AEPD (Spain) - EXP202310943
| AEPD - EXP202310943 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 5(1)(f) GDPR |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | 11.04.2025 |
| Decided: | |
| Published: | 23.05.2025 |
| Fine: | 60,000 EUR |
| Parties: | AIRE NETWORKS DEL MEDITERRÁNEO, S.L. |
| National Case Number/Name: | EXP202310943 |
| European Case Law Identifier: | n/a |
| Appeal: | Not appealed |
| Original Language(s): | Spanish |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | ap |
The DPA fined a telecommunications provider €60,000 for violating its data security obligations before and after a data breach. During the breach, a data subject couldn’t access essential services on their phone, and later noticed unauthorised transactions from their bank account.
English Summary
Facts
AIRE NETWORKS (the controller) suffered a data breach. As a result, the data subject was unable to access services on their phone, since they could not make calls or connect to the internet. The data subject later noticed three unauthorized bank transfers from their account during the time of the data breach. The data breach took place on the extranet (a private computer network) shared by the controller and the mobile phone stores that distributed products of the controller (the processor). The usernames and passwords of several of the processor’s employees were accessed from the extranet, which also allowed individuals to access to data subjects’ personal data and make copies of eSIM cards. The data subject brought the complaint to the AEPD on 21 July 2023.
The controller argued that after reporting the data breach to the DPA, they implemented appropriate security measures that prevented several data breach attempts.
Holding
The DPA found that the controller had not complied with the principle of data security and confidentiality (Article 5(1)(f) GDPR). The controller must proactively implement appropriate technical and security measures in relation to the level of risk. Despite the arguments of the controller, the DPA did not consider the measures before or after the data breach sufficient. This included a lack of security measures before the breach (e.g. not temporarily blocking the access of an employee on leave) and ineffective measures taken after the initial data breach. The fine was initially set at €100,000 but pursuant to Law 39/2015, a Spanish law concerning administrative proceedings, the DPA informed the controller that it may make a voluntary payment of the proposed fine and waive their right to appeal. This action reduces the imposed fine by 20%. The fine can be reduced by a further 20% if the controller acknowledges its liability. The controller opted for both and reduced the fine by 40%, paying the reduced sanction amount of €60,000.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.
1/25
File No.: EXP202310943
RESOLUTION TERMINATING THE PROCEDURE FOR RECOGNITION OF LIABILITY AND VOLUNTARY PAYMENT
From the procedure initiated by the Spanish Data Protection Agency and based on the following
BACKGROUND
FIRST: On April 11, 2025, the Presidency of the Spanish Data Protection Agency agreed to initiate sanctioning proceedings against AIRE NETWORKS DEL MEDITERRÁNEO, S.L. (hereinafter, AIRE NETWORKS), through the agreement
transcribed below:
<<
File No.: EXP202310943
AGREEMENT TO INITIATE SANCTIONING PROCEDURE
Regarding the actions taken by the Spanish Data Protection Agency and based on the following
FACTS
FIRST: On July 21, 2023, a complaint was filed with the Spanish Data Protection Agency for a possible infringement attributable to AIRE
NETWORKS DEL MEDITERRÁNEO, S.L. with Tax Identification Number (NIF) B53704599 (hereinafter, AIRE
NETWORKS).
The facts brought to the attention of this authority were:
The complainant stated that, on June 27, 2023, his telephone line was cut off.
On June 28, 2023, he went to the mobile phone store ***COMPANY.1, where ***PRODUCT.1 of the telecommunications operator AIRE NETWORKS is distributed.
There, he was provided with a duplicate SIM card.
On June 29, 2023, the complainant checked his online banking and detected the following unauthorized bank transactions:
- Two transfers of ***AMOUNT.1 euros on June 28, 2023, to a Spanish bank account.
- One transfer of ***AMOUNT.2 euros on June 28, 2023, to a Lithuanian bank account.
- One transfer of ***AMOUNT.2 euros on June 28, 2023, to a Spanish bank account.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 2/25
On June 29, 2023, he filed a police report, and on July 3, 2023, he filed a complaint with the bank ***BANCO.1. The complainant subsequently stated that he detected emails indicating a change in the device associated with online banking and a change in the digital password.
Along with the letter, the following was provided:
- A copy of the email sent by the complainant to ***EMAIL.1 dated
July 10, 2023, with the following content: "On June 27, 2023,
I lost my phone; I couldn't make calls or have an internet connection.
I then contacted the sales representative ***COMPANY.1. The marketing company,
after consulting with you by phone, followed your instructions and changed my SIM card. First, I request to know when I lost my phone and why. My sales representative informs me
that it seems you had some security and tampering problem with my SIM card. As a result,
***AMOUNT.3 euros has been stolen from my bank through bank transfers I
didn't authorize. We undoubtedly believe that my identity has been stolen
following your security breach. After consulting with the CNMC, I am advised
to speak with you first to resolve the issue. this issue before
forwarding the case to the CNMC itself. At the same time, my sales representative informs me that
for data protection reasons, you should have contacted
me to inform me of the security issue you encountered, especially when the data at risk was highly sensitive
such as bank details. (…)” (sic)
- Copy of the email sent by ***EMAIL.1 to the complainant dated
July 11, 2023, with the following content: “Good afternoon A.A.A., As
we have informed you by phone, we are completely willing and
interested in collaborating with you and resolving the incident. Therefore,
we ask that you send us a copy of the complaint filed so that we have all the
information possible and always look out for your best interests.” (sic)
- Copy of the email sent by the complainant to ***EMAIL.1 dated
July 11, 2023, with the following content: "We attach the report that we filed as soon as we detected the unauthorized transfers by the account holder.
As you can see, the bank transactions were made when the
phone failed. The report is a living document and is open to adding
information and evidence relevant to the case."
- Copy of the email sent by ***EMAIL.1 to the complainant dated
July 12, 2023, with the following content: "We forwarded the document to
our legal department so they can take the necessary steps to resolve the incident. We will inform you as soon as possible."
- Copy of the email sent by ***EMAIL.2 to the complainant on July 11, 2023, with the following content: "For clarification purposes, from Aire Networks del Mediterráneo, S.L.U. we offer your mobile telephone service, which you contracted through one of our mobile telephone marketing agents, in this case "***COMPANY.1". We have an online platform with Virtual Office (VO) functions. This extranet is the platform that Aire Networks makes available to its marketing agents and employees for the administrative management of its end-customers' telecommunications services. This platform allows them to manage various procedures related to the telephone service, such as registering or canceling services, checking usage, duplicating SIM cards, billing, etc. Last Wednesday, July 28, June ***COMPANY.1
informed us that the owner of the line ***TELEPHONE.1 is
without service and that he has checked the line in the Virtual Office (Aire Networks extranet) and sees that a duplicate SIM card in eSIM mode has been requested for it, which he claims he has not done. Given what could be
the commission of possible fraud, we proceeded to block said eSIM and analyze
what happened. From this analysis, the following records are derived: Access log to the Virtual Office (Aire Networks extranet)
made by the user "***NIF.1" which belongs to "***COMPANY.1"
made one minute before the duplicate request (...). From Aire
Networks, we proceeded to report the events to the prosecutor's office as an affected party.
For this reason, A.A.A., we also ask that you keep us
informed of the status of your claim with your bank, where you have
requested the reversal of the transfers, since this information It is of great help in assessing the damage caused and thus being able to provide the prosecutor's office with as much information as possible in our complaint for the investigation of the crime." (sic)
- Copy of the bank book from ***BANK.1, where the claimant appears as the account holder and which includes four transfers entitled
"TRANSFER TO B.B.B.", effective on June 28, 2023, for a total of ***AMOUNT.3 euros.
- Copy of the following transfers issued by bank ***BANK.1, where the claimant appears as the originator and "B.B.B." as the beneficiary, with
the issue date issued on June 27, 2023:
Transfer to account ***ACCOUNT.1 of bank ***BANK.2
for an amount of ***AMOUNT.4 euros.
Transfer to account ***ACCOUNT.2 at bank ***BANK.3
for an amount of ***AMOUNT.4 euros.
Transfer to account ***ACCOUNT.2 at bank ***BANK.3
for an amount of ***AMOUNT.5 euros.
Transfer to account ***ACCOUNT.2 at bank ***BANK.3
for an amount of ***AMOUNT.5 euros.
- Copy of the police report filed on June 29, 2023, in which the
claimant states that he has not made four transfers from his account number ***ACCOUNT.3 at the bank ***BANK.1 for the amount of
***AMOUNT.3 euros, nor has he authorized anyone to do so, that he has not shared his passwords with anyone, and that he has contacted the bank
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 4/25
to clarify the facts and has been informed that someone has accessed his application and made the transfers.
SECOND: In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter, LOPDGDD), this complaint was forwarded to AIRE NETWORKS so that it could analyze it and inform this Agency within one month of the actions taken to comply with the requirements set forth in the data protection regulations.
On September 5, 2023, this Agency received a response letter from AIRE NETWORKS:
“(…) We wish to inform you that the complaint filed by A.A.A. that gives rise to this request for prior information is related to the security breach that we reported to the Spanish Data Protection Agency on June 27, 2023, at 7:23:07 PM, registration number ***REGISTRATION.1. This communication was subsequently expanded in a timely manner regarding the events, the status of the breach, the measures taken, as well as its consequences and effects on security.
This security breach occurred as a result of the leak of the usernames and passwords of four of our marketing agents (Data Processors), including the one mentioned by A.A.A. in its letter to you, ***COMPANY.1 (Tax ID: ***TAX.1) and one of our employees. As a result of This breach occurred due to unauthorized access to its Virtual Offices (extranet) (hereinafter VO) through illicit computer intrusion and interception of computer data transmissions. For clarification purposes, and for better understanding, the VO (extranet) is the platform that Aire
Networks, as a telecommunications service provider, makes available
to its Marketing Agents (including ***COMPANY.1) for the administrative
management (contracting, billing, portability, cancellations, eSIM duplicates,
etc.) of the services offered to end customers.
Note: The contract for third-party data processing (Art. 28 GDPR)
“Data processing contract by ***COMPANY.1 and on behalf of Aire
Networks del Mediterráneo S.L.U.”, signed by ***COMPANY.1 (Marketing Agent) was attached to the breach notification. (with registration number
***REGISTRATION.1), however, we are again attaching in this response
extracts from said contract, which include the necessary instructions to
prevent security breaches, the Marketing Agent's duty to verify the
identity of clients to carry out transactions; and the Marketing Agent's duty to adopt standards and security measures regarding safekeeping and
custody that guarantee data security and prevent unauthorized access.
You can see these extracts from the aforementioned contract on the following pages.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 5/25
In Clause Nine, Section 9.6 of said contract, where ***COMPANY.1 is
“THE OPERATOR,” the following is stated: "In all cases, the OPERATOR will comply
with the regulations applicable to the protection of personal data,
adopting the technical and organizational measures that guarantee the security of the
data, its conservation, and prevent its alteration, loss, or unauthorized access."
In Clause Thirteen, "CONFIDENTIALITY AND DATA PROTECTION", section 13.1 states:
"The OPERATOR and all its personnel agree to:
a) Use the personal data being processed, or those collected for inclusion, only for the purpose of this assignment. Under no circumstances may it
use the data for its own purposes. AIRENETWORKS will be responsible for the
processing of the data of the end users to whom it provides services in relation to the provision of such services, and must process them
in accordance with the provisions of current data protection legislation, without prejudice to the fact that the OPERATOR may also be responsible
for the processing of said end user data for those services that the OPERATOR provides to them. For this purpose, the end users will be informed of this circumstance at the time of data collection so that they consent to the processing by both companies.
b) Process the data in accordance with AIRE NETWORKS' instructions. If the
OPERATOR considers that any of the instructions violate the GDPR or
any other data protection provision of the Union or of the
Member States, the OPERATOR will immediately inform AIRE
NETWORKS (...).
d) Not to communicate the data to third parties, unless it has the
express authorization of AIRE NETWORKS, in the legally
permissible cases. The OPERATOR may communicate the data to other data processors of the same controller, in accordance with AIRE
NETWORKS' instructions. In this case, AIRE NETWORKS will identify, in advance and
in writing, the entity to which the data must be communicated, the data to be communicated, and the security measures to be applied to proceed with the
communication (...).
g) Ensure that the persons authorized to process personal data
expressly and in writing agree to respect the confidentiality and
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 6/25
comply with the corresponding security measures, of which they must be duly informed.
h) Keep the documentation proving compliance with the obligation established in the previous section available to AIRE NETWORKS.
i) Ensure the necessary training on personal data protection for persons authorized to process personal data.
The letter from AIRE NETWORKS, received on September 5, 2023,
continues to state the following:
“In accordance with what was reported in our communication to this Agency, we conducted a broad internal investigation to ascertain the facts and, although we were unable to identify the origin/cause of the credential leak (we continue to investigate in addition to the investigations already initiated by the Prosecutor's Office of the ***LOCALITY.1 area, which has more resources to identify this origin), it was determined that even though the necessary and appropriate technical and organizational measures had been proactively adopted before the incident to guarantee the security of personal data, unauthorized access to the affected Virtual Offices (VO) (extranet) did not occur due to a lack or poor implementation of the preventive measures implemented or due to the exploitation of technical vulnerabilities in our infrastructure that could be used for a direct attack, but rather through the obtaining of legitimate access credentials, duly encrypted. by one or
several criminals with advanced computer skills through digital means or
technical procedures that are difficult to detect and trace, which allowed,
exceptionally, the aforementioned incident to occur. As a result
of this, in no case was the duplicate of the A.A.A. eSIM card
due to an error, non-compliance, or lack of diligence in verifying the
identity of the legitimate holder by our staff, but rather for the reasons
previously stated and evidenced in the communication.
Finally, we would like to state that, as previously indicated,
as an affected party, Aire Networks filed a complaint with the
Prosecutor's Office of ***LOCALITY.1 (...), having placed ourselves at the disposal of the State
Security Forces and Corps, who have opened the corresponding
investigation, just as we do with you, to offer maximum
collaboration in the investigation and clarification of these events that have
led to this cybercrime."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 7/25
THIRD: On October 13, 2023, in accordance with Article 65 of the LOPDGDD (General Data Protection Act), the claim was admitted for processing.
FOURTH: The Subdirectorate General for Data Inspection carried out preliminary investigations to clarify the facts in question, pursuant to the functions assigned to supervisory authorities in Article 57.1 and the powers granted in Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VIII of the LOPDGDD.
As a result of the actions taken, the following matters have been learned:
On April 17, 2024, AIRE NETWORKS submitted a written response to this Agency's request, from which the following information is extracted:
Affected persons ***AMOUNT 6 with identification details (name, surname, nationality, date of birth, and ID) and contact details (email, telephone, postal address), and other
***AMOUNT 7 also with direct debit details.
***AMOUNT 7 potential affected parties whose financial details could be viewed (direct debit details).
They report unauthorized access through the access credentials of marketing agents by cybercriminals, resulting in
***NUMBER: 8 customers being affected thanks to the incident being reported by them, having had money stolen from their bank accounts due to the illegal duplication of eSIMs.
They indicate that, as of the date of their response to this letter, they are only aware of the
use of ***QUANTITY.8 eSIM cards, illegally obtained by the
cybercriminals, through which they were able to receive SMS messages
intended for the ***QUANTITY.8 holders of the ***QUANTITY.8 mobile lines
affected as part of the expiration process of the security measures
applied by the bank's payment systems (***BANK.1).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 8/25
On July 12, 2024, they notified those affected by SMS with the following
text: "INFO: We inform you that you have a communication regarding your mobile line.
Access URL ***URL.1 (code: XXXXXX)". A screenshot of the
website with the contents of several communications is attached.
Of the ***NUMBER.6 clients affected by the security breach caused by unauthorized access to the Virtual Office of the data processor (4 Marketing Agents and 1 employee), we are only aware that their personal data has been used by third parties in the two cases described (one of them being A.A.A. with NIF ***NIF.3, whose name appears in this Agency's records for having filed a claim).
They indicate that they are not aware that the personal data obtained as a result of the breach has been published on the internet or that it has been indexed by search engines, following the investigative actions carried out by their Cybersecurity team.
Regarding the reason why the implemented security measures did not prevent the security incident, they indicate the following:
"The implemented security measures did not prevent the security incident due to two fundamental causes:
1. The lack of diligence in safeguarding the access credentials to the ***SISTEMA.1 system (extranet) by the marketing agents (4) and to the ***SISTEMA.1 system by one of our employees (C.C.C.
whose confidentiality agreement has already been submitted to the AEPD).
2. In one of the cases, the cybercriminals had control of the email account (***EMAIL.2) where the authentication factor code was received. The illicit acquisition of these credentials is what allowed a cybercriminal to act as if they were a marketing agent."
AIRE NETWORKS attaches the chronological evolution of the events as Annex I to its response of April 17, 2024:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 9/25
June 24 and 25:
Valid and invalid access attempts were observed in the name of agent
***AGENT.1 to the AIRE NETWORKS intranet on June 24 and 25 from
an IP address registered in ***COUNTRY.1.
“The marketing agent informs us by opening a ticket that
several (14) mobile lines have lost service and that, upon consulting their records, he sees that duplicate eSIM cards have been created that he did not request. He is provided with the access logs with his credentials in which these requests were made, and the marketing agent informs us that he did not proceed with these accesses.”
“Additional security measures implemented:
• The aforementioned duplicate eSIMs are blocked to prevent
possible illicit use.
• The marketing agent is instructed to create new SIM duplicates to restore service to the affected lines.
• The IP(s) from which the unauthorized accesses were made are blocked through firewalls so that they cannot access any of our systems.
• All users of said marketing agent are forced to change the access password to ***SISTEMA.1 (Aire Networks extranet).”
June 26:
On June 26, two valid access attempts were observed on behalf of agent
***AGENT.2 to the AIRE NETWORKS intranet from the same IP address
indicated in the previous case, which is registered in ***COUNTRY.1.
“The marketing agent informs us by opening a ticket that
several (7) mobile lines have lost service and that, upon consulting their records,
he sees that duplicate eSIM cards have been created that he did not
request. He is provided with the access logs with his credentials in which
these requests were made, and the marketing agent informs us
that he did not proceed with these accesses.”
“Additional security measures implemented:
• The aforementioned duplicate eSIMs are blocked to prevent
possible illicit use.
• The reseller is instructed to create new SIM duplicates to
restore service to the affected lines.
• The IP(s) from which the unauthorized access was made are
blocked through firewalls so that they cannot access any of our systems.
• A password change to access ***SISTEMA.1 (Aire Networks extranet) is forced on all users of all resellers.
• Access to ***SISTEMA.1 (Aire Networks extranet) is blocked for all
IPs that are NOT geolocated in Spain (Attempt: “access blocked from invalid IP”).”
June 26-28:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 10/25
From June 26-28, several valid accesses were observed in the name of agent ***EMPRESA.1 to the AIRE NETWORKS intranet from different IP addresses located in different regions of Spain.
Actions carried out during these accesses:
Duplicate eSIMs (2) made with the access credentials of the marketing agent ***EMPRESA.1 with CIF ***NIF.1 and with an email address (***EMAIL.3) that, according to the complainant, is not theirs and which was used in the various accesses in the name of the other agents indicated above in this report.
"The marketing agent informs us by opening a ticket that
several (2) mobile lines have lost service and that, upon consulting their records, he sees that duplicate eSIM cards have been created that he did not
request. He is provided with the access logs with his credentials in which these requests were made, and the marketing agent informs us
that he did not proceed with these accesses."
"Additional security measures applied:
• The aforementioned duplicate eSIMs are blocked to prevent
possible illicit use.
• The previous SIM card is restored to service so that the owner is
without service for as little time as possible.
• The IP(s) from which the unauthorized accesses were made are
blocked through firewalls so that they cannot access any of
our systems.
• All passwords for all users are overwritten with unvalidated passwords, and a password change is forced again for all users
of all marketing agents."
June 27 and 28:
On June 27 and 28, several accesses were recorded by employee C.C.C. with DNI ***NIF.2.
Actions taken during these accesses: Duplicate eSIMs (13) were created
with the employee's access credentials.
"As a new security measure, colleagues in the support department
receive an instant alert for each eSIM created by the employee (C.C.C.) and activate internal protocols to investigate what happened."
“Additional security measures implemented:
• Access to ***SISTEMA.1 is disabled for said employee, who is on sick leave at the time of the events.
• The aforementioned duplicate eSIMs are blocked to prevent
possible illicit use.
• Service is restored to the previous SIM card so that the owner is without service for as little time as possible.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 11/25
• The IP(s) from which unauthorized access was made are blocked through firewalls so that they cannot access any of our systems.
• All employee passwords are overwritten with unvalidated passwords, and all company employees are forced to change their passwords.”
June 29, 2023:
"Additional security measures implemented:
• Access to ***SYSTEM.1 Employees is limited by a firewall so that it can only be accessed from our office IP addresses."
June 30:
On June 30, new attempts were recorded to access the VIRTUAL OFFICE and
EMPLOYEES by the employee C.C.C., which were thwarted (according to the complainant) by the implemented security measures.
“Additional security measures applied:
(…)
July 6:
“Additional security measures applied:
(…)
July 7:
“At this point, and given the evidence of the commission of a cybercrime, Aire
Networks decides to file a complaint with the Prosecutor's Office of ***LOCALIDAD.1
to initiate the corresponding criminal investigations
against whoever participated in the events described,
constituting the crime of computer intrusion and interception of computer data transmissions (197 bis CP) and the crime of fraud using electronic means.
(248.2 CP). (…)”
July 8:
A validated access to the virtual office is observed in the name of ***COMPANY.2
with CIF ***NIF.4.
Duplicates of (…) eSIMs were requested with the credentials of the agent indicated
above.
Five other thwarted access attempts are noted.
On page 38/79, a RISK ANALYSIS AND MANAGEMENT report is presented (which lists all the threats that may affect the ***SISTEMA.1 platform, including "Unauthorized Access") where, according to the change control (page 40/79), the latest security modifications "Update to ENS Alta" date from April 27, 2022, and
"Update of security objectives" date from June 1, 2002. The aforementioned "Risk Analysis and Management" follows the international standard ISO/IEC 27001, according to the complainant.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 12/25
This standard specifies the requirements necessary to establish, implement,
maintain, and improve an information security management system according to the Deming Cycle, or PDCA cycle (an acronym for Plan, Do, Check, Act).
In this risk analysis, the respondent indicates:
"Object
(…)
The respondent's conclusions regarding this risk analysis are as follows:
"After interviews with the responsible personnel, analyzing the documentation provided, and conducting the fieldwork to prepare the risk analysis, it has been concluded that the current risk level within the scope of the ISMS is generally at a Medium-Low level.
Currently, there is an implemented base of controls with a maturity level of L2-L3, reaching at least a level of L4 in those assets that are related to services within the certified scope of ENS Alta, which significantly reduces the inherent risk that potentially exists for the assets. These controls or safeguards are included within the area of security, contingency measures, and backup measures. (...).
As a summary of the above, it can be concluded that the degree of implementation of the ISMS, for the defined scope, is adequate and that risk management will be necessary in those areas where the risk accepted by Management is exceeded. The management system is maturing, although it is true that sometimes, in order to increase the level of maturity in certain areas, the effort involved does not compensate for the degree of actual risk reduction.
“…Results obtained from the Information Security Risk Analysis
Based on everything presented so far and after calculating the Potential Risk (Inherent), Residual Risk (Actual), and Residual Risk (Future), the results reflected in document RG-S-03 Risk Analysis and Management (2023) have been presented to Management in the presentation of this report.”
On pages 60/79, it states:
“The following are the projects to implement controls and safeguards to minimize security risks for the assets involved:
(…)
The respondent presents a brief excerpt from the risk analysis for the 2023 financial year (pages 78/79).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 13/25
FIFTH: According to the report collected from the AXESOR tool on February 3, 2025, the entity AIRE NETWORKS is a company established in 2002, with a turnover of €107,746,223 in 2023.
LEGAL BASIS
I
Jurisdiction
In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR) and as established in Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter, LOPDGDD), the Presidency of the Spanish Data Protection Agency is competent to initiate and resolve this procedure.
II
Procedure
Likewise, Article 63.2 of the LOPDGDD establishes that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development, and, insofar as they do not contradict them, in a subsidiary capacity, by the general rules on administrative procedures."
In accordance with Article 64 of the LOPDGDD, and taking into account the characteristics of the alleged violations committed, a sanctioning procedure shall be initiated.
The procedure will last a maximum of twelve months from the date of the initiation agreement. After this period, the proceedings will expire and, consequently, the proceedings will be archived, in accordance with the provisions of Article 64 of the LOPDGDD.
If no objections are made to this initial resolution within the stipulated period, it may be considered a proposed resolution, as established in Article
64.2.f) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP).
III
Preliminary Questions
Article 4(1) of the GDPR defines "personal data" as: "any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person shall be any person whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person."
Article 4(2) of the GDPR defines “processing” as: “any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.”
Article 4(7) of the GDPR defines “controller” or “controller” as: “the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing; where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.” In turn, Article 4.8 of the GDPR defines the "processor" or "processor" as "the natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller."
In the present case, in accordance with Articles 4.1 and 4.2 of the GDPR, personal data processing is established, since AIRE NETWORKS collects and stores personal data of natural persons, including, among other things: name, surname, nationality, date of birth, identity document, email address, telephone number, and postal address.
AIRE NETWORKS carries out this activity in its capacity as data controller, since it determines the purposes and means of such activity, pursuant to Article 4.7 of the GDPR. In this regard, clause thirteen of the "Data Processing Agreement by ***EMPRESA.1 and on behalf of Aire Networks del
Mediterráneo S.L.U.," states the following: "(...) AIRENETWORKS will be responsible for the processing of the data of the end users to whom it provides services in relation to the provision of such services, and must process them in accordance with the provisions of current data protection legislation (...)"
On the other hand, ***EMPRESA.1, classified as a marketing agent, would be considered the data processor on behalf of AIRE NETWORKS.
IV
Unfulfilled Obligation. Integrity and Confidentiality
Article 5.1(f) of the GDPR states:
"1. Personal data shall be:
(…)
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 15/25
f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, through the application of appropriate technical or organizational measures ("integrity and confidentiality")."
The aforementioned principle of integrity and confidentiality obliges data controllers to ensure that personal data are processed securely, preventing unauthorized access, misuse, or disclosure to unauthorized third parties. This includes implementing appropriate technical and organizational measures to protect data against potential personal data breaches, both external and internal. These measures must be appropriate to the risks that may arise from the processing and must be reviewed and updated periodically to ensure their effectiveness.
In this regard, data controllers must guarantee the integrity and confidentiality of the personal data being processed through technical and organizational measures of all kinds. Compliance with this precept would therefore be verified by: i) the adoption and implementation of technical and organizational measures of all kinds aimed at ensuring the confidentiality and integrity of the personal data being processed; ii) the absence of situations resulting in the loss of confidentiality or integrity of the personal data being processed. Non-compliance, on the other hand, would result from the absence of measures or non-compliance with those adopted and a loss of confidentiality of the data being processed.
In this case, as AIRE NETWORKS acknowledged in its letter dated September 5, 2023, the breach of the confidentiality principle occurred due to a security breach resulting from the leak of access credentials to a corporate extranet called ***SISTEMA.1, which allegedly allowed the attackers to carry out improper actions, including the issuance of a duplicate SIM card that facilitated subsequent thefts from the bank accounts of the victims through online banking systems. The credential leak included employee accounts and those of an external provider, which would demonstrate the existence of deficiencies in the management of security access to the system. Several AIRE NETWORKS marketing agents were allegedly involved in this personal data breach; in addition to ***EMPRESA.1, ***AGENTE.1, ***AGENTE.2, and ***EMPRESA.2. All of this, according to the information provided
as part of the investigations carried out by this AEPD.
Initially, AIRE NETWORKS links the personal data breach to the following circumstances:
1. "The lack of diligence in safeguarding the access credentials to the ***SISTEMA.1 system (extranet) by the marketing agents
(4) and to the ***SISTEMA.1 system by one of our employees
(C.C.C. whose confidentiality agreement has already been submitted to the AEPD).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 16/25
1. In one of the cases, the cybercriminals had control of the email account (***EMAIL.2) where the authentication factor code was received. The illicit acquisition of these credentials is what allowed a cybercriminal to act as if they were a marketing agent."
However, it can be said that, neither before nor after the attacks, the measures appear to have been adequate. Thus, in the case of one of the leaks—from IP addresses located in ***COUNTRY.1—as a reactive measure, access to ***SYSTEM.1 (Aire Networks extranet) was blocked for all IP addresses not geolocated in Spain (Attempt: "access blocked from invalid IP address"). In other words, this basic security measure, which would prevent access from IP addresses not located in Spain, given that AIRE NETWORKS' commercial activity and, therefore, its marketing agents would be located in Spain, had not been previously adopted. This shortcoming undoubtedly facilitated this personal data breach. This measure is reported regarding the attack suffered by ***AGENT.1 (June 24/25), but the following day, June 26, ***AGENT.2 also suffered two attacks from the same IP address located in ***COUNTRY.1. In this case, the following measure was adopted: "The IP address(es) from which the unauthorized access was made are blocked through firewalls so that they cannot access any of our systems." This would seem to show that the previously adopted measure of blocking access to IP addresses not located in Spain would have had no effect.
On the other hand, in the case of ***COMPANY.1, and referring to the claim that led to this procedure, it is reported that two duplicate eSIMs were created using the credentials of this marketing agent and using an email address—***EMAIL.3—that does not correspond to that of the complainant. This fact indicates that there were no measures in place to verify the accuracy of the email address with the customer's actual address, which should have been available since it was a duplicate card, in this case, an eSIM. Furthermore, this same email address was used for various logins in the name of other agents involved.
Another circumstance that indicates a lack of measures to prevent the loss of confidentiality of the data being processed is that, in another of the detected cases, the credentials of an employee who was on sick leave at the time of the events were used. This circumstance, which should have been taken into account, for example, to temporarily block the employee's credentials, was not detected until after the attack. An
attack that could have been avoided, in this specific case, if, as we said, the employee's credentials had not remained valid while he was on sick leave and, logically, he could not use them.
Finally, on June 30 and July 6, they reported the implementation of a relevant measure, two-factor authentication (2FA), for access to ***SISTEMA.1 by all company employees and for access to ***SISTEMA.1 by all marketing agents. However, in the
investigation and when reporting on the reason why the security measures implemented had not prevented the incident, AIRE NETWORKS indicated that:
"In one of the cases, the cybercriminals had control of the email account (***EMAIL.2) where the authentication factor code was received. The illicit acquisition of these credentials allowed a cybercriminal to act as if they were a marketing agent."
Therefore, it is unclear whether the measure of having 2FA for access i) was implemented but failed to prevent the incident; or ii) was adopted later, as stated in relation to the actions carried out on June 30 and July 6.
Consequently, the procedure the respondent had in place to access its customers' personal data, which revealed a lack of adequate security measures in its systems, as the respondent has acknowledged, would have allowed a personal data breach to occur, resulting in the loss of confidentiality of credentials, which facilitated unauthorized access to the personal data of 40 individuals, including the two owners of the two affected mobile lines, which had consequences for their bank accounts. This would constitute a violation of Article 5.1.f) of the GDPR, exposing the personal data to unauthorized access with detrimental consequences for the complainant and all other affected parties. Therefore, based on the evidence currently available, the agreement to initiate sanctioning proceedings, it is considered that the known facts could constitute an infraction, attributable to AIRE NETWORKS, for violating the article transcribed above.
V
Classification of the violation of Article 5.1.f) of the GDPR and classification for the purposes of
statute of limitations
Article 83.5 of the GDPR classifies the violation of the following articles as an administrative offense, which shall be punishable, in accordance with paragraph 2, by administrative fines of up to EUR 20,000,000 or, in the case of a company, by
an amount equivalent to a maximum of 4% of the total annual global turnover of the preceding financial year, whichever is higher:
"a) the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9;"
For its part, the LOPDGDD (Organic Law on the Protection of Personal Data) in its Article 71, "Infractions," states that:
"The acts and conduct referred to in sections 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law, constitute infringements."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 18/25
For the sole purposes of the statute of limitations, Article 72.1 of the LOPDGDD (Organic Law on Personal Data Protection) establishes the following:
"In accordance with the provisions of Article 83.5 of Regulation (EU) 2016/679, infringements that constitute a substantial violation of the articles mentioned therein, and in particular the following, are considered very serious and will be subject to a three-year statute of limitations:
a) The processing of personal data in violation of the principles and guarantees established in Article 5 of Regulation (EU) 2016/679."
VI
Proposed Sanction
In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR must be observed, which state:
“1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article for infringements of this Regulation referred to in paragraphs 4, 9, and 6 are, in each individual case, effective, proportionate, and dissuasive.
2. Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or as a substitute for the measures provided for in Article 58(2)(a) to (h) and (j). When deciding on the imposition of an administrative fine and its amount in each individual case, due account shall be taken of:
a) the nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation that concerned, as well as the number of data subjects affected and the level of damage suffered by them;
b) the intentionality or negligence of the breach;
c) any measures taken by the controller or processor to mitigate the damage suffered by the data subjects;
d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures they have implemented pursuant to Articles 25 and 32;
e) any previous breaches committed by the controller or processor;
f) the degree of cooperation with the supervisory authority to remedy the breach and mitigate any adverse effects of the breach;
g) the categories of personal data affected by the breach;
h) the manner in which the supervisory authority became aware of the breach, in particular whether the controller or processor notified the breach and, if so, to what extent;
i) where the measures referred to in Article 58(2) have been previously ordered against the controller or processor in question in relation to the same matter, compliance with such measures;
j) adherence to codes of conduct pursuant to Article 40 or certification mechanisms approved pursuant to Article 42, and
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 19/25
k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement."
For its part, Article 76 "Sanctions and Corrective Measures" of the LOPDGDD (Spanish Data Protection Act) provides:
"1. The sanctions provided for in sections 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the grading criteria established in section 2 of the aforementioned article.
2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account:
a) The continuous nature of the infringement.
b) The connection between the infringer's activity and the processing of personal data.
c) The benefits obtained as a result of the infringement.
d) The possibility that the affected party's conduct could have led to the infringement.
e) The existence of a merger by absorption process subsequent to the infringement, which cannot be attributed to the infringement. to the acquiring entity.
f) The impact on the rights of minors.
g) Having a data protection officer, when not mandatory.
h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms in cases where there are disputes between them and any interested party.
In the present case, considering the seriousness of the potential violation, paying special attention to the consequences its commission has on those affected, a fine would be imposed, in addition to the adoption of measures, if appropriate.
The fine imposed must be, in each individual case, effective, proportionate, and dissuasive, in accordance with the provisions of Article 83.1 of the GDPR. To guarantee
these principles, AIRE NETWORKS's turnover of 107,746,223 in 2023 is considered as a preliminary matter.
For the purposes of deciding on the imposition of an administrative fine and its amount, in accordance with the evidence available at the time of the decision to initiate sanctioning proceedings, and without prejudice to the outcome of the investigation, it is considered appropriate to grade the sanction to be imposed according to
the following circumstances, contemplated in the aforementioned provisions.
Prior to this, it is deemed that the following circumstances exist:
- The nature, severity, and duration of the breach, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damages suffered (Article 83.2, letter a) of the GDPR): The security breach at AIRE NETWORKS, resulting from the leak of access credentials to the corporate extranet, known as ***SISTEMA.1, allowed the attackers to access the personal data of 40 people and carry out improper transactions, including the issuance of a duplicate SIM card that facilitated subsequent thefts from the bank accounts of two affected parties through online banking systems on June 27, 2018. 2023. It should be noted that the breach affected other interested parties in addition to the complainant and was facilitated by the failure to adopt basic measures such as blocking access via foreign IP addresses, temporarily blocking the access credentials of employees on sick leave, or properly implementing two-factor authentication for access by the entity's employees or marketing agents. It is also noteworthy that some of the measures adopted did not prevent subsequent successful access. - The categories of personal data affected by the breach (Article
83.2 (g) of the GDPR): In this regard, it should be noted that, according to information provided by AIRE NETWORKS, the breach affected: "Affected persons
***AMOUNT.6 with identification data (name, surname, nationality, date of birth, and ID) and contact information (email, telephone, postal address), and others ***AMOUNT.7 also with direct debit data." It should be noted that both the identification number and financial data are considered by the European Data Protection Board (EDPB) as personal data that must be included among those referred to in Article 83.2 (g). Likewise, Section 57 of Guidelines 04/2022, on the calculation of administrative fines under the GDPR, states the following:
“Regarding the requirement to take into account the categories of personal data concerned [Article 83(2)(g) of the GDPR], the GDPR
clearly highlights the types of data that merit special protection and, therefore, a stricter response with regard to fines. This
refers, at a minimum, to the types of data referred to in Articles 9 and 10 of the GDPR and to data outside the scope of these articles whose dissemination would cause immediate harm and damage to the data subject (for example,
location data, data on private communications, national identification numbers, or (...)). In general, the more of these categories of data are involved or the more sensitive the data, the more weight the supervisory authority can
attribute to this factor.”
Likewise, the following grading factors are considered aggravating factors:
- The connection between the offender's activity and the processing of personal data (Article 76.2, letter b) of the LOPDGDD): The activity of AIRE NETWORKS, and more specifically, the processing in which the confidentiality breach occurred, is intrinsically linked to the processing of personal data, since its operation involves the collection, storage, management, and transmission of customer information. Thus, in order to provide the telephone and internet service, the defendant must process personal data such as the name, address, telephone number, email address, and bank details of customers.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 21/25
The balance of the circumstances contemplated in Article 83.2 of the GDPR and 76.2 of the LOPDGDD, with respect to the infringement committed by violating the provisions of
Article 5.1.f) of the GDPR, allows for the initial imposition of an administrative fine of €100,000.00.
Therefore, in light of the above, the President of the Spanish Data Protection Agency,
HAS RESOLVED:
FIRST: TO INITIATE SANCTIONING PROCEEDINGS against AIRE NETWORKS DEL
MEDITERRÁNEO, S.L., with NIF B53704599, for the alleged violation of Article
5.1.f) of the GDPR, as defined in Article 83.5 of the GDPR.
SECOND: TO APPOINT R.R.R. as investigating judge and S.S.S. as secretary,
indicating that they may be challenged, if appropriate, in accordance with the provisions of
Articles 23 and 24 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector (LRJSP).
THIRD: INCORPORATE into the file, for evidentiary purposes, the claim filed by the complaining party and its documentation, as well as the documents obtained and generated by the Subdirectorate General of Data Inspection in the proceedings prior to the initiation of this sanctioning procedure.
FOURTH: THAT for the purposes set forth in Article 64.2 b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, the applicable sanction would be an administrative fine of €100,000.00, without prejudice to the outcome of the investigation.
FIFTH: NOTIFY this agreement to AIRE NETWORKS DEL MEDITERRANEO, S.L., with Tax Identification Number (NIF) B53704599, granting it a hearing period of ten business days to formulate its allegations and present any evidence it deems appropriate. In its written allegations, it must provide its Tax Identification Number (NIF) and the procedure number shown in the heading of this document.
In accordance with the provisions of Article 85 of the LPACAP (Spanish Civil Code), it may acknowledge its liability within the period granted for the formulation of allegations to this initiation agreement; this will entail a 20% reduction in the appropriate penalty imposed in this procedure. With the application of this reduction, the penalty would be set at €80,000.00, and the procedure would be resolved with the imposition of this penalty.
Likewise, at any time prior to the resolution of this procedure, the applicant may voluntarily pay the proposed fine, which will result in a 20% reduction in its amount. With the application of this reduction, the fine would be set at €80,000.00, and its payment will terminate the procedure, without prejudice to the imposition of the corresponding measures.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 22/25
The reduction for voluntary payment of the fine may be combined with the reduction applicable for acknowledgment of liability, provided that this acknowledgment of liability is made clear within the period granted for submitting allegations at the opening of the procedure. Voluntary payment of the amount referred to in the preceding paragraph may be made at any time prior to the resolution. In
this case, if both reductions were applicable, the penalty amount would be set at €60,000.00.
In any case, the effectiveness of either of the aforementioned reductions will be conditional on the express withdrawal or waiver of any administrative action or appeal against the penalty.
For these purposes, if you opt for either of them, you must send a clear communication to the
General Subdirectorate of Data Inspection indicating which of the two reductions you are opting for, or if you are opting for both.
If you choose to voluntarily pay any of the amounts indicated above (€80,000.00 or €60,000.00), you must do so by depositing it into account IBAN: ES00-0000-0000-0000-0000-0000
(BIC/SWIFT Code: CAIXESBBXXX) opened in the name of the Spanish Data Protection Agency at the banking institution CAIXABANK, S.A., indicating in the entry the reference number of the procedure that appears in the heading of this document and the reason for the reduction in the amount you are applying for. You must also send proof of payment to the Subdirectorate General of Inspection.
Finally, please note that, in accordance with Article 112.1 of the LPACAP,
there is no administrative appeal against this decision.
1479-290125
Lorenzo Cotino Hueso
The President of the Spanish Data Protection Agency
>>
SECOND: On May 13, 2025, AIRE NETWORKS proceeded to pay the fine in the amount of €60,000.00, making use of the two reductions provided for in the initiation agreement transcribed above, which implies acknowledgment of liability in relation to the events referred to in the initiation agreement and their legal classification.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 23/25
LEGAL BASIS
I
Jurisdiction
In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR) and as established in Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), the President of the Spanish Data Protection Agency is competent to resolve this procedure.
Likewise, Article 63.2 of the LOPDGDD establishes that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, this Organic Law, the regulatory provisions issued in its development, and, insofar as they do not contradict them, in a subsidiary capacity, by the general rules on administrative procedures."
II
Termination of the Procedure
Article 85 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), under the heading "Termination of Sanctioning Procedures," provides the following:
"1. Once a sanctioning procedure has been initiated, if the offender acknowledges responsibility, the procedure may be terminated with the imposition of the appropriate sanction.
2. When the sanction is solely monetary in nature, or when one monetary sanction and another non-monetary sanction may be imposed, but the inadmissibility of the second sanction has been justified, voluntary payment by the alleged offender, at any time prior to the resolution, will entail the termination of the procedure, except with regard to restoring the altered situation or determining compensation for damages caused by the commission of the offense. Infraction.
3. In both cases, when the sanction is solely monetary in nature, the
body competent to resolve the procedure will apply reductions of at least 20% on the amount of the proposed sanction, which may be combined.
These reductions must be specified in the notification of initiation of the procedure, and their effectiveness will be conditional on the withdrawal or waiver of any administrative action or appeal against the sanction.
The percentage reduction provided for in this section may be increased by regulation.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 24/25
III
Voluntary payment and acknowledgment of liability
In accordance with the provisions of the aforementioned Article 85 of the LPACAP (Spanish Civil Code), the notified initiation agreement provided information on the possibility of acknowledging liability and voluntarily paying the proposed penalty, which would entail two cumulative reductions of 20% each. With the application of these two reductions, the penalty would be set at €60,000.00, and payment would imply the termination of the procedure, without prejudice to the imposition of the corresponding measures.
Following notification of the aforementioned initiation agreement, AIRE NETWORKS has proceeded to acknowledge liability and voluntarily pay the penalty, taking advantage of the two planned reductions. Pursuant to Section 3 of Article 85 of the LPACAP, the effectiveness of the aforementioned reductions will be conditional on the withdrawal or waiver of any administrative action or appeal against the penalty.
It should be noted that, in accordance with the provisions of the LPACAP, as well as the Supreme Court's jurisprudence on this matter, the exercise of voluntary payment by the alleged liable party does not exempt the administration from the obligation to resolve and notify all proceedings, regardless of their method of initiation. Similarly, Article 88 of the aforementioned law establishes that the resolution that concludes the procedure will decide all issues raised by the interested parties and any other issues arising from it.
Therefore, in accordance with applicable legislation and having assessed the criteria for graduating sanctions, the Presidency of the Spanish Data Protection Agency RESOLVES:
FIRST: TO DECLARE the commission of the violations and CONFIRM the sanctions determined in the operative section of the initiation agreement transcribed in this resolution.
The sum of the aforementioned amounts results in a total of €100,000.00.
After AIRE NETWORKS DEL MEDITERRÁNEO, S.L. has made prompt payment and acknowledged liability, pursuant to Article 85 of the LPACAP, the aforementioned total will be reduced by 40%, resulting in the final amount of €60,000.00.
The effectiveness of the aforementioned reductions is, in all cases, subject to the withdrawal or waiver of any administrative action or appeal.
SECOND: DECLARE the termination of procedure EXP202310943, in accordance with the provisions of Article 85 of the LPACAP.
THIRD: NOTIFY this resolution to AIRE NETWORKS DEL
MEDITERRÁNEO, S.L.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 25/25
FOURTH: In accordance with the provisions of Article 85 of the LPACAP, which conditions the reduction for voluntary payment and acknowledgment of liability on the withdrawal or waiver of any action or appeal through administrative channels, this resolution will become final and fully enforceable upon notification.
In accordance with the provisions of Article 50 of the LOPDGDD, this resolution will be made public once it has been notified to the interested parties.
Against this resolution, which ends the administrative process as provided for in
art. 114.1.c) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, interested parties may file an administrative appeal before the Administrative Litigation Division of the National Court, in accordance with the provisions of Article 25 and section 5 of the fourth additional provision of Law 29/1998, of July 13, regulating the Administrative Litigation Jurisdiction, within two months from the day following notification of this action, as provided for in Article 46.1 of the aforementioned Law.
However, in accordance with the provisions of Article 90.3.a) of the LPACAP, the final administrative decision may be provisionally suspended if the interested party expresses their intention to file an administrative appeal. If this is the case, the interested party must formally notify this fact in writing to the Spanish Data Protection Agency, submitting it through the Agency's Electronic Registry [https://sedeaeps.gob.es/sede-electronica-web/], or through any of the other registries provided for in Article 16.4 of the aforementioned Law 39/2015, of October 1. They must also forward to the Agency the documentation proving the effective filing of the contentious-administrative appeal. If the Agency does not become aware of the filing of the contentious-administrative appeal within two months from the day following notification of this resolution, it will terminate the precautionary suspension. 936-200325
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es




