AEPD (Spain) - EXP202306737

From GDPRhub
AEPD - EXP202306737
Authority: AEPD (Spain)
Jurisdiction: Spain
Relevant Law: Article 5(1)(d) GDPR
Article 6(1) GDPR
Type: Complaint
Outcome: Upheld
Started: 29.03.2023
Decided: 17.12.2025
Published:
Fine: 30,000 EUR
Parties: GAOLANIA SERVICIOS, S.L.
Unknown
National Case Number/Name: EXP202306737
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Spanish
Original Source: AEPD (in ES)
Initial Contributor: Niovi Gk

The DPA fined an energy supplier €30,000 for not verifying data concerning a customer energy connection, resulting in a change of the energy supplier for the wrong person.

English Summary

Facts

On 29 March 2023, a data subject complained to the DPA after their electricity provider had been changed without their consent. The data subject had not requested any switch and objected upon being notified.

GAOLANIA SERVICIOS S.L. (the controller) is a utilities provider. It initiated the change following a contract with a third party who provided a CUPS identifier. However, this identifier corresponded to the electricity supply point of a different data subject. The controller failed to verify the accuracy of this information and proceeded with the switch.

As a result, the controller processed the personal data of the wrong data subject and changed their electricity provider, even though the data subject had no relationship with the controller.

The controller argued that it had relied on information provided by a third party and that the error originated from that source.

Holding

First, the DPA held that the controller infringed Article 5(1)(d) GDPR, as it failed to ensure the accuracy of personal data, relying on an incorrect identifier that led to the misidentification of the data subject. The DPA initially investigated a potential infringement of Article 6(1)(a) GDPR (lack of consent), but subsequently reclassified the case as a breach of the data accuracy principle under Article 5(1)(d) GDPR. The DPA stated that the CUPS identifier is long (containing 20-22 characters) and susceptible to error. Therefore, the risk of data accuracy is an aspect that the controller should have considered.

Second, the DPA found that the processing lacked a legal basis under Article 6(1) GDPR, since the data subject had neither consented to the processing nor entered into a contract with the controller.

Third, the DPA emphasised that controllers must verify personal data before processing and cannot rely solely on information provided by third parties.

The DPA imposed an administrative fine of €30,000, taking into account the negligent conduct and the impact on the data subject.

Comment

This case was somewhat unusual because the DPA imposed a fine primarily for a violation of Article 5(1)(d) GDPR, which is less commonly the main basis for sanctions.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.

1/47

• File No.: EXP202306737

RESOLUTION OF SANCTIONING PROCEEDINGS

From the proceedings initiated by the Spanish Data Protection Agency and based on the following:

CONTENT

BACKGROUND..........................................................................................................5

FIRST: On March 29, 2023, a complaint was filed with the
Spanish Data Protection Agency regarding a possible infringement attributable to

GAOLANIA SERVICIOS, S.L. with Tax Identification Number B98717457 (hereinafter, GAOLANIA

SERVICES or the respondent).............................................................................5

SECOND: In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter LOPDGDD), said complaint was forwarded to GAOLANIA

SERVICES, so that it could proceed with its analysis and inform this Agency within one month of the actions taken to comply with the requirements established in data protection regulations.......................................................6

THIRD: On June 29, 2023, in accordance with Article 65 of the LOPDGDD, the complaint was admitted for processing.........................................................7

FOURTH: On August 16, 2023, the complainant filed an appeal

optional appeal for reconsideration through the AEPD Electronic Registry, against the
resolution issued in file EXP202306737, in which it expresses its
disagreement with the contested resolution.............................................................7

FIFTH: The Sub-Directorate General for Data Inspection proceeded to carry out

preliminary investigative actions to clarify the facts in
question, by virtue of the functions assigned to supervisory authorities in
Article 57.1 and the powers granted in Article 58.1 of Regulation (EU)

2016/679 (General Data Protection Regulation, hereinafter GDPR), and in
accordance with the provisions of Title VIII of the LOPDGDD.............................8

SIXTH: According to the report obtained from the AXESOR tool, the entity
GAOLANIA SERVICIOS is a company incorporated in 2015, and with a

volume of business transactions of €172,191,969 in 2023....................................13

SEVENTH: On December 18, 2024, the Director of the Spanish Data Protection Agency

agreed to initiate sanction proceedings against the
respondent, in accordance with the provisions of Articles 63 and 64 of Law 39/2015, of

October 1, on the Common Administrative Procedure of Public Administrations
(hereinafter, LPACAP), for the alleged infringement of Article 6.1 of the
GDPR, classified in Article 83.5 of the GDPR........................................................13

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 2/47

EIGHTH: The aforementioned initiation agreement was notified in accordance with the rules established

in Law 39/2015, of 1 of October, of the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), the respondent submitted a statement of allegations on January 6, 2025, requesting the dismissal of the present sanctioning procedure and formulating, in summary, the following considerations:

................................................................................................................14

TENTH: Notification of the proposed resolution...............................................14

ELEVENTH: Allegations against the proposed resolution...........................................14

PROVEN FACTS................................................................................................15

FIRST: The claimant held an electricity contract with

***COMPANY.1, with CUPS number ***REFERENCE.1 and supply address

“***ADDRESS.1”, as shown on the invoice sent by ***COMPANY.1 on January 4, 2023, to their email address, which was submitted with the claim..............15

SECOND: On January 26 In 2023, there was a change of ownership and supplier of the claimant's electricity contract, in favor of

GAOLANIA, as indicated by GAOLANIA itself in its letter of June 14,

2023, in response to the transfer of the claim.....................................................15

THIRD: According to what was indicated in GAOLANIA's letter of June 14,

2023, “The quality department of ***COMPANY.2 made a data verification call

on January 27, 2023, (…) in which it was confirmed that [the
interlocutor] provided a CUPS code different from the one initially provided, according to the recording

with Reference “2_Quality verification call ***COMPANY.2” specifically at

minute 7 and 31 seconds:..........................................................................................16

FOURTH: As indicated by the claimant in an email sent on January 28,

On January 27, 2023, at 10:23 AM, at ***EMAIL.1, a copy of which is attached to the claim, received an SMS from ***COMPANY.1 on their mobile phone with the following text:

“Info ***COMPANY.1: Your distributor has accepted the change of supplier requested by you, which implies cancellation of your contract with ***COMPANY.1. Info

at ***PHONE.1”.................................................................................................16

FIFTH: On January 30, 2023, the claimant sent an email to

***EMAIL.3, a copy of which is attached to this claim, with the subject line “Request for
CUPS withdrawal: ***REFERENCE.1” and the following content: “(…) I confirm
that you have made an error in notifying ***COMPANY.1 of the change of ownership and

of the electricity supplier (now yours) for the property located at

ADDRESS.1. The account holder for that property remains my
mother, A.A.A., who resides in that property. SHE HAS NEVER REQUESTED

A CHANGE OF OWNERSHIP OR ELECTRICITY SUPPLIER, and wishes to maintain the contract signed with ***COMPANY.1.

Exercising our right of withdrawal, please inform ***COMPANY.1

that A.A.A. wishes to maintain the same contract with ***COMPANY.1, corresponding

to the CUPS code: ***REFERENCE.1. (…)”.......................................................................17

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 3/47

SIXTH: On February 3, 2023, an email was sent to the claimant from

EMAIL.2, a copy of which is attached to this claim, with the following content:

“Good afternoon, Following our conversation, I confirm that a replacement has been requested

since the distributor's initial request was rejected, it has been requested
again. We are awaiting authorization for the replacement.”...........................17

SEVENTH: On February 9, 2023, the claimant sent an email to

***EMAIL.2 and ***EMAIL.3, a copy of which is attached to this claim, with the subject

“CUPS: ***REFERENCE.1. Error in changing the account holder and supplier” and the
following content: “(…) We have never requested a change of account holder or
supplier. Our details are: Account Holder (before you

changed it): A.A.A., with ID number ***NIF.1. Address where the electricity is supplied:

***ADDRESS.1. CUPS: ***REFERENCE.1. Although we should not
request a cancellation of something we did not do, the fact is that today is the

14-day period in which the right of withdrawal can be exercised. In this
case, it would be a REPLACEMENT of the account holder and supplier. The energy supplier

***COMPANY.1 tells us that if you do not request a replacement, it cannot

be provided. We have no record that GAOLANIA SERVICIOS, S.L. has actually
requested a replacement, despite the repeated requests we have made
to you in writing and by telephone. Please, B.B.B., send us a copy of

the replacement request you have sent to the distributor i-DE, Redes Eléctricas
Inteligentes, S.A.U., and contact me today to inform me of
what is happening. (…)”..................................................................................17

EIGHTH: On February 9, 2023, an email was sent to the claimant,

a copy of which is attached to this claim, from ***EMAIL.2, with the subject “CUPS:

REFERENCE.1. Error changing ownership and supplier” and the

following content: “Good afternoon, We have requested the reinstatement of your contract from the distributor again on

06/02/23. The request numbers are

***REFERENCE.2 and ***REFERENCE.3. Best regards.”..............................................17

NINTH: On February 10, 2023, an email was sent to the claimant,

a copy of which is attached to the claim, from ***EMAIL.4, with the subject

“[REF_***REFERENCE.4] CUPS: ***REFERENCE.1. Error changing ownership

and supplier” and the following content: “Good afternoon: The reinstatement of your
supply with CUPS ***REFERENCE.1 has been requested and we are awaiting
a response from ***COMPANY.1 ELECTRIC DISTRIBUTION S.A.We will keep you informed.

......................................................................................18

TENTH: On March 3, 2023, the claimant sent an email, a copy of which is attached to this claim, to ***EMAIL.3, with the subject

“[REF_***REFERENCE.5] CUPS: ***REFERENCE.1. Error when changing the ownership

and the supplier” and the following content: “Good afternoon: On February 26, 2023, GAOLANIA SERVICIOS, S.L. requested a change of ownership and supplier from i-DE, mistakenly entering the CUPS number ***REFERENCE.1, which

corresponds to our supply at ***ADDRESS.1. Upon being notified by

COMPANY.1 that such changes in ownership and

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 4/47

supplier, we demanded that GAOLANIA immediately rectify these
errors, so that the service would return to the same point it was at before
their intervention. Although GAOLANIA informs us that they have repeatedly

requested the restoration of the service,
***COMPANY.1 insists that THEY HAVE NOT
RECEIVED THESE REQUESTS FROM GAOLANIA, AND THAT THEY HAVE ALREADY
INFORMED GAOLANIA HOW THEY SHOULD PROCEED. THEY DO NOT UNDERSTAND

WHY GAOLANIA IS NOT RESPONDING WITH THE DOCUMENTS THAT THEY
INDICATE (C1-08 or C2-08). In the email dated February 27, GAOLANIA was informed

of the procedure to follow to request the restoration of the supply.”......................18

ELEVENTH: On March 7, 2023, an email was sent to the claimant, a copy of which

is attached to the claim, from ***EMAIL.4, with the subject:

“[REF_***REFERENCE.5] CUPS: ***REFERENCE.1. Error changing ownership

and the energy supplier” and the following content: “Good morning, We inform you that the

replacement has been requested, as you requested.”.....................................18

TWELFTH: On June 14, 2023, an email was sent to the claimant,

a copy of which is attached to the GAOLANIA letter of June 14, 2023, from

***EMAIL.5, with the subject “QUALITY APOLOGY ***COMPANY.2” and the following

content: “This email serves to reiterate our sincerest apologies

from the Quality Department of ***COMPANY.2. We deeply regret the
situation you experienced due to the incorrect CUPS code issued by one of our

customers. Please be assured that appropriate measures are being taken

to prevent similar cases from occurring again. Receive our warmest regards and
we are at your service.”.......................................................................................18

THIRTEENTH: On June 14, 2023, an email was sent to several
recipients of the domain ***DOMAIN.1, a copy of which is attached to the letter from

GAOLANIA dated June 14, 2023, with the subject “ALWAYS verify before
submitting the contract to the distributor” and the following content: “Good morning verification team,

I remind you that it is a PRIORITY that, when verifying

data with a client regarding their contract, this verification is carried out BEFORE the contract
is submitted to the Distributor, as explained in the department's
procedures. Greetings...........................................................................................18

LEGAL BASIS.................................................................................19

I. Jurisdiction......................................................................................................19

II. Preliminary Issues............................................................................................19

III. Breach of Obligation. Accuracy......................................................................20

IV. On the Change in Legal Classification Made in the Proposed Resolution

Proposed Resolution and the Allegations Submitted to the Initiation Agreement..................................24

V. Allegations to the Proposed Resolution.........................................................24

FIRST: Regarding the violation of the principle of accuracy in the processing of data

under Article 5.1 GDPR.................................................................................24

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 5/47

SECOND: Analysis of the Circumstances that Determine the Sanction. The Proposed
The resolution omits all circumstances that mitigate the responsibility of the data controller.

............................................................................30

THIRD: The aggravating factor considered in the proposed resolution has already been included in the assessment of the infringement..........................................................................40

FOURTH: Adoption of new additional internal measures...............................41

VI. Classification of the infringement and its classification for the purposes of the statute of limitations........42

VII. Sanction to be imposed on GAOLANIA..............................................43

BACKGROUND

FIRST: On March 29, 2023, a complaint was filed with the Spanish Data Protection Agency regarding a possible infringement attributable to GAOLANIA SERVICIOS, S.L., with Tax Identification Number (NIF) B98717457 (hereinafter, GAOLANIA SERVICIOS or the respondent).

The facts brought to the attention of this authority were:

The complainant stated that, having an electricity supply contract with The

commercial company ***COMPANY.1, and its distributor ***COMPANY.3,
became aware that GAOLANIA SERVICIOS had requested a change of ownership of its supply and a switch to the commercial company GAOLANIA SERVICIOS, without its consent.

The following documents were submitted with the written complaint:

- An email sent to ***COMPANY.1 by the complainant on January 28, 2023, indicating that on January 27, 2023, they received a text message from
***COMPANY.1 informing them of the cancellation of their service after the request to switch

commercial companies was accepted, and the complainant stated that they had not requested said switch.

- Emails sent to the complainant by ***COMPANY.1 in response to the previous email, on January 28 and 30, 2023, stating the following: “1) we cannot contact you to inform you, Since the same data protection law prevents us from accessing your data without your consent,

we cannot exert any force when retaining a contract given the current legislation, which obliges us to transfer the data to another company at the express request of the distributor responsible for the supervision and maintenance of the supply. In this case, ***COMPANY.4. If a change of company has occurred without your consent, you must contact the company responsible for making the change and file the corresponding complaint with them, since if the issue is resolved within the 14-day period established for withdrawal, your contract will be reinstated with us.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 6/47

- Emails sent to GAOLANIA SERVICIOS by the complainant on January 30, February 9, and March 3, 2023, indicating that they had not requested any contract, and on February 10, 2023, requesting the cancellation of the changes of ownership and company, as well as the reinstatement of their contract.

- Emails sent by GAOLANIA SERVICIOS to the complainant on February 3, 9, and 10, and March 7 March, informing of the request for reinstatement to
your distributor ***COMPANY.3.

- Emails sent by the claimant to ***COMPANY.3 on February 9, 2023, requesting the reinstatement of the supply account to
***COMPANY.1.

- Response from ***COMPANY.3 on February 17, 2023, stating the following: “We must inform you that it is your energy supplier who must correctly register any type of modification along with the supporting documentation in the contracts they manage. Therefore, we regret that we cannot assist you with a procedure that is beyond our jurisdiction, and for which we have neither the protocol nor the technical capacity” (sic).

SECOND: In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the guarantee of digital rights (hereinafter referred to as the LOPDGDD), the complaint was forwarded to GAOLANIA SERVICIOS,
so that it could analyze it and inform this Agency within one month,

of the actions taken to comply with the requirements of the
data protection regulations.

On June 14, 2023, this Agency received a written response from
GAOLANIA SERVICIOS, stating the following:

1. That the request to change suppliers to GAOLANIA SERVICIOS
was processed by telephone call in which a third party (a customer of the
entity) provided the Universal Supply Point Code (CUPS), an essential piece of information
to carry out the change of supplier with the distributor.

A transcript of the conversation has been attached as documentary evidence,

providing their CUPS: (…).

2. That in the call made by the data controller to the aforementioned third party (customer) 24 hours later, for data verification, a different CUPS code was provided: (...).

3. That, in parallel, the data controller managed the change of energy supplier through the distribution company. However, once the error was detected, the data controller contacted the distribution company again to cancel the change.

4. Coincidentally, the incorrectly provided CUPS code belonged to another property (which is why the distribution company was able to process it); thus affecting the owner of this property (the complainant).

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 7/47

5. That it is concluded that the events that gave rise to the complaint stem from a human error on the part of the customer when providing the property's meter number (CUPS code).

6. That a copy of the communication sent to both the third party and the complainant, informing them of the error and the actions taken to resolve it, has been provided.

THIRD: On June 29, 2023, in accordance with Article 65 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights), the complaint was admitted for processing.

Subsequently, by resolution dated August 10, 2023, the complaint was archived, as it was understood that it had been addressed and, therefore, that the initiation of a sanctioning procedure was not warranted.

FOURTH: On August 16, 2023, the complainant filed an optional appeal for reconsideration through the Electronic Registry of the Spanish Data Protection Agency (AEPD) against the resolution issued in file EXP202306737, expressing her disagreement with the contested resolution.



On February 13, 2024, a resolution was issued upholding the appeal for reconsideration filed by the claimant, highlighting the following:

“In this case, the CUPS number was not properly verified. On the contrary, the Commercial Department of GAOLANIA
SERVICIOS, S.L. requested a change of supplier to ***EMPRESA.1

on January 27, before the data verification had actually taken place. Therefore, the CUPS code corresponding to the appellant's address (***ADDRESS.1), which was unrelated to the contract, was used, instead of the one that appeared in the contract signed by a third party (***ADDRESS.2), which was completely different.

No verification was carried out to ensure that the CUPS code corresponded to the contract, neither through the address nor through the verification call that GAOLANIA
SERVICIOS, S.L. claims to have made. Instead, the change was processed.” directly,
causing harm to the appellant, who was not involved in the contract being

executed. Therefore, in this case, the appeal
filed should be upheld.”

FIFTH: The Deputy Directorate General for Data Inspection carried out
preliminary investigative actions to clarify the facts in
question, pursuant to the functions assigned to supervisory authorities in

Article 57.1 and the powers granted in Article 58.1 of Regulation (EU)
2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VIII of the LOPDGDD.

As a result of the actions taken, the following information has been obtained:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 8/47

It was verified that GAOLANIA submitted the following in entry ***REFERENCE.7:

Annex 1 with a copy of the contract signed with the third party on January 26, 2023

including the claimant's CUPS code,
Annex 2 with a copy of the communication sent
to the claimant on June 14, 2023 informing them of the error, and
Annex 3 with the instructions addressed to the Quality Department on the same date.

It was verified that said contract was signed on January 26, 2023, prior to
the data verification call of January 27, 2023.

Once the error was detected, GAOLANIA contacted the distributor again to cancel the change, as evidenced by the documents provided by the claimant (replacement request numbers ***REFERENCE.2 and ***REFERENCE.3).

It was verified in the claim documentation that these two numbers corresponded to the request numbers provided by GAOLANIA to the claimant in an email dated February 9, 2023, informing them that they had requested the replacement of the contract from the distributor on February 6, 2023.

GAOLANIA has stated that:

- This manager has adopted a series of measures to prevent the
repetition of similar errors in the future:

a) The Quality Department will make verification calls to customers before

proceeding with the change of energy supplier, to confirm that the data
provided by the customer is correct (see ANNEX 3 of 14/6/2023).

Additionally, the feasibility of the following measures is being analyzed:

b) Requesting the customer to take a photo or copy of the document where the CUPS code is located

so that it can be verified by ***COMPANY.2 personnel.

c) Requesting all customers to perform an additional verification at the time of
signing the contract.”

Regarding the response to the request dated May 8, 2024, by

GAOLANIA:

1. A copy of the Record of Personal Data Processing Activities is provided, specifically regarding the personal data processing activities carried out
in the context of the service contract with GAOLANIA
SERVICIOS S.L., as detailed in ANNEX 1.

Page 11 shows that the identified risk level for Customer data processing is Moderate. The risk of identity theft is only considered
for the High and Very High risk levels. In the case
in question, an erroneous change of supplier and account holder occurred

based on an incorrect CUPS code that corresponds to a different account holder than the
claimant.


C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 9/47

2. A description of the procedure for changing energy suppliers to

GAOLANIA SERVICIOS S.L. for an individual is provided, specifying the
differences depending on whether or not there is a change of ownership.

a. Current regulations and protocols governing the procedure.

“As applicable regulations to the parties involved and the process of changing suppliers, we highlight Directive (EU) 2019/944 of the European Parliament and of the Council of 5 June 2019, Royal Decree 1955/2000 of 1 December,

which regulates the activities of transport, distribution,
marketing, supply and authorization procedures for electrical energy installations,
and Law 24/2013 of 26 December, on the Electricity Sector.

However, the Resolution of 20 December 2016,

issued by the Regulatory Oversight Chamber of the CNMC, is essential, approving

the new formats for the information exchange files between
distributors and suppliers. This resolution was subsequently
amended in 2019.

This Resolution establishes the processes between supplier and distributor,

file exchange formats and steps to be followed to execute
contracts, changes and Withdrawals.

The information exchange files referred to in the aforementioned resolution
are standardized documents, approved by the National Commission

for Markets and Competition, which regulate the flow of communications or
messages between the affected parties to execute a commercial process.

These files define the communication procedures between electricity and gas distributors
and retailers and are regulated in Annexes I and II,
respectively, of the aforementioned resolution.

The documentation and processes for registering a new supply point
are completely separate from the contracting process for changing energy suppliers.

In turn, changing energy suppliers can be done without changes or with changes in
ownership.

Before contracting, the contracting party is asked to provide all the necessary
data for the supplier change process. Once the data has been collected by the customer, the protocol in file A5_29 (Request for
information on a supply point prior to contracting) is followed.

This process requests the technical data of the supply point to be contracted
in real time. and compares it with the data provided by the
potential customer.

Once verified, the corresponding protocol is followed, which

allows the exchange of information between the incoming supplier, the
outgoing supplier, and the distributor for a supplier change or
for activation at a supply point.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 10/47

These protocols are the only channels for changing
suppliers and are carried out electronically in accordance with the
provisions established by the CNMC.

The distributor verifies the data and can pause the process, cancel it, or request additional information if an error is detected. The distribution company is the one that knows the exact details of the previous owner—CUPS code, etc.

Finally, the distributor authorizes the change and proceeds to implement it at the supply point.

On the other hand, ***COMPANY.2 establishes internal training manuals for the correct use of the supplier change files.

At this supply point, ***COMPANY.2 submitted a request with code

C2-01 CT (change of supplier with change of account holder) on

01/26/2023:”

It is verified that a screenshot is provided with this information, showing

the CUPS code ending in (...) corresponding to the claimant.

It is verified that there is no data related to the account holder's information or the
address of the supply point. The CUPS code is the field that uniquely identifies
the supply point.

“On the same day, ***COMPANY.2 receives confirmation from the distributor with code

C2-02A CT (acceptance of the change):”

It is verified that a screenshot is provided with this information, showing

the CUPS code ending in (...).

It is verified that there is no data related to the account holder's information or the
address of the supply point.

b. Identification of who can initiate the change request and mechanisms for

verifying the circumstances that allow it endorse.

“A person with access to the supply point data could process a
new contract under their responsibility. All data must be provided
by the contracting party.

The customer guarantees the truthfulness and accuracy of the data provided and assumes
the consequences arising from erroneous or incorrect data indicated in
the request.

The advanced electronic signature certificate verifies the telephone number used for
the signature and the email address used to download the contractual
documents, along with the IP address used to sign the contract.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 11/47

c. List of parties involved in the procedure with a description of the actions performed by each.

“According to Annex I of the Resolution of December 20, 2016, issued by the Regulatory Oversight Chamber of the CNMC, the following parties are involved:

(i) Current Supplier: Active energy supplier at a supply point. For the purposes of contract termination, this is the supplier that requests the distributor to terminate a previous access contract.

(ii) New Supplier: New supplier that requests the distributor to change the supplier in its favor or to register a new supply.

(iii) Outgoing Supplier: Supplier that ceases supplying the consumer once the switching process has been completed and the change of supplier is effective.

(iv) Distributor: Owner of the distribution network where the supply point is located, responsible for the information system for the supply points and for meter reading at the consumption points. It carries out essential procedures for processing requests to change suppliers.

Their respective definitions and details of their obligations can also be found in the Electricity Sector Law.”

d. Specification of the existing channels for requesting a change.

“The only existing and authorized channel for requesting a change is detailed in section a. and is expressly included in the Resolution of December 20, 2016, issued by the Regulatory Oversight Chamber of the CNMC.

The distributor and the supplier only exchange information through this electronic channel.”

e. List of data and, where applicable, copies of documents that the supply point holder must provide to request the change.

“The data that the customer must provide to process the contract are the following: (i) name and surname, (ii) ID/Tax ID number, (iii) telephone number, (iv) email address, (v) CUPS code, (vi) address of the supply point (street, number, clarification, postal code), (vii) bank details for direct debit payment.

The regulations do not require any documentation to be submitted to proceed with the change.

However, in some cases, or in the event of disputes regarding changes of ownership, additional documentation or previous invoices for the supply point may be requested.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 12/47

f. Where applicable, mechanisms used to verify that the change of
supplier
with and without a change of ownership has been consented to by the original owner of the
supply point.

“These are not required from the incoming supplier.”

g. List of evidence stored to verify that the procedure has been
followed correctly.

“***COMPANY.2 stores the contractual documents,

commercial calls made, if any, and advanced electronic signature certificates
that guarantee the authenticity of the signature.

Furthermore, the history of communications between the supplier and
distributor for processing the change of supplier can be

verified through the electronic .xml files issued by both parties.”

3. Evidence available in response to the previous questions
regarding the change of supplier and ownership
of the affected electricity CUPS code, which occurred on the indicated date, and
which has not yet been submitted.

(…)

It is verified that Royal Decree 1435/2002, of December 27, which
regulates the basic conditions of energy purchase contracts and
access to low-voltage networks, was amended by Royal Decree

1074/2015, of November 27, which modifies various provisions
in the electricity sector. Article 2 of the aforementioned Royal Decree approved
an amendment to Article 7.2 of Royal Decree 1435/2002,

including that: “In any case, neither the energy suppliers nor the
National Commission on Markets and Competition may access
any information that directly identifies the owner of the

supply point […]”.

       It is verified that the CNMC provides the following in document IS/DE/014/21 of December 22, 2022, in its Annex II, “Recommendations to marketers and distributors to reduce the incidence and mitigate the harm caused by CUPS code overlaps,” subsequent to the date of the events of January 26, 2023:

“A. Recommendations for marketers to reduce the incidence of CUPS code overlaps. The following recommendations are formulated to facilitate the verification of information by marketers in case of detecting inconsistencies (either through the consumer themselves or via messaging with the distributor through which they receive information using Format P0 for electricity or A5_29 for gas) or due to rejections during the process of switching marketers:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 13/47

1. It is recommended that the staff of the Customer Service Departments (CSD) of energy suppliers receive more appropriate training. In particular, during the contracting process, they should be trained to identify and verify the correct

correspondence between the supply point address and the CUPS code, and both
with the CUPS code holder. They should also provide the consumer with
accurate and correct information and advise them on how to proceed in these cases, and
also identify subsequent requests to cancel the access contract
whose origin may be a “CUPS code mismatch.”

2. During the contracting process, it should be verified whether the consumer claims to be the holder
of the supply point at the indicated address, and it should be confirmed that they are the user
with the rightful title.

3. In any case, if a change is made without contractual modifications

(Formats C1 or A1_02) and is subsequently rejected, the data should be checked
again with the contracting consumer in general, and in
particular, it should be ensured that the supply point address and the CUPS code
are correct, before sending a new request to change

the energy supplier. of the account holder (Formats C2 or A1_41). […]”

(…)

According to Gaolania, in the telephone request of 1/26/2023 to change the
energy supplier, a third party (a customer of the company, different from the
claimant) provided the Universal Supply Point Code (CUPS), information

essential to carry out the change of supplier with the
distributor. A transcript of the conversation is attached, providing
the CUPS: (...) (which corresponds to the claimant). (…) Gaolania concludes that the
events stem from a human error by the customer when reciting the meter number
of the property (CUPS).

SIXTH: According to the report obtained from the AXESOR tool, the entity
GAOLANIA SERVICIOS is a company incorporated in 2015, with a turnover of €172,191,969 in 2023.

SEVENTH: On December 18, 2024, the Director of the Spanish Data Protection Agency

agreed to initiate sanction proceedings against the respondent,
in accordance with the provisions of Articles 63 and 64 of Law 39/2015, of October 1,
on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), for the alleged infringement of Article 6.1 of the GDPR, as defined in
Article 83.5 of the GDPR.

EIGHTH: Having been notified of the aforementioned initiation agreement in accordance with the regulations established in
Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), the respondent submitted a statement of allegations on January 6, 2025, requesting the dismissal of these sanctioning proceedings and formulating, in summary, the following considerations:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 14/47

- Preliminary point: the appeal for reconsideration was directed against another company for reasons unrelated to the initiation agreement of the sanctioning proceedings, and its resolution was not notified to GAOLANIA SERVICIOS.

- First allegation: ***COMPANY.2 cannot verify the address in the distributor's database during the contracting process.

- Second allegation: Processing of CUPS data provided by the client and absence of
infringement of Article 6.1 of the GDPR. Lack of unlawfulness and culpability.

Presumption of innocence. ***COMPANY.2 acted in good faith and with the utmost diligence.

- Third allegation: Violation of the principle of proportionality. Lack of gradation
of the sanction. Aggravating circumstances considered in the initiation agreement and lack of consideration
of mitigating circumstances.

NINTH: Proposed resolution. Change of legal classification.

The proposed resolution introduces a change in the legal classification that the
initiation agreement made of the conduct for which GAOLANIA
SERVICIOS is held responsible. The proposal considers that the conduct that is the subject of the

claim does not constitute an infringement of Article 6.1. of the GDPR, but rather a violation of Article 5.1.d) of the GDPR, the principle of data accuracy (particularly regarding the CUPS personal data that was processed).

Consequently, on October 15, 2025, the proposed resolution was formulated as follows:

“That the President of the Spanish Data Protection Agency sanction GAOLANIA SERVICIOS, S.L., with Tax Identification Number B98717457, for an infringement of Article 5.1.d) of the GDPR, as defined in Article 83.5 of the GDPR, with a fine of €30,000.”

TENTH: Notification of the proposed resolution.

The notification, carried out electronically in accordance with the LPACAP (Law on Administrative Procedure of Public Administrations), was made available to GAOLANIA SERVICIOS on October 15, 2025, the date on which the notification was accepted by the respondent, as evidenced by the document in the administrative file that confirms both points.

ELEVENTH: Allegations against the proposed resolution.

On October 29, 2025, the respondent submitted its allegations against the proposed resolution. It requested that the proceedings be dismissed.

Alternatively, it requested that the least restrictive measure be imposed in accordance with Article 83 of the GDPR, imposing the minimum penalty.

GAOLANIA SERVICIOS structures its arguments through a preliminary allegation, which provides a chronological description of the facts, and four

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 15/47

allegations whose content, in essence, reiterates what was already alleged in its previous submission,
specifically:

- First allegation: Regarding the violation of the principle of accuracy of data processing under Article 5.1 GDPR.

- Second allegation: Analysis of the circumstances that determine the severity of the sanction. The proposed resolution omits all those circumstances that mitigate the responsibility of the data controller.

- Third allegation: The aggravating factor considered in the proposed resolution has already been included in the assessment of the infringement.

- Fourth allegation: Adoption of new additional internal measures.

From the actions taken in this proceeding and the documentation contained in the file, the following facts have been established:

PROVEN FACTS

FIRST: The claimant held an electricity contract with ***COMPANY.1, with CUPS number ***REFERENCE.1 and supply address “***ADDRESS.1”, as shown in the invoice sent by ***COMPANY.1 on January 4, 2023, to their email address, which was submitted with the claim.

SECOND: On January 26, 2023, the claimant's electricity contract was transferred to GAOLANIA, as indicated by GAOLANIA itself in its response to the claim dated June 14, 2023.


According to the document, “according to the voice recording of the aforementioned conversation, with Reference: “1_Call from collaborator to Mr. MEJ” and specifically
at 1 minute and 32 seconds, the caller dictates the CUPS number to the
telemarketer: Transcript 1:
Telemarketer:
“(…) Now then, I would also like to inform you that at your address at ***ADDRESS.2.

Please provide the CUPS number (…)”
Caller's response:
“***REFERENCE.1 (…)”

The recording of this call is also submitted with the written objections to the

initiation agreement of this sanctioning procedure.

As indicated by GAOLANIA in its letter of March 5, 2024, “At this
supply point, ***COMPANY.2 submitted a request with code C2-01 CT (change of
supplier with change of account holder) on 01/26/2023.” A screenshot of this request is attached.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 16/47

And “On the same day, ***COMPANY.2 received confirmation from the distributor with code C2-

02A CT (acceptance of the change).” A screenshot of this confirmation is attached. such confirmation.

THIRD: According to what is indicated in the GAOLANIA document of June 14, 2023, “The quality department of ***COMPANY.2 made a data verification call on January 27, 2023, (…) in which it was confirmed that [the

caller] provided a CUPS code different from the one initially provided, according to the recording
with Reference “2_Quality verification call ***COMPANY.2” specifically at
minute 7 and 31 seconds:

Transcript 2:
Telemarketer:

“(…) and below is the CUPS code, c, u, p, s, do you see that it starts with ES and is a very long number?”

[Interlocutor]: “Ah! Yes, CUPS, yes, CUPS.”

Telemarketer: “Okay, please tell me.”
[Interlocutor]: “***REFERENCE.6”

According to what GAOLANIA indicated in its letter of June 14, 2023, regarding the actual facts that motivated the claim, “in this case, they correspond to a human error on the part of the customer when reciting the meter number of the property (CUPS), and it is confirmed that this is an isolated case since nothing similar had ever happened in the eight years since the founding of ***COMPANY.2.”

FOURTH: According to the claimant in an email sent on January 28, 2023, to ***EMAIL.1, a copy of which is attached to this claim, on January 27, 2023,

at 10:23 a.m., she received an SMS from ***COMPANY.1 on her mobile phone with the following text:
“Info ***COMPANY.1: Your distributor has accepted the change of supplier
requested by you, which implies cancellation of your service with ***COMPANY.1. Info at
***PHONE.1.”

That same day, the claimant contacted ***COMPANY.1, stating that she had not

requested the change of supplier, and was referred to the I-DE Distributor of the
***COMPANY.1 GROUP, where she was informed that the previous day there had been
a change of ownership and supplier, in favor of GAOLANIA SERVICIOS S.L.

The claimant also indicates that she has filed a claim requesting the

withdrawal of said cancellation.


C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 17/47

FIFTH: On January 30, 2023, the complainant sent an email to
***EMAIL.3, a copy of which is attached to this complaint, with the subject line “Request for withdrawal of CUPS: ***REFERENCE.1” and the following content: “(…) I confirm that you have made an error in notifying ***COMPANY.1 of the change of ownership and
supply company (now yours) for the property located at

***ADDRESS.1. The account holder for the electricity supply to that property remains my mother,
A.A.A., who resides in said property. SHE HAS NEVER REQUESTED A CHANGE OF
OWNERSHIP OR ELECTRICITY SUPPLIER,
and wishes to maintain the contract signed with ***COMPANY.1. Exercising our right of withdrawal, we kindly request that you inform ***COMPANY.1 that A.A.A. wishes to maintain the same contract with ***COMPANY.1, corresponding to the CUPS code:

***REFERENCE.1. (…)”.

SIXTH: On February 3, 2023, an email was sent to the claimant from ***EMAIL.2, a copy of which is attached to this claim, with the following content: “Good afternoon,
Following our conversation, I confirm that a replacement has been requested, as it was rejected by the distributor. We have requested it again.

We are awaiting authorization for the replacement.”

SEVENTH: On February 9, 2023, the claimant sent an email to
***EMAIL.2 and ***EMAIL.3, a copy of which is attached to this claim, with the subject
“CUPS: ***REFERENCE.1. Error when changing the account holder and energy supplier” and the following content: “(…) We have never requested a change of account holder or

energy supplier. Our details are: Account Holder (before you changed it):
A.A.A., with ID number ***NIF.1. Address where the electricity is supplied:
***ADDRESS.1. CUPS: ***REFERENCE.1. Although we shouldn't
request a cancellation of something we didn't do, the fact is that today marks the end of the 14-day period in which the right of cancellation can be exercised. In this case,
it would be a REPLACEMENT of the account holder and energy supplier. The energy supplier ***COMPANY.1

tells us that if you Since they do not request a replacement, it cannot be granted.
We have no record that GAOLANIA SERVICIOS, S.L. has actually requested a replacement, despite repeated requests we have made to them in writing and by telephone. Please, B.B.B., send us a copy of the replacement request that you have sent to the distributor i-DE, Redes Eléctricas Inteligentes, S.A.U., and contact me today to inform me of what is happening. (...)”

EIGHTH: On February 9, 2023, an email was sent to the claimant, a copy of which is attached to this claim, from ***EMAIL.2, with the subject “CUPS:
***REFERENCE.1. Error when changing the ownership and the supplier” and the following content: “Good afternoon, We have again requested the replacement of your contract from the distributor on 06/02/23. The application numbers are

***REFERENCE.2 and ***REFERENCE.3. Best regards.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 18/47

NINTH: On February 10, 2023, an email was sent to the claimant, a copy of which is attached to this claim, from ***EMAIL.4, with the subject
“[REF_***REFERENCE.4] CUPS: ***REFERENCE.1. Error when changing the account holder and
the energy supplier” and the following content: “Good afternoon: The restoration of your
supply with CUPS ***REFERENCE.1 has been requested and we are awaiting

a response from ***COMPANY.1 ELECTRICAL DISTRIBUTION S.A. We will keep you informed.”

TENTH: On March 3, 2023, the claimant sent an email, a copy of which is attached to this claim, to ***EMAIL.3, with the subject line
“[REF_***REFERENCE.5] CUPS: ***REFERENCE.1. Error when changing the account holder and

the energy supplier” and the following content: “Good afternoon: On February 26, 2023,
GAOLANIA SERVICIOS, S.L. requested i-DE to change the account holder and
the energy supplier, mistakenly entering the CUPS number ***REFERENCE.1, which
corresponds to our supply at ***ADDRESS.1. When ***COMPANY.1 notified us
that these changes in account holder and energy supplier had occurred, we requested
GAOLANIA to immediately correct these errors so that the service

would return to the same state it was in before their intervention. Although
GAOLANIA repeatedly informed us that They have requested the restoration of service.

***COMPANY 1 insists that they have NOT received these requests from Gaolania, and that they have already informed Gaolania how they should proceed. They do not understand why Gaolania is not responding with the documents they requested (C1-08 or C2-08). In the email of February 27th,

Gaolania was informed of the procedure to follow to request the restoration of the supply.

ELEVENTH: On March 7, 2023, an email was sent to the claimant, a copy of which is attached to this claim, from ***EMAIL.4, with the subject:
“[REF_***REFERENCE.5] CUPS: ***REFERENCE.1. Error changing the ownership and

the energy supplier” and the following content: “Good morning, We inform you that the replacement has been requested, as you requested.”

TWELFTH: On June 14, 2023, an email was sent to the complainant, a copy of which is attached to GAOLANIA's letter of June 14, 2023, from ***EMAIL.5, with the subject line “QUALITY APOLOGY ***COMPANY.2” and the following

content: “This email serves to reiterate our sincerest apologies
from the Quality Department of ***COMPANY.2. We deeply regret the situation you experienced due to the incorrect CUPS code issued by one of our clients. Please be assured that appropriate measures are being taken
to prevent similar cases from occurring again. Sincerely,

we remain at your disposal.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 19/47

TENTH THIRD: On June 14, 2023, an email was sent to several recipients
from the domain ***DOMAIN.1, a copy of which is attached to GAOLANIA's letter of June 14, 2023, with the subject line “ALWAYS verify before sending the contract to the

distributor” and the following content: “Good morning verification team, I remind you that it is a PRIORITY that, when verifying a client's contract, this verification is carried out BEFORE the contract is sent to the
Distributor, as explained in the department's procedures.
Regards.”

LEGAL BASIS

I
Jurisdiction

In accordance with the powers conferred upon each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR) and as established in Articles 47, 48.1, 64.2 and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter LOPDGDD), the Presidency of the Spanish Data Protection Agency is competent to resolve this procedure.


Likewise, Article 63.2 of the LOPDGDD (Spanish Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) stipulates that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the implementing regulations issued thereunder, and, insofar as they do not contradict them, subsidiarily, by the general rules on administrative procedures."

II. Preliminary Issues

Article 4.1 of the GDPR defines "personal data" as:

"any information relating to an identified or identifiable natural person ("data subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier,

such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person."

Article 4.2 of the GDPR defines "processing" as:

"any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction."

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 20/47

Article 4.7 of the GDPR defines "controller" as:

"the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing; where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its appointment may be laid down by Union or Member State law."

Article 4.7 of the GDPR defines "processor" as:

"the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller."

"the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller." In this case, in accordance with Articles 4.1 and 4.2 of the GDPR,
the processing of personal data is established, since GAOLANIA SERVICIOS carries out, among other processing activities, the collection and storage of personal data of natural persons, such as: name and surname, telephone number, address, and email address.

GAOLANIA SERVICIOS carries out this activity in its capacity as data controller, as it is the entity that determines the purposes and means of such activity, pursuant to Article 4.7 of the GDPR.

III. Obligation breached. Accuracy

Article 5, “Principles relating to processing,” states:

“1. Personal data shall be: (…)

(d) accurate and, where necessary, kept up to date; every reasonable step shall be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);

With regard to this principle, Recital 39 of the GDPR, among other things, indicates that: “(39) (…) in order to ensure that personal data are not kept longer than necessary, the controller shall establish time limits for their erasure or periodic review. Every reasonable step should be taken to ensure that inaccurate personal data are rectified or erased.”


And recital 71: “(...) in order to ensure fair and transparent processing
with regard to the data subject, taking into account the specific circumstances and context
in which the personal data are processed, the controller should use
appropriate mathematical or statistical profiling methods,
implement appropriate technical and organizational measures to ensure, in particular, that

factors which introduce inaccuracies into the personal data are corrected and
the risk of error is minimized, secure personal data in a manner which takes into account the possible risks to the interests and rights of the data subject and

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 21/47

prevent, inter alia, discriminatory effects on natural persons on the grounds of
race or ethnic origin, political opinions, religion or belief, trade union membership,
genetic status or health condition or sexual orientation, or processing which leads

to measures producing such effects.”

These provisions enshrine the principle of "accuracy," which requires the data controller to verify the accuracy of the data subject's information through the implementation of appropriate measures.

The conduct of the respondent that is the subject of this proceeding is related to the termination of the electricity supply contract that the complainant had for their home with ***COMPANY.1.

The termination of the complainant's electricity contract occurred because

GAOLANIA, when processing a change of supplier and ownership of the network access contract with the local distributor for a customer's home, linked these changes to an electricity CUPS code that was not held by the complainant, but rather by the complainant.

The documentation in the file also proves that GAOLANIA,

when managing the change of supplier, communicated through the SCTD,

following the format established by the CNMC, that the CUPS code was that of the
complainant.

In this regard, this Agency wishes to point out that, according to the transcript of the

conversations between GAOLANIA and the complainant, which are attached to the written response
to the transfer of the complaint, as well as the recording of the call of
January 26, 2023, submitted with the allegations against the agreement to initiate these
procedures, the following CUPS code was provided in the call that took place on January 26, 2023: ***REFERENCE.1 (that of the complainant); However, in the

call of January 27, 2023, to verify the details of the change of energy supplier, another supply point was provided (CUPS:
***REFERENCE.6), and despite these being different CUPS codes, GAOLANIA did not
perform any additional verification.

In this regard, the documentation in the file shows that

GAOLANIA violated the principle of accuracy because it processed inaccurate data, a CUPS code
that the person requesting the change of energy supplier did not own.

All processing of personal data must respect the principles governing it,
set out in Article 5 of the GDPR, including the principle of accuracy.

According to the GDPR, the data controller is obliged to take all reasonable measures at all times to ensure the accuracy of the personal data it collects or otherwise processes.

The activities or measures that the data controller must implement or adopt to ensure the accuracy of the data cannot translate into disproportionate demands, but "reasonable" measures are required, making it necessary to assess the purpose and context of the processing. In this regard, while

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 22/47

recital 39 of the GDPR refers to "reasonable measures to ensure that inaccurate personal data are rectified or erased," Article 5.1.d) of the GDPR links the accuracy of the data to the purposes for which it is processed.


C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 22/47 The National Court stated in its Judgment of 27/02/2008 (Appeal 210/2007)

that “The principle of truthfulness or accuracy is of great importance, insofar as it not only requires that data be collected for processing in accordance with a series of criteria (principle of proportionality) and that they be used for purposes compatible with those that motivated their collection (principle of purpose limitation), but also requires that whoever collects and processes personal data guarantee and protect that the information being processed is not inaccurate and is up-to-date. Failure to comply with or violation of the principle of truthfulness can have significant consequences for the data subject.” (Emphasis added)

Furthermore, Article 5.2. The GDPR incorporates the principle of proactive responsibility, whereby the data controller is responsible for compliance with paragraph 1 (and therefore, relevant to this discussion, paragraph d) and must be able to demonstrate such compliance. The principle of proactivity transfers to the data controller the obligation not only to observe the principles governing the processing, but also to be able to demonstrate such compliance.


It is worth mentioning Opinion 3/2010 of the Article 29 Working Party (WP29) -WP173-, issued during the validity of Directive 95/46/EC, which was repealed by the GDPR, but whose reflections are still applicable today. This Opinion considers the “essence” of proactive responsibility to be the obligation of the data controller to implement measures that, under normal circumstances, ensure compliance with data protection rules in the context of processing operations, and to have available documents demonstrating to data subjects and supervisory authorities what measures have been adopted to achieve compliance with the rules governing the fundamental right to the protection of personal data.

In previous paragraphs, it has been noted that, in accordance with Article 3 (“Formalization of access tariff and energy acquisition contracts”) of the Royal Decree... 1435/2002 allows consumers to choose to contract for energy and "access to the networks" through a supplier. In such cases, the supplier may only contract with the distributor for network access as the consumer's agent.

The incoming supplier is, in these cases, the customer's sole point of contact with the distributor. This explains why Article 3 of Royal Decree 1435/2002 stipulates that the supplier "transfers to the distributor the data necessary for supply." (Emphasis added) The data that the incoming supplier "transfers" to the distributor is, as indicated, the data that the incoming supplier has collected from its customer.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 23/47

Article 3 of Royal Decree Royal Decree 1435/2002 also reminds us that the incoming supplier, in this case GAOLANIA, as the data controller, is subject to the provisions of the GDPR. In this regard, it states:

“The collection, processing, and transfer of this data must at all times comply with the provisions established in the applicable regulations on the protection of personal data.” (Emphasis added)

The reference to data protection regulations made in the aforementioned Article 3 of Royal Decree 1435/2002 demonstrates the importance of reminding entities operating in the electricity sector that their specific regulations are not grounds for disregarding the obligations imposed on them by the regulations governing the fundamental right to the protection of personal data.

From the documentation in the file, it can be inferred that GAOLANIA did not collect or obtain from its client any document that would allow it to verify that he was the CUPS code holder. Furthermore, it can be inferred that the client did not even provide the CUPS code correctly, since he indicated a different CUPS number in each call.

The defendant, by virtue of the principle of accuracy that it is obligated to observe, should have been able to prove that the data provided as a result of the change of supplier was correct and that the CUPS code it was going to use matched that of the supply point for which its client was requesting a contract. At a minimum, it should have been able to prove that the CUPS code on which it carried out the supplier change procedures was indeed correct.

The defendant requested a change of energy supplier without verifying the accuracy of the data, to ensure the accuracy of the CUPS code, and without taking any other measures to guarantee beforehand that the CUPS code to be provided to the distributor was assigned to its client. This constitutes a clear lack of diligence in complying with the principle of accuracy, which requires taking measures to prevent the processing of inaccurate or erroneous data, such as verifying the accuracy of the data with its client, which it failed to do.

In this case, the element of culpability in the infraction—the presence of which is necessary for administrative liability to arise, since strict liability is prohibited in our legal system—lies in GAOLANIA's serious lack of diligence in complying with the principle of data accuracy.

The Supreme Court has consistently held that negligence exists whenever a legal duty of care is disregarded; that is, when the offending party does not act with the required diligence, which will be determined by considering the circumstances, such as the special value of the protected legal interest and the professional status of the offending party.

Applying the aforementioned doctrine, the National Court, among others in Judgments dated
February 14, 2002, September 20, 2002, and April 13, 2005, requires entities that process data to exercise special diligence when carrying out its use or processing, given that it concerns

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 24/47

the protection of a fundamental right of the individuals to whom it refers, and therefore, those responsible for processing must be especially diligent and careful when carrying out operations with them and always opt for the interpretation most

favorable to the protection of that right.

This absolute lack of diligence on the part of GAOLANIA is reflected in the mere fact that a different CUPS code was provided during the (precisely) data verification call. And that despite the fact that the CUPS number did not match the one initially
provided, no further checks were carried out, and the

supplier was changed without further action.

The foregoing considerations demonstrate that GAOLANIA processed inaccurate personal data (the claimant's CUPS number) and that, despite its obligation
to comply with the principle of accuracy and the burden of proving such compliance, it has not

provided any evidence or indications that it had implemented any measures
to ensure compliance. Furthermore, the content of the calls made on January 27 and 28,
2023, reveals a complete lack of due diligence on the part of GAOLANIA.

Therefore, the known facts are considered to constitute an infringement,
attributable to GAOLANIA SERVICIOS, for violation of Article 5.1.d) of the GDPR,

transcribed above.

IV. Regarding the change in legal classification made during the proposed resolution process and the arguments presented against the initial agreement

The proposed resolution in this procedure modified the legal classification of the conduct described in the agreement to open the disciplinary proceedings. During the proposal process, it was deemed appropriate to replace the initial classification of a violation of Article 6.1.a) of the GDPR and classify the action for which GAOLANIA is held responsible as a violation of the principle of accuracy established in Article 5.1.d), an infringement classified under Article 83.5.a) of the GDPR and considered by the LOPDGDD, for the purposes of the statute of limitations (Article 72.1.a), as a very serious infringement.

This change in legal classification is in accordance with the law, as the facts on which the charges against the defendant were based, as set forth in the initial agreement, remain unchanged. The respondent has not submitted any arguments regarding

this change in legal classification.

With regard to the arguments presented against the initiation of these
disciplinary proceedings, responses were provided in the order
set forth by GAOLANIA in the proposed resolution. These arguments are not

included in this resolution because the legal classification of the conduct was changed
in the proposed resolution, and the proposed resolution pertains to a different article
than the one cited in this resolution.

V. Allegations to the Proposed Resolution

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 25/47

Regarding the allegations submitted to the proposed resolution of this sanctioning procedure, the following responses are provided in the order presented by GAOLANIA SERVICIOS:

FIRST: Concerning the violation of the principle of accuracy in data processing under Article 5.1 GDPR.

GAOLANIA SERVICIOS maintains that (i) measures were in place to prevent the events that occurred, and if the change did take place, it was primarily due to the error of GAOLANIA's client in providing the CUPS code, as well as the lack of complete information in the SIPS file, which prevented the detection of any discrepancies in the address;

and (ii) Following the verification call on January 27, 2023, GAOLANIA took
actions aimed at clarifying the facts and subsequently restoring the
supply:

“(…) In this regard, the facts on file demonstrate that the request
to change suppliers was made using the CUPS code initially recorded and that

after the verification call, the supply was restored.

Therefore, contrary to the conclusions reached in the Proposed Resolution,

(…) by the customer, without discrepancy in the SIPS code consulted and without rejection by the
distributor. In fact, (…), as stated in the preliminary actions detailed

in the Proposed Resolution. That is to say, (…).

It was precisely after the verification call on January 27 that the active contract was processed by the Quality Department, and they proceeded to carry out
several actions aimed at further verification.

For this reason, we must It should be emphasized that the facts considered in the Proposed Resolution as an infringement stem from an erroneous interpretation by the Spanish Data Protection Agency (AEPD) regarding the sequence of events that occurred during the change of energy supplier and the incorrect interpretation of the actions taken by my client.

Consequently, a correct interpretation of the sequence of events determines that there was no unlawful conduct on the part of my client.

At this point, the chronology of events, which even appears in the Proposed Resolution, does not coincide with the AEPD's interpretation of the change of energy supplier.

And it is at this point that we must reiterate that the initial sales call made by the manager, the subsequent signing of the contract (where we now know the incorrect CUPS code was included), and the request for the change of energy supplier all occurred on January 26, 2023. The same day, the distributor accepted the request without objection and it was activated the following day, January 27th. It was subsequently, on the same day, that COMPANY 2 made a verification call to confirm the contract details with the client. During this call, a different piece of information was detected than the one initially provided by the client, which allowed for an investigation. Consequently, under no circumstances was a change of supplier requested with knowledge of the existence of an incorrect CUPS code.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 26/47

Regarding the non-compliance with section d) of Article 5 of the GDPR, (…) the key to understanding that this provision has been infringed lies in two fundamental questions:

first, whether my client had sufficient measures in place for the processing of the data, assuming it was correct and accurate, and second, whether, once the error was detected, the company acted accordingly. The personal data that had been inaccurately processed was rectified without delay.

Regarding these two issues, the Proposed Resolution results in a

negative response from the Spanish Data Protection Agency (AEPD) to justify the proposed sanction. However, as we have already stated and will now explain, this pronouncement
in the Proposed Resolution stems from an incorrect interpretation of the sequence of events in the case file, since it maintains that my client was aware of the discrepancy in the CUPS code before proceeding with the change of supplier.

(i) ***COMPANY.2 carried out the minimum checks required to proceed with the change of supplier.

Firstly, it is undisputed that this party obtained, through the data processor

via a prior sales call, the CUPS code provided by my client's client, fulfilling the obligations assumed between the data processor and the data controller. Therefore, the inaccurate data was collected due to the
voluntary contribution of the client, who provided an incorrect CUPS code that actually belonged to the
claimant.

However, the Proposed Resolution omits that once the data was processed by
my client, the contractual documentation pending
review and signature was sent to the client. As indicated in section b) of the Second Allegation of the
statement of allegations submitted on January 6, 2025, the client's written review and signature of the documentation is required. In other words, the client

confirmed in writing that the CUPS code provided in the previous call was correct, and proceeded
to sign the contract.

Similarly, in said electronic supply contract, the client confirms that
the data provided is complete and truthful: “The client declares having read and
understood the Coverage and Conditions, both the specific ones (those listed on

page 1) and the general ones of this document, especially the financial
conditions contained therein, and declares their agreement with them.” expressly authorizing Gaolania Servicios S.L. to process the change of supplier with the Distribution Company and to access the consumer data contained in the information exchange system for the management of the change of supplier.

Furthermore, it declares that the information and data reflected above are
complete and truthful” (page 4, last paragraph of the electricity supply contract
signed by the customer).

Therefore, the customer had a pre-contractual document to review and correct the

error in the CUPS code initially provided, and not only did they fail to do so, but by signing it, they guaranteed that the information was truthful and complete before proceeding with the change
of energy supplier. ***COMPANY.2 thus had an appearance of
accuracy in the processing of the data provided by the customer.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 27/47

Regarding the sales call where the CUPS code was provided by the customer, in the statement of allegations
of January 6, 2025, we cited the Judgment of the National Court

dated June 12, 2020, to whose content we refer again, where in the
case examined, the energy supplier stated that it had a recording
of the new account holder, the data provided for the
switch of energy supplier appearing to be truthful, and argued that there was no unlawfulness or culpability in its
conduct precisely because of this apparent truthfulness in the contract, the
recording being sufficient to process the switch of energy supplier. The

National Court overturned the imposed sanction, concluding that the conduct of the
energy supplier did not constitute an infringement:

“If the contract is entered into by telephone, it is generally sufficient to
consider that the minimum due diligence required is exercised by providing a recording of the

telephone conversation between the company processing the data and the person
who consents to the contract and provides their own personal data
of the affected party.”

Therefore, the interpretation of the National Court applicable to this case determines that the measures my client had in place to guarantee the Accuracy

of the data were adequate and sufficient for the purpose of the processing.

However, the Proposed Resolution maintains that it is not applicable to the case at hand (first paragraph on page 39). It is surprising that, given the undeniable similarity of the grounds assessed by the National Court, the

Proposed Resolution considers it inapplicable because that ruling overturned a sanction for an act related to data impersonation, when the case at hand involves an error by the new data subject. We will not comment on the criteria used by the
Proposed Resolution to reject its application to the present case, since it is based once again on the belief that my client had a

discrepancy between two CUPS data points collected, a matter that has already been rejected and that is not consistent with the events detailed in this file.

However, this party does not understand how a call from the person who provided the data in a case of identity impersonation is accepted as minimal proof of due diligence, and the Proposed Resolution The resolution does not apply this interpretation to a simple

good faith error on the part of the client when providing the processed data.

Likewise, despite the difference in the factual circumstances between the case at hand and
the case examined by the National Court, we must remember that the key to the
National Court's Judgment of June 12, 2020, is precisely

that the marketing company fulfills the minimum diligence requirement and, therefore, complies with a
correct measure to guarantee the processing of the data if it has a telephone recording.

In other words, according to the National Court's criteria, ***COMPANY.2 had

fulfilled the minimum diligence required by having the telephone recording of the
client with the CUPS error. Furthermore, my client obtained
a new confirmation of the data from the client through review and signature.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 28/47

of the documentation containing the processed data and performed a SIPS query which
did not yield any information about the address that would allow for the identification of an error in the data.

Furthermore, although the Proposed Resolution considers there to be an infringement of Article
5 of the GDPR for not having minimum measures in place to guarantee the accuracy of the data,
it is perfectly clear that ***COMPANY.2 had appropriate measures in place which
have been ratified by the National Court and employed other additional measures
beyond the minimum required, which also failed to detect the inaccuracy in the
data processing.

Regarding the SIPS query and the assessment made by the Proposed Resolution,
my client carried out a check using the SIPS file, to which it has limited access
without access to the complete information held by the distributor.

When the information was requested, there was neither a refusal nor any indication of the

existence of erroneous data. In fact, as we indicated in our brief Regarding the allegations, Recommendation IS/DE/014/21 of the National Commission for Markets and Competition (hereinafter, “CNMC”), in establishing best practices, acknowledges that outdated information sometimes exists or recognizes that the supplier does not have all the information because it is not included in the SIPS (Integrated Service Provider Information System).

Consequently, even the CNMC is fully aware that the supplier's use of information before submitting a request to change suppliers is limited through the SIPS and even acknowledges that the distributor's databases may be outdated, leading to rejections. This is further proof that ***COMPANY.2 does not have access to verify the CUPS (Supply Point Code) address beforehand, as the information is very limited, as previously described.

Similarly, the analysis carried out in the Proposed Resolution of Recommendation IS/DE/014/21 is based on a rejection by the distributor that allows for identifying that This concerns an incorrect CUPS code in the supplier's application.

However, in this case, the Distributor did not check its own databases and
did not reject the request to change suppliers; instead, it was accepted on the
same day. Therefore, ***COMPANY.2 had no basis or reason to suspect
of an error in the CUPS code provided by its client (…).

(ii) ***COMPANY.2 took steps to correct the inaccurate data in accordance with Article

5 of the GDPR.

Article 5 of the GDPR itself establishes the obligation to correct inaccurate data without
delay: “Personal data shall be: (…) accurate and, where necessary, kept up to date;

All reasonable measures will be taken to ensure that personal data that is inaccurate with regard to the purposes for which it is processed ("accuracy") is erased or rectified without delay.

Regarding this point, based on the facts in the file, my client's conduct cannot be considered unlawful since, contrary to the interpretation of the Proposed Resolution, ***COMPANY.2 took additional measures and actions after the verification call on January 27, 2023.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 29/47

GAOLANIA SERVICIOS carried out the rectification simultaneously:

(i) it paused billing at the point of supply to avoid any harm,

and

it contacted the data processor to obtain all the necessary explanations. Details of the contractual phase: (iii) the restoration of service was requested on January 27, 2023, and accepted by the distributor on January 30. (iv) Customer service personnel followed up on the case to confirm the disconnection, as they observed a delay in the distributor's actual restoration.

Regarding the customer contract, the information was corrected and there were no further issues.

Regarding the claimant's CUPS code, it is surprising that despite the distributor's speed in processing the activation, which was completed in less than 24 hours, there was a delay in the distributor's actual restoration, resulting in several inquiries from the claimant to this party.

At this point, it should be noted that although the Proposed Resolution expressly mentions the responses provided by this party to the claimant regarding the management and the supplementary requests for restoration, to the
distributor on February 6, 2023, and February 9, 2023, including the email apologizing to the claimant for the inconvenience caused, the fact is that the Spanish Data Protection Agency (AEPD) fails to mention that the replacement was initially requested by my client on January 27, 2023, the same day the verification recording took place.

The withdrawal request made by ***COMPANY.2 to ***COMPANY.1

The distribution letter dated January 27, 2023, was attached as DOCUMENT No. 8 in the statement of allegations dated January 6, 2025. This being an essential fact of my client's actions, the Proposed Resolution does not address this point, merely citing the subsequent supplementary requests that my client had to make due to the distributor's delay in carrying out the

replacement.”

First, the defendant alleges that the change request, the signing of the contract
with the incorrect CUPS code, and its acceptance by the distributor occurred on January 26,
2023, and that it was the following day, January 27, when a call was made to
confirm the collected data, during which the discrepancy was detected. However, this

sequence of events does not absolve GAOLANIA of responsibility, but rather confirms
its lack of due diligence.

Thus, the call made on January 27th lacks the necessary validity to comply with the
principle of accuracy in data processing required by the GDPR, since,

the contract had already been processed and accepted by the distributor the previous day, said
call does not constitute a verification mechanism for the processed data, but rather a
mere post-contract check or quality audit of a fait accompli. For
there to be a genuine verification that guarantees the accuracy of the data, the comparison
of the processed data should have taken place before processing the

registration and the subsequent change of the complainant's supply. Therefore, carrying out
a data confirmation when the change is already effective in the distributor's systems is contrary to the obligation imposed by Article 5.1.d) of the GDPR.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 30/47

Specifically, in this case, the confirmation of the data by the client of
GAOLANIA through the signing of the contract on January 26 does not release the company from its
duty of due diligence. By signing, the client expresses their intention to enter into the contract, but this does not

replace the duty to guarantee the accuracy of the CUPS code. The fact that the
company itself required a telephone verification on the 27th demonstrates that the
signing of the contract was not considered a sufficient mechanism by GAOLANIA to guarantee the
accuracy of the data.

In this regard, and with respect to the lack of complete information in the SIPS file,

which GAOLANIA claims prevented the detection of any discrepancies in the address,
it is worth recalling that CNMC report IS/DE/014/21 expressly states that, when inconsistencies or discrepancies exist between the information provided by the consumer and that registered in the SIPS, the supplier must carry out additional checks, such as subsequent contacts, requests for supplementary documentation, or other equivalent measures, before proceeding with the change. These guidelines reflect a standard of due diligence required of the supplier, aimed at preventing foreseeable errors and ensuring the correct identification of the supply point.

In this case, a lack of due diligence is evident from January 27th onwards,

when the discrepancy between the CUPS code provided by the customer in the two calls was confirmed. The claimant sent emails to the company from January 28th onwards, expressly requesting that their service not be modified. This demonstrates that GAOLANIA's handling of the error was not swift enough to prevent the improper processing of data once it was discovered.

Furthermore, regarding GAOLANIA's assertion that the responsibility lies solely with the customer who provided incorrect information, it should be noted that data protection regulations impose a duty of proactive responsibility on the data controller, as outlined in Article 5.2 of the GDPR. This includes the obligation to anticipate and mitigate the risks inherent in data processing. This is also reflected in the general obligations that Article 24 of the GDPR imposes on data controllers: “1. Taking into account the nature, scope, context and purposes of the processing and the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organizational measures to ensure and be able to demonstrate that processing is carried out in accordance with this Regulation. These measures shall be reviewed and updated where necessary.”

In this case, it is important to note that the CUPS code is a long (20 or 22 characters) and complex alphanumeric string, making it highly susceptible to errors, whether due to customer negligence when providing it or a possible data entry error by GAOLANIA's own employees. Therefore, the inaccuracy of this data is not an
unforeseeable circumstance, but a risk that the respondent should take into
consider and implement pre-contractual control systems that

guarantee the accuracy of the data. Therefore, it is the respondent who has the obligation to
verify the accuracy of the data before affecting the rights of third parties.

For all the foregoing reasons, this allegation is dismissed.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 31/47

SECOND: Analysis of the circumstances that determine the sanction. The proposed

resolution omits all those circumstances that mitigate the responsibility of the
data controller.

GAOLANIA states the following: “(…) we emphasize that the alleged subject of this
case represents an isolated incident and that no similar situation had occurred before, nor has the claimant suffered any damages. Regarding
culpability, the absence of unlawfulness in the conduct of my
client was highlighted, and all actions taken to restore the

supply were emphasized, also noting that the origin was a human error on the part of the
client with no intention of harming the claimant.

(…) Although these points were not assessed, the Proposed Resolution included the following circumstances that determine the proposed sanction:

(i) The nature, seriousness, and duration of the infringement, taking into account the
nature, scope, or purpose of the processing operation in question, as well as
the number of data subjects affected and the level of damages they have suffered (Article 83.2(a) of the GDPR).

On this point, regarding the duration Regarding the alleged infringement, the Spanish Data Protection Agency (AEPD) states that
the processing of the inaccurate data occurred between January 26, 2023, and March 7, 2023. With respect to this period, it should be noted that on January 27, 2023, GAOLANIA SERVICIOS requested a replacement from the distribution company,
the same day it became aware of the potential error in the CUPS code, as documented.

The delay in the replacement was caused by the distribution company, since once the replacement has been requested,
the energy supplier cannot take any further action, and the deadlines
are the responsibility of the distribution company. It is surprising that despite less than 24 hours having elapsed for activation, the distribution company delayed the effective replacement for more than a month. However, as we have indicated, this delay was attributable to the distribution company, given that

the energy supplier correctly requested the replacement on January 27, 2023.

Regarding the seriousness of the The Proposed Resolution indicates that, since it is a core activity of the responsible party, namely the marketing of energy, it is a

principal activity of the responsible party and therefore constitutes serious misconduct. We will address this
point in the following argument regarding the aggravating circumstance found.

Furthermore, as stated in our written arguments of January 6,

2025, the claimant has not even directed their actions against GAOLANIA

SERVICIOS, as the appeal for reconsideration was filed exclusively against
***EMPRESA.1 for failing to reinstate them to the same conditions they had before the
change of energy supplier. It is also important to note that there is a complete
absence of economic damage to the claimant, since they recovered their original contract
at no cost and were not billed for the time it was active with my client.

Additionally, this is not a case of conduct affecting multiple individuals,
as the exceptional nature of the events has already been conveyed on several occasions.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 32/47

occurred, and there is no assessment, not even provisionally, of the damages suffered by the claimant.

Regarding the severity for assessing the infringement, the Judgment of the National Court of October 3, 2024, in relation to Article 83.2.a of the GDPR, in a much more serious case than the one at hand, rules out its applicability because:
“With regard to section a), the nature, seriousness, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage they have suffered.” This aggravating circumstance reflected in the sanctioning resolution cannot be considered as such, since no specific damages have been proven, nor is there a large number of affected individuals, nor has the current account held by the claimant remained active over time, having been closed by the bank.

(ii) Intentionality or negligence in the infringement (Article 83.2(b) of the GDPR).

The Proposed Resolution indicates that there has been a serious lack of diligence in not carrying out any additional checks after being provided with a different CUPS code in the two calls with the client.

This party does not understand how this conclusion has been reached. It appears, based on the facts, that after the verification call of January 27, 2023, when a discrepancy arose between the CUPS codes, several measures were actively taken, including verification with the data processor and the restoration of the supply.

Therefore, it is categorically false that GAOLANIA SERVICIOS did not carry out any additional checks or procedures once the different CUPS code was provided

on the second call.

Furthermore, the Proposed Resolution failed to consider that there was no intention
to harm the claimant and that all necessary actions were diligently taken
to return the CUPS code to its previous holder and their previous
supplier.

In fact, there is no evidence to suggest even
any intent on the part of my client who provided the incorrect CUPS code; there was only a human error that went undetected.

Contrary to the Proposed Resolution's assertion of gross negligence
based on an erroneous analysis and interpretation, this party has always maintained
that internal controls do exist and are functioning. In this regard,
internal measures were adopted that allowed for the detection of the error in the processing of the
data and the rectification of the client's data, as well as the reinstatement of the

claimant's information.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 33/47

In addition, this party states that there are several circumstances that mitigate the
liability for any potential infringement by ***COMPANY.2 and that have not been
considered in either the Initiation Agreement or the Proposed Resolution:

(iii) Any measures taken by the data controller to mitigate the
damages suffered by the data subjects.

In our initial response to the request dated June 14, 2023,
we already outlined all the measures taken by ***COMPANY.2, based on the

flexibility of the regulation that allows for “any measure” adopted by the data controller.

At this point, a call was made to the client after the change was processed to re-verify all the data (Quality Department). Following the discrepancy in the CUPS code,

an internal investigation was initiated ex officio to clarify the facts with the data processor, requesting all relevant information. Furthermore, the supply point was immediately restored, and finally, a written apology was sent to the complainant for what happened.

(iv) Any prior infringement committed by the data controller.

Regarding this section, neither the Commencement Agreement nor the Proposed Sanction mentions that there is no prior infraction committed by ***COMPANY.2, nor does it take this circumstance into account when determining the imposed sanction.

(v) The degree of cooperation with the supervisory authority in order to remedy

the infraction and mitigate any potential adverse effects.

***COMPANY.2 not only cooperated and provided all the information related to the
facts from the first notification of the complaint, but also
took proactive measures after detecting the error to return the CUPS code to its holder and
thus avoid any potential consequences, without the claimant being charged or billed for

consumption, and the dispute was resolved in favor of the claimant.

(vi) Any other aggravating or mitigating factor applicable to the circumstances of the
case, such as any financial benefits obtained as a result of committing
the infraction.

Furthermore, Article 76.2 of the LOPD (Spanish Data Protection Act) also stipulates that consideration may be given to,
among other things, the possibility that the affected party's conduct could have induced the
commission of the infringement. Although this does not refer to the claimant's conduct per se,
it is applicable by analogy to the conduct of the client of ***COMPANY.2, as they are the

third party who incorrectly provided the CUPS code of a third party and verified such data in writing
in the contract.

Despite the fact that the origin lies in a third party's error, neither the Initiation Agreement nor the
Proposed Sanction has taken this into account in relation to the
unlawfulness and culpability of the conduct, nor has it considered

this circumstance to at least mitigate the liability of ***COMPANY.2.

Finally, ***COMPANY.2 has not obtained any economic benefit
as a result of the alleged events. Moreover, not only was no benefit obtained

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 34/47

but the toll costs, charges corresponding to the period the
claimant was registered, were neither billed nor passed on to either the claimant or the
customer of ***COMPANY.2. Nor was the consumption corresponding to the

period of registration billed.

From all of the above, it is clear that neither the Initiation Agreement nor the Proposed
Sanction properly considered the circumstances of the case on an
individual basis, especially all those that mitigate liability and that
directly influence the determination of the proposed fine amount.


It is especially relevant that the lack of consideration of the factors
related to the applicable penalty for my client has resulted in the
Proposed Sanction again omitting the mitigating circumstances
of ***COMPANY.2's liability, which must be considered in order to

determine the penalty.”

First, GAOLANIA states that: “(…) the claimant has not even directed
his actions against GAOLANIA SERVICIOS, since the appeal for reconsideration was
filed exclusively against ***COMPANY.1 for not restoring him to the same
conditions he had before the change of supplier. Furthermore, it is important to

point out that there is a complete absence of economic damage to the claimant, since
they recovered their original contract at no cost and were not billed for the time it was active with
my client.”

This Agency wishes to remind you that the concept of damage in the GDPR is broad and is not

limited to economic damages. Thus, Recital 75 expressly states that
risks to the rights and freedoms of natural persons can cause
both material and non-material damages, specifically citing among
such damages the loss of control over their personal data.

The CJEU has ruled similarly in its recent Judgment of 4 September 2025 (Case C-655/23), stating that the mere loss of control
constitutes compensable non-material damage, without the need for tangible
financial loss:

“59. Second, as the European Commission has pointed out in its

written observations, Situations such as those invoked in the main proceedings,

relating to “damage to reputation” as a consequence of a
breach of personal data security or a “loss of control”
over such data, are expressly included among the examples of possible damages
listed in recitals 75 and 85 of the GDPR.

60. In particular, the Court of Justice has emphasized that it is clear from the illustrative list
of the “damages” that data subjects may suffer, contained
in recital 85, first sentence, of the GDPR, that the EU legislator
intended to include in these two concepts, in particular, the mere

“loss of control” over the personal data of those data subjects
as a consequence of an infringement of that Regulation, even if there has not
been any actual misuse of the data in question. Such a
loss of control may be sufficient to cause “non-material damages.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 35/47

within the meaning of Article 82(1) of said Regulation, provided that
the data subject demonstrates that they have actually suffered such damages, however minimal, without this concept of "non-material damages" requiring proof of the existence of additional tangible negative consequences.

Therefore, the absence of proven economic damages does not eliminate the existence of non-material damages arising from the GDPR infringement. Thus, in the present case, it is evident that the claimant suffered a loss of control over their data,

being forced to take steps to reverse a change of supplier
that they had not consented to. This loss of control over their own supply contract constitutes non-material damages as defined by the CJEU.

Secondly, regarding the following statement by GAOLANIA: "Although

their The origin lies in a third-party error; neither the Initiation Agreement nor the Proposed Sanction has taken this into account in relation to the unlawfulness and culpability of the conduct. Furthermore, it has not considered this circumstance to at least mitigate the responsibility of ***COMPANY.2.” We refer to the response given in the first allegation, where it has already been stated that the fact that the inaccurate data stems from a client error does not exempt GAOLANIA from its responsibility, since it is GAOLANIA, as the data controller, that has the legal obligation to comply with the principle of accuracy in Article 5.1.d) of the GDPR, and must foresee the possibility of errors in the communication of the CUPS code. GAOLANIA is responsible for providing effective mechanisms for verifying accuracy, and the client cannot be held responsible for the duty of care.

Thirdly, GAOLANIA states that the proposed resolution incorrectly assesses the duration and severity of the alleged infringement, given that the energy supplier requested the restoration of service on January 27, 2023,

and the distributor was responsible for the subsequent delay; that there were no economic losses for the claimant nor any impact on multiple stakeholders; and that it did not act negligently, since, after detecting the discrepancy in the CUPS code, immediate measures were taken to clarify and correct the error, without any intentionality or lack of diligence.

Regarding the severity of the infringement, the “Guidelines 04/2022 for the calculation of administrative fines under the GDPR” indicate that the GDPR stipulates that due consideration must be given to the circumstances that determine the severity of the infringement in an individual case. It should be noted that, contrary to the interpretation given
by the respondent, sections a), b) and g) of Article 83 of the GDPR are not

considered, for the purposes of imposing the sanction, either as aggravating or
mitigating factors in the strict sense, but rather as circumstances that must be taken into
considerable when assessing the starting point regarding the seriousness of an
infringement. In other words, the nature, seriousness, and duration of the infringement, the
intent or negligence, and the categories of data affected are the elements

that define the infringement itself.

To assess the nature, seriousness, and duration of the infringement, the aforementioned Guidelines
indicate that the following specific elements must be evaluated:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 36/47

a) The nature of the infringement: the interest that the
infringed provision seeks to protect and the place of the
infringed provision within the framework of data protection must be reviewed. In this case,

Article 5.1.d) of the GDPR aims to ensure that the personal data

processed by controllers are accurate and truthful, avoiding errors
that could affect the proper provision of the service or generate
negative consequences for data subjects. Furthermore, the Guidelines

stipulate that the supervisory authority may examine the extent to which the
infringement prevented the effective application of the provision and the
achievement of the objective it was intended to protect. In the present case,

the infringement in question prevented the objective pursued by the
infringed provisions, since the processing of an
inaccurate CUPS code led to the processing of an unauthorized
contractual change, directly affecting the correct identification of the supply point
and the exercise of the complainant's rights regarding the

management of their own contract.

b) The seriousness of the infringement, assessed in light of the specific
circumstances:

i. The nature of the processing, including the context in which it is functionally based and all the characteristics of the

processing. The aforementioned Guidelines stipulate that when the
nature of the processing entails greater risks, for example,

when decisions or measures are taken with negative
effects for the data subjects, as in the present case,

where the use of the CUPS code of a third party who is not a customer of the
respondent resulted in a change of

supplier being processed without the consent of the complainant, the holder
of the supply point, altering their contractual situation and

generating an unsolicited modification to an essential service
such as the electricity supply. The aforementioned Guidelines also stipulate that a supervisory authority may

give greater weight to this factor when there is a clear

imbalance between the data subjects and the controller,

as in the present case.

ii. The scope of the processing, with reference to the local,
national, or cross-border scope of the processing carried out and the
relationship between this information and the actual scope of the processing

in terms of resource allocation by the

controller. The aforementioned Guidelines explain

that this element highlights a real risk factor,

linked to the greater difficulty for the data subject and the supervisory authority

in curbing unlawful conduct as

the scope of processing increases. The greater the

scope of processing, the greater the weight the supervisory authority

can attribute to this factor. In the present case, it is
a national processing activity.

iii. The purpose of the processing: The aforementioned Guidelines explain

that the supervisory authority can also consider whether the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 37/47

purpose falls within the core activities

of the controller. And that the more central
the processing is to the core activities of the controller or
the processor, the more serious the
irregularities in this processing will be. The supervisory authority

may give more weight to this factor in these
circumstances. In this case, the processing of personal data
for handling changes of ownership and
supplier constitutes an essential and core activity
of an energy supplier, so
any inaccuracy in identifying the

supply point has a direct impact on the proper provision
of the service.

iv. The number of interested parties specifically, but also
potentially affected: The aforementioned Guidelines indicate that
the greater the number of interested parties involved, the greater

the weight the supervisory authority may attribute to this
factor. And that, in many cases, the infringement can also be considered
to have "systemic" connotations and, therefore,
may affect, even at different times, other
interested parties who have not submitted complaints or
reports to the supervisory authority. And that, depending on the

circumstances of the case, the supervisory authority may
consider the relationship between the number of affected
stakeholders and the total number of stakeholders in that context

(for example, the number of citizens, customers, or employees),

in order to assess whether the infringement is systemic. In the
present case, although the incident directly affected

only the complainant, the use of an incorrect CUPS code

to process a contractual change demonstrates a potential risk
of impact on other stakeholders if internal controls related to the verification of essential supply data are not strengthened.

In this
sense, the lack of verification of the CUPS code supplied by the

customers has the potential to be reproduced in other situations, which

would give it a certain systemic character for assessment purposes, insofar as the affected process forms
part of the ordinary operations of the party against whom the complaint was filed.

v. The level of harm suffered and the extent to which the
conduct may affect individual rights and freedoms:

The aforementioned Guidelines indicate that, in accordance with recital 75 of the GDPR, the level of
harm suffered refers to physical, material, or
non-material damage. In this case, the claimant suffered
non-material harm insofar as the change of

supplier without their consent generated uncertainty
and affected the proper management of their electricity supply and
the reinstatement of the contract they had with their
supplier prior to said change.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 38/47

a) Duration of the infringement: the aforementioned Guidelines stipulate that, in general, a supervisory authority may give greater weight to an infringement of longer duration. They also indicate that certain conduct could have been unlawful under the previous regulatory framework, thus adding an additional element to assess the seriousness of the infringement. And that the longer the duration of the infringement, the greater the weight the supervisory authority may give to this factor. In the present case, it has been established that the infringement took place between January 26, 2023, and March 7, 2023, the date on which the complainant's original contract was reinstated.

Regarding the intentional or negligent nature of the infringement, in this case,
this Agency has already indicated on numerous occasions that it does not consider that there was
any intent to infringe on the part of GAOLANIA, but rather that it has

acted with gross negligence. In this respect, the aforementioned Guidelines indicate
that, depending on the circumstances of the case, the supervisory authority may also
assess the degree of negligence. GAOLANIA is a large company that must safeguard
the rights and freedoms of its customers and third parties, including, among others, the fundamental right
to the protection of their personal data. In this case, this
Agency considers that it has not been diligent in verifying that the data

provided for switching energy providers is correct. This is
especially relevant given that it is not only a company from which
greater professionalism could be expected, but also an entity accustomed to processing
personal data. In this regard, the judgment of the National Court of 17 October 2007 (appeal no. 63/2006) is very illustrative, stating that “…the Supreme Court has consistently held that

negligence exists whenever a legal duty of care is disregarded, that is,
when the offender does not act with the required diligence. And in assessing the
degree of diligence, special consideration must be given to the professional status of the individual,

and there is no doubt that, in the case now under examination, when the appellant's activity involves the constant and extensive handling of personal data,

the rigor and meticulous care to comply with the relevant legal provisions must be emphasized.”

To deny the existence of negligent conduct on the part of GAOLANIA
would be tantamount to acknowledging that its conduct—whether by action or omission—has been diligent.

Obviously, this perspective of the facts is not shared, since it has been

proven that there was a lack of due diligence prior to processing the change of energy supplier, as the CUPS code provided by the customer was not properly verified before submitting the request. This resulted in the activation of an operation on an incorrect supply point without the claimant's consent.

Furthermore, GAOLANIA alleges that the Spanish Data Protection Agency (AEPD) failed to consider, when determining the proposed sanctions, all the mitigating circumstances that, in its opinion, were present in the conduct under investigation.

Regarding GAOLANIA's assertion that the supply point was immediately restored, it should be clarified that this action constitutes an obligation arising from the very error that prompted these proceedings. As the aforementioned guidelines state, “in the event of an infringement, the controller or the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 39/47

processor must do everything within their power to mitigate the
consequences of the breach for the individuals affected.” In other words, the restoration cannot be considered a voluntary act of diligence, but rather the fulfillment of a

obligation to correct and mitigate imposed by the regulations in the face of a breach of the
principle of data accuracy.

Regarding the fact that there are no prior infringements committed by GAOLANIA,
the aforementioned guidelines state the following: “the absence of prior infringements cannot be considered a mitigating factor, since compliance with the

GDPR is the norm. If no prior infringements have been committed, this factor can be considered neutral.”


Regarding GAOLANIA's cooperation with this Agency in providing information
relating to the facts from the initial notification of the complaint, this is not considered

a mitigating factor. Responding to the complaint is a right
that benefits the respondent, as it gives them the opportunity to make any
statements they deem appropriate regarding the complaint. However,
the information subsequently provided within the framework of the preliminary
investigation proceedings is in compliance with a mandatory legal obligation and
not voluntary cooperation that could be considered a mitigating factor.

In this respect, Article 58.1.a) of the GDPR grants the Agency investigative powers, expressly authorizing it to “order the controller and the processor,
and, where applicable, the controller's or processor's representative,
to provide any information it requires for the performance of its functions.” Therefore,

responding to the information requests made by this Agency
during the investigation phase is an obligation of the respondent, and
failure to comply is classified as an infringement under Article 83.5.e) of the GDPR: “failure to comply with a decision or a requirement of the supervisory authority.”

Furthermore, Article 72.1.ñ) of the LOPDGDD classifies as a very serious infringement, solely for the purposes of the statute of limitations, the obstruction or refusal to provide information
required by the authority, establishing a three-year statute of limitations for
this type of conduct, which implies the mandatory nature of cooperation.

Finally, this Agency wishes to point out that the lack of

benefits obtained by GAOLANIA cannot be considered a mitigating circumstance. The Judgment of the National Court, dated May 5, 2021, appeal no. 1437/2020, which states: “It considers, on the other hand, that the absence of a prior infringement should be taken into account as a mitigating factor.
Well, Article 83.2 of the GDPR establishes that the following circumstance must be considered for the imposition of the administrative fine, among others: “(e) any prior infringement committed by the controller or the processor.” This is an aggravating circumstance; the fact that the prerequisite for its application is not met means that it cannot be taken into consideration, but it does not imply or permit, as the plaintiff claims, its application as a mitigating factor.” Applied to the present sanctioning procedure, the lack of the prerequisite for its application with respect to Article 76.2.c) of the LOPDGDD, that is, obtaining benefits as a consequence of the infringement, does not allow its application as a mitigating factor.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 40/47

This grading criterion is established in the LOPDGDD (Spanish Data Protection Act) in accordance with the provisions of Article 83.2.k) of the GDPR, according to which administrative fines will be imposed taking into account any “aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement,” it being understood that avoiding a loss has the same nature for these purposes as obtaining benefits.

If we add to this the fact that sanctions must be effective, proportionate, and dissuasive in each individual case, as provided for in Article 83.1 of the GDPR,

admitting the absence of profit as a mitigating factor is not only contrary to the factual circumstances contemplated in Article 76.2(c), but also contrary to the provisions of Article 83.2(k) of the GDPR and the aforementioned principles.

Thus, considering the absence of profit as a mitigating factor would nullify the deterrent effect of the fine,

insofar as it diminishes the impact of the circumstances that actually affect its amount. In any case, the administrative fines
established in the GDPR, pursuant to Article 83.2, are imposed
based on the circumstances of each individual case, and the
absence of profit is not considered an appropriate and determining factor for assessing
the seriousness of the infringing conduct.

Finally, regarding the case law cited by GAOLANIA as
the “Judgment of the National Court dated October 3, 2024” with reference number
“ECLI: ES:AN:2024:4885” to question the application of Article 83.2(a)
of the GDPR, this Agency must point out that no such judgment can be located

with the paragraph mentioned by the reference number or date indicated by the claimant. However, it should be noted that this Agency does not agree
with the application of the alleged paragraph attributed to the National Court to the present
case. This resolution is based on the current and applicable criteria of
Guidelines 04/2022 on the calculation of administrative fines, which establish

a specific methodology for assessing the seriousness of the infringement according to its
nature. Thus, a 2024 ruling by the National Court would review
sanctioning resolutions issued prior to the adoption of the aforementioned guidelines, and therefore, it is not appropriate to invoke a ruling that does not take into account the criteria currently in force at the
European level. Furthermore, as previously analyzed,
GAOLANIA insists on considering the elements of Article 83.2.a) as

aggravating circumstances, when Guidelines 04/2022 consider them as
elements that allow for assessing the starting point regarding the seriousness of an
infringement.

For all the reasons stated above, this appeal is dismissed.

THIRD: The aggravating circumstance considered in the proposed resolution has already been included
in assessing the infraction.

GAOLANIA continues its statement of allegations, noting that: “Closely related to the previous point, we must indicate that, by not assessing the content of the third section of the statement of allegations dated January 6, 2025, the Proposed Sanction also fails to address the arguments presented regarding the aggravating circumstances identified in the Initiation Agreement.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 41/47

However, the Proposed Resolution considers the following as an aggravating circumstance for the purpose of determining the sanction: “The connection between the offender's activity and the processing of personal data (Article 76.2, letter b), of the LOPDGDD): The clear connection between the business activity of GAOLANIA SERVICIOS and the processing of personal data.” For its business, GAOLANIA SERVICIOS operates as an electricity supplier and needs to process personal data, which impacts the level of risk involved in the processing it carries out, both for clients and third parties.

However, the connection between the main activity of ***EMPRESA.2, namely the sale of energy services, and the fact that the processing of personal data falls within the core activities of the Data Controller, in accordance with Directive 4/2022 of the European Data Protection Board (EDPB), has already been considered by the Proposed Resolution as a circumstance for assessing the nature and severity of the infringement, and therefore cannot be considered an aggravating circumstance.

In this regard, the Judgment of the National Court of October 3, 2024 (ECLI: ES:AN:2024:4885), although it deals with a different circumstance, is improperly considered. employee

As an aggravating factor, the Court rules that it has ruled on this point on numerous occasions, finding that the circumstance cannot be applied as an aggravating factor when it is inherently part of the offense itself.

Regarding the consideration of the fact that GAOLANIA's activity is linked to the processing of personal data as an aggravating factor, this Agency wishes to point out that Article 83.2 of the GDPR stipulates that "When deciding on the imposition of an administrative fine and its amount in each individual case, due account shall be taken of: (...) k) any other aggravating or mitigating factors applicable to the circumstances of the case..."

In this regard, the Spanish legislator has included in Article 76 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) that: “2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account:

(…)

b) The connection between the infringer's activity and the processing of personal data.”

This Agency simply takes into account this circumstance, provided for by the legislator, when deciding whether to impose an administrative fine.

It should be noted that, of course, for the purposes of deciding whether to impose an administrative fine, an infringement committed by a natural person or a small business unfamiliar with the processing of personal data cannot be considered the same as one committed by a company like GAOLANIA, which is accustomed to processing the personal data of hundreds of clients and non-clients. Of course, it is considered

that the infringement is more serious for the purposes of imposing a fine if the data controller is among the latter, as is the case with GAOLANIA. This has been
pointed out by the National Court in its ruling SAN 65/2017, dated February 7, 2017, when it adopted the doctrine of the Supreme Court, "in assessing the degree

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 42/47

of diligence, special consideration must be given to the professionalism or lack thereof of the individual, and there is no doubt that, in the case under examination, when the appellant's activity involves the
constant and extensive handling of personal data, emphasis must be placed on

rigor and meticulous care in complying with the legal requirements in this regard."

For all the reasons stated above, this appeal is dismissed.

FOURTH: Adoption of new additional internal measures.

GAOLANIA states that: “in accordance with the initial response letter of June 14, it adopted the following control measures: “a) The Quality Department will make verification calls to customers before proceeding with the change of energy supplier to confirm that the data provided by the customer is correct (see Annex 3).” Additionally, following the Proposed Resolution, my client has adopted the following additional measures:

a) Verification through SIPS and P0 in case of error or missing data.

b) In case of discrepancy or missing data in the SIPS file, the processing of the contract is automatically halted, and therefore, the request to change energy supplier is not processed until the verification call is made.

c) Special verification call campaign. In the event of missing SIPS data that would allow the customer's data to be compared with the data in the distributor's database, the incident created will be... form

automatically by the system will go to a special verification call campaign.

That is, staff will have a specific campaign to make calls
for this reason, so that they do not enter the verification call queue and the
task has priority.

For these purposes, this party requests that the adoption of

additional measures be considered adopted and accredited to guarantee compliance with the provisions of Article
5.1.d) GDPR in order to prevent a recurrence of a situation or incident such as the
claim that is the subject of this sanctioning procedure.”

Having received in the statement of allegations the information that GAOLANIA has

adopted the necessary measures to prevent the recurrence of the events
that determined the infringement committed, this Agency acknowledges receipt thereof, without this statement implying any pronouncement on the regularity
or legality of the measures adopted.

It is noted that Article 5.2 of the GDPR establishes the principle of proactive responsibility, stating that “The controller shall be responsible for compliance with paragraph 1 and be able to demonstrate such compliance.” This principle refers to the obligation of the controller not only to design, implement, and observe appropriate legal, technical, and organizational measures to ensure that data processing complies with the regulations, but also to remain actively vigilant throughout the entire processing lifecycle to ensure proper compliance and be able to demonstrate it.

For all the reasons stated above, this claim is upheld.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 43/47

VI. Classification of the Infringement and its Scope for Purposes of the Statute of Limitations

Article 83.5 of the GDPR classifies as an administrative infringement the violation of the following articles, which will be sanctioned, in accordance with paragraph 2, with administrative fines of up to EUR 20,000,000 or, in the case of an undertaking, up to 4% of its total annual global turnover of the preceding financial year, whichever is higher:

"(a) the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7 and 9; (...)"

For its part, the LOPDGDD, in its Article 71, Infringements, states that:

“The acts and conduct referred to in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law, constitute infringements.”

For the sole purpose of determining the statute of limitations, Article 72.1 of the LOPDGDD (Spanish Data Protection Act) establishes the following:

"In accordance with the provisions of Article 83.5 of Regulation (EU) 2016/679, the following infringements are considered very serious and shall be subject to a three-year statute of limitations:

infringements that constitute a substantial breach of the articles mentioned therein, and in particular, the following:

(b) The processing of personal data without any of the conditions for lawful processing established in Article 6 of Regulation (EU) 2016/679 being met."

VII. Sanction to be imposed on GAOLANIA

In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR must be observed. These articles state:

“1. Each supervisory authority shall ensure that the imposition of administrative fines under this Article for infringements of this Regulation referred to in paragraphs 4, 9 and 6 is, in each individual case, effective, proportionate and dissuasive.

2. Administrative fines shall be imposed, depending on the circumstances of each individual case, as an additional measure to, or in lieu of, the measures provided for in Article 58(2)(a) to (h) and (j). When deciding on the imposition of an administrative fine and its amount in each individual case, due consideration shall be given to:
(a) the nature, seriousness and duration of the infringement, taking into account the nature, scope or purpose of the operation of the processing in question, as well as

the number of data subjects affected and the level of damage they have suffered;

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 44/47

b) the intentionality or negligence of the infringement;

c) any measures taken by the controller or processor to remedy the damage suffered by the data subjects;

d) the degree of responsibility of the controller or processor, taking into account the technical and organizational measures implemented pursuant to Articles 25 and 32;

e) any previous infringements committed by the controller or processor;

f) the degree of cooperation with the supervisory authority in order to remedy the infringement and mitigate its possible adverse effects;

g) the categories of personal data affected by the infringement;

h) how the supervisory authority became aware of the infringement, in particular whether the controller or the controller notified the infringement and, if so, to what extent;

(i) where the measures referred to in Article 58(2) have been previously ordered against the controller or processor concerned in relation to the same matter, compliance with those measures;

(j) adherence to codes of conduct pursuant to Article 40 or to approved certification mechanisms pursuant to Article 42; and

(k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefitsfinancial gains obtained or losses avoided, directly or indirectly, through the infringement.”

For its part, Article 76 “Sanctions and Corrective Measures” of the LOPDGDD (Spanish Data Protection Law) stipulates:

“1. The sanctions provided for in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the criteria for determining the severity of the sanction established in paragraph 2 of said article.

2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account:

a) The ongoing nature of the infringement.

b) The connection between the infringer's activity and the processing of personal data.

c) The benefits obtained as a result of committing the infringement.

d) The possibility that the data subject's conduct could have induced the commission of the infringement.” e) The existence of a merger by acquisition subsequent to the commission of the infringement, which cannot be attributed to the acquiring entity.

f) The infringement of the rights of minors.

g) The appointment of a data protection officer, when not mandatory.

h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms in cases where disputes arise between them and any interested party.

In this case, considering the seriousness of the potential infringement, and especially the consequences for the affected party, a fine would be appropriate, in addition to the adoption of measures, if applicable.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 45/47

The fine imposed must be, in each individual case, effective, proportionate, and dissuasive, in accordance with Article 83.1 of the GDPR. To guarantee these principles, the turnover of

GAOLANIA SERVICIOS was €172,191,969 in 2023.

For the purposes of deciding on the imposition of a fine Given the administrative nature and amount of the infraction, it is considered appropriate to determine the appropriate sanction based on the following circumstances, as outlined in the aforementioned provisions.

Preliminary considerations are based on the following circumstances:

- The nature, severity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage suffered.

(Article 83.2(a) of the GDPR): GAOLANIA SERVICIOS processed the CUPS number linked to the complainant from January 26, 2023, until March 7, 2023, the date on which the complainant's registration with her previous company was processed, assigning it to a third party, a client of theirs, without verifying the accuracy of this data.

Guidelines 4/2022 of the European Data Protection Board Data (EDPB) for calculating administrative fines under the GDPR, adopted on May 24, 2023, indicate that the “purpose of the processing” will lead the supervisory authority to assign greater weight to the seriousness of the infringement.

The Guidelines specify in this regard that “The supervisory authority may also consider whether the processing of personal data falls within the core activities of the controller. The more central the processing is to the core activities of the controller or processor, the more serious the infringements in that processing will be. The supervisory authority may give greater weight to this factor in these circumstances.” (Emphasis added)

Taking these guidelines into account, the seriousness of the irregularities is evident
given that the purpose of the processing in which the GDPR was violated was
within the core activities of GAOLANIA SERVICIOS, namely the
marketing of electricity services, particularly in connection with the

electricity supply contract involving a change of supplier that it carried out.

- The intent or negligence in the infringement (Article 83.2, letter b), of the GDPR):
The defendant acted with a serious lack of diligence in the processing it
carried out during its core business activities, by failing to perform any

additional checks after being provided with a different CUPS code in the two
calls with its client.

Regarding the degree of diligence it is obliged to exercise in complying with
data protection regulations, it is worth citing the judgment of the National High Court of Justice of 17 October 2007 (appeal 63/2006),
which Despite having been issued under the previous regulations, it remains

fully applicable. It states that “[...] the Supreme Court has consistently held that negligence exists whenever a legal duty of care is disregarded, that is, when the offender does not act with the required diligence. And in the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 46/47

assessment of the degree of diligence, special consideration must be given to the professional status
or lack thereof of the individual, [...] (Emphasis added)

We refer to the considerations made in this regard in the Legal Basis regarding the infringed article.

The following factors are also considered as aggravating circumstances:

- The connection between the offender's activity and the processing of personal data (Article 76.2, letter b), of the LOPDGDD): The clear link between the business activity of GAOLANIA SERVICIOS and the processing of personal data. As an electricity supplier, GAOLANIA SERVICIOS needs to process personal data, which

affects the level of risk involved in its processing activities, both for clients and third parties.

No mitigating circumstances are found.

The assessment of the circumstances contemplated in Article 83.2 of the GDPR and Article 76.2 of the LOPDGDD,

regarding the infringement committed by violating the provisions of
Article 6.1 of the GDPR, allows for the proposal of an administrative fine of
€30,000.00.

Therefore, in accordance with applicable legislation and having considered the criteria for

the determination of penalties, the existence of which has been established, the President of
the Spanish Data Protection Agency
RESOLVES:

FIRST: TO IMPOSE on GAOLANIA SERVICIOS, S.L., with Tax Identification Number B98717457, for an

infringement of Article 5.1.d) of the GDPR, classified in Article 83.5 of the GDPR, a
fine of €30,000.00.


SECOND: NOTIFY GAOLANIA SERVICIOS, S.L. of this resolution.

THIRD: This resolution will become enforceable once the deadline for filing the

optional appeal for reconsideration (one month from the day following the
notification of this resolution) has expired without the interested party having exercised this right.

The sanctioned party is advised that they must pay the imposed sanction once
this resolution becomes enforceable, in accordance with the provisions of Article 98.1.b)
of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), within the voluntary payment period
established in Article 68 of the General Collection Regulations, approved by Royal
Decree 939/2005, of July 29, in relation to Article 68 of the LPACAP. 62 of Law 58/2003, of December 17, by depositing the fine, indicating the Tax Identification Number (NIF) of the sanctioned party and the procedure number shown in the heading of this document, into the restricted account

IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX), opened in the name of the Spanish Data Protection Agency at CAIXABANK, S.A. Otherwise, collection will be pursued during the enforcement period.


C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 47/47

Once the notification has been received and is enforceable, if the enforceability date falls

between the 1st and 15th of each month, inclusive, the deadline for making the voluntary payment will be the 20th of the following month or the next business day thereafter. If the date falls
between the 16th and the last day of each month, inclusive, the payment deadline will be
the 5th of the second following month or the next business day thereafter.

In accordance with Article 50 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights), this
Resolution will be made public. Publication will take place once it has been notified to
the interested parties.

This resolution, which concludes the administrative process pursuant to Article 50 of the LOPDGDD, may be appealed. 48.6 of the

LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, the
interested parties may, optionally, file an appeal for reconsideration with the
Presidency of the Spanish Data Protection Agency within one month from the day following notification of this resolution, or directly file an
contentious-administrative appeal with the Contentious-Administrative Chamber of the

National Court, pursuant to the provisions of Article 25 and paragraph 5 of
the fourth additional provision of Law 29/1998, of July 13, regulating the
Contentious-Administrative Jurisdiction, within two months from the day following notification of this act, as provided for in Article 46.1 of the

said Law.

Finally, it is noted that, in accordance with the provisions of Article 90.3 a) of the LPACAP, a
final administrative decision may be provisionally suspended if the
interested party expresses their intention to file an appeal with the Administrative Court.

If this is the case, the interested party must formally communicate this fact by

submitting a written communication to the Spanish Data Protection Agency through
the Agency's Electronic Registry [https://sedeaepd.gob.es/sede-electronica-
web/], or through one of the other registries provided for in Article 16.4 of
Law 39/2015, of October 1. They must also provide the Agency with
documentation proving the effective filing of the appeal with the Administrative Court.

If the Agency is not notified of the filing of the appeal within two months from the day following
notification of this resolution, the provisional suspension will be terminated.

938-101025
Lorenzo Cotino Hueso

President of the Spanish Data Protection Agency

6 Jorge Juan Street www.aepd.es
28001 – Madrid sedeaepd.gob.es