals 51 and 75 of the GDPR distinguish
a group of personal data that, by their nature, are particularly "sensitive"
due to the significant risk that their processing may entail for fundamental rights and
freedoms, as it may cause physical, material, or immaterial harm.
This group or category includes, in addition to the specially protected data
regulated by Article 9 of the GDPR, many others. Recital 75 mentions the
personal data whose processing may entail a risk of varying severity and
probability for the rights and freedoms of natural persons and
refers to those whose processing "may give rise to discrimination,
identity theft or fraud, financial loss, damage to reputation,
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 199/204
loss of confidentiality of data subject to professional secrecy, unauthorized reversal of pseudonymization, or any other significant economic or social harm."
The numerical identifier of the DNI, together with the verification character corresponding
to the tax identification number, unequivocally identifies a natural person.
This quality makes it particularly sensitive data, since if
its processing is not accompanied by the necessary technical and organizational measures
to ensure that the person identified with it is truly its owner, a third party can
easily impersonate a natural person, or, in other words,
can commit identity fraud, with the risks that this entails for the
privacy, honor, and assets of the person impersonated.
No factors are found that mitigate the culpability or unlawfulness
of the conduct that violates Article 5.1.a) of the GDPR.
In light of the factors identified, it is agreed to sanction CDE for violating
Article 5.1.a) of the GDPR with an administrative fine of €100,000 (one hundred thousand euros).
4.5. Violation of Article 14 of the GDPR:
These factors from Article 83.2 of the GDPR, which reflect a greater unlawfulness of the conduct and/or culpability of the respondent, are considered aggravating factors:
-Article 83.2.a): "the nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage suffered."
-Article 83.2.a): "the nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage suffered."
The nature, scope, and purpose of the processing operation are, in this case, factors that demonstrate the extraordinary seriousness of the processing carried out.
In this regard, the origin of the data—related to the IAE (Tax Income Tax)
and the company census—must be taken into consideration. Pursuant to Law 4/2014, the CDE is authorized to process the data for the exclusive purpose of compiling the public company census, the electoral census, and the public-administrative functions granted to it by law, including those related to the public census and its management (ex Article 5.1.g). For its assigned function of managing the public census, CDE has access to information from the tax authorities and has processed the data obtained, incorporating it into a file that it transmits to CAMERDATA in execution of a private contract. The purpose
of using information obtained while acting as a public authority for a
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 200/204
private purpose, such as transferring it to CAMERDATA, demonstrates the seriousness
of the processing under consideration, from the perspective of its unlawfulness.
CDE transfers the data of individual entrepreneurs obtained
from tax authorities to CAMERDATA with full knowledge that they will be used for commercial purposes (as provided for in the contract signed by CDE) and,
therefore, with knowledge of the risks to the fundamental rights and freedoms of the data subjects that such processing could entail. CDE is aware
of the purpose of the database it transfers. Not only because of the aforementioned contractual provision,
but also because CAMERDATA's processing of the data is in line with its corporate purpose, a fact that CDE is aware of, as it is a company formed by several Official Chambers, including CDE, on whose Board of Directors it sits.
Also relevant is the extremely high number of people affected
by the unlawful processing of their data, around 1.5 million individuals
who are entrepreneurs. The seriousness of the conduct is amplified if one considers the low expectations that those affected may have had that the processing
that constitutes a violation of Article 6.1 could actually be carried out.
The continued unlawful processing of the data of self-employed entrepreneurs is also significant. We note that the processing is maintained for
one year and, unless the entrepreneur's status is terminated, it continues until the next update. This processing operation began, at the latest, with the contract signed between CDE and CAMERDATA in 2016.
After the GDPR came into force on May 25, 2018, in 2019, the Agreement was signed with the AEAT (Tax Agency), which regulates the conditions and procedure for accessing the information provided by this tax authority.
Article 83.2.b): "intentionality or negligence in the violation."
Article 28.1 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector, provides: "Only natural or legal persons […] who are responsible for them due to intent or negligence may be sanctioned for acts constituting an administrative violation." In this regard, the Supreme Court, in its Judgment
of March 18, 2005 (Recital No. 7707/2000), states that "an administrative offense could not be deemed to have been committed if the subjective element of culpability were not present, or, in other words, if the conduct typically constituting an administrative offense was not attributable to intent or negligence."
Article 83.2.g) GDPR: "The categories of personal data affected
by the violation."
Among the personal data of individual entrepreneurs that are subject to transfer to CAMERDATA is the NIF (Tax Identification Number), either in plain text or as a hash of the NIF.
The NIF of individuals is sensitive data due to the risk that its processing may pose to the fundamental rights and freedoms of its owner. Although the literal wording of Article 83.2.g) of the GDPR appears to link this criterion for scaling the fine exclusively with Article 9 of the GDPR (the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 201/204
special categories of personal data), the GDPR nevertheless contains references
to other classifications of data that respond to the purpose pursued by
Article 83.2 of the GDPR: to scale the fine in accordance with the principles
of proportionality and effectiveness. Thus, recitals 51 and 75 of the GDPR distinguish
a group of personal data that, by their nature, are particularly "sensitive"
due to the significant risk that their processing may entail for fundamental rights and
freedoms, as it may cause physical, material, or immaterial harm.
This group or category includes, in addition to the specially protected data regulated by Article 9 of the GDPR, many others. Recital 75 mentions personal data whose processing may entail a risk of varying severity and likelihood for the rights and freedoms of natural persons and refers to data whose processing "may give rise to discrimination,
identity theft or fraud, financial loss, damage to reputation,
loss of confidentiality of data subject to professional secrecy, unauthorized reversal of pseudonymization, or any other significant economic or social harm."
The numerical identifier of the DNI, together with the verification character corresponding
to the tax identification number, unequivocally identifies a natural person.
This quality makes it particularly sensitive data, since if
its processing is not accompanied by the necessary technical and organizational measures
to ensure that the person identified with it is truly its owner, a third party can
easily impersonate a natural person, or, in other words,
can commit identity fraud, with the resulting risks to the
privacy, honor, and assets of the person impersonated.
There are no apparent factors that mitigate the culpability or unlawfulness
of the conduct that violates Article 14 of the GDPR.
In light of the factors assessed, it is agreed to sanction CDE for violating
Article 14 of the GDPR with an administrative fine of €100,000 (one hundred thousand euros).
XVIII
Corrective Measures
Article 58.2 of the GDPR provides that "Each supervisory authority shall have all of the following corrective powers:
[…]
d) order the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate,
in a specified manner and within a specified period."
The imposition of this measure is compatible with the sanction of an administrative fine, as provided for in Article 83.2 of the GDPR.
This resolution orders CDE, as a corrective measure, pursuant to Article 58.2.d) of the GDPR, to terminate its transfer to CAMERDATA of the personal data of individual entrepreneurs it receives from the tax authorities pursuant to Article 8 of Law 4/2014. This measure must be adopted within a maximum of one month from the date the sanctioning resolution becomes final and enforceable.
Please note that failure to comply with the possible order to adopt measures imposed by this body in the sanctioning resolution may be considered an administrative violation pursuant to the provisions of the GDPR, classified as a violation in Articles 83.5 and 83.6. Such conduct may lead to the opening of a subsequent administrative sanctioning procedure.
Therefore, in accordance with applicable legislation and having assessed the criteria for graduating sanctions whose existence has been proven,
the Presidency of the Spanish Data Protection Agency RESOLVES:
FIRST: TO IMPOSE on the CHAMBER OF COMMERCE, INDUSTRY, SERVICES AND NAVIGATION OF SPAIN, with NIF Q2802216H, for a violation of Article 6.1 of the GDPR, as defined in Article 83.5.a) of the GDPR, an administrative fine in the amount of €100,000 (one hundred thousand euros).
SECOND: IMPOSE an administrative fine of €100,000 (one hundred thousand euros) on the Spanish Chamber of Commerce, Industry, Services and
Navigación de España, with Tax Identification Number (NIF) Q2802216H, for a violation of Article 5.1.b) of the GDPR, as defined in Article 83.5.a) of the GDPR.
THIRD: IMPOSE an administrative fine of €100,000 (one hundred thousand euros) on the Spanish Chamber of Commerce, Industry, Services and
Navigación de España, with Tax Identification Number (NIF) Q2802216H, for a violation of Article 5.1.f) of the GDPR, as defined in Article 83.5.a) of the GDPR.
FOURTH: IMPOSE an administrative fine of €100,000 (one hundred thousand euros) on the Spanish Chamber of Commerce, Industry, Services and
Navigación de España, with Tax Identification Number (NIF) Q2802216H, for a violation of Article 5.1.a) of the GDPR, as defined in Article 83.5.a) of the GDPR.
FIFTH: IMPOSE an administrative fine of €100,000 (one hundred thousand euros) on the Spanish Chamber of Commerce, Industry, Services and
Navigación de España, with Tax Identification Number (NIF) Q2802216H, for a violation of Article 14
of the GDPR, as defined in Article 83.5.b) of the GDPR.
SIXTH: ORDER the CHAMBER OF COMMERCE, INDUSTRY, SERVICES AND NAVIGATION OF SPAIN, with NIF Q2802216H, pursuant to Article 58.2.d)
of the GDPR, within one month of this resolution becoming final and enforceable, to certify that it has proceeded to terminate the transfer to CAMERDATA of personal data of individual entrepreneurs that it receives from the tax authorities pursuant to Article 8 of Basic Law 4/2014 on Official Chambers of Commerce, Services, Industry and Navigation.
SEVENTH: This resolution will become enforceable once the deadline for filing an optional appeal for reconsideration expires (one month from the day following notification of this resolution) without the interested party having exercised this right.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 203/204
The sanctioned party is hereby notified that they must pay the imposed sanction once this resolution becomes enforceable, in accordance with the provisions of Article 98.1.b) of the LPACAP (Spanish Taxpayer Protection Act), within the voluntary payment period established in Article 68 of the General Collection Regulations, approved by Royal Decree 939/2005, of July 29, in conjunction with Article 62 of Law 58/2003, of December 17, by making a payment, indicating the sanctioned party's NIF (Tax Identification Number) and the procedure number shown in the heading of this document, into the restricted account IBAN number: ES00-0000-
0000-0000-0000-0000 (BIC/Code). SWIFT: CAIXESBBXXX), opened in the name of the
Spanish Data Protection Agency at the banking entity CAIXABANK, S.A.
Otherwise, the collection process will be carried out during the enforcement period.
Once the notification is received and enforced, if the enforcement date is between the 1st and 15th of each month, inclusive, the deadline for making the voluntary payment will be the 20th of the following month or the next business day after, and if it is between the 16th and last day of each month, inclusive, the payment deadline will be the 5th of the second following month or the next business day after.
In accordance with the provisions of Article 50 of the LOPDGDD (Organic Law on the Protection of Personal Data), this Resolution will be made public once it has been notified to the interested parties.
Against this resolution, which ends the administrative process pursuant to Article 48.6 of the LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, the interested parties may optionally file an appeal for reconsideration before the Presidency of the Spanish Data Protection Agency within one month from the day following notification of this resolution or directly file an administrative appeal before the Administrative Litigation Division of the National Court, in accordance with the provisions of Article 25 and Section 5 of the Fourth Additional Provision of Law 29/1998, of July 13, regulating the Administrative Litigation Jurisdiction, within two months from the day following notification of this act, as provided for in Article 46.1 of the aforementioned Law.
Finally, it is noted that, in accordance with the provisions of Article 25 of the LOPDGDD, the interested parties may file an administrative appeal before the Presidency of the Spanish Data Protection Agency within one month from the day following notification of this decision. According to Article 90.3 a) of the LPACAP,
a final administrative decision may be provisionally suspended if the
interested party expresses their intention to file an administrative appeal.
If this is the case, the interested party must formally notify this fact by
writing to the Spanish Data Protection Agency, submitting it through
the Agency's Electronic Registry [https://sedeaepd.gob.es/sede-electronica-
web/], or through one of the other registries provided for in Article 16.4 of the aforementioned LPACAP. They must also forward to the Agency the documentation proving
the effective filing of the administrative appeal. If the Agency does not
become aware of the filing of the administrative appeal within
two months from the day following notification of this resolution,
it will terminate the provisional suspension.
938-101224
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 204/204
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es
- ↑ Article 8, Law 4/2014, of April 1, Basic Law of the Official Chambers of Commerce, Industry, Services and Navigation https://www.boe.es/buscar/act.php?id=BOE-A-2014-3520#a8
- ↑ This database, however, does not contain the data subjects’ NIF and meets the requirements of data minimisation under Article 5(1)(c) GDPR. The Spanish Supreme Court also concluded that including data subjects' NIF in the public database is not necessary or proportionate. See STS 02/11/2016, recurso 2538/2015.




