AEPD (Spain) - EXP202303454

From GDPRhub
AEPD - EXP202303454
Authority: AEPD (Spain)
Jurisdiction: Spain
Relevant Law: Article 5(1) GDPR
Article 6(1) GDPR
Art. 20 LOPDGDD
Type: Complaint
Outcome: Upheld
Started: 21.02.2025
Decided: 11.04.2025
Published: 23.07.2025
Fine: 200,000 EUR
Parties: SD IBERIAN PORTFOLIOS, S.A
National Case Number/Name: EXP202303454
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Spanish
Original Source: AEPD (in ES)
Initial Contributor: ap

The DPA fined a company that buys outstanding loans from banks €200,000 for unlawfully including a data subject’s debt in a public credit registry, with the knowledge that said debt had been exonerated two years before in the course of insolvency procedures.

English Summary

Facts

SD IBERIAN PORTFOLIOS, S.A (the controller) bought a credit from a data subject’s bank. The bank was informed of the data subject's insolvency proceedings. Data relating to the data subject's debt was included at the controller's request in ASNEF (Spanish National Registry of Financial Statistics, a public credit registry). The data subject requested ASNEF in November 2022 to erase the data, and in response ASNEF deleted the data as a precautionary measure.

The data subject later filed an access request in 2023 and found out that the data was included in the ASNEF database again. The data was transferred despite the fact that said debt was exonerated following insolvency proceedings in 2021. The data subject requested the data to be deleted, and presented a complaint to the DPA in January 2023. In response, ASNEF temporarily removed the data for up to three months.

In this case, the controller has a contract with SERVDEBT ESPAÑA, S.L (the processor) to manage proceedings of the debts bought by the controller. The controller argued that the data subject never sent a confirmation of debt forgiveness, and that it should not be expected to consult the public registry (Registro Público Concursal) every time it acquires a new credit.

It is interesting to note that the controller is established in Luxembourg. However, the Luxembourgish DPA allowed the Spanish DPA to issue the decision, because the affected data subjects were in Spain (Article 56(2) GDPR and 56(5) GDPR). Furthermore, Article 77 GDPR allows the data subject to file a complaint to a supervisory authority of the Member State of their habitual residence. The DPA began the sanctioning proceedings against the controller in February 2025.

Holding

According to the DPA, the processing did not meet the requirements under Spanish data protection law (Organic Law on Protection of Personal Data and Guarantee of Digital Rights or LOPDGDD). Article 20 LOPDGDD has specific requirements for data processing for credit information purposes. The DPA stated that the inclusion of the data subject’s debt in the ASNEF database was unlawful; the data subject’s debt was exonerated, and therefore the requirement of enforceability did not apply. The DPA also considered the fact that the controller was aware of this exoneration from the data subject’s data erasure requests.

Furthermore, the DPA considered this a violation of Article 5(1) GDPR and 6(1) GDPR. There is a potential presumption of lawfulness if the processing meets the conditions of Article 20 LOPDGDD. However, the processing was not lawful under the LOPDGDD, and the controller could also not rely on any of the legal basis under Article 6(1) GDPR.

Finally, the DPA dismissed the controller’s arguments. Under national bankruptcy law, the creditor is responsible for notifying credit information systems if previously reported debts have been exonerated. The contract between the data subject’s bank and the controller explicitly states that the buyer (the controller) is aware of this. The debtor is also allowed to carry out a request to update the information, however, it is not an obligation.

The DPA fined the controller €200,000. The DPA considered this a serious violation of the data subject’s rights, due to the lack of lawfulness and that it affected the data subject’s financial solvency.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.

1/36

 File No.: EXP202303454

SANCTIONING PROCEDURE RESOLUTION

From the procedure initiated by the Spanish Data Protection Agency and based

on the following

BACKGROUND

FIRST: Ms. A.A.A. (hereinafter the complainant) filed a complaint with the Spanish Data Protection Agency on January 26, 2023. The complaint is directed against SD IBERIAN PORTFOLIOS, S.A. with Tax Identification Number (NIF) ***NIF.1 (hereinafter the respondent or IBERIAN). The grounds for the complaint are as follows: the complainant states that her personal data is included in the ASNEF (Spanish Taxpayer Registry) at the request of the respondent, in relation to a debt assigned by BANCO SANTANDER, S.A. (hereinafter SANTANDER), despite being granted discharge from the unsatisfied liability, the complainant requested the deletion of its data from ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE
SOLVENCIA Y CRÉDITO, S.L. (hereinafter ASNEF-EQUIFAX), providing the publication in which the discharge was stated, and responding with the precautionary removal of the data associated with its identifier. Relevant documentation provided by the complainant:

- Publication of the Public Bankruptcy Registry, dependent on the Ministry of the Presidency, Justice, and Parliamentary Relations, which states that the complainant was definitively granted the BEPI on 11/02/2021.
- Document from ASNEF-EQUIFAX regarding the inclusion of its data at the request of the respondent on 11/23/2022 and 01/26/2023.

SECOND: The controller's main establishment in the European Union is located in Luxembourg, but the matter under review has only local repercussions, pursuant to Article 56.2 of the GDPR.
Therefore, the procedure provided for in Article 56.3 of the GDPR was followed, as well as its processing as a case of local impact.

In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter LOPDGDD), this complaint was forwarded to SERVDEBT ESPAÑA, S.L. on March 30, 2023. representative in Spain and data processor of the respondent, to proceed with its analysis and inform this Agency within one month of the actions taken to comply with the requirements established in the data protection regulations.

The transfer, which was carried out in accordance with the rules established in Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), was received on April 4, 2023, as recorded in the acknowledgment of receipt included in the file.

THIRD: On April 26, 2023, in accordance with Article 65 of the LOPDGDD (Spanish Data Protection Act),
the complaint submitted by the complainant was admitted for processing.

FOURTH: On April 26, 2023, the complainant filed a written statement stating: "HAVING RECEIVED THE ACCEPTANCE OF THE SAME DUE TO THE EXPIRY OF THE TERM, IT IS INDICATED THAT THE CLAIMING ENTITY IS SD IBERIAN PORTFOLIOS:
SD IBERIAN PORTFOLIOS, S.A. 17, BOULEVARD F.W. RAIFFEISEN, L-241, LUXEMBOURG.

WITHOUT PREJUDICE TO THE FACT THAT THE CREDIT ASSIGNOR IS BANCO SANTANDER, AND THAT APPARENTLY THE AFOREMENTIONED ENTITY CAN TAKE ACTIONS THROUGH THE COMPANY SERVDEBT.

IN VIEW OF THE FOREGOING, SD IBERIAN PORTFOLIOS SHOULD BE DECLARED AS THE CLAIMING ENTITY, AS IT IS THE ENTITY THAT REGISTER THE DEBT IN THE
NON-PAYMENT FILES."

FIFTH: The Subdirectorate General of Data Inspection proceeded to carry out preliminary investigative actions to clarify the facts in question, pursuant to the functions assigned to the supervisory authorities in Article 57.1 and the powers granted in Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VII, Chapter I, Section Two, of the LOPDGDD.

SERVDEBT ESPAÑA, S.L. on August 21, 2023, submitted a response to the transfer, in which it states the following:

- That it is mandated by IBERIAN to manage the debts.

- On February 25, 2021, SANTANDER assigned to IBERIAN (the "Assignee") all rights and actions arising from the Financing Facility, including principal, interest, compensation, and any other monetary obligations arising therefrom (the "Credit"), pursuant to a sales contract executed in a policy on that same date by the notary of Madrid, Mr. B.B.B., with number XX, Section X of his transaction registry book.
- SANTANDER has transferred to the Assignee the personal data related to the Credit that was provided by the claimant and that is necessary for its management and enforceability;
- IBERIAN, as the new controller of your personal data,

following the assignment of the Credit, processes the personal data for the purpose of managing and controlling the Credit, including debt collection, as well as complying with legal obligations;
- Likewise, to fulfill the service provision contract, the
Assignee has provided the defendant with their personal data related to the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 3/36

Credit, necessary for its management and enforceability (including, but not limited to, name, surname, NIF/CIF, DNI/NIE, address, contract date and number, amount of collection rights, bank account number and account holder, whether or not it is included in financial solvency and credit files, legal proceedings, if applicable, and other data relevant to the purpose pursued).

- On 03/23/2021, a letter of assignment was sent to the claimant informing them of the assignment that had taken place.

- The personal data that has been transmitted to the respondent, as a result of the assignment agreement between SANTANDER as Assignor, and IBERIAN, as Assignee, is as follows: Type of Personal Data
Name A.A.A. Tax identification number ***NIF.1 Address

***ADDRESS.1 Telephone numbers ***TELEPHONE.1 ***TELEPHONE.2
- In addition, the complainant was also informed that, if he did not pay the debt, his data would be included in the credit and bankruptcy information systems managed by the following entities: ASNEF and EQUIFAX, as stated in the letter of March 23, 2021. - On July 7, 2021, the complainant sent an email informing them of the existence of insolvency proceedings and that they were awaiting the final BEPI:
or From: A.A.A. Sent: (….) To: (...) Subject: Re: File(s) No.(s)
***FILE.1 Good morning, As I have already indicated to Banco Santander on several occasions, I am currently in bankruptcy proceedings as a natural person (Second Chance Law). I believe you called me a few months ago and I explained the situation. I told you that you could appear in person in the proceedings, which had a deadline of March 17, 2021. However, you have not appeared in person.

Therefore, I understand that the debt claim is no longer valid. I am awaiting the BEPI; once I obtain it, you must remove my debt from your files or databases. I am attaching the sealed copy of the bankruptcy proceedings. Best regards. A.A.A.
- The final BEPI was published on April 17, 2023.
- As a result, all data in the ASNEF/EQUIFAX file was deleted on April 28.

Relevant documentation provided by the complainant:

- Power of attorney granted by SD IBERIAN PORTFOLIOS, S.A. to SERVDEBT ESPAÑA, S.L. to act as its representative for the management of credits

defined in the loan portfolio assignment agreement entered into between SD IBERIAN PORTFOLIOS, S.A. and BANCO SANTANDER, S.A. on February 25, 2021.
- Letter dated March 23, 2021, regarding the assignment of credit between BANCO SANTANDER, S.A. and SD IBERIAN PORTFOLIOS, S.A. sent to the claimant informing them of this assignment (This letter contains a "Data Protection Information" clause stating: "Following the assignment referred to in this communication, Banco Santander S.A. has transferred to the Assignee the personal data relating to the Credit that you provided and that are necessary for its management and enforceability. The legal basis legitimizing this assignment is the existence of a legitimate interest based on a legal authorization to carry out this assignment. The Assignee, as the new controller of your personal data following the assignment of the Credit, will process your personal data for the purpose of managing and controlling the Credit, including debt collection, as well as complying with legal obligations.Likewise, this processing is based on (i) the need for the execution and control of the contractual relationship between you and the Assignee; (ii) legitimate interest if the holder of the Loan is a legal entity and you act as its representative; and, where applicable, (iii) compliance with applicable legal obligations (e.g., prevention of money laundering). Furthermore, to fulfill the service provision contract, the Assignee has provided ServDebt España S.L.U. with your personal data related to the Loan, which is necessary for its management and enforceability (including, but not limited to, name, surname, NIF/CIF, DNI/NIE, address, contract date and number, amount of collection rights, bank account number and account holder, whether or not it is included in financial solvency and credit files, legal proceedings, if applicable, and other data relevant to the purpose pursued). Your personal data will be
retained for the duration of the contractual relationship and,
subsequently, will remain blocked until the statute of limitations for any potential claims or legal requirements has elapsed. Your data may be accessed by other service providers of the Assignee (e.g., in the systems and technology, administrative management and document destruction, legal services, notary services, logistics, and recovery departments), as well as by any agency, public administration, state security force, or court, to comply with legal obligations. Likewise,
if you do not pay the debt within the established period, your data
may be included in the financial solvency and credit files
indicated in this letter." The body of the letter states that "If

you do not regularize your debt within 30 days of
receiving this communication, the legally established procedures
may be initiated so that your data is included in credit and financial insolvency information systems managed by the following entities:
ASNEF").
- Publication of the Public Bankruptcy Registry, dependent on the Ministry of

the Presidency, Justice and Parliamentary Relations, stating that the
claimant was definitively granted the BEPI on 11/02/2021
(the date of issue of this publication being 04/17/2023, a date that is intended to be used as proof of knowledge of the inclusion
of the BEPI of the claimant in the Public Bankruptcy Registry by
SERVDEBT).

- Screenshot of the exclusion of the claimant's data from the ASNEF file dated April 28, 2023.

On January 18, 2024, requests for information were sent to ASNEF-EQUIFAX and SERVDEBT ESPAÑA, S.L.

On January 25, 2024, ASNEF-EQUIFAX submitted a response to the request for information, in which it made, among others, the following statements:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 5/36

- According to the consultation of the Auxiliary Notification File in the ASNEF file,
it is noted that the inclusion in the file of the data of A.A.A., with DNI ***NIF.1, With registration dates of 11/02/2022 and 01/09/2023, at the request of the entity IBERIAN, the interested party has been notified through communications referenced 2022-11-1105567 and 2023-01-1153514, issued on 11/03/2022 and 01/10/2023, respectively. These communications are sent by regular mail to the address provided by the creditor, that is,
***ADDRESS.1. The corresponding supporting documentation is attached to this document, including:
o Certification issued by ARTEOS DIGITAL, S.L., as the successor entity to

SERVINFORM, S.A. (formerly EMFASIS BILLING & Marketing Services, S.L.), provider of the Generation, Printing, and Provision of the Postal Service
o Postal Certifications and/or Unipost, certifying the date the reference inclusion notification was issued, along with all other communications issued

in the same process without any incident that would have prevented its execution, as well as the date it was made available to the postal service.

Copy of the inclusion notification.

Delivery note and delivery note for the Post Office 2812096 and Hispapost,
with their acceptance value date.

Certification issued by the service provider for the recording and safekeeping of returned notifications, Ilunion CEE Contact Center SA, certifying that the reference inclusion notification is not in their custody, nor has it been processed for any reason for return, dated
01/22/2024.

- Currently, there are no data registered in our ASNEF and ASNEF COMPANIES files associated with Ms. A.A.A., with DNI ***NIF.1, by any creditor entity.
- After consulting our Auxiliary File of Cancelled Transactions in the ASNEF file, it appears that the data of Ms. A.A.A., registered at the time by IBERIAN on 11/02/2022, were cancelled on 11/30/2022, the reason for the cancellation being "C. GDPR,” which means they are removed during the processing of legal proceedings in our Consumer Service Department (CSD) due to the failure to receive a response from the creditor within the established period.
- The inclusion with an entry date of 01/09/2023 was also provisionally canceled by us on 02/06/2023, for the same reasons that led to the removal of the first entry. The consumer again exercised her right to cancellation in our files on 01/26/2023, and since IBERIAN did not respond to the data confirmation requested at that time, the data was removed.
- There is also evidence of a third inclusion of the complainant's data by IBERIAN. The data was registered for the same operation on 04/10/2023 and was removed on 04/28/2023, in this case directly by the creditor entity itself.
- Provides screenshots of the additions and removals from the ASNEF file.

For its part, the claimant filed a written response to the request on 01/30/2024, in which it states, among other things:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 6/36

- While it is not possible to obtain the registration date from the public bankruptcy registry, it is possible to prove that the BEPI was registered on 11/21/2022, as this is the date the attached list of publications was issued.

- That the first registration in the ASNEF file was on November 2nd, and that on 01/09/2023 the debt was registered again, having full knowledge of the existence of the Exoneration.

SERVDEBT ESPAÑA, S.L. filed a response to the request on February 1, 2024, in which it states, among other things, the following:

- That on March 23, 2021, the claimant was sent a notification of the assignment of credits, indicating the following: • the assignment of credits that took place on February 25, 2021 • the current creditor • the contract number in question • the amount owed on that date • payment details • information regarding data protection.

- In addition to the letter announcing the assignment of credits, an email was sent on July 7, 2021 requesting payment (A screenshot of an email addressed to the claimant is included, but it does not include the date, the email address to which it was sent, or who sent it).
- That on On July 7, 2021, I received an email from the claimant informing them that "As I have already informed SANTANDER on several occasions, I am in bankruptcy proceedings as a natural person (Second Chance Law). I believe you called me a few months ago and I informed you of the situation. I told you that you could appear in person in the proceedings, which had a deadline of March 17, 2021. However, you have not appeared, so I understand that the debt claim is no longer valid. I am waiting for the BEPI (Insolvency Proceedings of the Bankruptcy Court). Once I receive it, you must remove my debt from your files or databases. I am attaching the sealed copy of the bankruptcy proceedings. Greetings."
- That this was the first communication sent by the claimant reporting the existence of a bankruptcy proceeding (in initial bankruptcy proceedings);

- That the claimant would later send the BEPI, which did not occur; with the BEPI, the data in ASNEF would be canceled and the claimant would be removed from the arrears file; therefore, we are awaiting the BEPI to be sent to remove the complainant from ASNEF, since the provisional granting of the benefit of exoneration from unsatisfied liability to the complainant does not constitute the exclusion of their data from the ASNEF file.

- That SERVDEBT ESPAÑA, S.L. only learned of the existence of the BEPI on April 17, 2023; and as a result, all data was removed from the ASNEF/EQUIFAX file on April 28.

SIXTH: Through the "Internal Market Information System" (IMI), regulated Under the GDPR, which aims to promote cross-border administrative cooperation, mutual assistance between Member States, and the exchange of information, on March 8, 2024, the DPA requested the Luxembourg Data Protection Authority to process the incident as a local case, although the Luxembourg Authority was competent to act, given that the data controller has its registered office and main establishment in Luxembourg.

The request was made under the circumstances established in Article 56.2 of the GDPR, as it involved a complaint alleging a potential infringement of the GDPR.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 7/36

While it refers to an establishment located in Luxembourg, it affects data subjects in Spain. On March 12, 2024, the Luxembourg Data Protection Authority notified the Spanish Data Protection Agency (AEPD) of its authorization to process the complaint as a local matter.

SEVENTH: On April 12, 2024, the Director of the Spanish Data Protection Agency (AEPD) agreed to initiate sanctioning proceedings against the respondent for the alleged infringement of Article 6.1 of the GDPR, as defined in Article 83.5.a) of the GDPR.

EIGHTH: After notification of the initiation agreement on May 10, 2024, the respondent has stated the following in summary: the lack of access to the file; a statement of what, in its opinion, were the facts that motivated the agreement to initiate the procedure; that at no time was IBERIAN aware of the granting of the BEPI until it was notified by SANTADER and that it was not notified by ASNEF-EQUIFAX of the deletion requests filed by the complainant, nor did it inform IBERIAN about the final granting of the BEPI; that the respondent has always complied with the applicable regulations and that, furthermore, it cannot be required to consult the public bankruptcy registry for each credit acquired; that the proposed sanction is manifestly disproportionate and that mitigating circumstances should be applied; that the case be filed and, if not, that the proposed sanction be reduced to a minimum.

NINTH: On September 10, 2024, it was agreed to open a period for the collection of evidence, with the following resolutions:

- To reproduce for evidentiary purposes the claims filed by the claimants and their documentation, as well as the documents obtained and generated by the inspection services that are part of the file.
- To reproduce for evidentiary purposes the allegations to the initiation agreement presented by the respondent and the accompanying documentation.

- Request the data controller to provide a copy of the credit assignment purchase agreement, drafted into a public deed, signed with SANTANDER, S.A., dated February 25, 2021, by virtue of which the defendant party acquired the creditor loan portfolio, as well as the information related to the claimant's credit, necessary for its enforceability: name, surname, NIF/CIF, DNI/NIE, address, date and contract number, amount of collection rights, etc. included in the aforementioned agreement.

On September 24, 2024, the defendant responded to the evidence submitted, the content of which is included in the file.

TENTH: On February 21, 2025, a Resolution Proposal was issued in the sense that the Presidency of the Spanish Data Protection Agency would sanction the respondent for violating Article 6.1 of the GDPR, as defined in Article 83.5 of the GDPR.

ELEVENTH: On March 17, 2025, a written statement of allegations was received from the respondent.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 8/36

From the actions taken in this proceeding, the following have been established:

PROVEN FACTS

FIRST. On January 26, 2023, the complainant filed a letter with the Spanish Data Protection Agency (AEPD) stating that their personal data had been included in the ASNEF file at the request of the respondent, related to debt assigned by Santander. Santander was notified of the insolvency proceedings, both judicial and extrajudicial, and the possibility of transferring data to solvency files was not provided for in the original contract. The respondent included the aforementioned debt in the ASNEF file and others. After requesting "cancellation" of the data from the ASNEF-EQUIFAX file, they responded with precautionary deletion, and the publication of the Public Bankruptcy Registry where the BEPI is recorded was sent to the complainant. It was subsequently included again, and a further deletion request was made.

SECOND. The complainant provided authorization to Mr. C.C.C., attorney, to act on their behalf.

THIRD. A letter from SANTANDER addressed to the claimant, dated March 23, 2021, informing them that on February 25, 2021, it had assigned to the respondent the rights and actions arising from the unpaid debt pursuant to a sales contract drawn up in a deed before the Madrid notary, Mr. B.B.B.

FOURTH. A publication from the Public Bankruptcy Registry, under the Ministry of the Presidency, Justice, and Parliamentary Relations, is provided, which states that the claimant was definitively granted the BEPI (Benefit of Exemption from Unsatisfied Liabilities) on November 2, 2021.

FIFTH. A copy of the contract signed between ASNEF-EQUIFAX

SERVICIOS DE INFORMACIÓN SOBRE SOLVENENCIA Y CREDITO SL and the respondent for the provision of Bureau Services is hereby provided.

SIXTH. On January 17, 2023, the complainant contacted the ASNEF file manager, the entity that maintains the common credit information system ASNEF-EQUIFAX, exercising the right to access their personal data.

On January 26, 2023, the complainant sent the information associated with their ID ***NIF.1, reported by the respondent, for products discovered on account, holder nature, with registration dates of January 9, 2023; viewing date of February 8, 2023; First and last due dates: May 29, 2019, and May 29, 2019, for an unpaid balance of (...) euros.
Likewise, the complainant was informed that his data had been accessed by (...).

SEVENTH. On November 30, 2022, the complainant contacted the ASNEF file manager, the entity that maintains the ASNEF-EQUIFAX common credit information system, exercising the right to delete his personal data. On November 30, 2022, the complainant informed him that, following the relevant checks, the entity(ies) SD IBERIAN PORTFOLIOS had been provisionally removed from the system for the data associated with the identifier: ***NIF.1.
He was also informed that his data had been accessed by (...).

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 9/36

EIGHTH. The respondent has provided a copy of the credit assignment purchase agreement, certified as a public deed, signed with BANCO de SANTANDER, S.A., dated February 25, 2021, by virtue of which it acquired a portfolio of creditor loans, including the one relating to the claimant.

NINTH. An ASNEF-EQUIFAX document dated 11/03/2022, No.
***REFERENCE.1, was sent to the complainant, stating:
We inform you that on 11/02/2022, the respondent entity requested the registration in the ASNEF file of the following personal data related to the non-payment of the contract it has with said entity:

PRODUCT UNPAID AMOUNT QUALITY
(…) (…) (…)

ARTEOS DIGITAL, S.L., in a letter dated 01/22/2024, stated that the communication with reference number ***REFERENCE.1 was generated, printed, and posted on the postal service on 11/04/2022.

Ilunion CEE Contact Center, S.A., in a letter dated January 22, 2024, stated that

After reviewing the files related to the service provided with Equifax, the Reference Notification ***REFERENCE.1 is not in custody at the offices of Ilunion CEE Contact Center, S.A., nor has it been processed for any reason for return.

TENTH. An ASNEF-EQUIFAX document dated 10/01/2023, No.
***REFERENCE.2, was sent to the complainant, stating:
We inform you that on 09/01/2023, the respondent entity requested the registration in the ASNEF file of the following personal data related to the non-payment of the contract it has with said entity:

PRODUCT UNPAID AMOUNT QUALITY
(…) (…) (…)

ARTEOS DIGITAL, S.L., in a letter dated 22/01/2024, stated that the

generation, printing, and posting to the postal service on 12/01/2023 of
the communication with reference number ***REFERENCE.2.

Ilunion CEE Contact Center, S.A., in a letter dated January 22, 2024, stated that, after reviewing the files related to the service provided with Equifax, the Reference Notification ***REFERENCE.2 is not in the custody of the Ilunion CEE Contact Center, S.A. offices, nor has it been processed for any reason for return.

ELEVENTH. It is noted that the complainant, through its representative, addressed the ASNEF file on 11/22/2022, stating, "We hereby request the cancellation of the data included in the file by SD IBERIAN PORTFOLIOS, since there is a discharge of legal debts registered in the Public Bankruptcy Registry. If they are not yet registered, an objection may be filed.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 10/36

Consequently, the data requested for debts prior to the publication of said resolution cannot be processed."

On November 30, 2022, the ASNEF file addressed the respondent, stating: "In relation to the File concerning the complainant with identifier ... who has requested the cancellation of their data, and of which they were notified on November 23, 2022, we inform you that, given the lack of a response from your esteemed entity, in accordance with the operating rules of the ASNEF File, we have proceeded to provisionally remove the data.

This removal is in accordance with established rules and as required by data protection regulations. However, if your entity does not agree with this removal and deems it appropriate, it may re-register the client with the data in its possession.

TWELFTH. It is noted that the respondent, through its representative, addressed the entity that maintains the common credit information system at ASNEF file, on January 26, 2023, stating: "This is the second time you have registered the same debt in the file despite having documented proof of its nonexistence with the resolution of the public bankruptcy registry, as is being done again.

Based on the foregoing, I formally request that you cease such actions, under penalty of initiating legal proceedings for violation of the Right to Honor, as well as filing a complaint with the AEPD (Spanish Data Protection Agency).

On February 6, 2023, ASNEF-EQUIFAX addressed the respondent, stating:

"In relation to the File concerning the complainant with identifier ... who has requested the cancellation of his or her data, and of which he or she was informed on January 30, 2023, we inform you that, given the lack of a response from your esteemed entity, in accordance with the operating rules of the ASNEF File, we have proceeded to provisionally delete the data.

This deletion is taking place in accordance with the established rules and as required by data protection regulations. However, if your bank does not agree with this cancellation and deems it appropriate, you may re-register the client using the data in your possession.”

THIRTEENTH. Finally, the respondent included the complainant’s data in the ASNEF common system on April 10, 2023.

PRODUCT UNPAID AMOUNT QUALITY

(…) (…) (…)

In a letter dated January 25, 2024, Equifax Ibérica, S.L., stated that “The data was registered for the same transaction on April 10, 2023, and canceled on April 28, 2023, in this case, directly by the creditor bank itself.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 11/36

FOURTEENTH. There is an undated payment request (the defendant states that it is dated 07/07/2021), submitted by the defendant to the claimant, requesting payment of the debt, stating in relation to the debt "that, at the time of the credit assignment, the debt amounted to (...) euros. However, due to the time elapsed, it currently amounts to (...) euros."

In response, the claimant sent an email dated 07/07/2021 in which he stated:

"(...) As I have already indicated to Banco Santander on several occasions, I am in bankruptcy proceedings as a natural person (Second Chance Law).
(...)
I am awaiting the BEPI (Insolvency Proceedings). Once I obtain it, my debt must be removed from their files or databases. (…)”.

FIFTEENTH. In a letter dated February 1, 2024, the respondent party, in response to the question raised by the AEPD: “Actions taken by that entity when the complainant informed them of the Resolution of definitive recognition of the discharge of unsatisfied liabilities registered in the Bankruptcy Publications Registry,” indicated that:

a) Servdebt only learned of the existence of BEPI on April 17, 2023;
b) As a result, all data from the ASNEF/EQUIFAX file was deleted on April 28.

LEGAL BASIS

I
Jurisdiction

In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR) and as provided for in Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR). Pursuant to Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter, LOPDGDD), the Presidency of the Spanish Data Protection Agency is competent to resolve this procedure.

Furthermore, Article 63.2 of the LOPDGDD establishes that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development, and, insofar as they do not contradict them, subsidiarily, by the general rules on administrative procedures."

II

Response to the allegations regarding the initiation agreement

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 12/36

1. First, the respondent alleges lack of access to the administrative file.

This statement is surprising because the respondent has not been notified once, but twice: the first, to the data controller, sent by the Spanish Data Protection Agency on May 10, 2024, at 1:00 PM, has expired due to the expiration of the deadline for appearance, May 21, 2024, and the second, sent to the data processor, with the date of availability: May 27, 2024, and the date of access to the content of the notification: May 28, 2024.

2. The respondent alleges that it has always complied with the applicable regulations and that it cannot be required to consult the public bankruptcy registry. Each credit acquired, that at no time was she aware of the granting of the BEPI and that she was not notified by ASNEF-EQUIFAX of the deletion requests made by the complainant, nor did the complainant inform her of the final granting of the BEPI.

The aforementioned statements certainly cannot be accepted, and they are once again surprising in light of the documentation provided to the file.

In the present case, it should be noted that it was the complainant herself who reported the process in which she was immersed through the email dated July 7, 2021, sent to the data processor, in which she responded to the debt demand letter, as follows:

From: A.A.A. ***EMAIL.1
Sent: (…)
To: (…)
Subject: Re: File(s) No.(s) ***FILE.1

“(…)
As I have already indicated on several occasions, Banco Santander, I am currently in bankruptcy proceedings as a natural person (Second Chance Law).
(…)

I am waiting for the BEPI (Insolvency Proceedings). Once I obtain it, they must remove my debt from their files or databases.
(…)".

And in response to the inclusion of their personal data in the common credit information system (ASNEF), the complainant contacted the joint data controller on two occasions: first, on November 22, 2022, stating that "We hereby request the *cancellation* of the data included in the file by SD IBERIAN PORTFOLIOS, since there is a discharge of judicial debts, registered in the Public Bankruptcy Registry. If they are not yet registered, an *opposition* may be exercised."

Consequently, the data requested for debts prior to the publication of said resolution cannot be processed.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 13/36

The cancellation request included, among other things, the granting of the BEPI (Benefit of Exemption from Unsatisfied Liabilities) dated November 2, 2021.

As a result of the previous request, the entity that maintains the common credit information system responsible for the ASNEF file contacted the respondent on November 30, 2022, stating: “In relation to the File relating to the complainant with identifier … who has requested the Cancellation of their data, and of which they were notified on November 23, 2022, we inform you that,

given the lack of a response from your esteemed entity, in accordance with In accordance with the operating rules of the ASNEF File, we have proceeded to provisionally remove the data.

This removal is carried out in accordance with the established rules and as required by data protection regulations. However, if your entity does not agree

with this removal and deems it appropriate, you may re-register the client using the data in your possession.

The complainant again contacted the entity that maintains the common credit information system for the ASNEF file on January 26, 2023, as a result of being notified of the new inclusion of their personal data in the file, stating: "This is the second time that you have registered the same debt in the file despite having documented its non-existence with the resolution of the public bankruptcy registry, as is being done again.
In light of the foregoing, I formally request that you cease such actions, under penalty of initiating legal proceedings for violation of the

Right to Honor, as well as filing a complaint with the AEPD (Spanish Data Protection Agency).

And again, the person responsible for the ASNEF file addressed the respondent in a letter dated February 6, 2023, stating: "In relation to the File concerning the complainant with identifier ... who has requested the Cancellation of their data, and of which you were notified on January 30, 2023, we inform you that, given the lack of a response from your esteemed entity, in accordance with the operating rules of the ASNEF File, we have proceeded to provisionally delete the data.
This deletion is taking place in accordance with the established rules and as required by data protection regulations. However, if your institution does not agree

with this deregistration and deems it appropriate, it may re-register the client using the data in its possession."

Furthermore, the respondent re-registered the complainant's data in the ASNEF common system on April 10, 2023.

3. The respondent alleges that the proposed sanction is manifestly
disproportionate and that mitigating circumstances of culpability that have not been taken into account should be applied to the sanction.

Regarding the alleged violation of the principle of proportionality in the amount of the sanction, the respondent is informed that Article 83.1 of the GDPR provides that "Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this article for violations of this

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 14/36

Regulation indicated in sections 4, 5, and 6 are, in each individual case,
effective, proportionate, and dissuasive."

Therefore, the fines, as deduced from the preceding provision, must be
effective, proportionate, and dissuasive to achieve the intended purpose

of the GDPR.

It is true that for this system to function with all the guarantees, it is
necessary that several elements be implemented fully and completely. The
application of rules outside the GDPR regarding the determination of fines in
each of the Member States applying their national law, whether due

to aggravating or mitigating circumstances not provided for in the GDPR—or in the LOPDGDD
in the Spanish case, as permitted by the GDPR itself—would make the system less effective,
which would lose its meaning, its teleological purpose. the legislator's will, resulting in the fact that
fines imposed for various violations would cease to be effective,
proportionate, and dissuasive. This would also deprive interested parties

of the effective guarantee of their rights and freedoms, weakening the uniform application
of the GDPR. The mechanisms for protecting citizens' rights and
freedoms would be diminished, and this would be contrary to the spirit of the GDPR.

The GDPR is endowed with its own principle of proportionality, which must be
applied strictly.

Regarding the principle of proportionality of sanctions, the National Court has stated in numerous rulings that the principle of proportionality
cannot be exempt from judicial review, since the margin of appreciation granted to the Administration in imposing sanctions within the legally established limits must be developed by weighing, in all cases, the

circumstances involved, in order to achieve the necessary and due proportionality between the alleged acts and the liability required, given that any sanction must be determined in accordance with the magnitude of the violation committed and according to a criterion of proportionality in relation to the circumstances of the act. Therefore, proportionality constitutes a regulatory principle imposed on the Administration and reduces the scope of its sanctioning powers.

Well, in accordance with the circumstances of this case, the principle of proportionality is not violated in determining the sanction, which is balanced and proportionate to the seriousness of the violation committed, the importance of the facts, as well as the circumstances taken into account to determine the sanction. No reasons are appreciated that further justify the reduction, especially considering the amount that such sanctions can amount to in accordance with Article 83.5 of the GDPR, which provides for the violation of Article 6.1 of the GDPR, “with administrative fines of a maximum of €20,000,000 or, in the case of a company, an amount equivalent to a maximum of 4% of the total annual global turnover of the previous financial year, whichever is higher.”

Regarding the fact that circumstances present in the present case that would mitigate culpability for the purposes of graduating the sanction have not been taken into account, including: The degree of cooperation with the authority (the defendant has acted at all times in cooperation with the AEPD), Data categories and impact on the rights of minors (the data being processed are not special categories of data and the rights of minors have not been affected), and the ongoing nature of the violation (it cannot be considered that it is a of a continuing violation).

It should be noted that any entity, corporation, business, etc., regardless of its size, is obliged to comply with personal data protection regulations from the moment it processes personal data. Small, medium-sized, and large companies that process the data of clients, suppliers, employees, partners, or any other entity in the development of their activities are obliged to comply with the GDPR and the LOPDGDD.

Since compliance with data protection regulations is an obligation for the respondent, the respondent cannot claim that cooperation with the independent or supervisory authority and the fact that the data processed are not specially protected can be considered mitigating circumstances of the respondent's culpability for the purposes of reducing the sanction to be imposed. However, they could be used as aggravating circumstances of the respondent's conduct if these circumstances had occurred, leading to an increase in the sanction. to be imposed.

For all these reasons, the allegations made by the respondent must be rejected.

III
Response to the allegations regarding the Proposed Resolution

1. The respondent alleges its disagreement with the facts stated in the Proposal and, although it does not deny having received the communications sent by ASNEF-EQUIFAX, it does deny that ASNEF informed it of the BEPI granting document to the complainant.

As already indicated in the previous grounds, the complainant informed the respondent of the bankruptcy proceedings in which it was immersed via an email dated July 7, 2021, and that it was awaiting the benefit of the final discharge of unsatisfied liabilities:

From: A.A.A. ***EMAIL.1
Sent: (…)

To: (...)
Subject: Re: File(s) No.(s) ***FILE.1

"As I have already informed Banco Santander on several occasions, I am in bankruptcy proceedings as a natural person (Second Chance Law).

I believe you called me a few months ago and I informed you of the situation. I told you that you could appear in person in the proceedings, which had a deadline of March 17, 2021. However, you have not appeared, so I understand that the debt can no longer be claimed.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 16/36

I am waiting for the BEPI (Insolvency Proceedings). Once I obtain it, you must remove my debt from your files or databases.
I am attaching the sealed copy of the bankruptcy proceedings.

Regards."

Therefore, the respondent cannot claim that they were unaware of the claimant's situation, as they not only discussed the matter personally in telephone conversations on July 7 and 21, 2021 (respondent dixit), but also informed them via email that they were awaiting the BEPI and even invited them to participate in the bankruptcy proceedings by appearing in person.

The respondent alleges that "the most the claimant could hope for was a hope that she would finally be granted discharge... but at no point does that hope require the respondent to discharge the claimant's debt."

However, this allegation must be rejected because the respondent lacks jurisdiction to grant discharge, as this is a tool granted by the judge to those who cannot pay their debts.

Furthermore, In response to the claimant's email, the creditor should have shown greater diligence and sensitivity to the situation the claimant was facing and should have taken into account the provisions of the credit purchase agreement, dated February 25, 2021, entered into with SANTANDER, where this type of situation is contemplated (Legal Basis V); thus, Clause 1, Purpose, Section 1.3, Limitation of the Seller's Liability, establishes that:

“(…)
1.3.2. Likewise, following the meetings between the Parties and the due diligence process conducted by the Buyer, in accordance with the provisions of Exhibit VI above, the Buyer declares that it is aware of and accepts the characteristics of the Credits and the Credit Data. In particular, the Buyer acknowledges and accepts that, without prejudice to the Seller's representations and warranties under this Agreement:
(A) …
(B) on the effective date, some of the Debtors whose Claims are transferred may be insolvent, have been declared bankrupt, or have requested bankruptcy, without prejudice to the guarantee contemplated in Clause 5.1 (E), and
(E) …
(…)”

Therefore, once the exemption has been granted, the GDPR and the Bankruptcy Law itself require that requests for data deletion be processed promptly and effectively, especially when the data may cause harm to the data subject.

However, in the present case, and as will be explained, there is no evidence that the respondent's actions were in accordance with data protection regulations, proving the lack of due diligence that the respondent did not

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 17/36

request additional documentation for the purpose of verifying the exoneration; on the contrary, it merely included the data in the ASNEF file, revealing its negligence, which cannot be justified by stating that what the claimant harbored was a mere hope.

Analyzing the events chronologically, on November 2, 2021, a resolution was issued definitively recognizing the discharge of the claimant's unpaid liability, and on that same date, the respondent requested the registration of the claimant's debt of (...) €, for the product "overdrawn on current account," in the ASNEF file.

As stated in point 2 of the previous Legal Basis, on November 3, 2022, ASNEF-EQUIFAX sent the claimant notification of the inclusion of its data in the file. The generation, printing, and delivery of the data to the postal service by the contracting company occurred on November 4, 2022.

On November 22, 2022, the claimant, upon notification of inclusion in the file, requested the deletion of the data included therein by the defendant as a result of the discharge of legal debts, registered in the Public Bankruptcy Registry. This request included the BEPI (Benefit of Discharge of Unsatisfied Liabilities) granted on November 2, 2021, complaining of this circumstance and stating that despite the multiple communications made to the creditor regarding the bankruptcy situation:

"FIRST. INCLUSION OF DATA IN THE ASNEF FILE
Having been informed by those responsible for the file
through a document issued on November 3, 2022, of the data incorporated into the file, SD IBERIAN has requested its inclusion
PORTFOLIOS by amount unpaid debt of (…) euros.
SECOND. NON-EXISTENCE OF DEBT. BANKRUPTCY PROCEEDINGS. BENEFIT OF DISCHARGE OF UNSATISFIED LIABILITIES.
PUBLICITY OF THE PUBLIC BANKRUPTCY REGISTRY.
Despite the multiple communications made to the creditor regarding the bankruptcy situation, the inclusion of my client's data has been improperly requested. Indeed, Ms. Elisabeth was discharged from any existing debt on November 2, 2021, with the declaration of the BEPI, as recorded in the public bankruptcy registry, a copy of which, in Section I of the Bankruptcy Edicts, is attached as document no. 1.

To this letter, the complainant submitted a copy of the publication of the

resolution definitively recognizing the discharge of the unsatisfied liability.

On November 30, 2022, ASNEF-EQUIFAX proceeded with the precautionary deregistration of the debt, sending the following information to the respondent:

"In relation to the File relating to A.A.A. with identifier ***NIF.1, who has requested the cancellation of their data, and of which they were notified on November 23, 2022, we inform you that, given the lack of a response from your

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 18/36

esteemed entity, in accordance with the operating rules of the ASNEF File, we have proceeded with the precautionary deregistration of the data.

This deregistration is in accordance with the established rules and as required by data protection regulations. However, if your entity does not agree
with this deregistration and deems it appropriate, may re-register the client with the data in its possession.
(…)”

On that same date, ASNEF-EQUIFAX sent the following communication to the

complainant:

“In accordance with your request for CANCELLATION of your data, registered in our offices on November 21, 2022, we inform you that, after the pertinent checks, the precautionary deletion of the data associated with the identifier:
***NIF.1 has been carried out with the entity(ies) SD

IBERIAN PORTFOLIOS in the ASNEF File. We are sending you a screenshot in which it expressly states
the non-existence of this data.

We also inform you that the information we attach as a Query History, in compliance with current regulations, refers to the entities that have consulted your data in the last six months, if such queries have occurred.

The data included by the entities in the ASNEF file is used to help entities that consult and provide information to prevent defaults and analyze solvency. The data included in the file may be anonymized for statistical analysis. The data included will be canceled or removed once the debts have been paid and, in any case, 5 years after the date of each unpaid due date included in the ASNEF file.

On January 9, 2023, the respondent included the claimant's debt of €(...) for the product "overdrafts on current accounts" in the ASNEF file.

On January 10, 2023, ASNEF-EQUIFAX sent the claimant notification of the inclusion of its data in ASNEF. The generation, printing, and posting of the postal service by the contracting company occurred on January 12, 2023.

On January 26, 2023, the complainant contacted ASNEF-EQUIFAX, stating:
"Dear Sirs,
The cancellation of the injured party's data is being sent.

This is the second time you have registered the same debt in the file despite having documented proof of its nonexistence with the resolution of the public bankruptcy registry, as is being done again.
In light of the foregoing, I formally request that you cease such actions, under penalty of initiating legal proceedings for violation of the

Right to Honor, as well as filing a complaint with the AEPD."

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 19/36

On February 6, 2023, ASNEF-EQUIFAX proceeded to provisionally cancel the registration of the aforementioned debt, sending the following communication to the respondent:

“In relation to the File relating to A.A.A. with identifier ***NIF.1, which has requested the cancellation of its data, and of which it was notified on January 30, 2023, we inform you that, due to the lack of a response from your esteemed entity, in accordance with the operating rules of the ASNEF File, we have provisionally canceled the data.

This cancellation is in accordance with the established rules and as required by data protection regulations. However, if your entity does not agree with this If the client is deregistered and deems it appropriate, the client may be re-registered using the data in its possession.
Sincerely."

On that same date, ASNEF-EQUIFAX sent the following communication to the complaining party:

"In accordance with your request for CANCELLATION of your data, registered in our offices on January 26, 2023, we inform you that, after the pertinent checks, the data associated with the identifier:
***NIF.1 has been provisionally deregistered with the entity(ies) SD IBERIAN PORTFOLIOS in the ASNEF File.
We are attaching a screenshot expressly stating the non-existence of the data.

We also inform you that the information we attach as a Query History, in compliance with current regulations, refers to the entities that have consulted your data in the last six months, if such queries have occurred.

The The data included by entities in the ASNEF file is used for the

purpose of helping entities that consult and provide information to prevent defaults and analyze solvency. The data included in the file may be anonymized for statistical analysis.
The data included will be canceled or removed once the debts have been paid and, in any case, 5 years after the date of each unpaid due date included in the ASNEF file.

(…)”

On April 10, 2023, the respondent again included a debt of the complainant of (…) €, for the product “overdrawn accounts” in the ASNEF file.

On April 28, 2023, the complainant's data was deleted at the request of the respondent, upon becoming aware of the BEPI.

It is important to mention that precautionary removal from the ASNEF file is a temporary measure applied by ASNEF-EQUIFAX while the creditor's response is received regarding a request for deletion or rectification made by the interested party.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 20/36

This is an effective measure when there is a suspicion that the inclusion or registration is incorrect, an error has been made in the registration procedure, the debt has been paid, or, as in the present case, when the debt is no longer payable.

It is important to note, as indicated, that the precautionary deregistration is temporary, with the joint controller, ASNEF-EQUIFAX, having a period of one month to resolve and respond to the request, which can be extended for another two months if necessary, as stipulated in Article 12 of the GDPR.

Therefore, if ASNEF-EQUIFAX confirms, after consulting the creditor, that the debt does not exist, the data will no longer be included in the file. However, if, on the contrary, it is confirmed that the debt is real, due, and payable, the data will be included in the file again.

The respondent does not deny the communications from ASNEF-EQUIFAX, but maintains that it has no record of having been sent the document granting the BEPI on both November 30, 2022, and February 6, 2023, along with the claimant's request for deletion.

However, it is evident that after the letters were sent to the respondent, notifying the respondent of the precautionary removals caused by ASNEF-EQUIFAX, in response to the claimant's request for deletion, and which also indicated that the removal was in accordance with established standards and as required by data protection regulations. However, if your bank does not agree with this deletion and deems it appropriate, you can re-register the client.

Using the data in your possession, on January 9, 2023, and April 10, 2023, the creditor re-entered the complainant's personal data into the ASNEF credit reporting system.

Therefore, even assuming that ASNEF did not forward the final BEPI certification to the respondent, in response to the complainant's deletion requests, the respondent did not take any action to verify whether the debt was true, due, and payable. As noted, the respondent's action was to re-enter the complainant's data in the solvency file, with the resulting damages.

2. The respondent alleges compliance with data protection regulations regarding credit information, and there is sufficient grounds for legal standing.

The respondent justifies the processing carried out on the grounds that its actions were in accordance with the GDPR and the LOPDGDD (Spanish Data Protection Act) because the inclusion in the file occurred at a time when the debt was due, and therefore it acted diligently in accordance with the information provided by both the complainant and the joint controller, ASNEF-EQUIFAX.

However, this argument cannot be accepted in light of the documentation submitted to the file; the respondent failed to observe the due diligence required by the GDPR, nor by the provisions of the contract signed with Santander: to comply with the obligations imposed by said Regulation. Therefore, it is now necessary to comply with the principle of legal standing.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 21/36

Regarding its willingness to comply with the provisions of the GDPR and the LOPDGDD,
refer to Ground V of this resolution, which clearly shows that the data processing carried out was not based on any of the legal grounds contained in Article 6.1 of the GDPR.

3. The respondent alleges its disagreement with the corrective measures included in the Proposal.

It is surprising that the respondent is surprised that the adoption of corrective measures is ordered to prevent incidents such as the one that occurred and that led to the opening of the sanctioning procedure for violation of Article 6.1 of the GDPR; Corrective powers that the GDPR grants to the AEPD as the supervisory authority, which are listed in Article 58.2, paragraphs a) to j). Specifically, letter d) of the provision establishes that the supervisory authority may "order the controller or processor to ensure that processing operations comply with the provisions of this Regulation, where appropriate, in a specified manner and within a specified period..." This measure was already contemplated in the Proposal and, in addition, it was indicated that

within six months of the final sanctioning resolution, if any, issued, the processing operations subject to this procedure must be brought into compliance with the applicable regulations and that "The text of this agreement establishes the facts that led to the violation of data protection regulations, from which it is clear what measures to be adopted, without prejudice

to the fact that the specific type of procedures, mechanisms, or instruments to implement them correspond to the sanctioned party, since it is the one who fully understands
its organization and must decide, based on proactive responsibility and a risk-based approach, how to comply with the GDPR and the LOPDGDD" and it was indicated "as a possible measure to be adopted, it is indicated that when it is proven that the BEPI (exemption from liabilities) is registered in the Public Bankruptcy Registry, any possibility of registration will be eliminated." of the debt in the aforementioned asset information systems."

The corrective power of Article 58.2.d) of the GDPR should be highlighted, as it may order the controller or processor to ensure that the processing operations comply with the provisions of the GDPR, where appropriate, in a specific manner and within a specified period. This measure is fundamental and constitutes a guarantee for the effective implementation of the Fundamental Right to the Protection of Personal Data.

Finally, corrective measures are important because they aim to resolve the violation committed and ensure that the effects of the violation can be corrected.

And this can only be achieved if the existence of the violation is declared through the appropriate procedure provided for in Article 64 of the LOPDGDD (Spanish Data Protection Act). Once declared, compliance with current legislation must be ordered, ensuring that the Fundamental Right to the protection of personal data of the interested parties is not further violated. However, the respondent's gesture in adopting measures of its own motion, such as the aforementioned removal of the data of all debtors included in files owned by ASNEF-Equifax, must always be recognized and valued. 4. The respondent alleges that the AEPD fails to take into account compliance with other facts, such as notifying the complainant of the transfer and deleting the data at the time it became aware of the BEPI.

The respondent claims that what the respondent seeks to be assessed as facts beyond its responsibility are, in fact, binding obligations.

Thus, the Purchase Agreement for the unsecured loan portfolio signed between Santander and the respondent on February 25, 2021, includes in its Clause 7, Communication of the Transfer. Data Protection, Section 7.1
Communication to Debtors, which establishes:

7.1.1 The Parties declare that it is appropriate to notify the Debtors…
7.1.2 To this end, the Parties have agreed to send joint communications, in the form of a letter signed by a representative of each Party…
7.1.3 The Parties agree that the communications will be sent by the entity that the Buyer notifies the Seller…

(…)”

And regarding the deletion of the registration of the data at the time it became aware of the BEPI, the Draft Resolution already includes the Royal
Legislative Decree 1/2020, of May 5, approving the Consolidated Text

of the Insolvency Law in its Article 492 ter. Effects of the exemption with respect to credit information systems, establishes that:

“1. The court ruling approving discharge through liquidation of the assets or final discharge in the case of a payment plan will include

an order to the affected creditors to notify the discharge to the credit reporting systems to which they had previously reported the non-payment or default of the discharged debt, so that their records can be updated accordingly. 2. The debtor may request a copy of the resolution to directly request that credit reporting systems update their records to record the exoneration.

5. The respondent alleges that the sanction is disproportionate and that mitigating circumstances should be taken into account.

The allegations regarding the lack of proportionality of the imposed sanction and the objections made to the aggravating circumstances contained in the Proposal and the request that certain factors be considered as mitigating factors reiterate what was stated in the written statement of allegations regarding the initiation agreement; issues that are included in the proposed resolution and also in this resolution.

Regarding the circumstances that should be taken into account in reducing the sanction to be imposed: "the absence of malicious intent in the processing of data, as well as a legitimate interest on the part of the debtor" (Judgment of the National Court of March 18, 2024), “the lack of intent, the diligent attitude of the plaintiff, and the absence or lack of economic benefits obtained” (Judgment of the National Court of January 3, 2021).

Regarding the lack of benefits obtained, it should be noted that such a circumstance can only operate as an aggravating factor and in no case as a mitigating factor.

Article 83.2.k) of the GDPR refers to "any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement."

And Article 76.2.c) of the LOPDGDD states that:

"2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account:

(…)
c) Benefits obtained as a result of committing the infringement."

Both provisions mention "benefits obtained" as a factor that may be taken into account in

the grading of the sanction, but not the "absence" or "nonexistence" of these benefits, which is what the defendant claims.

In this regard, the AN Judgment of 05/05/2021, rec. 1437/2020, refers to the need for the factual "condition" contemplated in the regulation to be met for a certain grading criterion to be applied, and, as stated, the absence of benefits is not among the circumstances regulated in the cited article.
This Judgment states: "...the fact that the condition for its application is not met means that it cannot be taken into consideration, but it does not imply or permit, as the plaintiff claims, its application as a mitigating circumstance."

Regarding "the lack of intentionality and the diligent attitude of the plaintiff," it should be noted that, in the present case, it is clear that the defendant did not act with the appropriate diligence. It should be remembered that the requirement of liability presupposes the presence of the subjective element of the violation, that is, culpability. This is an essential requirement, as it governs our Administrative Sanctioning Law, which prevents the imposition of sanctions based on the objective liability of the alleged offender.

The presence of the subjective element, or culpability in the broad sense, as a condition for the emergence of liability has been confirmed by the Constitutional Court, among others, in its STC 76/1999, which states that administrative sanctions share the same nature as criminal sanctions, being one of the manifestations of the State's ius puniendi, and that, as a requirement derived from the principles of legal certainty and criminal legality enshrined in Articles 9.3 and 25.1 of the Spanish Constitution, their existence is essential for their imposition.

Similarly, Law 40/2015 on the Legal Regime of the Public Sector
provides the following in Article 28, Liability:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 24/36

“1. Only natural and legal persons, as well as, when a law recognizes their legal capacity, groups of affected parties, unions and entities without legal personality, and independent or autonomous assets, who are found liable for such acts due to intent or negligence, may be sanctioned for acts constituting an administrative infraction.”

Therefore, administrative liability may be claimed based on intent or negligence, with mere failure to comply with the duty of care being sufficient in the latter case.

Examples of a lack of diligence in complying with the obligations imposed on the data controller by data protection regulations include the following rulings:

In the National Court's ruling of 10/17/2007 (Recital 63/2006), it is stated: "The Supreme Court has been understanding that negligence exists whenever a legal duty of care is disregarded, that is, when the offender fails to behave with the required diligence. And in assessing the degree of diligence, the professionalism of the subject must be especially considered, and there is no doubt that, in the case now under consideration, when the appellant's activity involves constant and extensive handling of personal data, rigor and exquisite care must be emphasized to comply with the legal provisions in this regard."

And the Supreme Court of Justice of April 29, 2010, which, in its sixth legal ground, stated: "The

issue is not whether the appellant processed the complainant's personal data without her consent, but rather whether or not she used reasonable diligence in trying to identify the person with whom she signed the contract."

It is worth recalling what Supreme Court of Justice of the European Union (STC) 246/1991 stated regarding the

culpability of legal entities: that they do not lack the "capacity to infringe the rules to which they are subject." "The capacity to infringe (...) derives from the legal interest protected by the rule being infringed and the need for such protection to be truly effective (...)"

In connection with the above, reference should be made to Article 5.2 of the GDPR (the principle of proactive accountability), according to which the data controller shall be responsible for compliance with the provisions of paragraph 1 and capable of demonstrating compliance. The principle of proactivity transfers to the data controller the obligation not only to comply with data protection regulations, but also to be able to demonstrate such compliance. Opinion 3/2010 of the Article 29 Working Party (WP29) - WP 173 - issued during the repealed Directive 95/46/EEC period, but whose reflections are still applicable today, states that the "essence" of proactive accountability is the controller's obligation to implement measures that, under normal circumstances, ensure compliance with data protection rules in the context of processing operations, and to have documents available that demonstrate to data subjects and supervisory authorities what measures have been adopted to achieve compliance with data protection rules. And on this issue, we must not forget Article 24.1 of the GDPR, which provides regarding the controller's liability: "Taking into account the nature, scope, context, and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organizational measures to ensure and demonstrate that the processing complies with this Regulation. These measures shall be reviewed and updated as necessary."

It is worth noting the diligence observed by the respondent in relation to the conduct it should have observed in relation to the conduct under review. The answer is that the diligence it should have observed was necessary to comply with the obligations imposed by Article 6.1 of the GDPR and which motivated the initiation of the procedure.

Therefore, in accordance with the principle of proactivity, the respondent
failed to adopt a diligent attitude to comply with the provisions of the GDPR, violating the
principle of lawfulness. This violation resulted in the complainant's data being

included in credit reporting systems without the debt being payable.

This conduct has existed, evidencing a lack of due diligence.

Regarding "the absence of malicious intent in the processing of data, as well as a legitimate interest on the part of the respondent," Article 83.2.k) contains a residual clause regarding the assessment of any other factor, mitigating circumstance, or aggravating circumstance applicable to the circumstances of the case." However, in the present case, having established the respondent's culpability, the absence of malicious intent cannot be assessed since it has been proven that the respondent failed to act with the due diligence required of it.

IV
Breached Obligation: Article 6.1 of the GDPR

The reported facts materialize in the inclusion of the complainant's personal data in common credit information systems, in relation to a debt acquired by the respondent from SANTANDER, and, despite being granted discharge of the unsatisfied liability, the debt was accessed to the file, which could constitute Violation of data protection regulations.

Article 5 of the GDPR establishes the principles that must govern the processing of personal data, and in section 1 states that:

“1. Personal data shall be:

a) processed lawfully, fairly, and transparently with the data subject (<<lawfulness, fairness, and transparency>>).
(…)”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 26/36

And in section 2, it establishes that:

“2. The data controller shall be responsible for compliance with the provisions of section 1 and be able to demonstrate this (<<proactive accountability>>).”

For its part, Article 6, Lawfulness of processing, of the GDPR in section 1, establishes that:

“1. Processing will only be lawful if at least one of the following conditions is met:

a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;

b) processing is necessary for the performance of a contract to which the data subject is party or, at the request of the data subject, in order to take steps pre-contractual to enter into a contract;

c) processing is necessary for compliance with a legal obligation to which the controller is subject;

d) processing is necessary to protect the vital interests of the data subject or of another natural person;

e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that

such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data,
in particular where the data subject is a child.

The provisions of letter (f) of the first paragraph shall not apply to

processing carried out by public authorities in the exercise of their duties."

Furthermore, Article 4 of the GDPR, Definitions, in paragraphs 1, 2, and 11, states that:

"1) "personal data" means any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person shall be any person whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person;

“2) “processing”: any operation or set of operations performed
on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring,

storage, adaptation or modification, extraction, consultation, use,
communication by transmission, dissemination or any other form of enabling
access, alignment or interconnection, restriction, erasure or destruction;

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 27/36

“11) “consent of the data subject”: any manifestation of free,
specific, informed, and unequivocal will by which the data subject accepts, either by a declaration or by a clear affirmative action, the processing of personal data that

concerns him or her.”

And Article 20 of the LOPDGDD, Credit Information Systems, establishes
that:

“1. Unless proven otherwise, the processing of personal data related to the breach of monetary, financial, or credit obligations by common credit information systems shall be presumed lawful when the following requirements are met:

a) The data has been provided by the creditor or by someone acting on its behalf or in its interest.

b) The data relates to certain, due, and payable debts, the existence or amount of which has not been the subject of an administrative or judicial claim by the debtor or through an alternative dispute resolution procedure binding between the parties.

c) The creditor has informed the affected party in the contract or at the time of requesting payment about the possibility of inclusion in such systems, indicating those in which it participates.

The entity that maintains the credit information system with data
relating to non-compliance with monetary, financial, or credit obligations
must notify the affected party of the inclusion of such data and inform them of the

possibility of exercising the rights established in Articles 15 to 22 of
Regulation (EU) 2016/679 within thirty days following
notification of the debt to the system, the data remaining blocked
during this period.
d) The data will only be kept in the system while the

non-compliance persists, with a maximum limit of five years from the due date
of the monetary, financial, or credit obligation.
e) That the data referring to a specific debtor may only be consulted when the person consulting the system maintains a contractual relationship with the affected party that involves the payment of a monetary amount, or the affected party has requested the conclusion of a contract involving financing, deferred payment, or periodic billing, as occurs, among other cases, in those provided for in the legislation on consumer credit contracts and real estate credit contracts. When the right to restrict the processing of data has been exercised before the system, challenging its accuracy in accordance with the provisions of Article 18.1.a) of Regulation (EU) 2016/679, the system will inform those who may consult it in accordance with the preceding paragraph of the mere existence of this circumstance, without providing the specific data regarding which the right has been exercised, pending a decision on the affected party's request. f) That, in the event that the request to enter into the contract is denied,
or the contract is not entered into as a result of the consultation carried out,
the person who consulted the system shall inform the affected party of the result of said consultation.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 28/36

2. The entities that maintain the system and the creditors, with respect to the processing of data relating to their debtors, shall have the status of joint data controllers, and the provisions of
Article 26 of Regulation (EU) 2016/679 shall apply.

The creditor shall be responsible for ensuring that the requirements for inclusion in the debt system are met, and shall be liable for any non-existence or inaccuracy.

3. The presumption referred to in paragraph 1 of this article does not cover cases in which the credit information is associated by the entity maintaining the system with information additional to that contemplated in said paragraph, related to the debtor and obtained from other sources, in order to carry out profiling of the debtor, in particular through the application of credit rating techniques.

1. It should be noted that data processing requires a legal basis.

In accordance with Article 6.1 of the GDPR, in addition to consent, there are other possible bases that legitimize data processing without the need for the data subject's authorization, in particular, when it is necessary for the performance of a contract to which the data subject is a party or for the implementation, at the request of the data subject, of pre-contractual measures, or when it is necessary for the satisfaction of legitimate interests pursued by the data controller or by a Third, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject that require protection of such data. Processing is also considered lawful when it is necessary for compliance with a legal obligation applicable to the data controller, to protect the vital interests of the data subject or another natural person, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller.

In the present case, the respondent is charged with violating Article 6.1 of the GDPR, as the unlawfulness of the processing carried out is evident, and none of the grounds for legality provided for in the aforementioned article have been established in relation to the processing of the data belonging to the complainant.

The respondent carried out the processing of the complainant's data without any legal grounds, since the presumption of lawfulness provided for in Article 20 of the GDPR does not apply. LOPDGDD, since the guarantees provided for in the aforementioned article have not been respected, given that the debt lacked the requirement of enforceability, as the claimant was granted the benefit of debt discharge. It should not be forgotten that the defendant had been aware of the debt discharge due to the claimant's data deletion requests submitted by ASNEF-EQUIFAX.

The LOPDGDD introduces a "iuris tantum" presumption of the prevalence of the legitimate interest of the data controller in certain specific cases,

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 29/36

including the processing of data in credit information systems.
Thus, when the guarantees provided for in Article 20 of the LOPDGDD are observed, the processing may be presumed lawful. Under Article 6.1.f) of the GDPR, this does not preclude the fact that legitimacy must be assessed on a case-by-case basis and without prejudice to the fact that the controller may carry out the legally required assessment when the aforementioned guarantees are not met, as clarified in the preamble to the law:

Title IV contains "Provisions applicable to specific processing operations," incorporating a series of assumptions that should in no case be considered exhaustive of all lawful processing operations. Among them, it is worth noting, first of all, those for which the legislator establishes a "iuris tantum" presumption of the prevalence of the controller's legitimate interest when they are carried out with a series of requirements. This does not exclude the legality of this type of processing when the conditions provided in the text are not strictly met, although in this case the controller must carry out the legally required weighing, as the prevalence of its legitimate interest is not presumed.

Among the aforementioned guarantees, Article 20 of the LOPDGG contemplates the requirement that "the data relate to certain, due, and payable debts, the existence or amount of which has not been the subject of an administrative or judicial claim by the debtor or through an alternative dispute resolution procedure binding between the parties" (Article 20.1.b) GDPR).

2. From the documentation provided, it appears that the claimant signed a contract with SANTANDER, which would generate a debt.

On February 25, 2021, SANTANDER and the respondent signed a credit purchase agreement, which was audited on the same date by the Madrid notary, Mr. B.B.B.

The respondent, as the new data controller following the assignment of the credit, processed the claimant's personal data for the purpose of managing and recovering the credit, including debt collection, as well as complying with legal obligations.

Thus, on March 23, 2021, a letter was sent to the claimant informing them of the assignment and, furthermore, that if they did not pay the debt, their data would be included in credit reporting systems.

On July 7, 2021, the claimant sent an email informing them of the existence of insolvency proceedings and that they were awaiting the BEPI:
"As I have already indicated to Banco Santander on several occasions, I am in bankruptcy proceedings as a natural person (second chance law).
I believe you called me a few months ago and I informed you of the situation, telling you that you could appear in person in the proceedings, which had a deadline of March 17, 2021.

But you have not appeared, so I understand that the debt claim is no longer valid. I am awaiting the BEPI; once I obtain it, you must remove my debt from your files or databases. I am attaching the sealed copy of the bankruptcy proceedings."

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 30/36

That is to say, it is not true, as stated by the respondent in the letter dated February 1, 2024, as reflected in the proven facts, that "Servdebt only learned of the existence of BEPI on April 17, 2023; the claimant, on July 7, 2021, already informed them of the bankruptcy proceedings in which it was involved and that it was awaiting a final resolution, and even invited them to appear in the proceedings, a matter that was rejected.

And the respondent's action was to include the claimant's data in common credit reporting systems, commonly called bad debt files; and not just once, but three times: November 2, 2022, for a debt of (…)
euros; on January 9, 2023, for a debt of (…) euros, and on April 10, 2023, for a debt of
(…) euros.

Furthermore, not only was the complainant the one who informed the respondent of the existence of the aforementioned procedure, but the same person in charge of the ASNEF-EQUIFAX credit information system informed them of the existence of the BEPI, not just once, but twice.

In its letter dated January 25, 2024, ASNEF-EQUIFAX stated that at this time, the consumer was registered in our ASNEF file at the request of SD IBERIAN PORTFOLIOS, so we requested confirmation of the data from said entity. We did not receive a response from them during the time period provided, so we had to act by canceling the data as a precautionary measure.

And that the inclusion The registration date for the transaction was January 9, 2023, and it was also provisionally canceled by us on February 6, 2023, for the same reasons that led to the deletion of the first entry. The consumer again exercised her right to deletion in our files on January 26, 2023, and since SD IBERIAN did not respond to the data confirmation requested at that time, the data was deleted.

Furthermore, it should be noted that Royal Legislative Decree 1/2020, of May 5, approving the Consolidated Text of the Bankruptcy Law, establishes in its Article 492 ter. Effects of the Exoneration on Credit Information Systems

The following:

“1. The court ruling approving the exoneration through liquidation of the assets or the definitive exoneration in the case of a payment plan will include an order to the affected creditors to communicate the exoneration to the credit information systems to which they had previously reported the non-payment or default of the exonerated debt, so that they can duly update their records.

2. The debtor may request a copy of the ruling to directly request the credit information systems to update their records to record the exoneration.”

Furthermore, in the credit purchase agreement signed with BANCO de SANTANDER, S.A., dated February 25, 2021, in Clause 1, Object, Section 1.3 Limitation of the seller's liability, it is established that:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 31/36

“(…)
1.3.1 The Parties acknowledge that the object of the agreement is the purchase and sale of the

Credit Portfolio as a whole, without individual consideration of each of the Credits comprising it and acquired by the Buyer.

1.3.2. Likewise, following the meetings between the Parties and the due diligence process carried out by the Buyer, in accordance with the provisions of Exhibit VI above, the Buyer declares that it is aware of and accepts the characteristics of the

Credits and the Credit Data. In particular, the Buyer acknowledges and accepts that, without prejudice to the Seller's representations and warranties under this Agreement:
(A) …
(B) on the effective date, some of the Debtors whose Credits are transferred may be insolvent, have been declared bankrupt, or have requested bankruptcy, without prejudice to the guarantee contemplated in Clause 5.1 (E), and
(E) some of the Credits may be subject to Law 7/1995 on Consumer Credit (or, where applicable, the new Law 16/2011 on Consumer Credit Contracts) and, where applicable, Law 7/1998 of April 13, on General Contract Conditions, as well as other related regulations.
(…)”

Therefore, based on all of the foregoing, it is considered that the actions of the defendant party constitute Violation of Article 6.1 of the GDPR, in conjunction with Article

20.1 of the LOPDGDD, violation of the principle of lawfulness in data processing, which requires the existence of a legitimate legal basis; violation that caused the claimant's data to be included in credit information systems without the debt being certain, due, or payable, a violation classified in Article 83.5.a) of the GDPR.

V
Classification of the violation of Article 6.1 of the GDPR

The violation attributed to the respondent is classified under Article 83.5 a) of the GDPR, which considers that the violation of "the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9" is punishable, in accordance with paragraph 5 of the aforementioned Article 83 of the aforementioned Regulation, "with administrative fines of a maximum of €20,000,000 or, in the case of a company, an amount equivalent to a maximum of 4% of the total global annual turnover of the preceding financial year, whichever is higher."

Article 71 of the LOPDGDD (Organic Law on the Protection of Personal Data), entitled "Infractions," states that: "The acts and conduct referred to in sections 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law, constitute infringements." And in its Article 72, it considers, for the sole purpose of calculating the statute of limitations, the following: "Infractions considered very serious:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 32/36

1. In accordance with the provisions of Article 83.5 of Regulation (EU) 2016/679, the following are considered very serious and will be subject to a three-year statute of limitations:

infringements that constitute a substantial violation of the articles mentioned therein, and in particular, the following:

(…)
b) The processing of personal data without any of the conditions for the lawfulness of processing established in Article 6 of

Regulation (EU) 2016/679.
(…)

VI
Proposed sanction for violation of Article 6.1 of the GDPR

In order to establish the administrative fine to be imposed, if the provisions contained in Articles 83.1 and 83.2 of the GDPR are observed, which state:

“1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article for infringements of this Regulation referred to in paragraphs 4, 5, and 6 are, in each individual case, effective, proportionate, and dissuasive.

2. Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or as a substitute for the measures provided for in Article 58(2)(a) to (h) and (j). When deciding whether to impose an administrative fine and its amount in each individual case, due account shall be taken of:

a) the nature, gravity, and duration of the infringement, taking into account the

nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage suffered by them;

b) the intentionality or negligence of the infringement;

c) any measures taken by the controller or processor to mitigate the damage suffered by data subjects;

d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures they have implemented pursuant to Articles 25 and 32;

e) any previous infringements committed by the controller or processor;

f) the degree of cooperation with the supervisory authority in order to remedy the infringement and mitigate the possible adverse effects of the infringement;

g) the categories of personal data affected by the infringement; (h) the manner in which the supervisory authority became aware of the infringement, in particular whether the controller or processor notified the infringement and, if so, to what extent;

(i) where measures referred to in Article 58(2) have been previously ordered against the controller or processor concerned in relation to the same matter, compliance with those measures;

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 33/36

(j) adherence to codes of conduct pursuant to Article 40 or to certification mechanisms approved pursuant to Article 42; and
(k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits.the profits obtained or losses avoided, directly or indirectly, through the infringement.

In relation to letter k) of Article 83.2 of the GDPR, the LOPDGDD, in its Article 76, "Sanctions and corrective measures," establishes that:

"2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account:

a) The continuous nature of the infringement.
b) The connection between the offender's activity and the processing of personal data.

c) The benefits obtained as a result of the infringement.
d) The possibility that the affected party's conduct could have led to the infringement.
e) The existence of a merger by absorption subsequent to the infringement, which cannot be attributed to the acquiring entity.

f) The impact on the rights of minors.
g) The availability of a data protection officer, when not mandatory.
h) The submission of the data controller or voluntarily entrusted with alternative dispute resolution mechanisms, in those

cases where there are disputes between them and any interested party."

- In accordance with the provisions transcribed, for the purposes of determining the amount of the penalty to be imposed in this case for the violation classified in Article 83.5.a)

and Article 6.1 of the GDPR (inclusion in defaulters' files without legal standing), for which the defendant is held responsible, the following factors are considered concurrent:

The nature and severity of the violation; the facts revealed affect a basic principle relating to the processing of personal data, such as the principle of legal standing, which the law penalizes with the greatest severity; The

damages suffered by the complainant that affect their financial solvency, including their personal data in common credit information systems at the request of the respondent in relation to a debt that lacked the enforceability requirement, having been exonerated from it. The damages caused to the complainant are evident, as their personal data were improperly included in the file, as well as the purpose of the processing operation, which was none other than to collect a non-existent debt (Article 83.2.a) of the GDPR).

The activity of the allegedly infringing entity is routinely linked to the processing of personal data examined in this proceeding. The defendant entity's activities require the processing of its debtors' personal data. Therefore, given the purpose of its business, the significance of the conduct that is the subject of this claim is undeniable (Article 76.2.b) of the LOPDGDD in relation to Article 83.2.k). (Article 76.2.b) of the LOPDGDD in relation to Article 83.2.k).

The intentionality or negligence in the infringement is evident, as the defendant included the data in common credit reporting systems without the debt meeting the requirements of Article 20.1 of the LOPDGDD and without carrying out the necessary assessment to prove the prevalence of its legitimate interest; Furthermore, the respondent, aware of the claimant's bankruptcy situation, since both ASNEF-EQUIFAX and the claimant had provided it with information about it, nevertheless re-registered the claimant's personal data in the common file system commonly known as "debtors," with the consequences and damages that this may entail. Also connected to the degree of diligence that the data controller is required to display in compliance with the obligations imposed by data protection regulations, we can cite the SAN (National Court of Justice)

of 10/17/2007. Although it was issued before the GDPR came into force, its ruling is perfectly applicable to the case we are analyzing. The ruling, after alluding to the fact that entities whose activities involve continuous processing of client and third-party data must observe an adequate level of diligence, specified that "(...) the Supreme Court has held that negligence exists whenever a legal duty of care is disregarded, that is, when the offender fails to behave with the required diligence. And in assessing the degree of diligence, the professionalism of the subject must be especially considered, and there is no doubt that, in the case under consideration, when the appellant's activity involves constant and extensive handling of personal data, rigor and exquisite care must be emphasized to comply with the legal provisions in this regard"

(Article 83.2, b) of the GDPR).

VII
Corrective Measures

The corrective powers that the GDPR confers on the AEPD as a supervisory authority are listed in Article 58.2, paragraphs a) to j).

Upon confirmation of the infringement, it is agreed that the controller shall be proposed to adopt appropriate measures to bring its actions into compliance with the regulations mentioned in this act, in accordance with the provisions of the aforementioned Article 58.2 d) of the GDPR, according to which each supervisory authority may "order the controller or processor to ensure that processing operations comply with the provisions of this Regulation, where appropriate, in a specified manner and within a specified period..." The imposition of this measure is compatible with the sanction consisting of an administrative fine, as provided for in Article 83.2 of the GDPR.

Therefore, it is considered appropriate to order that the respondent, within six months of the final sanctioning resolution being issued, in any case, adapt the procedures related to the processing of personal data in credit information systems to the applicable regulations, in particular the procedure for handling requests to exercise rights raised by individuals affected by such processing. The text of this agreement establishes the facts that led to the violation of data protection regulations, from which it is clear what the measures to be adopted are, without prejudice to the specific type of procedures, mechanisms, or instruments to implement them being the responsibility of the sanctioned party, as it is the party that fully understands its organization and must decide, based on proactive responsibility and a risk-based approach, how to comply with the GDPR and the LOPDGDD. However, in the present case, as a possible measure to be adopted, it is indicated that when it is proven that the BEPI (discharge of liabilities) is registered in the Public Bankruptcy Registry, any possibility of recording the debt in the aforementioned asset information systems must be eliminated. Please be advised that failure to comply with the order imposed by this body may be considered an administrative offense pursuant to the provisions of the GDPR, classified as an offense in Articles 83.5 and 83.6, and such conduct may lead to the opening of a subsequent administrative sanctioning procedure.

Therefore, in accordance with applicable legislation and having assessed the criteria for graduating the sanctions whose existence has been proven,

The Presidency of the Spanish Data Protection Agency RESOLVES:

FIRST: TO IMPOSE on SD IBERIAN PORTFOLIOS, S.A., with NIF ***NIF.1, for a violation of Article 6.1 of the GDPR, classified in Article 83.5.a) of the GDPR, a fine of €200,000 (two hundred thousand euros).

SECOND: ORDER SD IBERIAN PORTFOLIOS, S.A., with Tax Identification Number (NIF) ***NIF.1, pursuant to Article 58.2.d) of the GDPR, within six months of this resolution becoming final and enforceable, to demonstrate that it has taken appropriate measures to prevent incidents such as those occurring in accordance with the provisions of Article 6.1 of the GDPR and, in particular, the one indicated in Grounds VII.

THIRD: NOTIFY SD IBERIAN PORTFOLIOS, S.A. of this resolution.

This resolution will become enforceable once the deadline for filing the optional appeal for reconsideration expires (one month from the day following notification of this resolution) without the interested party having exercised this right. The sanctioned party is hereby warned that they must pay the imposed sanction once this resolution becomes enforceable, in accordance with the provisions of Article 98.1.b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), within the voluntary payment period established in Article 68 of the General Collection Regulations, approved by Royal Decree 939/2005, of July 29, in relation to Article 68 of the General Tax Collection Regulations. 62 of Law 58/2003, of December 17, by depositing the fine, indicating the sanctioned party's NIF (Tax Identification Number) and the procedure number shown in the heading of this document, into the restricted account IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX), opened in the name of the Spanish Data Protection Agency at CAIXABANK, S.A. Otherwise, the fine will be collected during the enforcement period.

Once the notification is received and enforced, if the enforcement date is between the 1st and 15th of each month, inclusive, the deadline to make the voluntary payment will be the 20th of the following month or the next business day after, and if it is between the 16th and last day of each month, inclusive, the payment deadline will be the 5th of the second following month or the next business day after.

In accordance with the provisions of Article 50 of the LOPDGDD (Spanish Organic Law on the Protection of Personal Data), this Resolution will be made public once it has been notified to the interested parties.

Against this resolution, which ends the administrative process pursuant to Art. 48.6 of the LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, interested parties may optionally file an appeal for reconsideration before the Presidency of the Spanish Data Protection Agency within one month from the day following notification of this resolution, or directly file an administrative appeal before the Administrative Litigation Division of the National Court, in accordance with the provisions of Article 25 and Section 5 of the Fourth Additional Provision of Law 29/1998, of July 13, regulating the Administrative Litigation Jurisdiction, within two months from the day following notification of this decision, as provided for in Article 46.1 of the aforementioned Law.

Finally, it is noted that pursuant to the provisions of Art. 90.3 a) of the LPACAP (Spanish Data Protection Act), a final administrative decision may be provisionally suspended if the interested party expresses their intention to file an administrative appeal.
If this is the case, the interested party must formally notify this fact by means of a written notice addressed to the Spanish Data Protection Agency, submitting it through the Agency's Electronic Registry [https://sedeagpd.gob.es/sede-electronica-web/], or through one of the other registries provided for in Article 16.4 of the aforementioned Law 39/2015, of October 1. They must also forward to the Agency the documentation proving the effective filing of the administrative appeal. If the Agency does not become aware of the filing of the administrative appeal within two months from the day following notification of this resolution, it will terminate the provisional suspension.

Lorenzo Cotino Hueso

President of the Spanish Data Protection Agency

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es