AEPD (Spain) - EXP202313830

From GDPRhub
AEPD - EXP202313830
Authority: AEPD (Spain)
Jurisdiction: Spain
Relevant Law: Article 6(1) GDPR
Article 28(3) GDPR
Article 83(1) GDPR
Article 83(2)(a) GDPR
Article 83(2)(b) GDPR
Article 83(2)(g) GDPR
Article 83(5)(a) GDPR
Article 71 LOPDGDD
Article 85(3) Law 39/2015
Type: Complaint
Outcome: Upheld
Started: 22.08.2023
Decided: 21.05.2025
Published: 23.06.2025
Fine: 3,000 EUR
Parties: Silvanergia 2022, S.L
Bassols Energia Comercial, SL
National Case Number/Name: EXP202313830
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Spanish
Original Source: AEPD (in ES)
Initial Contributor: Marina Stoler

The DPA fined a utilities company €3,000 for processing data without a legal basis, violating Article 6(1) GDPR.

English Summary

Facts

On 22 August 2023, a data subject filed a complaint with the DPA against Silvanergia 2022, S.L. (the controller).

On 16 August 2023, an agent of the controller contacted the data subject, claiming to call on behalf of their energy provider, Bassols Energía, S.A. (Bassols), to update the electricity rate according to new government regulations. The agent asserted that they already possess the data subject’s data, requiring solely their confirmation by email. The referred data consisted of the data subject’s full name, ID number, address, Universal Supply Point Code number[1], and 12 digits of their bank account.

The controller sent an email to the data subject, reminding them of the pending signature to update the tariff. This contained a contract in the name of Bassols. The data subject refused to sign the contract once they noticed that the controller was not their electricity supply company, as they did not intend to enter into a new contract with the controller.

The controller contacted the data subject again to ask why they had not signed the contract. In response, the data subject asked the controller how it obtained their data, in order to exercise their right to erasure (Article 17 GDPR). The controller replied that the data was obtained by third-party firms, despite the data subject denying that they had provided any of their data to them. The data subject tried to contact the controller again but discovered that the e-mail address and phone number of the controller were listed as nonexistent. The data subject then contacted Bassols and requested the deletion of their personal data. Bassols claimed that it had been a victim of identity fraud committed by the controller, as the contract received via email by the data subject was in the name of Bassols.

During its investigations, the DPA found that Bassols was part of a business group, which includes an electricity marketing company named Bassols Energía Comercial SL (BEC). The DPA later identified the controller as the company that had contacted the data subject claiming to be their energy provider, as it was confirmed by the data subject's telecommunications provider. BEC explained to the DPA that it had previously contracted the controller for telemarketing services, in order for the controller to find new clients for BEC. The two companies no longer worked together because the controller had not signed the contract, which would establish it as a processor on behalf of BEC. In addition, BEC claimed that it did not provide the data subject's personal data; this is only done once the processor signs a confidentiality agreement. The DPA requested information from the controller on the sources of the data subject's personal data. The controller claimed the data was obtained through a supplier (anonymised by the DPA), however, was unable to provide evidence.

On 22 November 2023, the complaint was allowed to proceed.

Holding

First, it is relevant to clarify the position of Silvarnergía in this complaint. The contract between Silvanergía and BEC established the former as a processor. However, the contract was not signed. Therefore, the DPA treated Silvernergía as a controller, in accordance with Article 4(7).

The DPA deemed the processing of the data subject’s personal data by the controller unlawful for three reasons. First, the controller's calls to the data subject (BEC' clients) for customer attraction did not rely on the legal basis of Article 6(1). Second, the DPA found that BEC did not have a contract with the controller for processing the data subject’s personal data. Consequently, the processing of the data subject’s personal data by the controller violated Article 28(3). Third, the DPA pointed out that the data subject has not even given their consent to the controller for processing their personal data.

Therefore, the DPA imposed a fine, according to Article 83(5)(a) in conjunction with Article 71 Organic Law on Protection of Personal Data and Guarantee of Digital Rights 3/2018 (LOPDGDD). Among other criteria, the fine amount was determined based on the controller's grave negligence and the type of data involved in the infringement. Under Article 83(2)(b), such a negligence was attributed to the controller’s use of personal data without directly obtaining it from the data subject, as well as the processing of that personal data without informing the data subject. Further, under Article 83(2)(g), the controller processed data that could uniquely identify the data subject, such as their ID number, Universal Supply Point Code number, and digits of their bank accounts.

The fine was initially set at €5,000, but pursuant to Law 39/2015, a Spanish law concerning administrative proceedings, the DPA informed the controller that it may make a voluntary payment of the proposed fine and waive their right to appeal. This action reduces the imposed fine by 20%. The fine can be reduced by a further 20% if the controller acknowledges its liability. The controller opted for both and reduced the fine by 40%, paying the reduced sanction amount of €3,000, based on Article 85(3) Law 39/2015.

Lastly, in addition to the administrative fine, the DPA imposed on the controller to cease processing its clients' personal data.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.

1/20

 File No.: EXP202313830

RESOLUTION TERMINATING THE PROCEDURE FOR RECOGNITION OF LIABILITY AND VOLUNTARY PAYMENT

From the procedure initiated by the Spanish Data Protection Agency and based on

the following

BACKGROUND

FIRST: On May 21, 2025, the Presidency of the Spanish Data Protection Agency agreed to initiate sanctioning proceedings against SILVANERGIA 2022, S.L. (hereinafter, SILVANERGIA), through the agreement transcribed below:

<<
File No.: EXP202313830

AGREEMENT TO INITIATE SANCTIONING PROCEDURE

Regarding the actions taken by the Spanish Data Protection Agency and based on the following

FACTS

FIRST: On August 22, 2023, a complaint was filed with the Spanish Data Protection Agency for a possible infringement attributable to

SILVANERGIA 2022, S.L. with Tax Identification Number (NIF) B72658313 (hereinafter, SILVANERGIA or the respondent).

The facts brought to the attention of this authority are as follows:

The complainant states that an agent of the respondent company contacted her by phone on
August 16, 2023, and informed her that they were calling from Bassols Energía, the energy supplier that holds her contract with Naturgy, to update her rate according to the new regulations published by the government. He told her that it was a very quick process because they already had all her information, and all that was needed was confirmation of it. He listed her full name, ID number, address, CUP number, and 12 digits of her bank account number. He indicated that, for data protection reasons, he could not provide the full number over the phone and urged her to complete it so that he could supposedly verify it, to which the complainant agreed.

Subsequently, they sent her a contract in the name of Bassols Energía via the

addresses "***EMAIL.1" and "***EMAIL.2" with the subject line "IMPORTANT! Reminder: Bassols Energía pending signature (CERTIFIED EMAIL from ***EMAIL.1.1)." Once the complainant opened the email, she received a call notifying her that she would receive an SMS with a password to sign the contract. The complainant did not access the signature after realizing that the company was not acting as the representative of her electricity supply company, but rather intended to sign a new contract.

When the company contacted the complainant again the next day to inquire as to why she had not proceeded with the signature, she asked where they obtained all her data and was told that they had obtained it from companies "like
(...)". The complainant claims not to have provided any information to such companies and again inquired about where they obtained the data so that she could exercise her right of withdrawal.

When she attempted to contact this company again, both the email address and the phone number used up to that point were listed as non-existent. Therefore, she contacted Bassols Energía, S.A., using the phone number listed on the website, to request the deletion of her personal data. The response she received was that the company had been the victim of identity theft, that the contract they had sent her was fake, and that the identity theft had already been reported.

SECOND: In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), this complaint was forwarded to Bassols Energía, S.A. so that it could analyze it and inform this Agency within one month of the actions taken to comply with the requirements set forth in the data protection regulations.

On November 16, 2023, a response was received from the company stating that BASSOLS ENERGIA, SA is part of a business group that includes an electricity supplier, BASSOLS ENERGIA COMERCIAL, SL, which deals with domestic end-customers. The company believes that the request could be addressed to it. In collaboration with the agency, the company is proceeding to respond to the request on behalf of this supplier. The company states in its letter that it contracted
the services of companies dedicated to promoting activities related to the commercialization of electricity, but that these contracts expressly established that these companies had their own customer base, or the capacity to generate one, to whom they would offer the products marketed by BASSOLS
ENERGIA COMERCIAL, SL. Ultimately, these companies acted independently as commercial agents.

Furthermore, with respect to the complainant, BASSOLS ENERGIA COMERCIAL, SL states that it is not registered as a customer, nor has it ever been, and that the telephone calls it claims to have received from this entity do not correspond

to the telephone numbers of the retailer.

THIRD: On November 22, 2023, in accordance with Article 65 of the LOPDGDD (Spanish Data Protection Act), the complaint was admitted for processing.

FOURTH: The Subdirectorate General for Data Inspection carried out preliminary investigations to clarify the facts in question, pursuant to the functions assigned to supervisory authorities in Article 57.1 and the powers granted in Article 58.1 of Regulation (EU)

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 3/20

2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VIII of the LOPDGDD.

As a result of the actions taken, the following details have been obtained:

- Through information obtained from the numbering registry on the CNMC website, https://numeracionyoperadores.cnmc.es/portabilidad/fija (document

"Diligence 2"), it is verified that, as of the date of investigation of this case, the operator of the originating number of the calls was:

***TELÉFONO.1 GAMMA OPERADORA DE COMUNICACIONES, S.A

Regarding the complained-about number ***TELÉFONO.1:

- In a response dated 03/15/2024 and registration number REGAGE24e00020140422,

NEOTEL 2000 S.L.U. (a subsidiary of GAMMA) indicates that the owner of the line on the date of the call to the complainant was SILVANERGIA 2022 S.L.U. and confirms the
receipt of two calls at 12:19:44 and 7:00:28 PM. TELEFÓNICA

(the complainant's phone operator) also confirms receipt of the calls.

A request for information requesting the reasons for the calls was sent to SILVANERGÍA dated 03/18/2024, which was found to have expired.

A reiteration was sent by mail dated 11/08/2024, from which the following response was obtained on 12/10/2024:

“…

In response to your request for information received on November 22, 2024, regarding file EXP202313830, we are writing to provide the requested information.

1. Confirmation of calls made to the number ***TELÉFONO.2 on August 16, 2023, between 12:00 PM and 8:00 PM:

- We cannot confirm the calls made to this number on the aforementioned date. Our call center only keeps records of calls made within the last year.

2. Reason for the call to the number ***TELÉFONO.2:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 4/20

- We cannot confirm that the call was made, as we do not have the call log for the aforementioned date.

3. Contractual relationship with the company BASSOLS ENERGÍA COMERCIAL, S.L.:

- Our company maintained a contractual relationship with BASSOLS ENERGÍA COMERCIAL, S.L. in the past, providing telemarketing services for them. However, we currently do not maintain any contractual relationship with this company. 4. Contractual relationship with the company AURORA ENERGY 2000, SLU:

- Our company has never had a contractual relationship with AURORA ENERGY 2000, SLU.

5. Contractual relationship with the company GESTION DE VENTAS IBERIA, SL:

- Our company has never had a contractual relationship with GESTION DE VENTAS IBERIA, SL.

6. How do you receive the numbers? Which should you make commercial calls to?

- The phone numbers we call are provided by various providers. These providers are responsible for filtering these numbers using the Robinson list.

7. Confirmation of a consultation of a list of numbers not to be called: - As mentioned in the previous section, the providers guarantee that any records will be filtered using Robinson. However, for several months now, and to ensure compliance with current data protection regulations, we have been performing a second Robinson filter from the call center. This filtering is performed automatically and constantly, so that calls cannot be made to numbers on this list…"

A request was made to SILVANERGÍA for a collaboration contract with BASSOLS ENERGÍA COMERCIAL. A response dated January 31, 2025, was received with a contract template that was neither signed nor completed by the parties.

On February 3, 2025, a new request was sent to SILVANERGIA requesting a contract signed with BASSOLS ENERGÍA COMERCIAL, to which a response was received

dated February 17, 2025. The request includes what appears to be a "Promotion Services Provision Contract," which shows:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 5/20

- The information of the alleged representative of BASSOLS ENERGÍA COMERCIAL appears, and the only identifying information on the part of the COLLABORATOR is the name "A.A.A." and the address "***ADDRESS.1."

- "BASSOLS ENERGÍA COMERCIAL" appears on one side and "VICO

FINANCIAL SERVICES" (the COLLABORATOR) on the other. It can be seen in the "Diligence 4" document that the latter has no connection with SILVANERGIA 2020, S.L.

- A single signature appears (with a signature certificate included at the end of the document)
of the COLLABORATOR, with no signature

of the representative of BASSOLS ENERGÍA COMERCIAL appearing anywhere in the document.

On February 18, 2025, SILVANERGIA was asked for the following information:

- Specify which specific personal data provider provided you with the claimant's data, and provide evidence that you have such a transaction, including the date it occurred.

- Copy of the agreement signed with said personal data provider
and, where applicable, any other documents establishing the

guidelines on the conditions of legitimacy of said transaction.

To which, on February 18, 2025, SILVANERGIA responded by attaching an invoice from

the provider ***PROVIDER.1 ((...)) dated June 10, 2023 (the date prior to the call to the complainant). No evidence is attached that the data acquired
from said provider was obtained legitimately.

On January 20, 2025, BASSOLS ENERGÍA COMERCIAL was requested to establish a contractual relationship with SILVANERGIA, to which, on February 4, 2025, it replied:

“……

II. To date, the marketing company, BASSOLS ENERGIA COMERCIAL, SL, has no commercial relationship with SILVANERGIA 2022, SL. However, in July

2023, they began commercial discussions with the aim of collaborating professionally. The purpose of the collaboration was for SILVANERGIA 2022, SL
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 6/20

to act as an external channel, attracting potential clients for BASSOLS ENERGIA
COMERCIAL, SL.

III. In anticipating a potential collaboration, BASSOLS ENERGIA COMERCIAL, SL sent a Collaboration Agreement, which was never returned or signed by SILVANERGIA 2022, SL, even though the representative complained several times about it, given that it was not contemplated to begin collaborating without the duly signed agreement.

Similarly, BASSOLS ENERGIA COMERCIAL, SL requested financial information from SILVANERGIA 2022, SL to validate the financial situation of the company with which they were willing to collaborate.

IV. At the end of August 2023, as a result of not having received the signed agreement and SILVANERGIA 2022, SL being found to have an irregular financial situation,

BASSOLS ENERGIA COMERCIAL, SL decided to end all business relations with SILVANERGIA 2022, SL.

V. As a result of the above, BASSOLS ENERGIA COMERCIAL, SL and

SILVANERGIA 2022, SL never formalized a written Contract. However,
this party is aware that SILVANERGIA 2022, SL began recruiting potential clients for BASSOLS ENERGIA COMERCIAL, SL during the months of

July and August 2023. Even without a signed contract, SILVANERGIA 2022, SL may have attempted to recruit some clients for BASSOLS ENERGIA COMERCIAL, SL.

VI. For clarification purposes, under no circumstances did BASSOLS ENERGIA COMERCIAL, SL

provide any personal data of clients to SILVANERGIA 2022, SL, since
according to internal protocol, data is only shared with collaborating companies

when the corresponding confidentiality agreement has been signed between the
Data Controller and the Data Processor.

FIFTH: According to the report collected from the AXESOR tool, the entity SILVANERGIA was established in 2022, with a turnover of €149,570 in 2023.

LEGAL BASIS

I
Jurisdiction

In accordance with the powers granted to each supervisory authority by Article 58.2 of the GDPR and as established in Articles 47, 48.1, 64.2, and 68.1 of the LOPDGDD (Spanish Data Protection Act), the President of the Spanish Data Protection Agency is competent to initiate and resolve this procedure.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 7/20

II
Procedure

Likewise, Article 63.2 of the LOPDGDD establishes that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development, and, insofar as they do not contradict them, in a subsidiary capacity, by the general rules on administrative procedures."

In accordance with Article 64 of the LOPDGDD, and taking into account the characteristics of the alleged infringement, a sanctioning procedure shall be initiated.

The procedure will last a maximum of twelve months from the date of the initiation agreement. After this period, the proceedings will expire and, consequently, the proceedings will be archived, in accordance with the provisions of Article 64 of the LOPDGDD.

If no objections are made to this initial resolution within the stipulated period, it may be considered a proposed resolution, as established in Article 64.2.f) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP).

III
Preliminary Questions

Article 4(1) of the GDPR defines "personal data" as: "any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is any person whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person."

Article 4(2) of the GDPR defines “processing” as: “any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.”

Article 4(7) of the GDPR defines “controller” or “controller” as: “the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing; where Union or Member State law determines the purposes and means of processing, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.” In turn, Article 4.8 of the GDPR defines the "data processor" or "processor" as the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 8/20

natural or legal person, public authority, service, or other body that processes personal data on behalf of the data controller.

In the present case, in accordance with the provisions of Articles 4.1 and 4.2 of the GDPR,
it constitutes the processing of personal data, since SILVANERGIA carries out, among other processing operations, the collection, storage, consultation, and use of personal data of natural persons, such as name and surname, ID number, address, and bank account numbers, among others.

SILVANERGIA carries out this activity in its capacity as data controller, since it determines the purposes and means of such activity pursuant to Article 4.7 of the GDPR. It should be noted that a written data processing contract was never formalized between BASSOLS ENERGIA COMERCIAL, SL and SILVANERGIA 2022, SL.

IV
Breached obligation. Lawfulness of Processing

The first paragraph of Article 6 of the GDPR states the following:

"1. Processing shall only be lawful if at least one of the following conditions is met:

a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;

b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

c) processing is necessary for compliance with a legal obligation applicable to the controller;

d) processing is necessary to protect the vital interests of the data subject or of another natural person;

e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms. of the data subject that require the protection of personal data, particularly when the data subject is a child.

The provisions of point (f) of the first paragraph shall not apply to processing

carried out by public authorities in the exercise of their duties.

Recital 40 of the GDPR provides that "For processing to be lawful, personal data must be processed with the data subject's consent or on another lawful basis established by law, whether in this Regulation or under other Union or Member State law to which this Regulation refers, including the need for compliance with a legal obligation
to which the controller is subject or the need for the performance of a contract with
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 9/20

to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract."

The processing of personal data requires a legal basis.

In the present case, SILVANERGIA, in July 2023, entered into commercial discussions with the aim of attracting potential clients for BASSOLS

ENERGIA COMERCIAL, SL. However, for the reasons explained above in the research activities, a written contract was not formalized. It should be noted in this regard that, in accordance with the provisions of Article 28.3 of the

GDPR

3. Processing by the processor shall be governed by a contract or other legal instrument, in accordance with Union or Member State law, which binds the processor

to the controller and sets out the subject matter, duration, nature and purpose of the processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller. Such contract or legal instrument shall stipulate, in

particular, that the The processor shall:

a) process the personal data only on documented instructions from the controller, including with respect to transfers of personal data to a third country or an international organization, unless required to do so by Union or Member State law to which the processor is subject; in such a case, the processor shall inform the controller of this legal requirement prior to processing, unless such law prohibits processing for important reasons of public interest;

b) ensure that persons authorized to process personal data have committed themselves to confidentiality or are subject to a statutory obligation of confidentiality;

c) take all necessary measures in accordance with Article 32;

d) comply with the conditions set out in paragraphs 2 and 4 for using another processor;

e) assist the controller, taking into account the nature of the processing, by of appropriate technical and organizational measures, whenever possible, to enable the controller to fulfill its obligation to respond to requests that aim to exercise the data subject rights set out in Chapter III;

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 10/20

f) shall assist the controller in ensuring compliance with the obligations set out in Articles 32 to 36, taking into account the nature of the processing and the information available to the processor;

g) shall, at the controller's discretion, delete or return all personal data once the provision of processing services has ended, and shall delete existing copies unless retention of the personal data is required by Union or Member State law;

h) shall make available to the controller all information necessary to demonstrate compliance with the obligations set out in this Regulation. Article 6.1 of the GDPR, as well as to enable and contribute to the performance of audits, including inspections, by the controller or another auditor authorized by the controller.

With regard to the provisions of point (h) of the first paragraph, the processor shall immediately inform the controller if, in its opinion, an instruction infringes this Regulation or other data protection provisions of the Union or of the Member States.

Despite not having this contract, SILVANERGIA made attempts to recruit customers for BASSOLS ENERGIA COMERCIAL, SL.

These commercial activities carried out by the respondent company were carried out without being covered by any contract with BASSOLS ENERGIA COMERCIAL, SL. That is, the telephone calls made to the complainant with the aim of recruiting them as a customer were not legitimized by Article 6.1 of the GDPR.

Furthermore, BASSOLS ENERGIA COMERCIAL, SL states that it did not provide any personal data of any of its clients to the defendant company because there was no confidentiality agreement between the data controller and the data processor.

In response to this Agency's request for information to SILVANERGIA regarding which personal data provider provided the complainant's data, it attaches an invoice from the provider ***PROVIDER.1, dated June 10, 2023, the date prior to the call to the complainant. This invoice states that 10,000 customer records were sold to the complainant, indicating "Own clients with acceptance of transfer and sale to third parties," although it does not provide a copy of the agreement signed with the data provider or any document establishing the conditions of legitimacy of the transaction.

It is That is, the respondent does not prove that the data acquired from the supplier company was obtained legitimately and that the consent of the interested parties was obtained.

Such processing, without being duly authorized to do so, implies an unlawful processing of the complainant's personal data and, consequently, an alleged violation of Article 6.1 of the GDPR.

Therefore, based on the evidence available at this time, in accordance with the agreement to initiate sanctioning proceedings, it is considered that the known facts could constitute an infringement, attributable to SILVANERGIA, for violation of the article transcribed above.

V
Classification of the infringement of Article 6.1 of the GDPR and qualification for the purposes of statute of limitations

Article 83.5 of the GDPR classifies the violation of the following article as an administrative infringement, which shall be sanctioned, in accordance with paragraph 2, with administrative fines of A maximum of EUR 20,000,000 or, in the case of a company, an amount equivalent to a maximum of 4% of the total annual global turnover of the previous financial year, whichever is higher:

"a) the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9;"

For its part, Article 71 of the LOPDGDD, on Infractions, states that:

"Infractions shall be the acts and conduct referred to in sections 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law."

For the sole purposes of the limitation period, Article 72.1 of the LOPDGDD establishes the following:

"Based on the provisions of Article 83.5 of Regulation (EU) 2016/679, ... (EU) 2016/679 are considered very serious and will be subject to a three-year statute of limitations for violations that constitute a substantial breach of the articles mentioned therein, and in particular, the following:

b) The processing of personal data without any of the conditions for the lawfulness of processing established in Article 6 of Regulation (EU) 2016/679 being met.

VI

Proposed sanction
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 12/20

In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR must be observed, which state:

“1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article for infringements of this Regulation referred to in paragraphs 4, 9, and 6 are, in each individual case, effective, proportionate, and dissuasive.

2. Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or as a substitute for the measures referred to in Article 58(2)(a) to (h) and (j). When deciding whether to impose an administrative fine and its amount in each individual case, due account shall be taken of:
(a) the nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation concerned, as well as the number of data subjects affected and the level of damage suffered by them;
(b) the intentionality or negligence of the infringement; (c) any measures taken by the controller or processor to mitigate the damage suffered by data subjects;
(d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures they have implemented pursuant to Articles 25 and 32;
(e) any previous breaches committed by the controller or processor;
(f) the degree of cooperation with the supervisory authority to remedy the breach and mitigate any adverse effects of the breach;

(g) the categories of personal data affected by the breach;
(h) how the supervisory authority became aware of the breach, in particular whether the controller or processor notified the breach and, if so, to what extent;
(i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned in relation to the same matter, compliance with those measures;
(j) adherence to codes of conduct pursuant to Article 40 or to certification mechanisms approved pursuant to Article 42; and (k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement.

For its part, Article 76 "Sanctions and Corrective Measures" of the LOPDGDD (Organic Law on Personal Data Protection) provides:

"1. The sanctions provided for in sections 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the grading criteria established in section 2 of the aforementioned article.

2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679,

the following may also be taken into account:
a) The continuous nature of the infringement.
b) The connection between the offender's activity and the processing of personal data.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 13/20

c) The benefits obtained as a result of committing the infringement.
d) The possibility that the affected party's conduct could have inducing the commission of the infringement.

e) The existence of a merger by absorption process subsequent to the commission of the infringement, which cannot be attributed to the acquiring entity.
f) The violation of the rights of minors.
g) Having, when not mandatory, a data protection officer.
h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms in cases where there are disputes between them and any interested party.

In the present case, considering the seriousness of the potential infringement, paying special attention to the consequences that its commission has on those affected, a fine would be appropriate, in addition to the adoption of measures, if appropriate.

The fine imposed must be, in each individual case, effective, proportionate, and dissuasive, in accordance with the provisions of Article 83.1 of the GDPR. To guarantee
these principles, SILVANERGIA's turnover (…) in 2023) is considered as a preliminary matter.

For the purposes of deciding on the imposition of an administrative fine and its amount, in accordance with the evidence available at the time of the decision to initiate sanctioning proceedings, and without prejudice to the outcome of the investigation, it is considered appropriate to grade the sanction to be imposed according to

the following circumstances, contemplated in the aforementioned provisions.

First, the following circumstances are deemed to exist:

- The nature, severity, and duration of the infringement, taking into account the

nature, scope, or purpose of the processing operation in question,
as well as the number of data subjects affected and the level of damages they have suffered (Article 83.2(a) of the GDPR): it should be taken into account

here that the respondent carried out its activity as a customer recruiter, without being covered by any contract, so it would not affect

only the complaining party.

- The intentionality or negligence in the infringement (Article 83.2(b) of the GDPR):
Gross negligence is manifested in the use of the personal data of the data subjects

without having obtained them directly from them and without them having
information about the processing of their personal data.

- The categories of personal data affected by the breach
(Article 83.2, letter g) of the GDPR): data has been exposed that

can unequivocally identify a person, such as
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 14/20

ID numbers, and which may be susceptible to misuse, such as identity theft, among others. In this regard, the European Data Protection Board (EDPB) itself, in its guidelines on the calculation of fines, adopted in May 2023, states the following (emphasis added): Regarding the requirement to take into account the categories of personal data concerned [Article 83(2)(g) of the GDPR], the GDPR clearly highlights the types of data that merit special protection and, therefore, a stricter response regarding fines. This

refers, at a minimum, to the types of data referred to in Articles 9 and 10 of the GDPR and to data outside the scope of these articles, the dissemination of which would cause immediate harm and damage to the data subject (for example,
location data, data on private communications, national identification numbers, or financial data, such as transaction summaries or credit card numbers). In general, the more of these categories of data are involved or the more sensitive the data, the more weight the supervisory authority may give to this factor.

Furthermore, the following grading factors are considered aggravating factors:

- The connection between the offender's activity and the processing of personal data (Article 76.2, letter b) of the LOPDGDD): The respondent
provided customer acquisition services, so in the course of its activity it routinely needs to process personal data.

For the purposes of deciding on the imposition of an administrative fine and its amount, in accordance with the evidence currently available in the decision to initiate sanctioning proceedings, and without prejudice to the outcome of the investigation, it is considered that the balance of the circumstances contemplated in Article 83.2 of the GDPR and Article 76.2 of the LOPDGDD, with respect to the infringement committed by violating the provisions of Article 6.1 of the GDPR, allows for the initial imposition of an administrative fine of €5,000.00.

IX
Adoption of Measures

If the violation is confirmed, the resolution issued may establish the corrective measures that the offending entity must adopt to end the breach of personal data protection legislation, in this case Article 6.1 of the GDPR, in accordance with the provisions of the aforementioned Article 58.2.d) of the GDPR, according to which each supervisory authority may "order the controller or processor to ensure that processing operations comply with the provisions of this Regulation, where appropriate, in a specified manner and within a specified period...".

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 15/20

Thus, the responsible entity may be required to bring its actions into compliance with personal data protection regulations, within the scope expressed in the previous Legal Basis.

This document establishes the alleged violation committed and the facts that could lead to this potential breach of data protection regulations. From this, it is clear what measures to be adopted, without prejudice to the sanctioned party's responsibility to implement the specific procedures, mechanisms, or instruments. The data controller is fully familiar with their organization and must decide, based on proactive responsibility and a risk-based approach, how to comply with the GDPR and the LOPDGDD. However, in this case, regardless of the foregoing, in accordance with the evidence currently available regarding the agreement to initiate sanctioning proceedings, the resolution adopted may require SILVANERGIA to adopt the following measure within a maximum period of one month from the date of the executive order finalizing this procedure:

- Cease processing personal data for its customer acquisition activities as long as it is not covered by any of the legal grounds set forth in Article 6.1 of the GDPR.

The imposition of this measure is compatible with the sanction of an administrative fine, as provided in Article 83.2 of the GDPR.

Please note that failure to comply with the possible order to adopt measures imposed by this body in the resolution of this sanctioning procedure may be considered an administrative infraction pursuant to the provisions of the GDPR, classified as an infraction in Articles 83.5 and 83.6. Such conduct may lead to the opening of a subsequent administrative sanctioning procedure.

Please also remember that neither the acknowledgment of the infraction committed nor, where applicable, the voluntary payment of the proposed amounts exempts you from the obligation to adopt the relevant measures to cease the conduct or correct the effects of the infraction committed, nor from the obligation to prove compliance with this obligation to this AEPD.

Therefore, in light of the above, the President of the Spanish Data Protection Agency,
HAS RESOLVED:

FIRST: TO INITIATE SANCTIONING PROCEEDINGS against SILVANERGIA 2022, S.L.,
with Tax Identification Number (NIF) B72658313, for the alleged violation of Article 6.1 of the GDPR, as defined in Article 83.5 of the GDPR.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 16/20

SECOND: TO APPOINT B.B.B. as investigating officer and C.C.C. as secretary.
indicating that they may be challenged, if applicable, in accordance with the provisions of Articles 23 and 24 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector (LRJSP).

THIRD: INCORPORATE into the file, for evidentiary purposes, the claim filed by the complaining party and its documentation, as well as the documents obtained and generated by the Subdirectorate General of Data Inspection in the actions prior to the initiation of this sanctioning procedure.

FOURTH: THAT for the purposes provided for in Article 64.2 b) of the LPACAP Law, the sanction that may be applicable would be an administrative fine of €5,000.00, without prejudice to the results of the investigation.

FIFTH: NOTIFY this agreement to SILVANERGIA 2022, S.L., with Tax Identification Number (NIF) B72658313, granting it a hearing period of ten business days to formulate any allegations and present any evidence it deems appropriate. In its written allegations, it must provide its Tax Identification Number (NIF) and the procedure number shown in the heading of this document.

In accordance with the provisions of Article 85 of the LPACAP (Spanish Civil Code), it may acknowledge its liability within the period granted for the formulation of allegations to this initiation agreement; this will entail a 20% reduction in the appropriate penalty imposed in this procedure. With the application of this reduction, the penalty would be set at €4,000.00, and the procedure would be resolved with the imposition of this penalty.

Likewise, at any time prior to the resolution of this procedure, the applicant may voluntarily pay the proposed penalty, which will result in a 20% reduction in its amount. With the application of this reduction, the penalty would be set at €4,000.00, and its payment would terminate the procedure, without prejudice to the imposition of the corresponding measures.

The reduction for voluntary payment of the penalty is cumulative with the reduction applicable for acknowledgment of liability, provided that this acknowledgment of liability is made clear within the period granted for submitting allegations at the opening of the procedure. Voluntary payment of the amount referred to in the preceding paragraph may be made at any time prior to the resolution. In this case, if both reductions were to be applied, the penalty would be set at €3,000.00.

In any case, the effectiveness of either of the aforementioned reductions will be conditioned on the withdrawal or waiver of any administrative action or appeal against the penalty.

If you choose to voluntarily pay any of the amounts indicated above (€4,000.00 or €3,000.00), you must pay this amount by depositing it into account IBAN: ES00-0000-0000-0000-0000-0000
(BIC/SWIFT Code: CAIXESBBXXX) opened in the name of the Spanish Data Protection Agency at CAIXABANK, S.A., indicating in the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 17/20

item the reference number of the procedure that appears in the heading of this document and the reason for the reduction in the amount you are applying for.

Likewise, you must send proof of payment to the Subdirectorate General of Inspection to continue with the procedure in accordance with the amount paid.

In compliance with Articles 14, 41, and 43 of the LPACAP (Spanish Civil Code), you are advised that, from now on, notifications sent to you will be sent exclusively electronically, through the Single Authorized Electronic Address (dehu.redsara.es) and the Electronic Office (sedeaepd.gob.es). If you do not access them, your rejection will be recorded in the file, the procedure being considered complete, and the procedure will be followed. You are informed that you can provide this Agency with an email address to receive notifications that notifications are available and that failure to provide this notification will not prevent the notification from being considered fully valid.

Finally, it is noted that, pursuant to Article 112.1 of the LPACAP, no administrative appeal may be filed against this act.

110425-260325
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency

>>

SECOND: On June 4, 2025, SILVANERGIA proceeded to pay the fine of €3,000.00, making use of the two reductions provided for in the initiation agreement transcribed above, which implies acknowledgment of liability for the events referred to in the initiation agreement and its legal classification.

THIRD: The initiation agreement transcribed above indicated that, if the infringement was confirmed, it could be agreed that the controller would be required to adopt appropriate measures to bring its actions into compliance with the regulations mentioned in this act, in accordance with the provisions of the aforementioned Article 58.2 d) of the GDPR, according to which each supervisory authority may "order the controller or processor to ensure that processing operations comply with the provisions of this Regulation, where appropriate, in a specific manner and within a specified period...".

Having acknowledged responsibility for the infringement, the measures included in the initiation agreement may be imposed.

LEGAL BASIS

I
Jurisdiction

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 18/20

In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR) and as established in Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), the President of the Spanish Data Protection Agency is competent to resolve this procedure.

Likewise, Article 63.2 of the LOPDGDD establishes that: "The procedures

processed by the Spanish Data Protection Agency shall be governed by the provisions
of Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development, and, insofar as they do not contradict them, in a subsidiary capacity, by the general rules on administrative procedures."

II
Termination of the Procedure

Article 85 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), under the heading "Termination of Sanctioning Procedures," provides the following:

"1. Once a sanctioning procedure has been initiated, if the offender acknowledges responsibility, the procedure may be terminated with the imposition of the appropriate sanction.

2. When the sanction is solely monetary in nature, or when one monetary sanction and another non-monetary sanction may be imposed, but the inadmissibility of the second sanction has been justified, voluntary payment by the alleged offender, at any time prior to the resolution, will entail the termination of the procedure, except with regard to restoring the altered situation or determining compensation for damages caused by the commission of the offense. Infraction.

3. In both cases, when the penalty is solely monetary in nature, the competent body responsible for resolving the procedure shall apply reductions of at least 20% on the amount of the proposed penalty, which may be combined.
These reductions must be specified in the notification of initiation of the procedure, and their effectiveness shall be conditional on the withdrawal or waiver of any administrative action or appeal against the penalty.

The percentage reduction provided for in this section may be increased by regulation.

III
Voluntary payment and acknowledgment of liability

In accordance with the provisions of the aforementioned Article 85 of the LPACAP, the notified initiation agreement provided for the possibility of acknowledging liability and voluntarily paying the proposed penalty, which would entail two cumulative reductions of 20% each. With the application of these two reductions, the fine would be set at €3,000.00, and its payment would imply

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 19/20

the termination of the procedure, without prejudice to the imposition of the corresponding measures.

Following notification of the aforementioned initiation agreement, SILVANERGIA has proceeded to acknowledge liability and voluntarily pay the fine, availing itself of the two reductions provided for. In accordance with section 3 of Article 85 of the LPACAP (Spanish Civil Code), the effectiveness of the aforementioned reductions will be conditional on the withdrawal or waiver of any administrative action or appeal against the fine.

It should be noted that, in accordance with the provisions of the LPACAP, as well as the Supreme Court's jurisprudence on this matter, the exercise of voluntary payment by the alleged offender does not exempt the administration from the obligation to resolve and notify all proceedings, regardless of their form of initiation. Similarly, Article 88 of the aforementioned law establishes that the resolution that concludes the procedure will decide all issues raised by the interested parties and any other issues arising from it.

Therefore, in accordance with applicable legislation and having assessed the criteria for graduating sanctions, the Presidency of the Spanish Data Protection Agency RESOLVES:

FIRST: TO DECLARE the commission of the violations and CONFIRM the sanctions determined in the operative section of the initiation agreement transcribed in this resolution.

The sum of the aforementioned amounts results in a total of €5,000.00.

After SILVANERGIA 2022, S.L. has made prompt payment and acknowledged liability, pursuant to Article 85 of the LPACAP, a 40% reduction is made to the aforementioned total, resulting in the final amount of €3,000.00.

The effectiveness of the aforementioned reductions is subject, in all cases, to the withdrawal or waiver of any administrative action or appeal.

SECOND: DECLARE the termination of procedure EXP202313830, in accordance with the provisions of Article 85 of the LPACAP.

THIRD: ORDER SILVANERGIA 2022, S.L. so that within one month

of this resolution becoming final and enforceable, it shall notify the Agency of the adoption of the measures described in the legal grounds of the initiation agreement transcribed in this resolution.

FOURTH: NOTIFY this resolution to SILVANERGIA 2022, S.L.

FIFTH: In accordance with the provisions of Article 85 of the LPACAP (Spanish Organic Law on the Protection of Personal Data), which conditions the reduction for voluntary payment and acknowledgment of liability on the withdrawal or waiver of any action or appeal in administrative proceedings, this resolution will become final in administrative proceedings and fully enforceable upon notification.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 20/20

In accordance with the provisions of Article 50 of the LOPDGDD (Spanish Organic Law on the Protection of Personal Data), this resolution will be made public once it has been notified to the interested parties.

Against this resolution, which ends the administrative process as provided for in
art. 114.1.c) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, interested parties may file an administrative appeal before the Contentious-Administrative Division of the National Court, in accordance with the provisions of Article 25 and section 5 of the fourth additional provision of Law 29/1998, of July 13, regulating the Contentious-Administrative Jurisdiction, within two months from the day following notification of this act, as provided for in Article 46.1 of the aforementioned Law.

However, in accordance with the provisions of Article 90.3.a) of the LPACAP, the final administrative decision may be provisionally suspended if the interested party expresses their intention to file an administrative appeal. If this is the case, the interested party must formally notify this fact in writing to the Spanish Data Protection Agency, submitting it through the Agency's Electronic Registry [https://sedeaepd.gob.es/sede-electronica-web/], or through one of the other registries provided for in Article 16.4 of the aforementioned Law

39/2015, of October 1. They must also forward to the Agency the documentation proving the effective filing of the contentious-administrative appeal. If the
Agency does not become aware of the filing of the contentious-administrative appeal within two months from the day following notification of this resolution, it will terminate the precautionary suspension.

1259-260325
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
  1. This is a unique code in Spain that identifies the household or business receiving energy. More information can be found here: https://www.endesa.com/es/te-ayudamos/sobre-tu-factura/que-es-el-cups