AEPD (Spain) - EXP202314247

From GDPRhub
AEPD - EXP202314247
Authority: AEPD (Spain)
Jurisdiction: Spain
Relevant Law: Article 6(1) GDPR
20.1.c LOPDGDD
Type: Complaint
Outcome: Upheld
Started: 26.08.2023
Decided: 08.04.2025
Published:
Fine: 200,000 EUR
Parties: IBERDROLA CLIENTES, S.A.U
National Case Number/Name: EXP202314247
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Spanish
Spanish
Original Source: AEPD (original decision) (in ES)
AEPD (internal appeal) (in ES)
Initial Contributor: ap

The DPA dismissed the internal appeal of a utilities company and imposed a €200,000 fine for unlawfully transferring data on the data subject’s debt to a credit information agency without informing the data subject prior to the transfer.

English Summary

Facts

A data subject entered into a contract with IBERDROLA CLIENTES, S.A.U (a utilities company, the controller) in October 2022. The data subject decided to terminate the contract early in December 2022. This came with a penalty of 114 euros in total, which the controller informed the data subject by mail. The payment request was issued on 1 March 2023, however, it was not sent by the post service until 14 March 2023. The controller requested ASNEF (a credit information agency) to include the information on the data subject’s debt on 27 March 2023. This was done despite the fact that the data subject had not received the payment request. The data was included in the ASNEF’s delinquency file on 28 March.

The data subject presented a complaint to the DPA on 26 August 2023. According to the data subject, the controller transferred data related to an outstanding debt to ASNEF without their knowledge. This was because the data subject was unaware of the debt and that their data would be included in a credit information agency system. The controller argued that the data subject was sufficiently informed, since the contract stated the possibility of transferring data to a credit information agency in cases of nonpayment. The request for payment also stated this possibility.

The DPA imposed a €200,000 fine on the controller on 8 April 2025, and the controller filed an internal appeal on 20 May 2025.

Holding

The DPA dismissed the internal appeal on the basis that the deadline to file the appeal had already passed.

In its initial decision, the DPA stated that the data transfer to the credit reference agency was unlawful under Article 6(1) GDPR. National law (Article 20 of the Spanish Data Protection Act) allows data processing by credit information agencies related to unfulfilled financial obligations. This processing, however, must meet specific conditions, and process data in line with the GDPR.

While the payment request was issued by the controller on 1 March, the national post service did not accept the shipment until 10 March. This was one day before the payment deadline (11 March). The post service did not send the payment request until 14 March. The DPA stated that the controller should have considered the time needed to deliver the payment request and pay the penalty. Furthermore, the controller transferred the data before receiving confirmation that the post service had not delivered the payment request. According to the DPA, the controller had not fulfilled its obligations of informing the data subject on the possibility of their data being included in credit information agency systems. This was the case despite the DPA acknowledging that the contract stated the possibility of transferring data to a credit information agency in cases of nonpayment. With this, the DPA considered the processing unlawful under Article 20(1)(c) of the Spanish Data Protection Act and Article 6(1) GDPR.

The DPA upheld the €200,000 fine and ordered the controller to adapt its processing operations to the applicable data protection law. The DPA considered this a serious violation of the data subject’s rights, as their data was included in a credit information agency system without allowing them to settle the debt first. Lawfulness of processing is also a principle of data protection under the GDPR. Finally, the DPA stated that the controller must ensure an adequate level of diligence when processing data.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.

1/18

 File No.: EXP202314247

SANCTIONING PROCEDURE RESOLUTION

From the procedure initiated by the Spanish Data Protection Agency and based on the following

BACKGROUND

FIRST: A.A.A. (hereinafter, the complainant) filed a complaint with the Spanish Data Protection Agency on August 26, 2023. The complaint is directed against IBERDROLA CLIENTES, S.A.U. with Tax Identification Number (NIF) A95758389 (hereinafter, the respondent). The grounds for the claim are as follows: the

claimant states that his personal data is registered in common credit reporting systems at the request of the defendant for a debt with which he disagrees, and for which he has never been required to pay or informed
about the possibility of his data being included in these systems.

He attaches with his claim an ASNEF report dated March 28, 2023,
which includes his data at the request of the defendant, and emails exchanged with the defendant.

SECOND: In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), this complaint was forwarded to the respondent so that it could analyze it and inform this Agency within one month of the actions taken to comply with the requirements set forth in the data protection regulations.

The transfer, which was carried out in accordance with the regulations established in Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), was received on October 18, 2023, as recorded in the acknowledgment of receipt included in the file.

The respondent responded, stating that the inclusion of the data in the ASNEF file was legitimate; That on January 2, 2023, the respondent was notified of the claim filed by the current claimant regarding his gas and electricity contracts, stating that he did not agree with the amounts charged. The claim was answered by the respondent; on February 6, 2023, a negative credit invoice was issued for the amount of €-53.09, in order to cancel the invoice dated January 25, 2023, for €53.09, which was the subject of the claim. However, due to a system error, this amount was not offset against the amount owed by the claimant, but was instead directly credited to the claimant's bank account through a deposit. Therefore, the payment request for the amount remained valid; that since the payment was not made, his data was communicated to the ASNEF (Spanish Association of Delinquency Funds) delinquency file after the aforementioned request had been made; That
for the same matter, a consumer complaint was received from the Community of Madrid, responding on 10/11/2023 that the inclusion in the ASNEF file occurred because more than a month had passed since the invoice payment deadline, without any payment having been made.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 2/18

THIRD: On 11/26/2023, in accordance with Article 65 of the LOPDGDD (Spanish Data Protection Act),
the complaint filed by the complainant was admitted for processing.

FOURTH: On April 8, 2024, the Director of the Spanish Data Protection Agency agreed to initiate sanctioning proceedings against the respondent for the alleged violation of Article 6.1 of the GDPR, as defined in Article 83.5.a) of the GDPR.

FIFTH: After receiving notification of the initiation agreement, the respondent requested an extension of the deadline for submissions; this was extended to another five days by means of a letter from the investigating judge dated May 3, 2024.

The respondent submitted a written statement of allegations dated May 8, 2024, stating in summary: that both parties signed a gas supply contract on October 19, 2022; On December 31, 2022, the complainant stated that he did not agree with the maintenance package and requested its cancellation. Likewise, the change of supplier was agreed upon. However, he was informed of the penalties for early cancellations and, for this reason, invoices were sent to him for both items. He was also sent a payment request for the unpaid invoices, indicating the consequences of non-payment, including the possibility of reporting the debt to the ASNEF (Spanish Association of Delinquency Funds) database. Following inclusion in the database, the complainant received a complaint, which was answered by the respondent, informing him of the purpose of the outstanding invoices. that
the defendant was entitled to claim the debt owed since, in accordance with Article 20 of the LOPDGDD, the requirements established for this presumption of legality were met, this processing being annexed to the contract and necessary for its execution, requesting the closing of the file.

SIXTH: On May 22, 2024, the investigating judge agreed to open a period for the collection of evidence, agreeing to the following:

- To reproduce for evidentiary purposes the claim filed by the claimant and its documentation, the documents obtained and generated by the Inspection Services that are part of the file.
- To reproduce for evidentiary purposes the allegations to the initiation agreement presented by the defendant and the accompanying documentation.

SEVENTH: On October 30, 2024, a Resolution Proposal was issued by the Director of the Spanish Data Protection Agency (AEP) ordering the respondent to sanction the respondent for a violation of Article 6.1 of the GDPR, as defined in Article 83.5.a) of the GDPR, with a fine of €200,000 (two hundred thousand euros).

On December 17, 2024, the respondent submitted a statement of allegations in which it indicated that it had informed the complainant that, in the event of non-payment, it would include the data in the ASNEF file in different ways: in the gas supply contract signed by both parties, where this possibility is included in Clause 7; by email, using the invoices issued and found to be unpaid, and through the payment request issued on March 14, 2024, which has been submitted to the file, demonstrating that the legitimacy established by Article 20.1 c) of the LOPDGDD has been fully established by complying with the requirements set forth therein.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 3/18

the same; as for the postal notification of the payment request, it was rejected at the destination; that is, it was not due to a delivery error, but rather because the person who was supposed to receive it refused to accept the corresponding certificate, as stated in the acknowledgment.

EIGHTH: From the actions taken in this proceeding, the following have been established:

PROVEN FACTS

FIRST. On August 26, 2023, the complainant filed a letter with the Spanish Data Protection Agency (AEPD) stating that his personal data was registered in common credit reporting systems at the request of the defendant for a debt with which he disagrees, and that he has never been required to pay or informed of the possibility of including his data in these systems.

SECOND. The gas supply contract No. ***REFERENCE.1 signed between the defendant and the claimant is provided.

THIRD. An ASNEF document dated March 28, 2023, is provided, stating:

We inform you that on March 27, 2023, the respondent requested the following personal data to be registered in the ASNEF file regarding the non-payment of the contract with said entity:

PRODUCT UNPAID AMOUNT QUALITY
ELECTRICITY GAS 113.89 DEBTOR

FOURTH. The following emails have been exchanged between the complainant and the respondent regarding the alleged events:

Sent: 04/10/2023
Subject: Inclusion in ASNEF:

“(…)

I recently received a notification from ASNEF requesting that I be included in said file at your request.
I would appreciate it if you could inform me of the amount you are claiming from me, for what reason, and when you notified me of the mandatory notification prior to inclusion in said file.

(…)”

Response from the respondent:

“(…)
Following your instructions, I am attaching the outstanding invoices for the gas contract
***REFERENCE.1. I have marked in red the invoice for which you have been included in the ASNEF files. The last notification for payment of said invoice was sent to you on 03/01/2023, indicating that the last date for The payment was due
on 03/11/2023:

Date Fac. Amount Balance Status
01/25/2023 53.09 53.09 113. Pending, Not direct debited, Demand letter sent
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 4/18

01/31/2023 60.80 60.80 123. Pending. Direct debited, Demand letter sent
I also detail the outstanding bills for the electricity contract ***REFERENCE.2:

Date Fac. Amount Balance Status
11/10/2022 1.53 5.27 126 Pending, Direct debited, Manual resubmission

For payment, I can send you the link you provided via SMS/email. In this case,
I would appreciate it if you could provide the phone number or email address where I can send it. This way,
you will receive a link that you will need to click and will take you to a screen where
the completed information will appear. You would need to choose the payment method (Bizum/Card) and

Enter your credit card details (card number/expiration date and CVV).
(…)”

Complainant:

“I need you to attach the invoices and provide me with the shipment tracking number with the communication.”

Respondent:

“Thank you again for your message. I am forwarding the outstanding invoices requested.

If you don't find them in your inbox, please check your spam or junk mail.

Regarding the tracking number, we don't have that information. You would have to contact ASNE directly to obtain it.”

Complainant:

“It is required by law that if Iberdrola is going to include me in the defaulters' file, they notify me by certified mail (certified mail or fax). I need those tracking numbers, otherwise I could claim damages for their inclusion."

FIFTH. The defendant has provided a payment request, dated
03/01/2023, with code ***REFERENCE.3, sent to the claimant, which states:

"(...)
We hereby notify you of the request for payment of the debt you owe of 113.89 euros, arising from outstanding invoices for the gas supply contracted with

***REFERENCE.1 that you have signed with us at ***ADDRESS.1:
(...)
What happens if the non-payment persists after March 11, 2023?
Since the due date of the unpaid invoice, late payment interest and additional collection fees have begun to accrue.

" The debt may be reported to the ASNEF bad debt file managed by ASNEF
EQUIFAX SERVICIOS DE INFORMACION SOBRE SOLVENCIA Y CREDITO SL -
N.I.F.: B82064833.

We will be forced to initiate legal action to recover the debt.
(…)”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 5/18

SIXTH. There is a Certificate of Impossibility of Delivery, dated 04/03/2023,
issued by Correos, which states that:

“(…)
Correos CERTIFIES that, according to the Information System

Your shipment ***REFERENCE.3, accepted on 03/10/2023
To: the claimant
(…)
Has been Returned to Origin due to surplus (not collected at the office) on 04/03/2023 at 08:21
By the employee…

Delivery management by the Unit…
First delivery attempt on 03/14/2023 at 12:13…”

SEVENTH. The contract provided states the following regarding the maintenance package:

GAS MAINTENANCE PACK
(…)
The duration of the GAS MAINTENANCE PACK will be one (1) year, automatically renewable for consecutive annual periods unless the CUSTOMER notifies the CUSTOMER otherwise fifteen (15) days prior to the end of each period.

(…)
Early termination of the GAS MAINTENANCE PACK by the CUSTOMER before the end of each annual service provision period will oblige the CUSTOMER to pay the price established for the entire current annual period that has not yet been paid, while maintaining the right to use the service during that period.

(…)
Monthly price: €8.95 (VAT not included). This price will be automatically updated on January 1 of each year the contract is in force, with the corresponding variation in the CPI (1)
(…)”

EIGHTH. The contract provided states the following regarding its duration:

CONTRACT DURATION
Contract end date: 5/16/2023.
The start date is subject to the existence of an access contract with the distributor and to any action taken on the facilities when necessary. This will be the first day of the established reading period, which will be indicated on the first invoice.
The contract may be extended for successive years in accordance with the General Conditions.

In the event of termination due to unilateral withdrawal by either party during the first year of the contract, the withdrawing party must pay the other a penalty of €0.40 per day remaining on the contract.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 6/18

NINTH. Invoice No. ***REFERENCE 4, dated January 31, 2023, is provided for the early termination penalty of €60.80.

TENTH. Invoice No. ***REFERENCE 5, dated January 25, 2023, is provided for the Gas Maintenance Service Regularization of Maintenance Fees for Early Termination of the Gas Service, amounting to €53.09.

LEGAL BASIS

I
Jurisdiction

In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (the General Data Protection Regulation, hereinafter GDPR), and as established in Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), the President of the Spanish Data Protection Agency is competent to resolve this procedure.

Likewise, Article 63.2 of the LOPDGDD establishes that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development, and, insofar as they do not contradict them, in a subsidiary capacity, by the general rules on administrative procedures."

II

Allegations to the Proposed Resolution

The respondent party, in its written submission, states that it not only informed the complainant of the possible consequences arising from a default in the contract signed between the parties, but that the complainant was also notified of the invoices containing the outstanding amounts.

The complainant was notified of these invoices via email, with details provided through a direct link to its Customer Area.

Additionally, in addition to the above, a payment request was issued on March 14, 2024. This document includes the outstanding amount and reiterates that, in the event of non-payment, your information may be communicated to the ASNEF (National Association of Financial Institutions) delinquency file. This notification also fully complies with the obligation to inform the interested party about the possibility of inclusion in a credit information file, thus ensuring the transfer of the debt in the process. It is true, as stated by the respondent, that the contract signed by both parties with reference number ***REFERENCE.1, for the supply of gas and the service called "Gas Maintenance Pack," includes in clause 7 both the consultation and the communication of data to files known as bad debt files in the event of non-payment: "IBERDROLA may consult financial solvency and credit files to assess the Customer's financial solvency and, based on these consultations, make decisions that affect them. It may make the entry into force of the Contract or its validity conditional on the provision of a payment guarantee. However, IBERDROLA will always grant the Customer the opportunity to allege anything it deems relevant in order to defend its right or interest. In the event of non-payment, IBERDROLA may notify the Customer of the non-payment. to said files, in compliance with current legislation."

It is also true that via email dated April 10, 2023,
after the payment request was sent, in response to the complainant's request for information regarding ASNEF's communication regarding the inclusion of their data in the file, the complainant was sent invoices
No. ***REFERENCE.4, dated January 31, 2023, for an early termination penalty of €60.80, and No. ***REFERENCE.5, dated January 25, 2023, for maintenance fees for early termination of the Gas Service, amounting to €53.09.

Finally, there is the payment request, dated March 1, 2023, with code
***REFERENCE.3, sent to the claimant. This attempt is to notify the claimant of the non-payment of the debt incurred in the amount of €113.89, arising from previous invoices, pending payment. It also states that in the event of non-payment, the debt may be reported to the ASNEF (Association of Financial Institutions) delinquency file and legal action may be initiated to recover the debt.

In response to these allegations, it should be noted that the facts presented regarding the postal notification of the payment request have not been refuted by the respondent, despite statements made to the effect that, given that the payment request was unsuccessful and with the intention of not misleading the complainant, the complainant was informed of the outstanding invoices via email dated April 10, 2023, that is, after the invoice was included in the file.

Article 20.1.c) of the LOPDGDD (Spanish Data Protection Act) mentions a prior payment request, not the delivery of invoices, as one of the requirements for inclusion.

As reported in the Resolution Proposal, the respondent has provided the Certification of Impossibility of Delivery, dated April 3, 2023, issued by the Postal Service, which stated:

“(…)
Correos CERTIFIES that, according to the Information System,
Your shipment ***REFERENCE.3, accepted on March 10, 2023
To: the complainant

(…)
Returned to Origin due to surplus (not collected at the office) on April 3, 2023 at 8:21 AM
By employee 379964, with the following associated information:
Delivery management by Unit…

1st Delivery attempt on March 14, 2023 at 12:13 PM by employee 379964,
resulted in 07. No one takes responsibility.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 8/18

The payment order was issued on March 1, 2023, but was not accepted for delivery by the Postal Service until March 10, 2023. It also stated that:

What happens if the non-payment persists after March 11, 2023?
From the due date of the unpaid invoice, late payment interest and additional collection fees have begun to accrue.The debt may be reported to the ASNEF bad debt file managed by ASNEF EQUIFAX SOLVENCY AND CREDIT INFORMATION SERVICES SL - Tax ID No.: B82064833.
We will be forced to initiate legal action to collect the debt.

The first delivery attempt was made on March 14, 2023, but was unsuccessful. Therefore, a notice is left so that the communication can be collected from the post office, where it will remain until it is returned to its origin on April 3, 2023.

However, the respondent requested registration with ASNEF on March 27, 2023, without the complainant having received the payment request and without the Post Office having returned to Origin due to a surplus (not collected from the post office) on April 3, 2023, the Certification of impossibility of delivery of the payment request with code

***REFERENCE.3; Therefore, as indicated in the Proposal, it was not considered appropriate and pertinent, but rather the opposite, to issue a demand for non-payment of the debt on a specific date, March 1, 2023, deposit it with the postal service for delivery to the claimant on March 10, 2023, informing them that if the non-payment persisted on the day following its deposit at the post office for forwarding (March 11, 2023), the debt would be reported to the ASNEF-EQUIFAX delinquency file and they would be required to take legal action to recover it.

Furthermore, the data was included in the file on March 27, 2023, without the claimant having received the payment demand and prior to the return of the demand to the source on April 3, 2023 by the Post Office.

Therefore, it follows that it has not been proven that the respondent has complied with each of the requirements established in Article 20.1 of the LOPDGDD, which constitutes a violation of the obligation to have a lawful basis for the processing of personal data, as provided for in Article 6.1 of the GDPR.

Therefore, the allegations made by the respondent cannot be admissible.

III

Breached obligation: violation of Article 6.1 of the GDPR

The facts complained of materialize in the inclusion of the complaining party's personal data in common credit reporting systems at the request of the respondent, in relation to a debt linked to a gas contract.

The complaining party disagrees with this debt, stating that payment has not been requested prior to inclusion in the aforementioned files, which could constitute a violation of personal data protection regulations.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 9/18

Article 6 of the GDPR, Lawfulness of Processing, establishes in its section 1 that:

“1. Processing shall only be lawful if at least one of the following conditions is met:

a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;

b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

c) processing is necessary for compliance with a legal obligation to which the controller is subject;

d) processing is necessary to protect the vital interests of the data subject or of another natural person;

e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

f) processing is necessary for the purposes of the legitimate interests pursued by the data subject. the controller or a third party, provided that

such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data,
in particular where the data subject is a child.

The provisions of point (f) of the first paragraph shall not apply to

processing carried out by public authorities in the exercise of their duties."

Furthermore, Article 4 of the GDPR, Definitions, in paragraphs 1, 2, and 11, states that:

“1) “personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is any person whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person;

“2) “processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, Deletion or destruction;

“11) “consent of the data subject” means any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she accepts, whether by a statement or by a clear affirmative action, the processing of personal data relating to him or her.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 10/18

And Article 20 of the LOPDGDD, Credit Information Systems, establishes that:

“1. Unless proven otherwise, the processing of personal data related to the breach of monetary, financial, or credit obligations by common credit information systems shall be presumed lawful when the following requirements are met:

a) That the data has been provided by the creditor or by someone acting on its behalf or in its interest.

b) That the data relates to certain, due, and payable debts, the existence or amount of which has not been the subject of an administrative or judicial claim by the debtor or through an alternative dispute resolution procedure binding between the parties.

c) That the creditor has informed the affected party in the contract or at the time of requesting payment about the possibility of inclusion in said systems,
indicating those in which it participates.
The entity that maintains the credit information system with data
relating to non-compliance with monetary, financial, or credit obligations
must notify the affected party of the inclusion of such data and inform them of the

possibility of exercising the rights established in Articles 15 to 22 of
Regulation (EU) 2016/679 within thirty days of
notification of the debt to the system, the data remaining blocked
during this period.
d) That the data will only be kept in the system while the

non-compliance persists, with a maximum limit of five years from the due date
of the monetary, financial, or credit obligation.
e) That the data referring to a specific debtor may only be
consulted when the person consulting the system maintains a contractual relationship
with the affected party that involves the payment of a monetary amount or

the affected party has requested the conclusion of a contract that involves financing, deferred payment, or periodic billing, such as This occurs, among other cases, in those provided for in the legislation on consumer credit contracts and real estate credit contracts.
When the right to restrict the processing of data has been exercised through the system, challenging its accuracy in accordance with the provisions of

Article 18.1.a) of Regulation (EU) 2016/679, the system will inform those who may consult it in accordance with the previous paragraph of the mere existence of this circumstance, without providing the specific data for which the right has been exercised, while the request from the data subject is being resolved.

f) That, in the event that the request to conclude the contract is denied,
or the contract is not concluded, as a result of the consultation carried out,
whoever consulted the system will inform the data subject of the result of said consultation.

2. The entities that maintain the system and the creditors, with respect to the processing of data relating to their debtors, will have the status of joint controllers. of the data, with the provisions of
Article 26 of Regulation (EU) 2016/679 applying.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 11/18

The creditor shall be responsible for ensuring that the requirements for inclusion in the debt system are met, and shall be liable for any non-existence or inaccuracy.

       3. The presumption referred to in paragraph 1 of this article does not cover cases in which the credit information is associated by the entity maintaining the system with information additional to that contemplated in said paragraph, related to the debtor and obtained from other sources, in order to carry out profiling of the debtor, in particular through the application of credit rating techniques.

1. It should be noted that data processing requires a legal basis.

In accordance with Article 6.1 of the GDPR, in addition to consent, there are other possible bases that legitimize data processing without the need for the data subject's authorization, in particular, when it is necessary for the performance of a contract to which the data subject is a party or for the implementation, at the request of the data subject, of pre-contractual measures, or when it is necessary for the satisfaction of legitimate interests pursued by the data controller or by a Third, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject that require protection of such data. Processing is also considered lawful when it is necessary for compliance with a legal obligation applicable to the data controller, to protect the vital interests of the data subject or another natural person, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller.

In the present case, the initiation agreement considered that the respondent had violated Article 6.1 of the GDPR, as the unlawfulness of the processing carried out, the inclusion of the complainant's data in common credit reporting systems, and there being no proven basis for legitimacy contained in the aforementioned article in relation to the processing carried out.

2. The respondent, in a letter dated December 23, 2023, stated that both The parties
signed gas supply contract No. ***REFERENCE.1; the aforementioned contract resulted in a debt linked to two items: a penalty for early termination of the gas contract, in the amount of €53.09, and a penalty for early termination of the Gas Maintenance Package and its corresponding regularization, in the amount of €60.80. Adding both items together, the debt amounts to €113.89. This debt was included in the so-called bad debtor files.

The unpaid invoices are listed: invoice No. ***REFERENCE.4, dated January 31, 2023, for a penalty for early termination in the amount of €60.80, and invoice No. ***REFERENCE.5, dated January 25, 2023, for the Gas Maintenance Service Regularization of Maintenance Fees for Early Termination of the Service. Gas for an amount of 53.09 euros.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 12/18

Furthermore, a notification from the ASNEF file, dated 03/28/2023, addressed to the complainant, indicates that the respondent has requested registration of their data in the ASNEF file as a result of non-payment of a debt they owe

to the complainant, amounting to 113.89 euros.

The respondent has provided the payment request, dated 03/01/2023, code ***REFERENCE.3, sent to the complainant,

“(…)

We hereby notify you of the request for payment of the debt you owe of 113.89 euros, arising from outstanding invoices for the gas supply under contract ***REFERENCE.1 that you have signed with us in ***ADDRESS.1:
(…)

The Certification of Impossibility of Delivery, dated
04/03/2023, issued by the Postal Service, is also provided, stating:

“(…)
Correos CERTIFIES that, according to the Information System,
Your shipment ***REFERENCE.3, accepted on 03/10/2023

To: the complaining party
(…)
Has been Returned to Origin due to surplus (not collected at the office) on
04/03/2023 at 08:21
By the employee…

Delivery management by the Unit…
First delivery attempt on 03/14/2023 at 12:13…”

However, the payment request was issued on 03/01/2023, but was not accepted for delivery by the Postal Service until March 10, 2023, and,

for added clarity, it states:

What happens if the non-payment persists after March 11, 2023?
From the due date of the unpaid invoice, late payment interest and additional collection fees have begun to accrue.
The debt can be reported to the ASNEF bad debt file managed by

ASNEF EQUIFAX SERVICIOS DE INFORMACION SOBRE SOLVENCIA Y CREDITO
SL - N.I.F.: B82064833.
We will be forced to initiate legal action to collect the debt.

It is noted that the delivery attempt was made on March 14, 2023, apparently without any success.

Therefore, a notice is left so that the communication can be collected from the post office, where it will remain until it is returned to its origin on April 3, 2023.

However, the respondent requested registration in the ASNEF file on
March 27, 2023, without the claimant having received the payment request.

That is, the respondent should have considered all the circumstances that occurred, since it is not the most appropriate approach to issue a debt payment request on a specific date, deposit it with the postal service for delivery to the claimant, and inform the respondent that if the non-payment persists on the day following its deposit at the post office for forwarding, the debt will be transferred to the ASNEF default file and the petitioner will initiate legal action to recover the debt.

As indicated in the preceding paragraph, the data was accessed on March 27, 2023, without the claimant having received the payment order and the unpaid debt, and without taking into account the delivery time or payment deadline; furthermore, the file was accessed prior to the return of the order to the originator on April 3, 2023.

Therefore, it is considered that the respondent's conduct violates and has not complied with the requirement set forth in Article 20.1.c) of the LOPDGDD: "c) That the creditor has informed the affected party in the contract or at the time of requesting payment about the possibility of inclusion in said systems, indicating those in which it participates."

In light of the foregoing, it is concluded that the respondent has violated the regulations on personal data protection, Article 6.1 of the GDPR, in conjunction with Article 20.1 of the LOPDGDD, an infringement classified as set forth in Article 85.3 of the GDPR.

III
Classification of the violation of Article 6.1 of the GDPR

The violation attributed to the respondent is classified in

Article 83.5 a) of the GDPR, which considers that the violation of "the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9" is punishable, in accordance with section 5 of the aforementioned
Article 83 of the aforementioned Regulation, "with administrative fines of a maximum of €20,000,000 or, in the case of a company, an amount equivalent to a maximum of 4% of the total global annual turnover of the preceding financial year, whichever is higher."

Article 71 of the LOPDGDD (Organic Law on the Protection of Personal Data), entitled "Infractions," states that: "The acts and conduct referred to in sections 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law, constitute infringements." And in its Article 72, it considers, for the purposes of prescription, that they are: "Infractions considered very serious:

1. Based on the provisions of Article 83.5 of Regulation (EU) 2016/679, the following are considered very serious and will be subject to a three-year statute of limitations:
(…)

b) The processing of personal data without any of the conditions for the lawfulness of processing established in Article 6 of Regulation (EU) 2016/679.
(…)

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 14/18

IV
Proposed sanction for non-compliance with Article 6.1 of the GDPR

In order to establish the administrative fine to be imposed, the following must be observed: provisions contained in Articles 83.1 and 83.2 of the GDPR, which state:

“1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article for infringements of this Regulation referred to in paragraphs 4, 5, and 6 are, in each individual case, effective, proportionate, and dissuasive.

2. Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or as a substitute for the measures provided for in Article 58(2)(a) to (h) and (j).When deciding whether to impose an administrative fine and its amount in each individual case, due account shall be taken of:

a) the nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage suffered by them;

b) the intentionality or negligence of the infringement;

c) any measures taken by the controller or processor to mitigate the damage suffered by data subjects;

d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures they have implemented pursuant to Articles 25 and 32;

e) any previous infringements committed by the controller or processor;

f) the degree of cooperation with the supervisory authority in order to remedy the infringement and mitigate the possible adverse effects of the infringement;

g) the categories of personal data affected by the infringement; (h) the manner in which the supervisory authority became aware of the infringement, in particular whether the controller or processor notified the infringement and, if so, to what extent;

(i) where measures referred to in Article 58(2) have been previously ordered against the controller or processor concerned in relation to the same matter, compliance with those measures;

(j) adherence to codes of conduct pursuant to Article 40 or certification mechanisms approved pursuant to Article 42; and

(k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement.

In relation to letter k) of Article 83.2 of the GDPR, the LOPDGDD, in its

Article 76, "Sanctions and corrective measures," establishes that:

"2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 15/18

a) The continuous nature of the infringement.
b) The connection between the offender's activity and the processing of personal data.

c) The benefits obtained as a result of the commission of the infringement.
d) The possibility that the affected party's conduct could have induced the commission of the infringement.
e) The existence of a merger by absorption process subsequent to the commission of the infringement, which cannot be attributed to the acquiring entity.

f) The impact on the rights of minors.
g) Have, when not mandatory, a data protection officer.
h) Voluntary submission by the controller or processor to alternative dispute resolution mechanisms in those

cases where there are disputes between them and any interested party."

- In accordance with the transcribed provisions, for the purposes of setting the amount of the fine to be imposed in this case for the violation of Article 6.1 of the GDPR, classified in Article 83.5.a), for which the defendant is held responsible, the following factors are considered concurrent:

The nature and severity of the violation; The facts revealed
affect a basic principle regarding the processing of personal data,
such as the principle of legitimacy, which the law imposes with the utmost severity. The level of damages suffered by the complainant affects its financial solvency, as it was included in common credit reporting systems at the request of the respondent in relation to a debt, ignoring the requirements of
Article 20 of the LOPDGDD (General Data Protection Act), without giving it time to pay the debt (Article 83.2.a) of the GDPR).

The activity of the allegedly infringing entity is linked to the processing of personal data of both clients and third parties. The processing of personal data is essential to the activity of the entity under complaint. Therefore, given its business volume, the significance of the conduct that is the subject of this complaint is undeniable (Article 76.2.b) of the LOPDGDD in relation to Article 83.2.k).

The intentionality or negligence of the infringement is evident, as the defendant included the data in bad debt files without the debt meeting the requirements of Article 20 of the LOPDGDD. Also connected to the degree of diligence that the data controller is required to display in compliance with the obligations imposed by data protection regulations, we can cite the SAN of 17/10/2007. Although it was issued before the GDPR came into force, its ruling is perfectly applicable to the case we are analyzing. The ruling, after alluding to the fact that entities whose activities involve continuous processing of client and third-party data must observe an adequate level of diligence, specified that "(...) the Supreme Court has considered that negligence exists whenever a legal duty of care is disregarded, that is, when the offender does not behave with the required diligence. And in assessing the degree of diligence, the professionalism of the individual must be especially considered, and there is no doubt that, in the case under consideration, when the appellant's activity involves constant and extensive handling of personal data, rigor and exquisite care must be emphasized to comply with the legal provisions in this regard" (Article 83.2, b) of the GDPR).

In accordance with the foregoing, it is deemed appropriate to propose a fine of €200,000 for violation of Article 6.1 of the GDPR.

V
Applicable Measures

If the violation is confirmed, it could be agreed that the controller will be required to adopt appropriate measures to bring its actions into compliance with the aforementioned regulations.

In this act, in accordance with the provisions of the aforementioned Article 58.2 d) of the GDPR, according to which each supervisory authority may "order the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specified manner and within a specified period...". The imposition of this measure is compatible with the sanction consisting of an administrative fine, as provided for in Article 83.2 of the GDPR.

Therefore, it would be considered appropriate to order the respondent, within one month of the finality of the resolution issued, to adapt the processing operations subject to this procedure to the applicable regulations. The text of this agreement establishes the facts that led to the violation of data protection regulations, from which it is clearly inferred what measures to be adopted, without prejudice to the fact that the specific type of procedures, mechanisms, or instruments to implement them are the responsibility of the sanctioned party, as it is the party with full knowledge of its organization and must decide, based on proactive responsibility and a risk-based approach, how to comply with the GDPR and the LOPDGDD. Specifically, it must comply with the requirements of the data protection regulations, legitimizing the processing in accordance with the requirements set forth in Article 20 of the LOPDGDD.

Please be advised that failure to comply with the order imposed by this body may be considered an administrative violation pursuant to the provisions of the GDPR, classified as a violation in Articles 83.5 and 83.6, and such conduct may lead to the opening of a subsequent administrative sanctioning procedure.

Therefore, in accordance with applicable legislation and having assessed the criteria for graduating the sanctions whose existence has been proven,

The Presidency of the Spanish Data Protection Agency RESOLVES:

FIRST: TO IMPOSE on IBERDROLA CLIENTES, S.A.U., with NIF A95758389, for a violation of Article 6.1 of the GDPR, classified in Article 83.5.a) of the GDPR,

a fine of €200,000 (two hundred thousand euros).

SECOND: ORDER IBERDROLA CLIENTES, S.A.U., with Tax Identification Number (NIF) A95758389, pursuant to Article 58.2.d) of the GDPR, within one month of this

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 17/18

resolution becoming final and enforceable, to certify that it has taken appropriate measures to adapt the processing operations subject to this procedure to the applicable regulations.

THIRD: NOTIFY IBERDROLA CLIENTES, S.A.U. of this resolution.

FOURTH: This resolution will become enforceable once the deadline for filing an optional appeal for reconsideration expires (one month from the day following notification of this resolution) without the interested party having exercised this right.
The sanctioned party is hereby notified that they must pay the imposed sanction once this resolution becomes enforceable, in accordance with the provisions of Article 98.1.b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), within the voluntary payment period established in Article 68 of the General Collection Regulations, approved by Royal Decree 939/2005, of July 29, in relation to Article 68 of the General Tax Collection Regulations. 62 of Law 58/2003, of December 17, by depositing the fine, indicating the sanctioned party's NIF (Tax Identification Number) and the procedure number shown in the heading of this document, into the restricted account IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX), opened in the name of the Spanish Data Protection Agency at CAIXABANK, S.A. Otherwise, collection will be carried out during the enforcement period.

Once the notification has been received and enforced, if the enforcement date falls between the 1st and 15th of each month, inclusive, the deadline for making the voluntary payment will be the 20th of the following month or the next business day after, and if it falls between the 16th and last day of each month, inclusive, the payment deadline will be the 5th of the second following month or the next business day after.

In accordance with the provisions of Article 50 of the LOPDGDD (Organic Law on the Protection of Personal Data), this Resolution will be made public once it has been notified to the interested parties.

Against this resolution, which terminates the administrative process pursuant to Article 48.6 of the LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, interested parties may optionally file an appeal for reconsideration before the Presidency of the Spanish Data Protection Agency within one month from the day following notification of this resolution, or directly file an administrative appeal before the Administrative Litigation Division of the National Court, in accordance with the provisions of Article 25 and Section 5 of the Fourth Additional Provision of Law 29/1998, of July 13, regulating the Administrative Litigation Jurisdiction, within two months from the day following notification of this decision, as provided for in Article 46.1 of the aforementioned Law.

Finally, it is noted that pursuant to the provisions of Art. 90.3 a) of the LPACAP, a final administrative decision may be provisionally suspended

if the interested party expresses their intention to file an administrative appeal. If this is the case, the interested party must formally notify this fact in writing to the Spanish Data Protection Agency, submitting it through the Agency's Electronic Registry [https://sedeagpd.gob.es/sede-electronica-web/], or through one of the other

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 18/18

registries provided for in Article 16.4 of the aforementioned Law 39/2015, of October 1. They must also forward to the Agency the documentation proving the effective filing of the administrative appeal. If the Agency does not become aware of the filing of the administrative appeal within two months from the day following notification of this resolution, it will terminate the precautionary suspension.

Lorenzo Cotino Hueso

President of the Spanish Data Protection Agency

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es