AEPD (Spain) - EXP202309453
| AEPD - EXP202309453 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 5(1)(f) GDPR |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | 28.05.2023 |
| Decided: | 15.04.2026 |
| Published: | 15.04.2026 |
| Fine: | 200,000 EUR |
| Parties: | AXA SEGUROS GENERALES, S.A. DE SEGUROS Y REASEGUROS |
| National Case Number/Name: | EXP202309453 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Spanish |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | ap |
The DPA fined an insurance company €200,000 for failing to ensure security of processing, which allowed a former employee to access a data subject’s account.
English Summary
Facts
AXA SEGUROS GENERALES, S.A. DE SEGUROS Y REASEGUROS (the controller) is an insurance company. In 2023, a former employee of the controller contacted a data subject, requesting them to provide information on their insurance to match the price on behalf of a different company. The data subject later received two SMS with a temporary code to access their online account, and a confirmation email that their access data had been changed. The data subject contacted the controller, as they had not used the codes or accessed their account. In response, the controller blocked their account, but later informed them that the former employee had stolen their identity to access their account. The data subject filed a complaint with the DPA.
During the DPA’s investigations, the controller confirmed that the data subject’s password was changed. In addition, the controller stated that it implemented additional security measures after the incident to prevent future identity theft incidents. The controller argued that the DPA could not find a violation of Article 5(1)(f) GDPR based solely on the fact that the incident took place, as this article does not require controllers to have completely effective security measures in place.
Holding
The DPA found a violation of Article 5(1)(f) GDPR. The controller did not properly manage the process of changing the data subject’s password, which allowed a third party to access the data subject’s insurance account information. The DPA considered the controller’s security measures insufficient to ensure security of processing; for example, the third party was able to impersonate the data subject based on their insurance number and the last four digits of their payment method. The DPA noted that this was a systematic error and evidence of the lack of diligence from the controller, as it had not implemented measures to ensure that former employees could not impersonate data subjects.
The DPA fined the controller €200,000. In addition, the DPA ordered the controller to implement adequate technical and security measures. The DPA stated that the fact that the controller operated in the insurance sector meant it was essential to ensure security of processing.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.
1/53 • File No.: EXP202309453 RESOLUTION OF DISCIPLINARY PROCEEDINGS TABLE OF CONTENTS BACKGROUND..........................................................................................................2 FIRST: Complaint received...............................................................................2 SECOND: Transfer of the complaint.....................................................................3 THIRD: Admission of the complaint......................................................4 FOURTH: Preliminary investigative actions........................................................5 FIFTH: Agreement to initiate disciplinary proceedings......................................13 SIXTH: Allegations against the initiation agreement................................................................13 SEVENTH. Change of instructor of the proceedings.................................................13 EIGHTH: Proposed resolution..........................................................................13 NINTH: Turnover and number of clients..............................................13 PROVEN FACTS................................................................................................14 LEGAL GROUNDS.................................................................................16 I. Jurisdiction.........................................................................................................16 II. Preliminary issues...............................................................................................16 III. Objections to the initiation agreement and response thereto............................17 FIRST. Possible expiration of the preliminary investigative proceedings.........17 SIXTH. Possible concurrence of infringements............................................................19 SECOND. On the factual scenario..............................................................21 THIRD. Infringement of Article 5.1.f) of the GDPR...............................................21 FOURTH. Infringement of Article 32 of the GDPR......................................................24 FIFTH. Role of the Data Controller.......................................................26 SEVENTH. Proportionality of the Sanction...........................................................27 IV. Allegations against the proposed resolution and response thereto..............33 FIRST. – ON THE EXPIRY OF THE PRELIMINARY INVESTIGATIVE PROCEEDINGS..................................................................................................33 SECOND. – ON THE FACTUAL BACKGROUND.............................................36 THIRD. – ON THE ALLEGED INFRINGEMENT OF ARTICLE 5.1 F)..............38 C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 2/53 FOURTH. - ON THE ROLE OF THE DATA CONTROLLER AND THE ASSOCIATED LIABILITY.........................................................................42 FIFTH. – ON THE COMPLAINT FILED AGAINST ***COMPANY.1....43 SIXTH. – ON THE AEPD'S CRITERIA IN PREVIOUS SIMILAR RESOLUTIONS......................................................................................................43 SEVENTH. – PROPORTIONALITY OF THE SANCTION.......................................43 V. Breach of Obligation. Article 5.1.f) GDPR Integrity and Confidentiality..........44 VI. Classification of the Infringement of Article 5.1.f) of the GDPR and its Qualification for the Statute of Limitations..............................................................................................................48 VII. Sanction for the Infringement of Article 5.1.f) GDPR.............................................49 VIII. Corrective Measures..........................................................................................51 RESOLVES:.................................................................................................................52 RESOLUTION OF SANCTIONING PROCEEDINGS From the proceedings initiated by the Spanish Data Protection Agency and based on the following BACKGROUND FIRST: Complaint Received On May 28, 2023, a complaint was filed with the Spanish Data Protection Agency regarding a possible infringement attributable to AXA SEGUROS GENERALES, S.A. DE SEGUROS Y REASEGUROS, with Tax Identification Number A60917978 (hereinafter, AXA or the respondent). The following facts are brought to the attention of this authority: The claimant states that on May 22, 2023, they received a call from their former manager at the defendant insurance company, where they no longer work, since they are now working at another agency, requesting that they again entrust their insurance policies to them and offering the same price. That same day, they received two text messages from the defendant providing a temporary password to access their customer area. Minutes later, they received an email from the defendant's security department, indicating that their login details had been changed and that they could now access their personal "MYAXA" account. Since the complainant had not accessed the account, they contacted the respondent by phone. The employee who answered rudely demanded that they provide all SMS messages and emails so that C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 3/53 their account could be blocked due to unauthorized access. The complainant refused. Subsequently, they contacted the respondent again and received a written response in which the respondent acknowledged that their identity had been impersonated to access their personal area by former agents/employees of that entity. The respondent indicated that they were involved in legal proceedings with the former managers and again requested the submission of the received messages in order to block the account. Along with the complaint, a screenshot of the SMS messages regarding the new, unsolicited access password is provided, as well as a copy of the email response from the complainant, dated May 24, 2023, which states the following: "Following this morning's conversation regarding the aforementioned matter, please allow me to first and foremost apologize again for the treatment you received in our offices, undoubtedly the result of a tense situation caused by actions that are clearly, at the very least, an illegal manipulation of your data by previous managers of your AXA contracts. I appreciate your understanding of how unpleasant it is for us to have to manage these situations, which have been recurring since AXA dismissed the previous managers. I fear that the manipulation of your data is not new, and we understand that its purpose is to monitor all communications between AXA and you in order to offer you services in the other companies where they now work." Managers... I reiterate what I indicated to you regarding the fact that this is an extremely serious situation, and we have the utmost interest in blocking such illegal access to your "MYAXA" account, for which we require your authorization... SECOND: Forwarding of the complaint In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD), this complaint was forwarded to AXA so that they could analyze it and inform this Agency, within one month, of the actions taken to comply with the requirements established in data protection regulations. Since the deadline granted for submitting the required information was insufficient, the respondent requested an extension. On July 27, 2023, the deadline was extended to a maximum of 10 business days, and within this period, AXA submitted its arguments as follows: “That, after becoming aware of the claim filed, AXA immediately opened an internal investigation to clarify the events involving the claimant and its former agent, confirming the following facts: o That AXA and ***COMPANY.1 maintained a contractual relationship for thirty-eight (38) years, during which ***COMPANY.1 provided its services as an agent to the defendant. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 4/53 o That on December 1, 2021, AXA notified ***COMPANY.1 of the termination of the contract through A notarized demand for the serious breach of its contractual and legal obligations. Or, as a consequence of the termination of the mediation agreement between ***COMPANY.1 and AXA Seguros Generales S.A., the former exclusive agency automatically ceases to distribute AXA Aurora Vida S.A. insurance and reinsurance. That, as of December 1, 2021, the commercial relationship between both parties was terminated in its entirety. That, from that date, ***COMPANY.2 (hereinafter, ***COMPANY.2) assumed the management of the claimant's insurance policies, replacing ***COMPANY.1. That, on May 22, 2023, ***COMPANY.1 contacted the claimant to request, as the former Agent for her insurance policies, to resume managing her insurance policies, offering her the same price she was paying at that time. Furthermore, in that telephone conversation, the former Agent told the claimant that he could find out the premium the claimant was currently paying for her policies. As the complainant explains in her complaint to the Spanish Data Protection Agency (AEPD), on that same day she received two SMS messages from AXA providing her with a password initially a temporary one, and later an email confirming that her login details for her "MYAXA" customer area had been successfully changed. Since the complainant had not made such a change to her MYAXA login details, she contacted her current agent, ***EMPRESA.2, to inform them of the situation. AXA was able to verify that the password change in the complainant's customer area occurred on May 22, 2023. Given that the claimant did not change her password and did not access her client area with that new password, it can be stated that there was probable unauthorized access by COMPANY.1, for the purpose of gathering information on the policies currently held by the claimant and their associated prices, in order to offer her insurance policies at the same price, as stated in the phone call made to the claimant on May 22, 2023. That AXA has thoroughly reviewed the password change process in the "MYAXA" application. That, based on the above, it can be stated that ***COMPANY.1 was able to gain unauthorized access by impersonating the claimant, using its prior knowledge of the policy information, in order to obtain more information about the policies held and thus offer her insurance policies at a competitive price, as evident in the description of the facts underlying this claim and request for information. THIRD: Admission of the Complaint On August 28, 2023, in accordance with Article 65 of the LOPDGDD (Spanish Data Protection Act), the complaint was admitted for processing. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 5/53 FOURTH: Preliminary Investigation The Deputy Directorate General for Data Inspection carried out preliminary investigations to clarify the facts in question, pursuant to the functions assigned to supervisory authorities in Article 57.1 and the powers granted in Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VIII of the LOPDGDD. As a result of the actions carried out, has been made aware of the following: POINT 1 Within the framework of the admission procedure AT/03557/2023, the entity AXA has reported the following: The event motivating the claim is that on May 22, 2023, the claimant received a call from a former AXA insurance agent, ***COMPANY.1, requesting that she entrust her insurance policies to him again and offering her the same price that AXA was offering at that time. After becoming aware of the claim filed, AXA opened an internal investigation to clarify the events involving the claimant and her former agent. During this investigation, AXA states that it has been able to verify the following facts: - That AXA and ***COMPANY.1 maintained a contractual relationship for thirty-eight (38) years, during which ***COMPANY.1 provided its services as an agent to the defendant. - That on December 1, 2021, AXA notified ***COMPANY.1 of the termination of the contract through a notarized notice due to serious breach of its contractual and legal obligations, specifically for collaborating in the distribution of insurance with a brokerage firm, which contravenes the rules on incompatibilities established in Article 145 of Royal Decree-Law 3/2020, of February 4, on urgent measures incorporating into Spanish law various European Union directives in the areas of public procurement in certain sectors; private insurance; and pension plans and funds (RD-L 3/2020, of February 4), which establishes that “Insurance agents may not act as insurance brokers or external collaborators thereof [...]”. This action constitutes a serious breach of the legal obligations of ***COMPANY.1, as well as its duty of loyalty and good faith, having infringed both the rules and instructions given by the insurance company, and the legislation regulating the distribution of private insurance. They provide evidence of the notarized notification that records the communication of termination of the contract by AXA to ***COMPANY.1 on December 1, 2021. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 6/53 - As a consequence of the termination of the mediation contract between COMPANY.1 and AXA, the former exclusive agency automatically ceases to distribute insurance from AXA Aurora Vida S.A. de Seguros y Reaseguros, with which AXA has a Network Assignment Agreement to market its products through the AXA Seguros Generales sales network, in accordance with Article 148 of Royal Decree-Law 3/2020 of February 4. - That, as of December 1, 2021, the commercial relationship between both parties is fully terminated. They indicate that there is an ongoing legal proceeding in the Court of First Instance No. 1 of A Coruña, where the appropriateness of the contract termination is being determined based on the aforementioned facts. - That, from that date, COMPANY 2 (hereinafter, COMPANY 2) assumes the management of the claimant's insurance policies, replacing COMPANY 1, with whom AXA currently maintains a contractual relationship as its exclusive insurance agent, as established in Royal Decree-Law 3/2020 of February 4, on urgent measures incorporating into Spanish law various European Union directives in the field of public procurement in certain sectors. Private insurance; pension plans and funds; tax and tax litigation. - That the claimant currently has a life insurance policy and an auto insurance policy with AXA Group entities, both contracted through the intermediary COMPANY.1 (auto insurance policy dated June 21, 2019, and life insurance policy dated August 12, 2021). Currently, the intermediary for these policies is Agent COMPANY.2. - They state that on May 22, 2023, ***COMPANY.1 contacted the claimant to request, as the former Agent for her insurance policies, to manage her insurance again, offering her the same price she was paying at that time. Furthermore, in that telephone conversation, the former Agent told the claimant that he could find out the premium she was currently paying for her policies. - They state that, as The complainant states in her complaint to the Spanish Data Protection Agency (AEPD) that on the same day, she received two SMS messages from AXA, initially providing her with a temporary password, and later an email confirming that her access details for her "MYAXA" customer area had been successfully modified. Since the complainant had not made this change to her "MYAXA" access details, AXA contacted her current agent, ***EMPRESA.2, to inform them of the situation. - Once AXA received the request for information from the AEPD, they were able to verify that the complainant's password had been changed on May 22, 2023. They indicate that, given that the complainant did not change her password and did not access her customer area with the new password, it is reasonable to conclude that there was likely unauthorized access. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 7/53 ***COMPANY.1, for the purpose of gathering information on the policies currently in force for the claimant and their associated prices, in order to offer insurance policies at the same price, as previously stated in the telephone call made to the claimant on May 22, 2023. - That, taking into account the facts presented, AXA has thoroughly reviewed the password change process in the MYAXA application, which is described below, in order to determine when ***COMPANY.1 was able to access the claimant's profile: o On the first screen of MYAXA access, the user's tax identification number (NIF) and password are required. If the user does not remember them, they are given the option to click on "Forgot my password." o After clicking on "Forgot my password," the NIF is requested again, and then it is indicated that a temporary password has been sent to the email address provided by the customer. Given that COMPANY.1 does not have access to the claimant's email inbox, they had to click on the "I have not received my verification code" option. At that point, a temporary password is sent again to the alternative method previously provided by the claimant (SMS to their mobile phone). Since ***COMPANY.1 also does not have access to the claimant's mobile phone, they must have pressed the "I haven't received my verification code" option again. The next screen that appears after selecting that option presents security questions, the information for which is highly likely to be known by ***COMPANY.1 (policy number and the last four digits of their payment method). It is at this point, once this information is entered, that the option to change the password is given. Screenshots of the MYAXA password change process are provided. - That, based on the above, AXA indicates that it can be affirmed that ***COMPANY.1 was able to gain unauthorized access by impersonating the claimant, using its prior knowledge of the information related to the policy, in order to obtain more information about the policies contracted and thus be able to offer insurance policies at a competitive price, as can be seen from the description of the facts that are the subject of this claim. - That, ***COMPANY.1 and AXA had a data processing agreement in place dated April 15, 2005, which was updated in July 2018 due to the entry into force of the new General Data Protection Regulation (GDPR), as stated in the email sent to COMPANY.1 on July 17, 2018. They provide an informational email that informs the agent of the application of the new data processing conditions and the new Data Processing Agreement Annex. ... C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 8/53 - They indicate that, therefore, ***COMPANY.1 would have breached the data processing agreement formalized with AXA while it was still in force, which stipulated that, once the relationship between both parties was terminated, the Processor (the agent) was obliged to return the personal data that it had processed on behalf of the insurer, as well as not being able to use it for any purpose not authorized by AXA nor retain any copy of it, as established in clause three, subsection C, which is transcribed below: “Upon the termination or expiration of the contracted service, the Agency / Exclusive Agent or Data Processor is obliged to return, or if the Company so indicates, to destroy, all media, electronic or otherwise, on which the personal data originating from the files are recorded.” ownership of the Company, as well as those generated during the provision of the contracted service, in accordance with the method communicated by the Company, carrying it out securely and confidentially, within 10 calendar days from the date of termination of the service, without retaining any copy thereof, so that they cannot be recovered or reconstructed, and without any external person, natural or legal, gaining access to the data, unless expressly authorized by the Company.” - They indicate that, likewise, clause nine of the same Processing Agreement regarding liability, stipulates the following: “In the event of non-compliance by the Agency / Exclusive Agent or Processor with the obligations set forth in this document and others arising from applicable data protection legislation, it shall be considered the Data Controller and, specifically, shall assume full liability that may be incurred by the Company as a result of any type of administrative sanction imposed by the relevant authorities, as well as damages arising from judicial or extrajudicial proceedings against the Company, including attorney's fees, court fees, and any other professional fees, even if their intervention is not mandatory, and shall also be considered grounds for early termination of the agreement.” It is verified that the provided agreement contains the aforementioned clauses. They state that based on the above, ***COMPANY.1 should assume full responsibility for any administrative sanctions that may be imposed by the Spanish Data Protection Agency (AEPD) as a consequence of the facts alleged by the claimant. - In the notarial request for termination of the Agency contract, delivered by a notary on behalf of AXA to ***COMPANY.1 on December 1, 2021, a copy of which is provided, the following appears: “Based on the relationship maintained, where it assumed the status of Data Processor acting on behalf of the data controller C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 9/53 File (the Company), it undertook to process the data in accordance with the Company's instructions and for the strict provision of the services entrusted, without being able to use them for any purpose other than that agreed upon. Therefore, once the commercial relationship that bound it to this Insurer has been terminated, it is obliged to return the personal data that it has processed on behalf of this entity, including that of the insured parties or potential clients, and is also prohibited from using them for any purpose not authorized by the Data Controller, AXA. Therefore, at this time, we require you to return, in electronic format, all personal data originating from the files owned by the Company, within three days of receiving this communication, without retaining any copies thereof and without any external person, whether natural or legal, gaining access to the data. In this regard, we inform you that the personal data to which you have accessed as the exclusive agent may not be used for any purpose other than that agreed upon, nor may it be communicated or transferred, even for its storage, to other natural or legal persons. […]” It is verified that the notary public, in the attached notarial deed, in person at the premises of ***COMPANY.1 and delivers the document terminating the relationship, which includes the request for the return of data, as stated in the preceding paragraphs. AXA has been asked to provide information regarding whether a certificate exists for the destruction or return of data upon termination of the relationship with company ***COMPANY.1, requesting a copy of the certificate if applicable. AXA representatives referred to the aforementioned contract and notarial deed, copies of which are included in these inspection proceedings. - They state that, considering the events that occurred, it can be affirmed that ***COMPANY.1 contacted the claimant, which proves that the agent retained and processed the personal data of former clients to which he had access when he was still an AXA Agent, and that he used them for a purpose not authorized by the defendant, which constitutes an improper use of the claimant's personal data, with ***COMPANY.1 breaching the obligations agreed upon and communicated by AXA regarding the personal data to which he may have had access as Data Processor, once the Insurance Agency contract was terminated. - That, in order to prevent situations similar to the one addressed in this request from occurring, AXA has implemented, as a measure within the password change process in "MYAXA", the replacement of the security questions section with a new screen indicating a system error, directing the user to a customer service phone number. They provide a screenshot of what is displayed instead of the security questions section. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 10/53 They indicate that in this way, if the person trying to access the customer area account does not remember their password and has not correctly received the verification codes through the provided channels, they should contact customer service by phone. This prevents possible identity theft by a third party who might have information about the customer's current policies. Furthermore, to prevent possible unauthorized access to the claimant's customer area, they indicate that they have decided to adopt, as a complementary measure, the deletion of the claimant's user account in the MYAXA application. Therefore, if the claimant wishes to access their customer area, they must restart the registration process in the application with new credentials. AXA concludes the following in its statement: It affirms that it has not violated any current regulations on personal data protection, since the infringements that have been the subject of the claim filed by the claimant are attributed to a former AXA agent (***COMPANY.1), with whom there is no longer any contractual relationship in force, and whose actions are outside the scope of AXA's control, and these actions have contravened the obligations agreed upon by the parties in relation to the personal data to which he may have had access as the Data Processor, once the Insurance Agency contract was terminated. That, despite having no connection whatsoever with ***COMPANY.1, the respondent has taken all possible measures to prevent similar incidents, and is currently considering initiating legal action against ***COMPANY.1 and against any individuals or legal entities that may be collaborating, by action or omission, in the practices that are the subject of this complaint. POINT 2. AXA has been requested to provide a copy of the access logs to the claimant's customer area from May 22, 2023, to May 28, 2023. A copy of the logged data showing the date, time, and source IP address of the access was requested. AXA has responded that, after conducting the necessary investigations, it has only been able to determine from the access logs that the password change was confirmed on May 22, 2023, and that the last login to "MYAXA" occurred on June 27, 2023, at 8:35 a.m. However, it has not been possible to determine the IP address from which the password change was made, nor the logins, as the MYAXA logs are deleted after 30 days. AXA has been asked to provide a copy of the access logging/audit procedure for the MyAXA application, as well as the rationale for adopting the 30-day data retention period. They provide a document, “Access Logging/Auditing Procedure for the AXA Customer Area Application: MyAXA,” which states the following: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 11/53 Access Logging/Auditing Procedure which states the following: ❖ Audit Logs: The audit logs contain information about the resources of the user directory, the tokens issued, and administrator access, including the date and time of the event. Audit log events are retained for seven (7) days. ❖ MyAXA Login Logs: Each user's login is recorded every time they log in, both correctly and incorrectly due to having entered their login credentials incorrectly. In this regard, the following information related to logins is recorded, among other things: • the logging user • the date and time • the IP address Access • Location. These audit log events are retained for thirty (30) days, and their purpose is to provide information on how users connect to the application. (…) POINT 3 ***COMPANY.1 has been required to provide proof of the origin of the data used to contact the claimant, as well as to change the password. Additionally, a printout of the claimant's data is requested. In response, the entity has stated the following: “1. This company was the exclusive insurance agent for AXA until December 1, 2021, when its agency contract was terminated by the AXA group of insurers. 2. When AXA terminated the agency contract, this company lost the ability to access any data related to clients or insurance policies contracted with AXA through this company. At that time, AXA seized all the physical and digital documentation in my office and cut off access to its database through the insurer's website. ***COMPANY.1 was responsible for processing AXA's client data, with AXA itself being the data controller, and access was exclusively through the insurer's website. 3. ***COMPANY.1 did not store any data while it was an agent from AXA, and even less so after becoming an agent, since access to the data was blocked, any type of personal data. We cannot provide printouts of that person's data or anyone else's, as we do not have it. 4. Regarding the access mentioned through “MYAXA,” said access was personal and exclusive to clients, and neither during nor after the business relationship with AXA did this company have access to the access codes of any of the clients. Until the moment ***COMPANY.1 became an AXA agent C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 12/53 it was not possible to access said private database in the way described in your letter (policy number and 4 digits of the payment method); the only way was with the code that AXA sent directly to the client. Although this party does not know if, currently, it is possible to access it in that way. 5. When AXA terminated the agency contract with this company, it "gave away" the clients and their policies to another AXA agency, which is the one with access to the data. 6. […The claimant…] was an AXA client, through this company, at the time of the termination of the business relationship between AXA and ***COMPANY.1. All personal data was stored by the Data Controller, which was the Insurer; this company does not store any data on that person (or any other) and, as already stated, lost access on December 1, 2021. 7. ***COMPANY.1 has no employees (nor did it in May 2023). The management is handled by the undersigned (Company Administrator), and it is uncertain whether I contacted […the claimant…] by telephone. Date. Furthermore, it is stated that it has not contacted said person after the termination of their status as an AXA agent (except to inform them of said termination at the time). 8. This party is unaware if the current AXA Agency (unless otherwise stated by ***COMPANY.2.) has contacted said person, and also this party is unaware if […the claimant…] is currently an AXA client, because, as stated, it has not had any further contact with them. 9. For these reasons, we cannot verify the origin of the personal data nor print it because ***COMPANY.1. has no such data. FIFTH: Agreement to Initiate Disciplinary Proceedings On February 25, 2025, the Presidency of the Spanish Data Protection Agency agreed to initiate disciplinary proceedings against the respondent, in accordance with the provisions of Articles 63 and 64 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), for the alleged infringement of Article 32 of the GDPR and Article 5.1.f) of the GDPR, as defined in Articles 83.4 and 83.5 of the GDPR. SIXTH: Allegations to the Initiation Agreement Once the aforementioned initiation agreement was notified in accordance with the rules established in the LPACAP, the respondent submitted a statement of allegations, which are reproduced and addressed in the third legal basis of this resolution. SEVENTH. Change of Investigating Officer C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 13/53 On August 6, 2025, the President of the Spanish Data Protection Agency (AEPD) ordered a change of investigating officer for this sanctioning procedure. This change was notified to the respondent, and the corresponding acknowledgment of receipt, dated August 12, 2025, is included in the administrative file. EIGHTH: Proposed Resolution On October 30, 2025, a proposed resolution was formulated, proposing the dismissal of proceedings related to the possible infringement of Article 32 of the GDPR and the imposition of a fine for an infringement of Article 5.1.f) of the GDPR, classified under Article 83.5 of the GDPR. It was also proposed that, pursuant to Article 58.2.d) of the GDPR, the company be required to demonstrate the effective implementation of appropriate technical and organizational security measures, not only to comply with the regulations, but also to demonstrate compliance to supervisory authorities and interested parties. NINTH: Turnover and Number of Clients According to the report obtained from the AXESOR tool, the entity AXA SEGUROS GENERALES, S.A. AXA Insurance and Reinsurance is a company with a turnover of €553 million in 2023. Furthermore, the investigation has obtained a copy of the content of AXA's website, which shows that, as of April 2024, the insurer had more than 3.5 million clients. In light of all the actions taken by the Spanish Data Protection Agency in this case, the following facts are considered proven: PROVEN FACTS FIRST: The claimant has a life insurance policy and an auto insurance policy with entities of the AXA Group (auto insurance policy dated June 21, 2019, and life insurance policy dated August 12, 2021). At the time these policies were taken out, ***COMPANY.1 acted as an AXA agent. SECOND: On May 22, 2023, at 3:34 p.m., the claimant received two SMS messages, both with identical text, from “AXA INSURANCE” informing them of the generation of a temporary password to access their online customer area. The text of the messages is as follows: “Hello A.A.A., this is your password to access your customer area: ***PHONE.1. Thank you.” C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 14/53 THIRD. On May 24, 2023, the claimant received a response via email from AXA SEGUROS, in which, regarding the possible access to their personal data, they stated the following: “I fear the manipulation of your data is not new, and we understand that its purpose is to monitor all communications between AXA and you in order to offer you positions with other companies where those managers now work. What they are doing is unacceptable, and when you authorize us, we will also take appropriate legal action.” FOURTH. Regarding the contractual relationship between AXA SEGUROS and ***COMPANY.1, the following is noted: a) AXA and ***COMPANY.1 maintained a contractual relationship, in which ***COMPANY.1 provided its services as an agent to the claimant. By virtue of this relationship, both entities had a personal data processing agreement in place. a) On December 1, 2021, AXA notified ***COMPANY.1 of the termination of the agreement through a notarized notice due to serious breach of its contractual and legal obligations. b) As a consequence of the termination of the brokerage agreement between ***COMPANY.1 and AXA Seguros Generales S.A., the former exclusive agency automatically ceased distributing AXA Aurora Vida S.A. de Seguros y Reaseguros insurance. c) As of December 1, 2021, the entire commercial relationship between the two parties was terminated. d) Legal proceedings are currently underway between the two companies in the Court of First Instance, where the validity of the contract termination is being determined based on the aforementioned facts. e) As of December 1, 2021, ***COMPANY.2 (hereinafter, ***COMPANY.2) has assumed the management of the claimant's insurance policies, replacing ***COMPANY.1, with whom AXA currently maintains a contractual relationship as its exclusive insurance agent. FIFTH. At the time the events giving rise to this disciplinary proceeding occurred, AXA had established the following procedure for recovering the password to access the customer area (“MYAXA”) on the AXA website: o On the first screen when accessing MYAXA, the user's NIF (Spanish Tax Identification Number) and password must be entered. If the password is not remembered, the user has the option to click on “Forgot my password.” C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 15/53 o Next, the NIF (Spanish Tax Identification Number) is requested again, and then it is indicated that a temporary password has been sent to the method provided by the client. In this case, an SMS to their mobile phone. o Once the above message has been sent, there is the option to select "I have not received my verification code." o At that moment, a temporary password is sent again to the alternative method previously provided by the claimant. Again, the option "I have not received my verification code" is available. o The next screen that appears after selecting this option presents security questions, requiring the following information from the policyholder: • Policy number • Last 4 digits of their payment method. o Once this information has been entered, the option to change the password is available. SIXTH. AXA has confirmed that the password was changed on May 22, 2023, and that access to the claimant's website area occurred from that date until June 27, 2023, at 8:35 a.m., when the last entry to "MYAXA" took place. It has also confirmed that the MYAXA logs were deleted after 30 days. SEVENTH. AXA states that, subsequent to the events, as a measure within the password change process on "MYAXA," it implemented the replacement of the security questions section referred to in the previous finding with a new screen indicating a system error and directing the user to a customer service phone number. According to AXA, the purpose of this modification is to prevent “the possible impersonation of a third party who might have information about the client's current policies.” LEGAL BASIS I. Jurisdiction In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR) and as established in Articles 47, 48.1, 64.2 and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter LOPDGDD), the Presidency of the Spanish Data Protection Agency is competent to resolve this procedure. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 16/53 II. Preliminary Issues Article 4.1 of the GDPR defines “personal data” as: “any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.” Article 4.2 of the GDPR defines “processing” as: “any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.” Article 4.7 of the GDPR defines the "controller" as: "the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its appointment may be laid down by Union or Member State law." Article 4.8 of the GDPR, in turn, defines the "processor" as the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller. ... In this case, in accordance with Articles 4.1 and 4.2 of the GDPR, the processing of personal data is established, since AXA carries out, among other processing activities, the collection and storage of personal data of natural and legal persons with whom it manages insurance, as well as their financial protection, savings, and real estate investments. For example: name and surname, date of birth, telephone number, email address, and financial and banking details. AXA carries out this activity in its capacity as data controller, since it is the entity that determines the purposes and means of such activity, pursuant to Article 4.7 of the GDPR. Article 4, paragraph 12 of the GDPR broadly defines “personal data breaches” (hereinafter referred to as a personal data breach) as “any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.” In this case, a personal data breach has occurred under the circumstances described above, categorized as a confidentiality breach, as C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 17/53 a loss of confidentiality of the complainant's personal data has occurred, exposing their data to a third party. III. Allegations to the initiation agreement and response thereto The respondent has essentially submitted the following allegations to the initiation agreement. The order of presentation in the statement of allegations is followed. FIRST. Possible expiration of the preliminary investigation proceedings The respondent considers that these proceedings have expired because more than 18 months (the period stipulated in Article 67 of the LOPDGDD) have elapsed since the AEPD's "first request." AXA cites a ruling from the National Court, dated March 29, 2019 (appeal no. 232/2017), which clarifies the effects of the expiration of the preliminary investigative proceedings. Regarding this argument, two distinct aspects should be addressed. First, the expiry period itself. AXA's argument is as follows: “The first notification issued by the Spanish Data Protection Agency (AEPD) concerning this case was received by AXA on July 17, 2023, the date on which the eighteen-month period, established by Article 67 of the Spanish Data Protection Act (LOPDGDD), began to run. Therefore, this period expired on January 17, 2025, before the adoption of the Agreement to Initiate these proceedings.” In other words, it considers that the 18-month period stipulated in Article 67 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) for carrying out preliminary actions begins to run from the moment of what it calls the "first notification." Upon verification of this procedure, it is observed that it corresponds to the transfer of the complaint, as provided for in Article 65 of the LOPDGDD, and therefore precedes the preliminary actions. Article 67.2 of the LOPDGDD establishes the following: "The preliminary investigative actions shall be subject to the provisions of Section 2 of Chapter I of Title VII of this Organic Law and may not have a duration exceeding eighteen months from the date of the decision to admit the complaint or from the date of the decision to initiate them when the Spanish Data Protection Agency acts on its own initiative." In this case, the claim was admitted for processing after the expiration of the three-month period following its filing, as established in Article 65.5 of the Spanish Data Protection Act (LOPDGDD). This is recorded in the administrative file and was notified to the claimant. The claim was admitted for processing on August 28, 2023. This date marks the end date for calculating the statute of limitations for the preliminary investigation. Given that the period for carrying out these preliminary investigations is 18 months, the deadline would be February 28, 2025, which would be the starting date. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 18/53 The preliminary investigation period concludes with the notification of the decision adopted by the Spanish Data Protection Agency (AEPD) after these investigations have been carried out. This may consist of either a resolution to close the proceedings, or an agreement to initiate disciplinary proceedings. The latter was the option adopted by the Agency, given the clear indications of an infringement contained in the file. The agreement to initiate these disciplinary proceedings was signed on February 25, 2025, and was notified electronically on the same day, as evidenced by the acknowledgment of receipt in the file. Therefore, the notification occurred within the time limit granted by law, and the preliminary investigative proceedings would not have expired. The second aspect to be addressed would be the judgment submitted by AXA regarding the expiration of the preliminary proceedings. Upon analysis, it is observed that the ruling does not address the calculation of the time limit, but rather the effects of the expiration of the proceedings should it have occurred: “…The imposition of the corresponding sanction on the plaintiff was based on the evidence and investigative activity carried out during the preliminary proceedings. The declaration of the expiration of these proceedings means that there was not sufficient evidence in the proceedings to impute the sanction ultimately imposed on the appellant. Therefore, this sanction must be annulled, and the appeal upheld.” This Agency fully agrees with this, but it is not applicable to this case, since, as has been demonstrated, the preliminary proceedings never expired. The allegations related to the alleged infractions and their amount are addressed below. The order of the allegations is altered to analyze, first, the allegation related to the possible concurrence of infringements (allegation SIXTH), given its potential impact on the classification of the infringements and, consequently, on the response to the remaining allegations. SIXTH. Possible concurrence of infringements AXA alleges that both infringements charged in the initial agreement (articles 5.1.f) for breach of data confidentiality and 32 of the GDPR for lack of security measures) would be penalizing the same alleged offense: the adequacy or inadequacy of the measures implemented regarding access to the MY AXA account. Thus, it states that “Article 32 of the GDPR specifies how to comply with the principle of integrity and confidentiality enshrined in Article 5.1.f) of the GDPR.” It cites a precedent from a sanctioning procedure by the Spanish Data Protection Agency (AEPD): reference number PS/00259/2021, in which the Agency itself acknowledged the existence of a concurrent infringement of Articles 5.1.f) and 32 of the GDPR. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 19/53 Finally, it argues that the “Guide to Fines” (Guidelines 04/2022 on the calculation of fines under the GDPR of the EDPB. Adopted on May 24, 2023) also contemplates the existence of medial concurrence, although AXA does not invoke any specific section of said Guide, but only makes a generic assertion. In relation to these arguments, the following should be noted: First, the assertion that “Article 32 of the GDPR specifies how to comply with the principle of integrity and confidentiality set out in Article 5.1.f) of the GDPR” must be rejected. It is true that one of the mechanisms to guarantee the principle of confidentiality can be the establishment of security measures. But it's not the only one: let's remember that the aforementioned Article 5.1.f) refers to the adoption of “appropriate technical or organizational measures.” These measures, particularly the organizational ones, do not necessarily have to be security measures. In any case, Article 5.1.f) states “that adequate security of personal data be guaranteed,” that is, a result such as that guarantee. Therefore, the infringement of Article 5.1.f) is configured as an “obligation of result” and, conversely, its violation also requires the production of a result, which would be the loss of confidentiality or integrity. On the contrary, Article 32 requires the adoption of security measures appropriate to the risk (paragraph 2 of said article), without requiring the production of a result for it to be considered violated. In this sense, this obligation is configured as an “obligation of means” (the adoption of security measures) and not an obligation of result (it is not necessary that there has been unauthorized access or a loss of integrity or availability). Regarding the allegation that both infringements would sanction the same alleged offense, AXA argues the following: “In this case, the determining factor in both infringements is the adequacy of the measures implemented regarding access to the MY AXA account. From the arguments presented by the Spanish Data Protection Agency (AEPD) in the Initial Agreement, it can be deduced that, in relation to the facts analyzed, there is a direct connection between the violations of both articles. Thus, the infringement of Article 32 of the GDPR, that is, the consideration of AXA's measures as insufficient or inadequate, is necessary and unavoidable for a breach of the principle of integrity and confidentiality to occur, that is, for the infringement of Article 5.1(f) of the GDPR to be identified.” To analyze this issue, we must begin by examining whether the lack of security measures detected, and based on which the charge under Article 32 of the GDPR was made, are all directly related to the loss of confidentiality, which is the sanction under Article 5.1.f). If it is concluded that this is the case, that is, that there is no security measure independent of the resulting loss of confidentiality, it could be considered that there is a concurrence of infringements. Charge under Article 5.1.f) C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 20/53 As detailed in the agreement initiating the sanctioning procedure, there was unauthorized access by a third party (the former AXA insurance agent) to the complainant's data. According to the account of the facts, this third party accessed the private area of the complainant's website, taking advantage of an insufficiently robust password change procedure for accessing that area. The result was said unauthorized access and, consequently, the loss of confidentiality of the complainant's data, for which AXA is responsible. In this regard, the following facts are relevant: the evidence established during the investigation of these proceedings, and especially the messages received by the claimant alerting her to a change in her access password to her AXA private area, the confirmation that the password was changed on May 22, 2023, and that access was made to the claimant's website from that date until June 27, 2023, at 8:35 a.m. This access resulted in a loss of confidentiality of the claimant's data being processed by the defendant. This loss of confidentiality was made possible by the lack of measures adopted by the data controller to ensure its security. For these purposes, it is crucial that AXA acknowledged that the entire password change process could be carried out by an unauthorized third party—as occurred in this case—a circumstance that demonstrates a lack of adequate measures to guarantee the security of the processing. Allegation under Article 32. This allegation reflects the lack of security measures that led to the commission of the infringement. Specifically, it is stated that AXA had significant deficiencies and lacked the necessary security guarantees in the processing of personal data; since, knowing only the Policy Number and the last 4 digits of the payment method (data easily accessible to employees and data processors), it was possible to change the password for accessing the customer area of the website. It is therefore considered that said process suffered from a lack of security measures appropriate to the risk. In conclusion, it is clear that the lack of security measures is completely linked to the resulting loss of confidentiality. This result occurred as a consequence of the identified lack of security measures. The following section addresses the obligations regarding the classification and amount of the infringements, with the necessary adjustments to the change in the charges. SECOND. Regarding the factual scenario. In this section, AXA only provides a chronological account of the events. - The claimant allegedly received a call from the former AXA agent (***COMPANY.1). Next, he receives two SMS messages and one email. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 21/53 (The latter informs that the MYAXA access data has been successfully modified.) The complainant files a complaint with AXA and is told that it would not be necessary to block the account. Previously, AXA had terminated the agent contract due to breach by ***COMPANY.1. It states that the breach has already been declared by a court ruling. It is deduced from all of this that ***COMPANY.1 would have engaged in irregular processing of the data for which it was initially responsible as an agent of AXA. And then would have accessed the complainant's MYAXA virtual private area. The complainant makes no allegations in this regard, only relating the facts as the defendant understands they occurred. THIRD. Infringement of Article 5.1.f) of the GDPR Regarding this allegation, it is argued that access to the data by unauthorized persons has not been proven. This possibility is only mentioned in the account of the complainant. In any case, AXA asserts that a penalty for the violation of Article 5.1.f) cannot be imposed solely on the mere occurrence of a result. This article mandates the implementation of appropriate technical and organizational measures to ensure the integrity and confidentiality of data, but in no case does it require absolute effectiveness of these measures. In this regard, it argues that "Article 5.1, paragraph f) of the GDPR, in accordance with the spirit of the regulation itself, establishes an obligation of means, not an absolute or result-based obligation." Thus, it argues, the penalty in this proceeding is based solely on the occurrence of a result. This implies that it would constitute the imputation of strict liability, which is prohibited under our legal system. The judgment of the Court of Justice of the European Union (regarding case C-683/212 Nacionalinis visuomenės sveikatos centras) indicates that supervisory authorities cannot impose requirements not provided for in the GDPR, and the GDPR only provides for liability for infringements involving intent or negligence. Therefore, since culpable conduct has not been proven, no sanction could be imposed in this case. Furthermore, it invokes Supreme Court Judgment No. 543/2022, of February 15, which states that: “The obligation to adopt the necessary measures to guarantee the security of personal data cannot be considered an obligation of result, which implies that, in the event of a personal data breach to a third party, there is liability regardless of the measures adopted and the activity carried out by the data controller or processor.” Thus, to fulfill an obligation of means, it would suffice to establish technically adequate measures and implement and use them with reasonable diligence. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 22/53 Regarding this allegation, the following response is appropriate. First, regarding the establishment of the loss of confidentiality. In this respect, it is necessary to refer to the account of the facts provided by the respondent in its reply to the request Information provided by the Agency's inspection bodies: “Once AXA received the request for information from the Spanish Data Protection Agency (AEPD), it was able to verify that the password in the claimant's customer area was changed on May 22, 2023. They indicate that, given that the claimant did not change her password and did not access her customer area with the new password, it can be concluded that there was likely unauthorized access by ***COMPANY.1, with the purpose of gathering information on the claimant's active policies and their associated prices, in order to offer her insurance policies at the same price, as stated in the phone call made to the claimant on May 22, 2023.” “Based on the above, AXA indicates that it can be stated that ***COMPANY.1 may have gained unauthorized access by impersonating the claimant, using prior knowledge of the information related to the policy, in order to obtain more information about the policies contracted and thus offer insurance policies at a competitive price, as demonstrated by the description of the events that are the subject of this claim.” “AXA has responded that after conducting the appropriate investigations, it has only been able to determine from the access log that on May 22, 2023, the password change was confirmed, and that on June 27, 2023, at 8:35 a.m., the last entry to “MYAXA” occurred. However, it has not been possible to determine from which IP address the password change was made, nor the accesses, since the MYAXA logs are deleted after 30 days.” The defendant itself verified that unauthorized access had occurred, by someone who was formerly an AXA agent but no longer held that position. These unauthorized accesses could have continued for at least a month. Furthermore, the defendant itself confirms the lack of measures in place to trace the access: the claimant contacted AXA after receiving messages alerting them to the password change, and AXA responded on May 24, 2023. Despite this response, AXA failed to take any measures to safeguard the affected private area and, especially, to preserve the access logs that were being created and which should have been available, as the 30-day retention period mentioned by the defendant had not yet expired. The defendant also argues that, should the confidentiality of the data be deemed to have been compromised, the penalty would only be based on the resulting outcome, disregarding the underlying issue. culpable and thereby incurring a case of strict liability. It must be ruled out that such an attribution is occurring. Indeed, for the infringement to be considered committed (the only one that remains after ruling out the continued existence of the two initially imputed infringements, that is, the one under Article 5.1.f), two elements must be present. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 23/53 First, as already stated, the production of a result. The complainant's data was accessed by someone who lacked the legal authority to do so. And second, that this breach of confidentiality was facilitated by the lack of technical and organizational measures stipulated in Article 5.1.f) to ensure its protection. As we have indicated and as detailed in the legal basis regarding the application of Article 5.1.f), the password recovery procedure established by AXA suffered from significant weaknesses. If an attacker were to successively select the options indicating that they had not received the SMS for password recovery, nor subsequently the email for identity verification, they would only need to answer verification questions. It cannot be ruled out that third parties might know the answers to these questions. This is especially true in this case, given that, according to the account of events provided by the defendant, the termination of the contract with the previous insurance agent was not an amicable process. Therefore, the negligence in establishing the technical and organizational measures (weakness of the password recovery or change procedure) and the resulting breach of data confidentiality constitute a clear violation of Article 5.1.f) of the GDPR. It is worth mentioning the judgment of the National Court of February 9, 2023, which addresses a substantially identical case. Regarding the loss of confidentiality, the defendant argued that the penalty was being imposed solely for the occurrence of a result, indicating that it constituted a case of strict liability. The National Court declares that: “Furthermore, it is clear that the risk of identity theft is a constant presence in Xfera's business activities. It is a real risk with the ultimate goal of impersonating another person and, in cases such as the one examined, facilitating the purchase of products or the acquisition of a duplicate SIM card by someone who is not the true owner. The appellant cannot claim that this risk was unknown to them. Regarding the alleged strict liability, the appealed decision does not hold Xfera responsible for the outcome, but rather for a loss of confidentiality linked to the inadequacy of the security measures implemented and, ultimately, due to a lack of due diligence on the part of said entity. Thus, the Spanish Data Protection Agency (AEPD) argues—page 858 of the file—that “it has been proven that the measures implemented by Xfera are insufficient (…) In a non-exhaustive manner, we will focus on the deficient design of the questions formulated in the security policy in order to to obtain the duplicate SIM card.” It only remains to say that the judgment submitted by the interested party to support its arguments (STS No. 543/2022, of February 15) is not applicable to this case, since C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 24/53 it refers to the obligation to establish security measures as an obligation of means.” And it is not applicable to this case for two reasons: first, because in this sanctioning procedure, the commission of an infringement of Article 5.1.f) is being alleged, which, as we have seen, does require the production of a result. And second, because AXA has cited the content of this judgment in connection with its arguments regarding Article 5.1.f), that is, before knowing that, according to the previous allegation, only this Last. FOURTH. Infringement of Article 32 of the GDPR In this section, AXA states that it had adequate and effective security measures in place for the password recovery process for the private customer area in MYAXA. Thus, it considers the password change procedure to be robust: if the password is forgotten, a temporary password is sent via SMS, and if this is not received, questions are asked about specific data related to the policy and the payment method used by the customer. No third party would have access to the information requested in the security questions used to recover the password. AXA further states that the fact that AXA agents had access to the data linked to the agents' policies does not justify classifying the measures as inadequate. It also considers that the Spanish Data Protection Agency (AEPD) does not provide a technical argument to support its claim of a lack of security measures. Therefore, The client area would have two-factor authentication (2FA). AXA also states that, following the termination of the contract, the return or destruction of personal data was guaranteed, and the former agent's access was revoked. Furthermore, the engagement agreement stipulated that if the instructions were violated, the agent would be held responsible for the data processing. It also imposed the obligation to return the data and not retain any copies. This obligation was reminded to the agent in the termination notification. AXA concludes by stating that there are no specific security measures mandated by the regulations. In any case, AXA asserts that it is complying with the provisions of Royal Decree 1720/2007, of December 21, which approves the Implementing Regulation of Organic Law 15/1999, of December 13, on the protection of personal data, without that, it claims, there is nothing additional required in this regard. Regarding these statements, the following should be noted: First, it should be made clear that the weakness of the procedure established by AXA for the recovery or generation of a new password constitutes, as stated in the preceding sections, an infringement of Article 5.1.f) of the GDPR. The infringement was caused by a procedure with weaknesses, as will be seen, and furthermore, it resulted in the loss of confidentiality of the complainant's data, which was accessed in an illegitimate manner by the previous AXA insurance agent. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 25/53 Regarding the assertion that said procedure would be secure, stating that “No third party would be in possession of the information requested in the security questions asked to recover the password,” It is necessary to remember what data is requested from someone who claims not to have received either the SMS or the email previously, in order to guarantee the applicant's identity. And the data requested is: policy number and the last 4 digits of their payment method. While this data cannot be said to be generally available, it cannot be ruled out that certain individuals, depending on their involvement in this sector's traffic, may have access to it. For these purposes, as already mentioned in the response to the previous section, the situation between AXA and ***COMPANY.1 following the termination of their business relationship is completely relevant. As AXA itself states in its background information, this termination was far from amicable, and the matter has ended up in court. Therefore, the possible unauthorized access to its clients' personal data, which ***COMPANY.1 He would have access in his capacity as a former agent of the first company. No precautions were established in this regard, so that, not only for the case of the claimant, but for any AXA client whose contract was handled by ***COMPANY.1, there was a real risk that, through a flawed procedure, access could be gained to the personal data of these clients. This is what happened, at least, in the case reported by the claimant. The procedure clearly suffered from weaknesses in this respect; and, aware of this, AXA argues in its defense that it had established a two-factor authentication system for this type of transaction. To that end, among its arguments, it provides a screenshot of the website. Analyzing this image, it can be seen that this option is set as optional for the client, that is, only if the client chooses it. Therefore, the two-factor authentication factor does not exist for all those clients who simply do nothing. In other words, don't activate it. Furthermore, in its arguments, AXA attempts to prove that ***COMPANY.1 returned or destroyed the data for which it was the data processor. Regarding this matter, two points should be noted. First, it provides no documentation (certificate of return or destruction, or similar) to prove that this occurred. Secondly, it must be stated that this aspect is not what led to the application of Article 5.1.f) in the present proceedings, but simply the discovery that the password recovery or new password generation procedure had weaknesses. Had it been robust (such as including questions whose answers were not available to a data processor or the mandatory implementation of two-factor authentication), the return of data, even though it is an obligation that must be demanded of the data processor, would have been irrelevant. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 26/53 Regarding the claim that there is no imposition of specific security measures by the regulations, we can only agree with this assertion. This Agency is not at any point indicating or suggesting what technical or organizational measures AXA should have established to guarantee the robustness of the password procedure. It merely states that it is clear that the procedure in place did not meet the minimum security and robustness requirements to guarantee data confidentiality. This is especially true given the clearly foreseeable risk for the data controller that the previous processor had access to information that would allow them to breach that confidentiality. Therefore, this allegation must be dismissed. FIFTH. Role of the Data Controller AXA, as the data controller, states that it established for its processor the obligations to process personal data, in accordance with its instructions, and furthermore, the obligation to return or destroy said data after the termination of the contract. In this regard, the alleged actions would imply that ***COMPANY.1 processed the data for its own purposes, which would entail its own liability, as expressly provided for in Article 28.10 of the GDPR. Therefore, the alleged actions would not constitute a lack of measures on the part of the data controller; rather, it is ***COMPANY.1, as the data processor, who has failed to comply with the controller's instructions; and thus, it would be the one in breach of the obligations set forth in the GDPR for data processors, specifically in Articles 28, 33, and 82. To address this allegation, it suffices to point out that the purpose of this sanctioning procedure is not the potential liability that ***COMPANY.1 might incur for the unlawful processing of personal data. On the contrary, the sanction is for AXA's failure to adopt appropriate measures of all kinds to guarantee the security of personal data. This is evidenced by AXA's establishment of a password recovery or generation procedure that did not meet sufficient technical and organizational standards to guarantee the confidentiality of personal data, as detailed throughout this resolution. Consequently, the claim must be dismissed. SEVENTH. Proportionality of the Sanction In this section, AXA includes arguments regarding the circumstances considered in determining the amount of the sanction. First, it should be noted that AXA disagrees with the aggravating circumstances considered in this procedure for determining the amount of the sanctions. Regarding this claim, two fundamental aspects should be noted. First, the respondent characterizes all the circumstances considered in the initial agreement as "aggravating." It must be clarified that this is not the case. In accordance with C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 27/53 with Guidelines 04/2022 on the calculation of fines under the GDPR, of 24 May 2023, of the European Data Protection Board Guidelines (hereinafter, the Fines Guide), the determination of the amount of the penalty follows successive stages. The first stage is the determination of the initial amount of the penalty. This is covered in Chapter 4, “Starting Point for Calculation,” of the Guide (sections 46 et seq.). Certain aspects expressly indicated in the guide are taken into account when calculating the initial amount. Among these factors (besides, obviously, the volume of business) are the “nature, seriousness, and duration of the infringement” (paragraphs 53 et seq.); the “intentional or negligent nature of the infringement” (paragraphs 55 et seq.); and the “categories of personal data affected” (paragraphs 57 et seq.). The application of these circumstances determines the base amount of the fine, upon which the aggravating or mitigating circumstances would then be applied. In the present proceedings, for each infringement, the circumstances specified in Chapter 4 of the guide were taken into account when calculating the initial amount. Specifically, the volume of business, the seriousness of the infringement, and the degree of intent or negligence involved, and, where applicable, the type of personal data affected. Aggravating circumstances were subsequently identified. Among them, the connection of the party being sued with the processing of personal data. This was stated in the initial agreement, distinguishing between circumstances for determining the amount, and, subsequently, aggravating or mitigating factors. Circumstances of Article 5.1.f) GDPR First, it considers that by stating the “Intentionality or Negligence” (circumstance of Article 83.2.b) GDPR), the initial agreement only refers to the production of a result, without demonstrating the presence of at least negligence. This is not the case. In fact, the reasoning behind the existence of this circumstance, in the initial agreement, indicated that “there is no doubt that, in the case now under examination, when the appellant's activity involves the constant and extensive handling of personal data, it is essential to emphasize the rigor and meticulous care required to comply with the relevant legal provisions. [Judgment of the National Court of 17/10/2007 (appeal no. 63/2006)]” In any case, as already indicated, the proposed resolution maintained only the imputation of the infringement of Article 5.1.f) GDPR. And it is argued, in the section on quantifying the penalty, to which we refer, that there is clearly negligence in the infraction, as AXA maintains a clearly weak password generation or recovery procedure by failing to take into account that the information requested by telephone may be in the possession of individuals other than the account holder and, furthermore, the immediate precedent of an amicable break with the previous insurance agent, which could increase the risks of unauthorized access. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 28/53 Regarding the aggravating circumstance of the habitual processing of personal data (Article 76.2.b) LOPDGDD), it considers that this circumstance must be directly related to the specific case. And in this case, AXA states, the infraction would have been committed by the activity of a third party. As is easily understood, this aggravating circumstance provided for in Article 76 of the LOPDGDD (Spanish Data Protection Law) refers to the status of the data controller. In this case, that controller is AXA, a large insurance company whose legal activity is clearly and directly related to the routine processing of personal data. This is for the purpose of managing the contracting, modifications, terminations, and, for example, claims related to the contracts it manages. There is no doubt that the facts are also directly related to this routine processing, given that there has been unauthorized access to the personal data of an AXA client through the client area of the website. This is the rationale behind the agreement initiating the sanctioning procedure: “AXA, in the course of its business, manages both its insurance and its financial protection, savings, and real estate investments, serving the financial needs of clients, both individuals and companies. Consequently, and for the purposes of complying with the legally established requirements, the exercise of said activity necessarily implies the knowledge and application of current regulations regarding the protection of personal data.” In this regard, it is worth mentioning the Judgment of the Administrative Chamber of the National Court of July 4, 2024, which, in relation to this aggravating circumstance, states: “Likewise, the assessment of the connection between the activity of the offender and the processing of personal data (Art. 72.2.b) of Organic Law 3/2018, of December 5) is correct, given that the activity of the appellant is linked to the processing of data of both clients and of third parties; the aforementioned connection is known since the entity, due to its activity, is in constant contact with clients and third parties, processing a large volume of data, which imposes a greater duty of care.” Consequently, this allegation must be dismissed. Circumstances of Article 32 GDPR Regarding the circumstance of intent or negligence in the infringement (Article 83.2.b) GDPR), as with Article 5.1.f), it considers that the motivation has a strict liability approach. This cannot be considered the case, since the initial agreement adequately justifies the consideration of this circumstance: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 29/53 “And in assessing the degree of diligence, special consideration must be given to the professionalism of the individual, and there is no doubt that, in the case now examined, when the appellant's activity involves the constant and extensive handling of personal data, emphasis must be placed on the rigor and exquisite care to comply with the legal requirements in this regard. [Judgment of the National Court of 17/10/2007 (appeal 63/2006)]” Regardless of the foregoing, as already indicated, the proposed resolution maintains only the charge under Article 5.1.f). With regard to the circumstances concerning the categories of data affected (Article 83.2.g GDPR), AXA alleges that the initial agreement mentions the processing of personal data related to “payment methods”. However, its regulations (Royal Decree-Law 19/2018, of November 23, on Payment Services, indicates in Article 3.12 that “With regard to the activities of payment initiation service providers and account information service providers, the name of the account holder and the account number do not constitute sensitive payment data.” In response, it is necessary to point out that the type of data affected, as already explained, does not constitute an aggravating circumstance, but rather one that is taken into account; that is, the data that has been affected, for the initial determination of the amount of the penalty, before the application, if any, of aggravating or mitigating circumstances. In this sense, the initial agreement explicitly states that “data especially relevant to the affected parties, including data of a financial nature, such as payment methods,” has been affected. It makes no reference to “sensitive” data, as AXA alleges. Let us also recall in this The aforementioned Guidelines on the Calculation of Fines, in paragraph 57, state the following: Regarding the requirement to consider the categories of personal data concerned [Article 83(2)(g) of the GDPR], the GDPR clearly highlights the types of data that warrant special protection and, therefore, a stricter response in terms of fines. This refers, at a minimum, to the types of data referred to in Articles 9 and 10 of the GDPR and to data outside the scope of these articles whose disclosure would cause immediate harm to the data subject (e.g., location data, data concerning private communications, national identification numbers, or financial data such as transaction summaries or credit card numbers). In general, the more of these categories of data involved or the more sensitive the data, the more weight the supervisory authority may give to this factor. Regarding the aggravating circumstance related to the habitual processing of personal data (Article 76.2.b) of the Spanish Data Protection Act (LOPDGDD), AXA argues that the mere fact of determining the data controller's economic activity cannot automatically constitute an aggravating circumstance. This would lead to a lack of due process. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 30/53 It suffices to refer to the response to the identical circumstance of the previous infringement, the doctrine of which is endorsed by the aforementioned National Court ruling reproduced therein. Mitigating circumstances that would apply. In this section, AXA argues that there are circumstances that should be considered mitigating factors. These would be the following: - The defendant proceeded to correct and adopt measures to mitigate the consequences arising from the breach, as well as to prevent possible similar situations (Art. 83.2 c). In relation to this possible mitigating factor, sections 75-76 of the aforementioned Guide on fines, which establish the following: “The adoption of appropriate measures to mitigate the damages suffered by the data subjects may be considered a mitigating factor that reduces the amount of the fine.” (section 75) Measures applied spontaneously before the controller or processor is aware of the start of the investigation by the supervisory authority are more likely to be considered a mitigating factor.” (Point 76) Regarding this allegation, it is necessary to analyze the wording of the possible mitigating circumstance, both in the GDPR and in the Guide to Fines. Reference is made to the adoption of measures to “mitigate the damages suffered by the data subjects.” It should be noted that AXA invokes this circumstance in a generic way, without explaining what measures it has adopted. If it refers, as seems plausible, to the strengthening of the password procedure, however laudable this action may be, it is clear that it does not prevent or mitigate the damages suffered by the affected party, since the confidentiality of their data had already been compromised. Preventing future incidents in no way mitigates or alleviates the damages resulting from the loss of control over their personal data. It is therefore not possible to apply this mitigating circumstance. - At no time were special categories of data processed (Art. 83.2 g). As already As indicated, this circumstance is one of those foreseen in the fines guide for determining the base amount. This resolution specifies which personal data would have been affected, for the purpose of being taken into account in determining the amount. - The degree of cooperation of AXA with the Spanish Data Protection Agency (AEPD) in order to remedy an alleged infringement and mitigate its possible adverse effects: it alleges that it C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 31/53 has responded in a timely manner to all requests for information made by this Agency, in line with this company's usual practice of full cooperation with the data protection authority (Art. 83.2 f) GDPR). In this regard, sections 96 and 97 of the Fines Guide impose a double requirement for this circumstance to be applied as a mitigating factor. In first In this case, as the respondent itself indicates in its allegations, the cooperation goes beyond the ordinary duty to collaborate with the supervisory authority. Indeed, the Guide states that the ordinary duty to cooperate is mandatory and, therefore, should be considered neutral (and not a mitigating factor). In this case, all actions that could be classified as "cooperation" with the supervisory authority fall within the duty to cooperate. In this sense, the information and documentation provided were submitted in response to requests from this Agency. The second requirement is that the cooperation has had the effect of limiting or preventing the negative consequences for the rights of individuals that might otherwise have occurred. As we have seen, this is not the case here, since the actions aimed to restore the service and prevent future incidents, but not to prevent or mitigate the damages suffered by those affected, whose power to control their personal data had already been compromised. This is stated in the Judgment of The National Court ruling of February 10, 2023, states: “The mitigating circumstances alleged are not applicable to this case; thus, the purported collaboration with the Spanish Data Protection Agency (AEPD) occurred almost two months after the infringement, in response to a request for information from the Agency itself, and was ineffective in remedying the infringement or mitigating its potential adverse effects, as required by Article 83.2 f) of the GDPR; regarding the absence of culpable or negligent conduct, the negligent conduct in data processing has been proven, which constitutes the culpable element of the infringement, and therefore cannot mitigate its effects of the infringement.” It is therefore not possible to apply this mitigating circumstance. - Adherence to codes of conduct pursuant to Article 40 or to certification mechanisms approved under Article 42 (Art. 83.2 j). In addition to the information already contained herein regarding the measures adopted by AXA, providing ISO/IEC 27001:2013 Certification In relation to this circumstance, it should be clarified that this certification is related to compliance with information security standards. That is, they are developed and applied from the perspective of risks to the organization, not the rights and freedoms of data subjects regarding their personal data. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 32/53 In fact, section 105 of the Fines Guide, in relation to this circumstance, refers to the codes of conduct provided for in Article 40 et seq. of the GDPR. These are drawn up from the perspective of protecting the fundamental right to data protection and (Article 38.3 LOPDGDD) will be approved by the supervisory authority. This is not the case here. Therefore, this suggested mitigating circumstance cannot be applied. - The non-existent benefit obtained by AXA in the factual scenario that concerns this proceeding. In any case, AXA would have been harmed, as already indicated, being an injured party in the irregular action of COMPANY.1 (Art. 83.2 k). It must be stated from the outset that this provision can only be considered an aggravating circumstance if the benefit was obtained. This grading criterion is established in the LOPDGDD in accordance with the provisions of Article 83.2.k) of the GDPR, according to which administrative fines will be imposed taking into account any “aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement,” it being understood that avoiding a loss has the same nature for these purposes as obtaining benefits. If we add to this that the sanctions must be “in each individual case” effective, proportionate, and dissuasive, as provided for in Article 83.1 of the GDPR, admitting the absence of benefits as a mitigating factor is not only contrary to the factual premises contemplated in Article 76.2.c), but also contrary to the provisions of Article 83.2.k) of the GDPR and the principles mentioned. Thus, considering the absence of benefits as a mitigating factor would negate the deterrent effect of the fine, insofar as it diminishes the impact of the circumstances that actually influence its amount, granting the responsible party a benefit they have not earned. It would be an artificial reduction of the penalty that could lead to the understanding that violating the rule without obtaining benefits, financial or otherwise, will not produce a negative effect proportional to the seriousness of the infraction. It is pertinent to cite the Judgment of the National Court, dated May 5, 2021, rec. 1437/2020, which states: “It considers, on the other hand, that the non-commission of a prior infringement should be taken into account as a mitigating factor. Article 83.2 of the GDPR establishes that the following must be considered for the imposition of the administrative fine: “e) any prior infringement committed by the controller or the processor.” This is an aggravating circumstance; the fact that the conditions for its application are not met means that it cannot be taken into consideration, but it does not imply C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 33/53 nor does it allow, as the plaintiff claims, its application as a mitigating factor”; applied to the case under consideration, the lack of the conditions for its application with respect to art. 76.2.c) of the LOPDGDD, that is, obtaining benefits as a consequence of the infringement, does not allow its application as a mitigating circumstance. IV. Allegations to the proposed resolution and response thereto The allegations that AXA has presented regarding the proposed resolution are analyzed and responded to below. The order of presentation in the statement of allegations is followed. FIRST. – ON THE EXPIRATION OF THE PRELIMINARY INVESTIGATIVE ACTIONS In this section, AXA reiterates one of the allegations it already made in relation to the agreement to initiate the proceedings. It insists that the deadline for carrying out preliminary investigative actions by this Agency would have expired before the start of the sanctioning proceedings. This is because it considers that the start of the deadline (“dies a quo”) occurs at the moment it received the “first request” from this Agency. From that moment until the notification of the agreement to initiate the proceedings, a period exceeding the 18 months prescribed by Article 67 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) would have elapsed. In response to this allegation, the proposed resolution indicated that what AXA considers the start of the preliminary proceedings is merely the written notification of the complaint, a step provided for in Article 65.4 of the LOPDGDD and prior to the commencement of the preliminary investigation. This investigation begins upon the admission of the complaint (Article 67.2 of the LOPDGDD). To this argument, already included in the proposed resolution, AXA now counters with the argument that, despite the AEPD's "formal criterion" of considering that the time limit for preliminary investigations begins with the admission of the complaint, what the AEPD calls "transfer" would actually be in the nature of preliminary investigative actions "de facto," since its entity was required to answer a significant number of questions, which would imply a certain amount of investigative activity. Regarding this allegation, the following must be answered. Articles 64 et seq. of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) determine the procedure that the AEPD must follow for processing complaints it receives for alleged violations of personal data protection regulations. To this end, it establishes several clearly differentiated phases: - First, there is a judgment on the admissibility of the complaint. Paragraphs 2 and 3 of Article 65 establish the grounds for inadmissibility. And with regard to the decision on its admissibility, paragraph 4 of the aforementioned article establishes an optional procedure, namely, forwarding the complaint to the data controller, so that, in its response, the controller can provide information and documentation that contributes to the adoption of said decision. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 34/53 - Secondly, after the complaint has been admitted, if the Spanish Data Protection Agency (AEPD) considers that further steps are necessary to reach a decision, regarding the initiation of possible sanction proceedings or, conversely, the dismissal of the case, the Agency may open a period of preliminary investigation. This period begins after the complaint has been admitted and concludes with the aforementioned decision. And for this purpose, Article 67 of the LOPDGDD establishes a maximum period of 18 months. - Finally, the sanctioning procedure itself, which, if any preliminary actions are carried out, will begin after these by means of the initiation agreement and has a maximum period of 12 months (Article 64.2 LOPDGDD). Well, all these procedural phases have been followed in the present procedure. First, once the complaint was received, on July 17, 2023, it was forwarded to AXA so that they could provide information and documentation for the decision on its admissibility. The complaint was admitted for processing because three months had passed since its filing (Article 65.5 LOPDGDD). And this admission was duly notified to the complainant, as provided in that same section. Following the acceptance of the case, it was determined that preliminary investigative actions were necessary. This led to two successive requests from the Spanish Data Protection Agency (AEPD) to AXA (dated 18/01/24 and 21/06/24). Subsequently, the final report on the preliminary investigative actions was issued (18/07/24), and finally, the initiation of a sanctioning procedure was initiated by means of a decision dated 25/02/25. All procedural phases have been scrupulously followed. And as explained in the response to the objections to the decision to initiate the procedure, the preliminary investigative actions did not expire, since the acceptance of the case was dated 28/08/24 and the notification of the decision to initiate the procedure occurred on 25/02/25. AXA now counters that, while this would formally be the established procedure followed by the Agency, a "formalistic" approach is being used, since it believes that the request for information made by the Spanish Data Protection Agency (AEPD) during the transfer process could actually be considered part of a preliminary investigation. However, this is not the case. Article 65.4, regarding the procedure for forwarding the complaint, states that: “4. Before deciding on the admissibility of the complaint, the Spanish Data Protection Agency may forward it to the data protection officer appointed by the controller or processor, if applicable, to the supervisory body established for the application of the codes of conduct, or to the body that assumes the functions of out-of-court dispute resolution for the purposes set out in Articles 37 and 38.2 of this Organic Law. (…) C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 35/53 If, as a result of these referrals, the controller or processor demonstrates that they have adopted measures to comply with the applicable regulations, the Spanish Data Protection Agency may reject the complaint.” This Agency did so, forwarding the claim details to AXA so that they could present their case.The most important point is that the request addressed to AXA states: “In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD), which establishes a mechanism prior to the admission of complaints to the Spanish Data Protection Agency, consisting of forwarding them to the Data Protection Officers appointed by the controllers or processors, for the purposes set forth in Article 37 of the aforementioned law, or to the controllers themselves when they have not appointed them, so that they may analyze said complaints and respond within one month, the relevant information contained in the complaint is being sent, summarized below.” The document makes it clear that this action falls within the decision-making process regarding admissibility. And after this procedure, the request was admitted for processing. Regarding the content of the information request, it cannot be stated that its level of exhaustiveness and specificity is such that it "de facto" implies the undertaking of an investigation, since it is formulated in very generic terms: - Submission of the technical reports or recommendations prepared by the Data Protection Officer or the security officer, regardless of their format, regarding the processing activities for which information is requested, as well as the subsequent actions taken or their absence, resulting from said technical reports or recommendations. - The decision adopted regarding this complaint. - Report on the causes that led to the incident that gave rise to the complaint. - Report on the measures adopted to prevent similar incidents, implementation dates, and controls carried out to verify their effectiveness. - Any other information considered relevant. Subsequently, it is also necessary to note that the two requests made by the Spanish Data Protection Agency (AEPD) within the framework of the preliminary investigation also clearly and precisely reflect the stage of the proceedings we are currently in. Both documents state that: “Within the framework of the actions carried out by the Deputy Directorate General for Data Inspection in order to clarify certain facts of which this Spanish Data Protection Agency has become aware, and in exercise of the powers conferred by Article 58.1 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, we hereby request the following information: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 36/53 Pursuant to the General Data Protection Regulation (hereinafter, GDPR), and Article 67 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD), you are requested to submit the following information within ten business days. Article 67 of the LOPDGDD, which regulates the preliminary investigation phase, is expressly mentioned. It is also important to note that the formal requests conclude with the following warning: “Failure to comply with this obligation could constitute the infringement specified in Article 72.1.ñ) of the LOPDGDD, which will be sanctioned in accordance with Article 58.2 of the GDPR.” Article 72.1.ñ) defines, for the purposes of the statute of limitations, the infringement consisting of: “ñ) Failure to provide access to the personnel of the competent data protection authority to the personal data, information, premises, equipment, and means of processing required by the data protection authority for the exercise of its investigative powers.” Note that this warning does not appear in the document forwarding the complaint because it was not part of the investigation phase, but rather the preliminary transfer phase for the decision on its admissibility. Therefore, it must be concluded that the transfer of the complaint, neither for reasons of form nor substance, constitutes a "preliminary investigative procedure," but rather, in addition to being an optional procedure as indicated in Article 65.4 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights), its purpose is to clarify the circumstances stated in the complaint in order to decide whether or not to admit it for processing. And thus, as stipulated in Article 67.2 of said law, the time limit for carrying out these preliminary actions begins to run from the moment of admission for processing. SECOND. – ON THE FACTUAL BACKGROUND Regarding the factual background that gives rise to the commission of the infringement, AXA makes the following considerations: Regarding the duration of the infringement, AXA only acknowledges two specific and isolated access points: May 22, 2023, when the password was changed, and June 27, 2023, when a "last access" is recorded. These would be only two specific access points, without these occurring continuously over time. Therefore, AXA asserts, a "duration of the infringement" of one month cannot be considered proven. Possible recurrence of events such as those analyzed. In this section, AXA refers to the email by which an agent of said company responded to the complainant. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 37/53 The email stated that events such as those that have given rise to the present proceedings were recurring. This statement indicates AXA, this would not be true. The agent allegedly included it with the intention of "providing some reassurance" to the client, and in any case, said agent would not be in possession of that information. AXA also refers to the civil lawsuit it has filed with ***COMPANY.1. According to the Judgment of 16/07/24 (which has not been submitted to the proceedings), the court declares proven "the existence of just cause that motivated the termination of the contract." All these aspects, AXA argues, must be taken into consideration, since they have a considerable impact on its potential liability. It concludes by stating that the Spanish Data Protection Agency (AEPD) cannot consider any fact that is not documented. Regarding this allegation, the following must be answered: firstly, it is unknown for what purpose the allegation of the duration of the infringement is made. In it, AXA insists that there were no continuous accesses to the personal data during the period between the password change (May 22, 2023) and the last recorded access (June 27, 2023). However, AXA indicates that only these two specific accesses were confirmed. In this argument, AXA does not deny that the accesses occurred (in fact, it later acknowledges that there was a loss of data confidentiality, albeit on an isolated basis). Furthermore, the proposed resolution did not take the duration of the infringement into account when determining the amount. Nor does it do so in this resolution. In any case, even if the accesses occurred on an isolated and specific basis, it is clear that both requirements for a breach of Article 5.1.f) of the GDPR were met: on the one hand, there was a loss of confidentiality, and on the other, there was an absence of effective measures. to safeguard it, the process was prolonged throughout the entire period, since otherwise the last access on June 27, 2023, would not have been possible. The allegation regarding the email that the AXA agent sent to the claimant is also irrelevant in this case. In the email, the agent implies that events such as those that gave rise to these proceedings are recurring. In any case, as we have stated, this factor is not relevant to the proceedings, since only the loss of confidentiality associated with the claimant's data and the lack of technical or organizational measures that this loss has revealed are being considered. The possible recurrence of the events is not. Finally, the fact that a favorable court ruling was obtained regarding the termination of the contract with its former agent, ***COMPANY.1, does not affect the liability of AXA. This is because the two procedures (the civil judicial proceeding and this sanctioning proceeding for the violation of data protection regulations) have different objectives. In the present sanctioning proceeding, AXA is accused of not having an effective and secure procedure C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 38/53 for changing the password to access the “MYAXA” customer area. Meanwhile, the object of the civil suit was the appropriateness of terminating the agency agreement between AXA and ***COMPANY.1. This allegation must therefore be rejected. THIRD. – ON THE ALLEGED INFRINGEMENT OF ARTICLE 5.1 F) In general, throughout this extensive section, AXA presents a series of arguments to to prove that it cannot be held responsible for a lack of technical or organizational measures to guarantee the integrity and confidentiality of the personal data for which it holds the status of data controller. It begins by stating that, regarding the alleged lack of measures, its information systems are designed so that AXA agents only have access to the data of the specific policies they manage. Therefore, the only ones who can know the data necessary to complete the password change procedure are the policyholder and the agent involved, while the policy is in effect. In the proposed resolution, it is stated that AXA should have considered the risk of unauthorized access that could occur due to the context of the amicable termination of the contract. However, AXA argues that this fact can never legitimize illicit use or malicious impersonation. Regarding this risk, it cannot be presumed that the former agent will act in bad faith simply because the contract was terminated. Therefore, it cannot be stated that there is a appreciable risk that AXA agents will attempt to impersonate their clients to access their private MYAXA area. AXA refers to Judgment 1066/2023 of February 9, 2023, issued by Section 1 of the Administrative Chamber of the National Court, which held that, in that case, a telecommunications operator was at fault, since to verify the client's identity it only required the name and telephone number. The judgment considers this data very basic and that additional data should have been required, although it does not specify what that data should have been. AXA interprets this judgment as a validation of the procedure it followed, which required the policy number and the last four digits of the bank account. AXA adds that the Spanish Data Protection Agency (AEPD) itself, in various resolutions and publications, classifies payment information and a person's name as sensitive or highly relevant data. And yet, it now considers this insufficient to prevent identity theft. Furthermore, it is alleged that the AEPD insists in its proposed resolution that AXA should have provided documentation proving that the data processor destroyed and/or returned the processed data. In this regard, AXA states that the file contains a declaration from COMPANY 1 stating that it does not possess the data. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 39/53 AXA further alleges that, following the termination of the contract, it deactivated the former agent's credentials. And in any case, the Spanish Data Protection Agency (AEPD) does not clarify what other measures should have been adopted in this regard. The data processing agreement obligated the processor to return or destroy the data. Thus, it would have been ***COMPANY.1 who failed to comply with the instructions by continuing the processing after the termination. AXA acknowledges the loss of confidentiality of the complainant's personal data, but maintains that the measures were adequate and sufficient. When it became aware of this breach, the complainant's user account was deleted from MYAXA. Additionally, it states that the website has a two-factor authentication system. It acknowledges (as already stated in the proposed resolution) that it is a system voluntary for the client, but if the user decides not to activate it, this could not lead to AXA being held liable for sanctions for non-compliance with the regulations. Finally, it indicates that there is no causal link between the identity theft of the claimant and the possible implementation of measures that AXA might take. It would theoretically be possible, it states, that the former agent could have obtained the information regarding the claimant's credentials through other means, such as through the claimant herself, when he contacted her by telephone. It concludes that no evidentiary activity would have been carried out in this regard. In relation to these allegations, it should be noted that the Spanish Data Protection Agency (AEPD) values positively the measure stipulating that each specific agent can only have access to the policies in which they themselves have been involved. The same applies to the withdrawal of credentials following the termination of the contract and the deletion of the complainant's user account. These measures, although adopted after the events in question, are welcomed and taken into account when imposing the corresponding sanction in this resolution. AXA considers that a prior amicable split with its former agent did not constitute a foreseeable risk of misuse of the stored personal data. Indeed, such misuse is a more than foreseeable risk given the history of unilateral termination of the contract with ***COMPANY.1, yet no measures were taken in this regard. However, the argument presented by AXA, that the personal data processed by ***COMPANY.1 were destroyed or returned after the termination of the contract, is taken into account. AXA refers to the ruling of the National Court of February 9, 2023, which deemed the measure of requiring only name and telephone number insufficient. Given that the proceedings in question required additional data (policy number and the last four digits of the bank account), AXA considers that it "incorporates the requirements identified by the National Court as demonstrating sufficient due diligence on the part of the data controller." In reality, the aforementioned ruling merely establishes that requiring such basic data for identification does not meet the security requirements for such identification, since this information could reasonably be in the possession of third parties. However, it does not C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 40/53 specify what additional data should be required. And what is clear is that the data required in this case could have been in the possession of a third party, especially given the previous amicable termination of the contract and the concerns expressed by AXA in its allegations of customer diversion to other insurers. The procedure should have been strengthened, and AXA failed to do so. AXA argues that this Agency considers personal data such as those related to payment methods to be particularly sensitive, whereas now, since it is using them as a means of authentication, it does not consider them sufficient for this purpose. Regarding this argument, it should be clarified that, indeed, payment methods can facilitate identity theft with the resulting financial losses for their holders, but this in no way means that data such as a bank account number is, per se, sufficient to identify a user (or in conjunction with the policy number). It is essential to use data that guarantees that it is only in the possession of the person seeking identification. And in this case, as we have seen, there was a real risk that the necessary data was in the possession of the person who, until recently, had been responsible for data processing, followed by an acrimonious split. Regarding the establishment of a two-factor authentication system, such as the one established by AXA for identification on the website, although it was not activated in the case analyzed, it should be considered a positive step. With respect to the former agent's malicious actions in accessing the claimant's data in an illegitimate manner, this is not a factor that can be considered to exempt or mitigate liability. The assessment focuses on what measures were in place to ensure that the password change procedure was secure. This is precisely to prevent attempts at illegitimate access to personal data from succeeding. AXA alleges that insufficient evidence has been presented to demonstrate that the access to the claimant's data was due to a possible lack of security measures. This is not the case; rather, the file contains more than enough evidence to establish this causal link: - The claimant received a phone call from the former AXA agent. - On the same day, the claimant received two text messages from the defendant providing a temporary password to access their customer area. Minutes later, she receives an email from the security department of the complainant, indicating that her login details have been changed and that she can now access her personal account. - These facts are inconsistent with AXA's assertion that "it would be theoretically possible for the former agent to have obtained the information regarding the complainant's credentials through other means, such as through her when he contacted her by phone." C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 41/53 - AXA has expressly acknowledged that, after conducting the appropriate investigations, the password change was confirmed on May 22, 2023, and that the last login to "MYAXA" occurred on June 27, 2023, at 8:35 a.m. - Furthermore, in the email that AXA sent to the claimant, it is explicitly acknowledged that “After this morning’s conversation regarding the aforementioned matter, please allow me to first and foremost reiterate my apologies for the treatment you received in our offices, undoubtedly the result of a tense situation caused by actions that clearly constitute, at the very least, an illegal manipulation of your data by previous management of your contracts with AXA.” - All of this is accompanied by the facts relating to the amicable termination of AXA’s contract with ***COMPANY.1 and the lack of a certificate proving that the latter proceeded to destroy or return the personal data processed as a processor. For all the reasons stated, this allegation must be rejected. FOURTH. - ON THE ROLE OF THE DATA CONTROLLER AND THE ASSOCIATED LIABILITY While AXA acknowledges that, in general, the obligations of the GDPR fall on the data controller, it asserts that the processor can also be held liable under Article 28.10 of the Regulation, which establishes such liability when it processes data for its own purposes, deviating from the controller's instructions. In this regard, it states that ***COMPANY.1 allegedly breached the contract and retained the data. Thus, AXA reiterates, the breach of confidentiality would not be related to a possible lack of measures, but rather to the unlawful actions of the responsible party. AXA concludes by stating that, based on the allegations, liability would be imposed solely for the outcome, as “infallible measures” would be demanded. Regarding this allegation, it is worth emphasizing that the subject of the proceedings in the present case is the lack of technical and organizational measures to guarantee an adequate and secure password change procedure for access to the MYAXA customer web area, for which AXA is responsible. As indicated in the response to the previous allegation, the fact that there was malicious action by a third party aimed at gaining access to personal data under AXA's responsibility in no way mitigates, much less exempts, said entity from its responsibility in the design of the procedure. On the contrary, had it been equipped with sufficient protective measures, access could not have occurred. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 42/53 In no way are “infallible measures” being demanded to guarantee the security of personal data. The system established by the GDPR is based on the need for the data controller to analyze, prior to processing, the risks that may arise for the rights and freedoms of the data subjects. And one of the most evident risks is the attempt at unauthorized external access to the data. This situation materialized according to the proven facts of this proceeding. Therefore, this allegation must be dismissed. FIFTH. – REGARDING THE COMPLAINT FILED AGAINST ***COMPANY.1 AXA states that on July 10, 2025, it filed a criminal complaint against ***COMPANY.1. This was due to the alleged systematic diversion of the client portfolio it managed to another entity, ***COMPANY.3. According to AXA, this only serves to demonstrate that the actions of ***COMPANY.1 were deliberate, unlawful, and fraudulent. This is further corroborated by the civil court ruling already issued, which found in favor of AXA regarding the termination of the contract. This allegation adds nothing new to the previous arguments, as it merely attempts to shift responsibility to the former agent, a point already refuted in previous sections. SIXTH. – ON THE AEPD'S CRITERIA IN PREVIOUS, SIMILAR RULINGS In this section, AXA mentions a precedent (without providing references, dates, or any other information that would allow its location) in which the AEPD allegedly dismissed a complaint against AXA itself, due, it claims, to fraudulent actions by a former agent. Lacking further details regarding the facts or the identification of the proceedings, it is not possible to rule on this allegation. In any case, the present ruling provides ample justification for attributing responsibility to AXA, based on the factors and documentation present in the proceedings. SEVENTH. – PROPORTIONALITY OF THE SANCTION Regarding the amount of the sanction, the following is alleged: firstly, it disagrees with certain circumstances that, in AXA's opinion, should have been taken into consideration as aggravating factors. And secondly, it proposes some others that should be considered as mitigating factors. It is observed that almost all of the allegations in this respect are merely repetition of those already made in the written response to the initial agreement. Only one of the circumstances is new and is addressed below. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 43/53 Regarding the seriousness of the infringement (Article 83.2.a) of the GDPR), AXA argues that, concerning the number of affected parties, the criterion of “potentially affected” clients cannot be used, but rather only the single client actually affected should be considered. In this respect, although a lack of technical and organizational measures to guarantee the confidentiality and integrity of personal data would affect all processed data, we accept the opposing argument that the impact on only one data subject has been proven. Consequently, the claim should be partially upheld. V. Breach of Obligation. Article 5.1.f) GDPR Integrity and Confidentiality Article 5.1(f) of the GDPR stipulates: "1. Personal data shall be: (...) (f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical and organizational measures (‘integrity and confidentiality’)." In relation to this principle, Recital 39 of the GDPR states that: “[...]Personal data should be processed in a manner that ensures appropriate security and confidentiality of the personal data, including to prevent unauthorized access to or use of the personal data and the equipment used for processing.” In this case, due to the improper management of the password change process in the claimant's customer area, AXA assigned a new password to a third party. This information allowed the third party to access the claimant's "MYAXA" customer area, taking control of it. In this case, it is on record that on May 22, 2023, the claimant received two SMS messages from AXA, initially providing a temporary password and later an email confirming that their access credentials to their "MYAXA" customer area had been successfully changed. The claimant contacted AXA to report this situation. AXA verified that the password change in the claimant's customer area occurred that same day, and this is documented in the case file. Since the claimant did not change her password and did not access her client area with that new password, AXA states that it can be concluded that there was probable unauthorized access by ***COMPANY.1, for the purpose of gathering information on the claimant's current policies and their associated prices, in order to offer her insurance policies at the same price, as stated in the phone call made to the claimant on May 22, 2023. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 44/53 It should be noted that this call occurred on the same day that the unauthorized and unconsented password change took place. ***COMPANY.1, in the same way that it would have contacted the claimant, could have changed the affected party's access password to her client area at AXA, given that, as her former insurance manager with AXA, it possessed the necessary data for this purpose (including the policy number and the last four digits of the bank account for changing the password). Consequently, it is evident that there has been unauthorized processing of the claimant's data, resulting in a breach of confidentiality, through a third party's access to her "MYAXA" client area, as acknowledged by AXA. This confirms the breach of confidentiality of the claimant's personal data. Regarding the measures necessary to guarantee such confidentiality, it is necessary to point out that the aforementioned provision does not establish a list of specific security measures according to the data being processed, but rather establishes the obligation for the controller to apply technical and organizational measures that are appropriate to the risk involved in said processing, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks of likelihood and severity for the rights and freedoms of the data subjects. Likewise, the measures must be appropriate and proportionate to the identified risk, determining those appropriate technical and organizational measures taking into account pseudonymization and encryption, the capacity to guarantee confidentiality, integrity, availability and resilience, the capacity to restore the availability and access to data after an incident, a verification process (not an audit), and an evaluation and assessment of the effectiveness of the measures. In any case, when assessing the adequacy of the level of protection, particular consideration must be given to the risks presented by data processing, such as the accidental or unlawful destruction, loss, or alteration of personal data transmitted, stored, or otherwise processed, or the unauthorized disclosure of or access to such data, which could cause physical, material, or immaterial damage. For its part, Recital 83 of the GDPR states that “(83) In order to maintain security and prevent processing from infringing the provisions of this Regulation, the controller or the processor shall assess the risks inherent in the processing and implement measures to mitigate them, such as encryption. These measures should ensure an appropriate level of security, including confidentiality, taking into account the state of the art and the cost of implementation in relation to the risks and the nature of the personal data to be protected. When assessing the risk in relation to data security, consideration should be given to the risks arising from the processing of personal data, such as the accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 45/53 or unauthorized disclosure of or access to such data, which may be in particular to cause physical, material, or immaterial damages.” In this case, it is established that AXA had the following password change process in the MYAXA application at the time of the events: • On the first screen of accessing MYAXA, the user is required to enter their NIF (Spanish Tax Identification Number) and password. If they do not remember it, they are given the option to click on “Forgot my password.” • After clicking on “Forgot my password,” the NIF is requested again, and then it is indicated that a temporary password has been sent to the method provided by the customer. Given that ***COMPANY.1 does not have access to the claimant's email inbox, they had to click on the option “I have not received my verification code.” • At that point, a temporary password is sent again to the alternative method provided by the claimant (SMS to her mobile phone). Since ***COMPANY.1 also does not have access to the claimant's mobile phone, she should have pressed the "I haven't received my verification code" option again. • The next screen that appears after selecting that option presents security questions, the information for which, in this case, is highly likely known by ***COMPANY.1 (Policy number and the last 4 digits of her payment method). • It is at this point, once this information is entered, that the option to change the password is presented. It is clear that AXA had significant shortcomings and lacked the necessary safeguards to ensure the security of personal data processing; since knowing only the Policy number and the last 4 digits of her payment method (data easily accessible to employees and data processors) it was possible to impersonate customers. This deficiency is evident in the fact that AXA has implemented, as a measure within the password change process in MYAXA, the replacement of the security questions section with a new screen indicating a system error, directing the user to a customer service phone number. AXA states that in this way, if the person trying to access their customer area account does not remember their password and has not correctly received the verification codes through the provided channels, they should contact the customer service phone number, thus preventing the possible impersonation of a third party who might have information about the customer's active policies. However, the effectiveness of this measure would not be guaranteed if the subsequent verification by customer service is not based on measures that ensure the protection of personal data. It also indicates that they have decided to adopt, as a complementary measure, the deletion of the claimant's user account in the "MYAXA" application. Therefore, if the claimant wishes to access her client area, she will have to restart the registration process in the application with new credentials. At this point, the ruling of the National Court issued on April 11, 2025, in appeal 793/2022, is relevant, as follows: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 46/53 Ultimately constituting further proof that the security measures in place at the time the events occurred were inadequate, the evidence that a change in these measures took place, as highlighted in the same statement of proven facts of the contested resolution (…) Thus, it can be stated that the deficiencies detected constitute a systemic or procedural error that demonstrates the defendant's lack of diligence in establishing guarantees in the processing of its clients' personal data, such that the principles that must be preserved in said processing—especially in this case, the principle of confidentiality—are violated. of the data - are guaranteed. In accordance with the available evidence, the known facts are considered to constitute an infringement attributable to AXA, for violation of Article 5.1.f) of the GDPR. Special consideration must be given to the context of AXA's prior amicable break with its former agent. This circumstance constituted a more than foreseeable risk, given the history of unilateral termination of the contract with ***COMPANY.1. And no measures were taken in this regard. It would have sufficed to introduce some additional identifying factor (for example, data held only by the client and not by the former agent) to eliminate this risk. This is further reinforced by the fact that AXA has not provided any certificate or documentary evidence that the personal data processed by ***COMPANY.1 were destroyed or returned after the termination of the contract. The aforementioned risk was foreseeable to such an extent that in its own arguments to the proposed resolution, AXA states that it observed the diversion of clients from AXA to an insurance brokerage. Referring to the termination of the contract with ***COMPANY.1, it states: “This termination became inevitable after it was established that the former agent had decided—and, in fact, carried out—the systematic diversion of the client portfolio he managed to ***COMPANY.3, flagrantly breaching the exclusivity agreement governing the exclusive agent. Furthermore, following the contract termination, all the agency's employees went on to work for COSNOR, which was accompanied by a wave of cancellations of policies linked to AXA, previously managed by ***COMPANY.1.” Therefore, the possibility of unauthorized processing of personal data by the former agent was not only a foreseeable risk, but one actually anticipated by AXA. Despite this, it did not take any measures to prevent it from happening, leaving in place an identification procedure that allowed unauthorized access to anyone who, like the former agent, possessed data associated with customer policies. VI. Classification of the infringement of Article 5.1.f) of the GDPR and its classification for the purposes of the statute of limitations Article 83.5 of the GDPR classifies as an administrative infringement the violation of the following articles, which will be sanctioned, in accordance with paragraph 2, with administrative fines of up to EUR 20,000,000 or, in the case of a company, of C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 47/53 an amount equivalent to up to 4% of the total annual global turnover of the preceding financial year, whichever is higher: "a) the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7 and 9; b) the rights of data subjects pursuant to Articles 12 to 22; c) the transfers of personal data to a recipient in a third country or an international organization pursuant to Articles 44 to 49; (d) any obligation under Member State law adopted pursuant to Chapter IX; (e) failure to comply with a decision or a temporary or permanent limitation on processing or the suspension of data flows by the supervisory authority pursuant to Article 58(2), or failure to provide access in violation of Article 58(1). For its part, the LOPDGDD, in Article 71, Infringements, states that: “The acts and conduct referred to in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law, constitute infringements.” For the sole purpose of determining the statute of limitations, Article 72.1 of the LOPDGDD (Spanish Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) establishes the following: "In accordance with the provisions of Article 83.5 of Regulation (EU) 2016/679, the following infringements are considered very serious and shall be subject to a three-year statute of limitations: those that constitute a substantial breach of the articles mentioned therein, and in particular, the following: a) The processing of personal data in violation of the principles and safeguards established in Article 5 of Regulation (EU) 2016/679." VII. Penalty for infringement of Article 5.1.f) GDPR In order to determine the administrative fine to be imposed, the following provisions must be observed: Articles 83.1 and 83.2 of the GDPR, which state: “1. Each supervisory authority shall ensure that the imposition of administrative fines under this Article for infringements of this Regulation referred to in paragraphs 4, 9 and 6 is, in each individual case, effective, proportionate and dissuasive. 2. Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or as an alternative to the measures provided for in Article 58(2)(a) to (h) and (j). When deciding on the imposition of an administrative fine and its amount in each individual case, due consideration shall be given to: (a) the nature, seriousness, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation concerned, as well as the number of data subjects affected and the level of damage suffered; C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 48/53 (b) the intent or negligence in the infringement; (c) any measures taken by the controller or processor to mitigate the damage suffered by the data subjects; (d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures implemented pursuant to Articles 25 and 32; (e) any prior infringements committed by the controller or processor; (f) the degree of cooperation with the supervisory authority with a view to remedying the infringement and mitigating its possible adverse effects; (g) the categories of personal data affected by the infringement; (h) how the supervisory authority became aware of the infringement, in particular whether and, if so, to what extent the controller or processor notified the infringement; (i) where the measures referred to in Article 58(2) have been previously ordered against the controller or processor concerned in relation to the same matter, compliance with those measures; (j) adherence to codes of conduct pursuant to Article 40 or to certification mechanisms approved pursuant to Article 42, and (k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement.” For its part, Article 76 “Sanctions and Corrective Measures” of the LOPDGDD (Spanish Data Protection Law) provides: “1. The sanctions provided for in paragraphs 4, 5 and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the criteria for determining the severity of the sanction established in paragraph 2 of that Article. 2. In accordance with the provisions of Article 83.2(k) of Regulation (EU) 2016/679, the following may also be taken into account: (a) The continuing nature of the infringement. ``` b) The connection between the infringer's activity and the processing of personal data. c) The benefits obtained as a result of committing the infringement. d) The possibility that the affected party's conduct could have induced the commission of the infringement. e) The existence of a merger by acquisition subsequent to the commission of the infringement, which cannot be attributed to the acquiring entity. f) The impact on the rights of minors. g) Having a data protection officer, where not mandatory. h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms in cases where disputes arise between them and any interested party. In this case, considering the seriousness of the potential infringement, and paying particular attention to the consequences for those affected, a fine would be appropriate, in addition to the adoption of measures, if applicable. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 49/53 The fine imposed must be effective, proportionate, and dissuasive in each individual case, in accordance with Article 83.1 of the GDPR. To guarantee these principles, AXA's turnover of €553 million in 2024 is considered. The maximum fine could amount to €22,120,000. For the purposes of deciding on the imposition of an administrative fine and its amount, it is considered appropriate to determine the appropriate sanction based on the circumstances set forth in the aforementioned provisions. Preliminary considerations indicate that the following circumstances are present: • The nature and severity of the infringement, taking into account the number of data subjects affected (Article 83.2, paragraph a). In this case, although the lack of measures could affect all AXA customers, in the present case, the impact on a single data subject has been proven. • Intentionality/Negligence in the infringement (Article 83.2, paragraph b) of the GDPR): In this same vein, the Supreme Court has consistently held that negligence exists whenever a legal duty of care is disregarded, that is, when the infringer does not act with the due diligence required. And in assessing the degree of due diligence, special consideration must be given to the professionalism or lack thereof of the individual, and there is no doubt that, in the case now under examination, when the appellant's activity involves the constant and extensive handling of personal data, emphasis must be placed on rigor and meticulous care in complying with the relevant legal requirements. [Judgment of the National Court of 17/10/2007 (appeal no. 63/2006)] • The categories of personal data affected by the infringement (Article 83.2 g). The lack of appropriate technical and organizational security measures affects data that is especially relevant to the data subjects, including data of a financial nature, such as payment methods. Thus, in accordance with paragraph 57 of Guidelines 4/2022 of the European Data Protection Board on the calculation of fines: Regarding the requirement to take into account the categories of data Personal data affected [Article 83(2)(g) of the GDPR], the GDPR clearly highlights the types of data that deserve special protection and, therefore, a stricter response with regard to fines. This refers, at a minimum, to the types of data referred to in Articles 9 and 10 of the GDPR and to data outside the scope of these articles whose disclosure causes immediate harm to the data subject (for example, location data, data on private communications, national identification numbers, or financial data, such as transaction summaries or credit card numbers). In general, the more of these categories C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 50/53 of data involved, or the more sensitive the data, the more weight the supervisory authority may attach to this factor. The following quality grading factors are also considered. Aggravating factors: • The connection between the offender's activity and the processing of personal data (Article 76.2, letter b), of the LOPDGDD). AXA, in the course of its business, manages both its insurance and its financial protection, savings, and real estate investments, serving the financial needs of its clients, both individuals and companies. Therefore, the adoption of technical and organizational security measures is essential to guarantee the processing of personal data that it carries out. Consequently, and for the purposes of complying with the legally established requirements, carrying out this activity necessarily implies knowledge and application of current regulations regarding the protection of personal data. In addition, the following mitigating factor is considered according to Article 83.2 of the GDPR: • Any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly. through the infringement” (Article 83.2.k) of the GDPR: The assessment of AXA's behavior in this case requires considering the actions taken by the entity aimed at complying with the provisions of the GDPR and the Spanish Data Protection Act (LOPDGDD), in accordance with the principle of continuous improvement. While acknowledging that this continuous improvement is an obligation for data controllers, it is deemed appropriate to consider the attitude shown by AXA, which, throughout the proceedings, has reported the implementation of various measures aimed at complying with data protection regulations. For the purposes of deciding on the imposition of an administrative fine and its amount, it is considered that the balance of the circumstances contemplated in Article 83.2 of the GDPR and 76.2 of the LOPDGDD, with respect to the infringement committed by violating the provisions of Article 5.1.f) of the GDPR, allows for the imposition of an administrative fine of TWO HUNDRED THOUSAND EUROS (€200,000). VIII. Corrective Measures The resolution issued may establish the corrective measures that the infringing entity must adopt to end the non-compliance with personal data protection legislation, in this case, Articles 5 and 25 of the GDPR, in accordance with the provisions of Article 58.2.d) of the GDPR, according to which each supervisory authority may "require the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specific manner and within a specified time frame..." Thus, the responsible entity may be required to adapt its actions to personal data protection regulations, to the extent expressed in the preceding Legal Basis. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 51/53 This document establishes the alleged infringement and the facts that could give rise to this possible violation of data protection regulations. From this, the measures to be adopted are clearly inferred, without prejudice to the fact that the specific procedures, mechanisms, or instruments for implementing them are the responsibility of the sanctioned party. The data controller is the one who fully understands their organization and must decide, based on proactive responsibility and a risk-based approach, how to comply with the GDPR and the LOPDGDD. However, in this case, regardless of the foregoing, the resolution adopted may require AXA to, within a maximum period of six months from the date the final resolution of this procedure becomes enforceable, adopt the following measures: Demonstrate the effective implementation of appropriate technical and organizational security measures, not only to comply with regulations, but also to demonstrate compliance to supervisory authorities and interested parties. The imposition of this measure is compatible with the sanction of an administrative fine, as provided for in Article 83.2 of the GDPR. It is advised that failure to comply with any order to adopt measures imposed by this body in the resolution of this sanctioning procedure may be considered an administrative infringement in accordance with the GDPR, specifically classified as an infringement in Articles 83.5 and 83.6, and such conduct may lead to the initiation of further administrative sanctioning proceedings. Therefore, in accordance with applicable legislation and having assessed the criteria for determining the severity of the sanctions, the existence of which has been proven, the Presidency of the Spanish Data Protection Agency RESOLVES: FIRST: To impose on AXA SEGUROS GENERALES, S.A. DE SEGUROS Y REASEGUROS, with Tax Identification Number A60917978, for an infringement of Article 5.1.f) of the GDPR, classified in Article 83.5 of the GDPR, a fine of €200,000.00 (two hundred thousand euros). C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 52/53 SECOND: To close the proceedings in relation to the possible infringement of Article 32 of the GDPR, classified in Article 83.4 thereof. THIRD: ORDER AXA SEGUROS GENERALES, S.A. DE SEGUROS Y REASEGUROS, pursuant to Article 58.2.d) of the GDPR, within a maximum period of SIX MONTHS from the date this resolution becomes final and enforceable, to demonstrate that it has complied with the following measure: Effective implementation of appropriate technical and organizational security measures, not only to comply with the regulations, but also to demonstrate compliance to the supervisory authorities and data subjects. FOURTH: NOTIFY AXA SEGUROS GENERALES, S.A. DE SEGUROS Y REASEGUROS of this resolution. FIFTH: This resolution will become enforceable once the period for filing an optional appeal for reconsideration (one month from the day following the notification of this resolution) has expired without the interested party having exercised this right. The sanctioned party is hereby notified that they must pay the imposed sanction once this resolution becomes enforceable, in accordance with the provisions of Article 98.1.b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), within the voluntary payment period established in Article 68 of the General Collection Regulations, approved by Royal Decree 939/2005, of July 29, in relation to Article 98.1.b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP). 62 of Law 58/2003, of December 17, by depositing the fine, indicating the Tax Identification Number (NIF) of the sanctioned party and the procedure number shown in the heading of this document, into the restricted account IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX), opened in the name of the Spanish Data Protection Agency at CAIXABANK, S.A. Otherwise, collection will be pursued during the enforcement period. Upon receipt of the notification and once it becomes enforceable, if the enforceability date falls between the 1st and 15th of each month, inclusive, the deadline for making the voluntary payment will be the 20th of the following month or the next business day thereafter, and if it falls between the 16th and the last day of each month, inclusive, the payment deadline will be the 5th of the second following month or the next business day thereafter. In accordance with the provisions of Article 50 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights), this Resolution will be made public. Publication will take place once it has been notified to the interested parties. This resolution, which concludes the administrative process pursuant to Article 50 of the LOPDGDD, may be appealed. 48.6 of the LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, the interested parties may, optionally, file an appeal for reconsideration with the Presidency of the Spanish Data Protection Agency within one month from the day following notification of this resolution or directly file an administrative appeal with the Administrative Chamber of the National Court, in accordance with the provisions of Article 25 and paragraph 5 of the fourth additional provision of Law 29/1998, of July 13, regulating the Administrative Jurisdiction, within two months from the C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 53/53 day following notification of this act, as provided for in Article 46.1 of the referred Law. Finally, it should be noted that, in accordance with the provisions of Article 90.3 a) of the LPACAP, the final administrative decision may be provisionally suspended if the interested party expresses their intention to file an appeal with the Administrative Court. If this is the case, the interested party must formally communicate this fact by means of a written communication addressed to the Spanish Data Protection Agency, submitting it through the Agency's Electronic Registry [https://sedeaepd.gob.es/sede-electronica- web/], or through one of the other registries provided for in Article 16.4 of the cited Law 39/2015, of October 1. They must also provide the Agency with documentation proving the effective filing of the appeal with the Administrative Court. If the Agency does not receive notification of the filing of an administrative appeal within two months from the day following notification of this resolution, it will terminate the precautionary suspension. 938-101025 Lorenzo Cotino Hueso President of the Spanish Data Protection Agency C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es




