AEPD (Spain) - EXP202318311
| AEPD - EXP202318311 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 5(1)(f) GDPR Article 28 GDPR |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | 17.10.2023 |
| Decided: | 04.09.2025 |
| Published: | 10.09.2025 |
| Fine: | 180,000 EUR |
| Parties: | SOCIEDAD DE GESTIÓN DE ACTIVOS PROCEDENTES DE LA REESTRUCTURACIÓN BANCARIA, S.A. |
| National Case Number/Name: | EXP202318311 |
| European Case Law Identifier: | n/a |
| Appeal: | Not appealed |
| Original Language(s): | Spanish |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | ap |
The DPA fined an asset management company €180,000 for failing to implement appropriate security measures in relation to a data breach affecting 360 employees, and for not establishing storage limitation periods in its contract with a processor.
English Summary
Facts
SOCIEDAD DE GESTIÓN DE ACTIVOS PROCEDENTES DE LA REESTRUCTURACIÓN BANCARIA, S.A. (also known as “Sareb”, the controller) is an asset management company. On 30 August 2023, STRATESYS TECHNOLOGY SOLUTIONS S.L. (a consulting company, the processor) notified a data breach to the DPA. The data breach happened to the processor, however, it affected approximately 360 employees of the controller.
The DPA began investigating after a data subject presented a complaint against the controller. The controller informed data subjects of the data breach. The controller argued that it was not the controller in this case, as its contract with the processor contained instructions on the processing of personal data.
Holding
The DPA first dismissed the controller’s argument, stating that it is the one determining the purposes and means of processing in accordance with Article 4(7) GDPR.
The DPA found a violation of Article 5(1)(f) GDPR, as the controller did not implement appropriate technical and organisational measures to ensure security of processing. In addition, the DPA noted that the contract between the controller and processor was vague, and contained only a series of objectives in terms of security rather than exact measures the processor should take.
The DPA also found a violation of Article 28 GDPR. The contract between the controller and processor did not include a storage period limitation. This meant the processor would store the data until the end of the contract. The DPA stated that, in accordance with Article 28(3) GDPR, the controller is responsible in ensuring that the contract complies with the GDPR.
The fine was initially set at €300,000 in total: €250,000 for the violation of Article 5(1)(f) GDPR, and €50,000 for the violation of Article 28 GDPR. The DPA considered it a serious violation, as it involved unauthorised access to data subjects’ ID information. According to the DPA, ID information is of sensitive nature, as it verifies a data subject’s identity. In addition, the DPA ordered the controller to implement appropriate security measures, as well as ensure the contract with its processor is compliant with the GDPR.
Pursuant to Law 39/2015, a Spanish law concerning administrative proceedings, the DPA informed the controller that it may make a voluntary payment of the proposed fine and waive their right to appeal. This action reduces the imposed fine by 20%. The fine can be reduced by a further 20% if the controller acknowledges its liability. The controller opted for both and reduced the fine by 40%, paying the reduced sanction amount of €180,000.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.
1/34
File No.: EXP202318311
RESOLUTION TERMINATING THE PROCEDURE FOR RECOGNITION OF LIABILITY AND VOLUNTARY PAYMENT
From the procedure initiated by the Spanish Data Protection Agency and based
on the following
BACKGROUND
FIRST: On July 9, 2025, the Presidency of the Spanish Data Protection Agency
agreed to initiate sanctioning proceedings against SOCIEDAD DE
GESTIÓN DE ACTIVOS PROCEDENTES DE LA REESTRUCTURACIÓN
BANCARIA, S.A. (hereinafter, SAREB), through the agreement transcribed below:
<<
File No.: EXP202318311
AGREEMENT TO INITIATE SANCTIONING PROCEDURE
TABLE OF CONTENTS
FACTS.......................................................................................................2
FIRST. Notification of STRATESYS breach......................................................2
SECOND. Notification of SAREB breach..............................................................3
THIRD: Complaint received..............................................................................3
FOURTH: Transfer of the complaint...................................................................4
FIFTH: Admission for processing......................................................................................4
SIXTH. Preliminary investigative actions against STRATESYS TECHNOLOGY SOLUTIONS S.L........................................................................................................4
1. Breach notifications to the AEPD.................................................................................4
2. Chronology of the events and causes that led to the breach....................................................7
3. Actions taken to minimize adverse effects and measures adopted for its final resolution.................................................................10
4. Technical and organizational measures adopted to prevent incidents such as the one that occurred.................................................................................................12
5. Forensic report prepared by ***COMPANY.1......................................................................13
6. Data affected........................................................................................................15
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 2/34
7. Data processor contract.................................................................................15
SEVENTH. Preliminary investigation actions against SAREB..................................16
1. Measures adopted by SAREB:..........................................................................17
2. Number of affected parties and type of data...........................................................18
3. Personal data retention period....................................................................19
EIGHTH: Turnover...................................................................................19
LEGAL BASIS......................................................................................20
I. Jurisdiction........................................................................................................20
II. Procedure........................................................................................................20
III. Preliminary issues........................................................................................20
1. General aspects of processing......................................................................20
2. Liability for infringements......................................................................21
IV. Breached obligation. Article 5.1.f) GDPR Integrity and Confidentiality..................22
1. Regulatory Regime and Breach...........................................................................22
2. Cause of the Breach...........................................................................................25
3. Types of Data Affected and Number of People......................................................25
4. Insufficient Measures to Ensure Confidentiality and Availability.......................................................................................................26
5. Conclusions.......................................................................................................29
V. Classification of the Violation of Article 5.1.f) GDPR and Qualification for the Purposes of the Limitation Period........................................................................................................29
VI. Proposed Sanction for Non-Compliance with Article 5.1.f) GDPR.................30
VII. Breached Obligation. Article 28 GDPR. Data Processor................................33
VIII. Classification of the violation of Article 28 of the GDPR and classification for the purposes of
limitation..............................................................................................................36
IX. Proposed sanction for non-compliance with Article 28 of the GDPR................................37
X. Corrective measures..........................................................................................38
IT IS AGREED:..........................................................................................................39
FIRST: Initiation of sanctioning proceedings....................................................39
SECOND: Appointment of investigating officer..............................................................39
THIRD: Incorporation of documentation into the file...................................40
FOURTH: Possible sanction...................................................................................40
FIFTH: Notification and period for submissions...................................................40
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 3/34
AGREEMENT TO INITIATE SANCTIONING PROCEDURE
Regarding the actions taken by the Spanish Data Protection Agency and
based on the following
FACTS
FIRST. STRATESYS Breach Notification
On August 30, 2023, this Agency was notified by the company
STRATESYS TECHNOLOGY SOLUTIONS S.L., with Tax ID No. B81866014 (hereinafter,
STRATESYS) of a personal data breach categorized as confidentiality and availability. The information provided was subsequently expanded through
a notification from the same company dated September 26, 2023. According to both documents, the company
had suffered a cyberattack that affected the confidentiality and availability
of personal data.
It is reported that as a result of the theft of STRATESYS information by ***PROGRAMA.1, the STRATESYS cybersecurity team has continuously monitored the deep web site where said ***PROGRAMA.1 has claimed responsibility for the attack, in order to detect as soon as possible the leak of the information that was stolen from our systems and to verify the type of information involved as quickly as possible. On Tuesday, September 26, 2023, STRATESYS gained access to the information (…). After analyzing this information, they discovered that it contains sensitive information about clients to whom STRATESYS provides services (…). Among the list of companies to which it provides services is SOCIEDAD DE GESTIÓN DE ACTIVOS PROCEDENTES DE LA REESTRUCTURACIÓN BANCARIA, S.A. with NIF
A86602158 (hereinafter, the respondent or SAREB).
SECOND. SAREB Breach Notification
On 10/6/2023, SAREB notified this Agency of a personal data breach categorized as confidentiality and availability. The
information provided was subsequently expanded by the same company's notification of 11/2/2023. According to both documents, on October 3, 2023, at 10:00, SAREB received notification from the supplier STRATESYS that a breach had occurred that affected (...).
This Agency would therefore be notified of the same breach suffered by STRATESYS, in which the latter would be the data processor and SAREB the data controller. The breach would have affected (...).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 4/34
THIRD: Complaint received
On October 17, 2023, a complaint was filed with the Spanish Data Protection Agency for a possible breach attributable to SAREB.
The complainant states that he/she (...) received an email in which the entity informed him/her that his/her personal data was linked to (...).
Along with the letter, a copy of the email notification of the existence of the breach, sent by SAREB, as the data controller, to the complainant, is provided.
FOURTH Transfer of the complaint
In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), this complaint was forwarded to both SAREB and STRATESYS so that they could analyze it and inform this Agency within one month of the actions taken to comply with the requirements set forth in the data protection regulations.
Both entities responded to the request for information on
January 25, 2024 and January 26, 2024, respectively.
FIFTH: Admission for processing
On January 17, 2024, in accordance with Article 65 of the LOPDGDD (Spanish Data Protection Act),
the claim was admitted for processing.
SIXTH. Preliminary investigation actions against STRATESYS
TECHNOLOGY SOLUTIONS S.L.
The Subdirectorate General for Data Inspection carried out preliminary investigative actions to clarify the facts in question, pursuant to the functions assigned to supervisory authorities in Article 57.1 and the powers granted in Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VIII of the LOPDGDD.
During these actions, the following entity was investigated: STRATESYS.
1. Notifications of the breach to the AEPD
a. Regarding the STRATESYS notification:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 5/34
The breach suffered by the provider STRATESYS was initially notified by this entity to the AEPD with a registration date of 08/30/23, and subsequently expanded with registration dates of 09/26/23 and 10/2/23.
This is a confidentiality and availability breach caused by the ransomware-type cyberincident that affected (…), acting as the data processor.
STRATESYS is a company that (…):
"(…)".
STRATESYS adds the following information in the breach notifications:
- (…).
- (…).
- (…).
- (…).
- (…).
- (…):
(…)
- (…)
In the last communication, STRATESYS states that it suspects that sensitive information containing the personal data of employees of its clients (companies and entities to which it provides services) has been stolen. Among them, SAREB.
a. Regarding the SAREB notification:
Regarding the SAREB breach, the breach was initially notified to the AEPD on 10/06/23 and subsequently expanded on 11/02/23. SAREB includes the following information in the breach communications:
- (…).
- (…).
- (…).
- (…).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 6/34
- (…).
- (…):
(…)
- (…)
- It states that they have reported the incident to the police authorities.
- It states that the affected individuals were informed on October 10, 2023, through a communication addressed personally to each affected person (postal, email, SMS, or similar).
- In the report provided with the second notification, SAREB states that,
according to public sources, (…) it has been disabled by Europol along with other
authorities and that as of the date the website was disabled, the link to download SAREB information had not been enabled.
- It indicates October 30, 2023, as the resolution date.
- Judging by the communication sent to the complaining party, the breach has
affected former employees who worked between November 2013 and
February 2017.
1. Chronology of the events and the causes that led to the breach.
As STRATESYS explains in its response to the request:
“• On August 24, 2023, (…);
• On August 27, 2023, (…);
• On August 28, 2023, at approximately 8:00 a.m. (…).
• On August 28, 2023, (…).
• After the initial investigation and analysis of the security incident, it was concluded that the incident had affected (…).
• On August 31, 2023, and in order to analyze the affected information, a company was contacted (…).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 7/34
• On September 4, 2023, with the assistance of the aforementioned data recovery expert company (…).
• Additionally, based on the investigations carried out, it has been concluded that
(…).
• As of now, the STRATESYS Cybersecurity Department
(…), detecting that:
• (…).
• (…).
• (…).
• (…).
• On September 29th, this company reported these new findings
to the AEPD as the data controller in the statement with Registration Number: (...).
• In the following days and after analyzing the information detected, all affected clients were notified, placing ourselves at their disposal to provide
support and assistance in any way they may require.
• On October 19th, 2023, INTERPOL dismantled the attackers' site
(…). (…).
• At no time was the download link for the information stolen from STRATESYS by the attackers enabled on its website. deep web, which makes it difficult
for third parties to access or download this information.”
STRATESYS acknowledges human error and (…):
“For the services provided to that client, the data was hosted on the (…).
[…]
(…).
[…]
(…).
(…).”
When asked why the information relating to SAREB employees was
stored on the file server of the (…) segment affected by
the cyberattack, STRATESYS again states that:
“(…).
(…).
2. Actions taken to minimize adverse effects and measures adopted for their final resolution
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 8/34
Regarding the actions taken to minimize adverse effects and the measures adopted for their final resolution, the respondent clarifies in its response
to the notification of the claim:
“(…):
• (…).
• (…).
• (…).
• (…).
• (…).
• (…).
• (…).
• (…).
• (…).
• (…).
It is noted that on August 28, 2023, STRATESYS notified the Civil Guard, INCIBE, and CCN-CERT of the incident via an email with the subject line: "Cyberattack by
(…)".
Regarding the security measures implemented,
(…).
After requesting confirmation of the existence of (…), the respondent states in its written response to the request for information:
“(…).
Following the incident, (…).”
(…)
“(…)”
(…).
(…):
(…).
For its part, document “***DOCUMENT.1” is dated 06/28/2023 and defines the
monitoring, hardening, user and password policies, etc. Specifically, it states for both servers and perimeter security:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 9/34
“(…).”
“(…).”
3. Technical and organizational measures adopted to prevent incidents such as the one that occurred.
In its response to the complaint, STRATESYS reports that “other additional guarantee and prevention measures have been taken to prevent a similar incident from occurring in the future, including the following:
• (…).
• (…).
• (…).
• (…).
• (…).
• (…).
• (…).
• (…).
4. Forensic report prepared by ***COMPANY.1
After requesting a copy of the forensic analysis performed after the breach, STRATESYS sent the report prepared by the external security firm ***COMPANY.1, "Technical Review of the Incident Response Process," prepared by ***COMPANY.1 in October 2023.
This document specifies the affected and recovered systems, as well as the affected infrastructure, the timeline of the attack, and the chronology of the actions taken.
The report concludes with the following:
"(…):
I. (…).
II. (…).
III. (…).
IV. (…).
V. (…)."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 10/34
***EMPRESA.1 includes a table in the report that, in addition to these conclusions, specifies the Strengths and Potential Improvements for each of the phases before and during the incident: Prevention, Detection, Analysis and Response, and
Recovery.
The following are specified as Potential Improvements:
1 (…).
2 (…).
3 (…).
4 (…).
5. Data Affected
STRATESYS indicates that 7,200 people were initially affected (estimated value), of which 360 people (estimated value) were SAREB employees.
▪ (…):
or (…).
or (…).
or (…).
▪ (…):
either (…).
or (…).
or (…).
or (…).
or (…).
6. Data Processor Contract
STRATESYS provides a copy of the data processor contract, with this entity acting
as the data processor and SAREB as the data controller, signed
by both entities on ***DATE.1. The contract acts as an Addendum (…). In
this contract, it is verified that the following are stated, among other aspects:
- (…).”
- (…)
[…]
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 11/34
(…)”
- “(…):
• (…).
• (…).
• (…).”
- “(…)”
- (…):
.- (…)
.- (…)
.- (…)
.- (…)
.- (…).
SEVENTH. Preliminary investigative actions against SAREB
The Subdirectorate General of Data Inspection proceeded, in addition to and as a
separate procedure from the previous actions, to carry out preliminary investigative actions to clarify the facts in question, pursuant to the
functions assigned to the supervisory authorities in Article 57.1 and the powers
granted in Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of
Title VIII of the LOPDGDD.
During these proceedings, the entity SAREB was investigated.
Regarding aspects related to the breach, the chronology
of the events, and the measures taken prior to and following the breach, SAREB is transmitting substantially the same information as that provided in the preliminary investigations to STRATESYS. The following summarizes the aspects of interest resulting from these preliminary investigations with SAREB.
SAREB provides a detailed account of all meetings and contacts held with STRATESYS to determine the causes and scope of the personal data breach.
1. Measures taken by SAREB:
“• (…).
• (…).”
Regarding the possible publication of the exfiltrated data:
(…)
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 12/34
(…)
(…):
• (…).
It also carried out the following:
(…).
(…).
(…).
(…).
(…):
- (…).
- (…).
- (…).”
1. Number of affected parties and type of data
SAREB reports that “(…).”
Regarding the categories of Personal Data affected, the respondent
specifies in its response to the notification of the complaint:
“(…):
(…)
(…):
• (…).
• (…).
• (…).”
(…).
2. Personal Data Retention Period
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 13/34
After being asked to explain the reason why the complainant's data is being retained years after the end of their contractual relationship, the respondent states in their response to the request for information:
“In accordance with Organic Law 7/2012, of December 27, which modifies Organic Law 10/1995, of November 23, of the Criminal Code regarding transparency and the fight against tax and Social Security fraud, and General Tax Law 58/2003, of December 17, the statute of limitations for crimes against Social Security and the Public Treasury is 10 years, which implies an obligation to retain the data.
used to calculate social security contributions and salary withholdings
during said period, in order to guarantee their availability for the accreditation
of tax or social security obligations if required by the Public Treasury
and Social Security, thus contributing to the prevention and
detection of potential violations."
In that same document, SAREB clarifies:
"There should be no confusion between the Complainant's data present in SAREB's information
systems (subject to the right of access exercised) and the data
affected by the data processor's personal data breach, which are limited to
those to which STRATESYS had access on behalf of and in the name of
SAREB, as necessary for the provision of the service performed by
this provider. The volume of the latter is much smaller than that of
the former, and the confidentiality of much of
this information has not been compromised due to the incident suffered by STRATESYS."
EIGHTH: Turnover
According to the report compiled by the AXESOR tool, SAREB is a company with (...) and a turnover of €2,118,629,000 in 2023.
LEGAL BASIS
I. Jurisdiction
In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679
(General Data Protection Regulation, hereinafter GDPR) and as established in Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), the President of the Spanish Agency for the Protection of Personal Data is competent to initiate and resolve this procedure. Data.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 14/34
II. Procedure
Likewise, Article 63.2 of the LOPDGDD establishes that: “The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development and, insofar as they do not contradict them, in a subsidiary manner, by the general rules on administrative procedures.”
In accordance with Article 64 of the LOPDGDD, and taking into account the characteristics of the alleged violations committed, a sanctioning procedure is initiated.
The procedure will last a maximum of twelve months from the date of the initiation agreement. After this period, it will expire and, consequently, the archiving of proceedings, in accordance with the provisions of
Article 64 of the LOPDGDD (General Data Protection Act).
If no objections are made to this initial agreement within the stipulated period, it may be considered a proposed resolution, as established in Article
64.2.f) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP).
III. Preliminary Questions
1. General Aspects of Processing
Article 4.1) of the GDPR defines "personal data" as: "any information relating to an identified or identifiable natural person ("the data subject"); An identifiable natural person is any person whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.
Article 4(2) of the GDPR defines "processing" as: "any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization,
structuring, storage, adaptation or alteration, retrieval, consultation,
use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction."
Article 4.7 of the GDPR defines the "controller" or "data controller" as: "the natural or legal person, public authority, agency or other body which,
alone or jointly with others, determines the purposes and means of the processing; If Union or Member State law determines the purposes and means of processing, the controller or the specific criteria for its appointment may be laid down by Union or Member State law.” In turn, Article 4.8 of the GDPR defines the “processor” or “processor” as the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 15/34
natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.
1. Liability for infringements
In the present case, in accordance with the provisions of Articles 4.1 and 4.2 of the GDPR,
it is established that personal data are being processed, since SAREB
carries out, among other processing operations, the collection and storage of personal data of natural persons, including data (…).
SAREB carries out this activity in its capacity as data controller, given that it determines the purposes and means of such activity pursuant to Article 4.7 of the GDPR. For its part, STRATESYS is considered the data processor, for which purposes both said company and SAREB have provided (…).
In both the notifications regarding the breach and its responses to the information requests of this Agency's Inspection, SAREB defends its
absence of liability for the events that occurred based on two
factors. On the one hand, (...). On the other hand, it alleges that it had entered into the appropriate
personal data processing contract with said company. It
would contain the instructions to the data processor regarding said processing.
In the current case, according to the information provided by SAREB, the
services entrusted to the data processor would be those of (...).
The existence of a data processor depends on a decision made by
the data controller, who may decide to carry out certain processing operations itself or contract all or part of the processing to a
data processor.
That is to say, the data processor, in order to be such, does not have any personal interest in the
result of the processing entrusted to it, without prejudice to the financial compensation it receives for the service provided, which is what occurs in the present case. Data processors have no personal interest; they act on behalf of and in the name of the controller, carrying out its orders and for its purposes, and this is what
determines their status as data processors from the outset.
This determines that the data controller is liable for actions contrary
to the GDPR carried out by its data processors, unless the latter acted as actual data controllers, deciding
on the purposes and means of the processing, as provided for in Article 28, Section 10, of the GDPR, an issue that did not arise in the present case.
Upon analyzing the data processing contract provided by SAREB, it is observed that it is limited to containing a series of general provisions related to the aforementioned processing. As an example, regarding the security measures that must be established by the data processor, the contract summarizes a series of objectives, rather than specific measures (guaranteeing confidentiality, adopting technical and organizational measures taking into account risks, and adopting all other technical, legal, and organizational measures that the data controller may inform you of, in accordance with the risk analysis it carries out, which are necessary to guarantee an adequate level of security). However, no specific measures are included, nor have the data controller provided any instructions that, in the execution of the contract, it has given to the data processor. Furthermore, although the contract for the processing of data reflects the possibility that the data controller may conduct audits of the processor's compliance, the data controller has not provided any information regarding this aspect. Therefore, the indications suggest that the data controller merely formally imposed the obligations in the contract, without monitoring whether they were actually fulfilled.
The responsibility, therefore, falls on the data controller, who determines the means and purposes of the processing. In this case, SAREB
IV. Breached obligation. Article 5.1.f) GDPR Integrity and Confidentiality
1. Regulatory Regime and Breach
Article 5.1.f) of the GDPR establishes:
"1. Personal data shall be:
(…)
f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, by applying appropriate technical or organizational measures ("integrity and confidentiality")."
In the present case, there has been a breach of confidentiality and availability of the personal data for which SAREB is responsible.
Loss of Confidentiality
Regarding the loss of confidentiality, the preliminary investigation report on STRATESYS's actions states the following:
Regarding the attacker's access to the data:
“(…);
(…);
(…).”
Regarding the possible publication of the exfiltrated data:
“(…):
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 17/34
(…).
(…).
(…).
(…)
There are indications, therefore, that at least the attacker had access to the exfiltrated data.
Regarding the publication of the data, although it is stated that the download link was never enabled, the truth is that STRATESYS technicians managed to access at least part of the information that was in the attacker's possession. The confidentiality of the data was therefore affected.
Loss of availability.
The breach affected the availability of the data for both the controller and the data processor. In this regard, the report The preliminary investigation actions of STRATESYS confirm the following:
(…).
(…).
It should be added that, in both breach notifications, from STRATESYS and SAREB (…).
Therefore, a breach of confidentiality and availability occurred.
1. Cause of the breach
The attack entry vector is analyzed in the preliminary investigation actions report after analyzing all the documentation in the file. The conclusions contained in said report indicate the following:
(…).
(…).
Therefore, two errors converged that made the cyberattack possible. (…).
2. Types of data affected and number of people
According to the notification issued by SAREB, they are the following:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 18/34
“(…):
(…):
(…):
• (…).
• (…).
• (…).”
(…).
3. Insufficient measures to guarantee confidentiality and availability
The lack or violation of measures to guarantee these aspects is noted in
the report of preliminary investigation actions.
(…):
But, in addition, the (…).”
Furthermore, the aforementioned report indicates the establishment of this measure as
subsequent to the breach:
“(…):
(…).”
(…):
(…):
“(…):
“(…).”
The combination of both factors facilitated both the attacker's access to the data,
and the fact that it could be viewed and extracted in plain text.
(…):
“(…).”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 19/34
(…):
“(…).”
(…).
(…).
“(…):
I. (…).
II. (…).
III. (…).
IV. (…).”
1. Conclusions
Based on the evidence available at this time of the agreement to initiate sanctioning proceedings, it is considered that the facts known could constitute an infringement, attributable to SAREB, for
violation of Article 5.1.f) of the GDPR, as transcribed above.
V. Classification of the violation of Article 5.1.f) of the GDPR and
classification for the purpose of limitation
Article 83.5 of the GDPR classifies as an administrative violation the violation of the following articles, which shall be punishable, in accordance with paragraph 2, with administrative fines of up to EUR 20,000,000 or, in the case of a company, an amount equivalent to a maximum of 4% of the total annual global turnover of the preceding financial year, whichever is higher:
"a) the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9;
b) the rights of data subjects pursuant to Articles 12 to 22;
c) transfers of personal data to a recipient in a third country or an international organization pursuant to Articles 44 to 45; 49;
d) any obligation under the law of the Member States adopted pursuant to Chapter IX;
e) failure to comply with a decision or a temporary or definitive restriction on processing or suspension of data flows by the supervisory authority
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 20/34
pursuant to Article 58, paragraph 2, or failure to provide access in violation of
Article 58, paragraph 1."
For its part, the LOPDGDD, in its Article 71, Infractions, states that:
"Infractions constitute the acts and conduct referred to in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law."
For the sole purpose of the statute of limitations, Article 72.1 of the LOPDGDD establishes the following:
"In accordance with the provisions of Article 83.5 of Regulation (EU) 2016/679, infringements that constitute a substantial violation of the articles mentioned therein, and in particular the following, are considered very serious and will be subject to a three-year statute of limitations:
a) The processing of personal data in violation of the principles and guarantees established in Article 5 of Regulation (EU) 2016/679."
VI Proposed sanction for non-compliance with Article 5.1.f) GDPR
In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR must be observed, which state:
“1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article for the infringements of this Regulation referred to in paragraphs 4, 9, and 6 are, in each individual case, effective, proportionate, and dissuasive.
2. Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or as a substitute for the measures provided for in Article 58(2)(a) to (h) and (j). When deciding whether to impose an administrative fine and its amount in each individual case, due account shall be taken of:
a) the nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation concerned, as well as the number of data subjects affected and the level of damage suffered by them;
b) the intentionality or negligence involved in the infringement;
c) any measures taken by the controller or processor to mitigate the damage suffered by data subjects;
d) the degree of responsibility of the controller or processor, taking into account any technical or organizational measures implemented by them pursuant to Articles 25 and 32;
e) any previous breach committed by the controller or processor;
f) the degree of cooperation with the supervisory authority to remedy the breach and mitigate the potential adverse effects of the breach;
g) the categories of personal data affected by the breach;
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 21/34
h) the manner in which the supervisory authority became aware of the breach, in particular whether the controller or processor notified the breach and, if so, to what extent;
i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned in relation to the same matter, compliance with those measures;
j) adherence to codes of conduct pursuant to Article 40 or to certification mechanisms approved pursuant to Article 42, and
k) any other aggravating or mitigating factors applicable to the circumstances of the case,
such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement."
For its part, Article 76 "Sanctions and corrective measures" of the LOPDGDD
provides:
"1. The sanctions provided for in paragraphs 4, 5, and 6 of Article 83 of Regulation
(EU) 2016/679 shall be applied taking into account the grading criteria
established in paragraph 2 of the aforementioned article.
2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679,
the following may also be taken into account:
a) The continuous nature of the infringement.
b) The connection between the offender's activity and the processing of personal data.
c) The benefits obtained as a result of the commission of the infringement.
d) The possibility that the affected party's conduct could have led to the commission of the infringement.
e) The existence of a merger by absorption process subsequent to the commission of the infringement, which cannot be attributed to the acquiring entity.
f) The impact on the rights of minors.
g) The availability of a data protection officer, when not mandatory.
h) Voluntary submission by the controller or processor to alternative dispute resolution mechanisms in cases where there are disputes between them and any interested party.
In the present case, considering the seriousness of the potential violation, especially considering the consequences its commission has on those affected, a fine would be imposed, in addition to the adoption of measures, if appropriate.
The fine imposed must be, in each individual case, effective, proportionate, and dissuasive, in accordance with the provisions of Article 83.1 of the GDPR. To guarantee these principles, SAREB's turnover, which amounts to €2,118,629,000 in 2023, is considered as a preliminary matter.
For the purposes of deciding on the imposition of an administrative fine and its amount, in accordance with the evidence currently available, the Initiation of sanctioning proceedings, and without prejudice to the outcome of the investigation, it is considered appropriate to grade the sanction to be imposed according to the following circumstances, contemplated in the aforementioned provisions.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 22/34
Preliminary, it is considered that the following circumstances apply:
• The nature, severity, and duration of the infringement, taking into account the
nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damages they have suffered (Article 83.2, letter a) of the GDPR):
(…).
(…).
(…).
• Negligence in the infringement (Article 83.2, letter b) of the GDPR). The negligence committed in causing the breach must be considered particularly serious. It is not a question of the data controller having to have planned measures
in addition to those already in place, (…).
• The categories of personal data affected by the
infringement (Article 83.2, letter g) of the GDPR). (…).
Special mention should be made of the DNI number. This involves the processing of sensitive data, as it allows for the direct and
unequivocal identification of a natural person. As established by Royal Decree
1553/2005, the DNI is a general personal numerical identifier, with
sufficient value to prove both the identity and nationality of the holder,
making it a particularly sensitive element within the personal data ecosystem. Furthermore, its improper use entails a high risk
of identity theft, property damage, or infringement of the right to honor, risks expressly contemplated in recital 75 of the GDPR.
Therefore, a systematic and final interpretation of the GDPR—in accordance with
recitals 51 and 75—allows the DNI to be considered as particularly sensitive data, given its potential to cause significant harm in the event of unauthorized use. In this regard, according to Guidelines 04/2022 on the calculation of fines under the GDPR, when assessing this circumstance, reference should be made not only to the "types of data covered by Articles 9 and 10 of the GDPR, but also to data outside the scope of these articles, the dissemination of which causes immediate harm or hardship to the data subject." Among these, it expressly mentions identity document numbers.
Likewise, the following grading factors are considered as aggravating factors:
• The impact on the rights of minors (Article 76.2, letter f) of the LOPDGDD). In this regard, (...).
The balance of the circumstances contemplated in Article 83.2 of the GDPR and 76.2 of the LOPDGDD, with respect to the infringement Committed by violating the provisions of
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 23/34
Article 5.1.f) of the GDPR, allows for the initial imposition of an administrative fine of €250,000.00.
VII. Breached Obligation. Article 28 GDPR. Data Processor
The provisions regarding the data processor are set out in Article 28 of the GDPR, which stipulates the following:
"1. Where processing is carried out on behalf of a controller, the controller shall only select a processor that offers sufficient guarantees to implement appropriate technical and organizational measures to ensure that the processing complies with the requirements of this Regulation and ensures the protection of the data subject's rights.
(…)
3. Processing by the processor shall be governed by a contract or other legal instrument, in accordance with Union or Member State law, which binds the processor to the controller and establishes the subject matter, duration, nature and purpose of the processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller.
During the investigation, both SAREB and STRATESYS provided a copy of the contract for the processing of personal data, in which SAREB appears as the data controller and SAREB as the data processor.
(…).
In relation to this aspect, SAREB, as the data controller, has reported the following:
- In the document entitled “(…):
(…).
(…).”
In response to the inspector's request on this matter, SAREB provides the following:
"In accordance with Organic Law 7/2012, of December 27, which modifies Organic Law 10/1995, of November 23, of the Criminal Code in relation to transparency and the fight against tax and Social Security fraud,
and Law 58/2003, of December 17, General Tax Law, the statute of limitations for crimes against Social Security and the Public Treasury is 10 years, which implies the obligation to retain the data
used to calculate social security contributions and salary withholdings during this period, in order to guarantee its availability for the accreditation of tax or social security obligations if required by law." the Public Treasury
and Social Security, thus contributing to the prevention and detection
of potential violations."
For its part, STRATESYS has provided the following
information regarding this aspect:
"In accordance with Stratesys' privacy policy and by virtue of the principle of
limitation of the retention period, as a general rule, personal data
is deleted when it is no longer necessary to fulfill the purpose for which it was collected (e.g., the termination of the contract between the data controller
and the data processor). Notwithstanding this,
exceptionally, personal data may be retained for a
specified period of time if certain circumstances arise, such
as compliance with a legal obligation."
Since STRATESYS acts as the data processor in this matter,
upon reviewing the content of the contract, it is noted that the only provision it contains regarding the retention of personal data by the
processor is the following (clause seven):
"7. Obligation to destroy data once the contract is completed.
(…).
Analyzing the rest of the contract, there is no additional provision regarding the data retention period by the data processor.
It can therefore be seen that no provision is included in the contract regarding the data retention period by the data processor. Thus, it would seem that, in accordance with the previous clause, the data processor would retain all personal data being processed until the end of the contract, however long that term may be.
The data processor processes data on behalf of the controller, and the legal relationship between both must be clearly defined in the contract. Additionally, the controller must issue, as soon as necessary because the contractual clauses are not sufficiently specific, specific subsequent instructions appropriate for executing the contract.
The mandatory content of the contract provided for in Article 28.3 of the GDPR implies both a formal and material obligation that falls primarily on the data controller. Thus, the aforementioned contract cannot be limited to reproducing the wording of said provision in a generic manner, since this does not truly comply with the obligation prescribed in the GDPR.
In the case analyzed here, it can be considered that SAREB has not duly complied with Article 28 of the GDPR, since the retention periods for personal data must be applied regardless of who actually carries out the processing, whether the controller or the processor. The contract must incorporate and be adapted to the retention periods for the processing. In this regard, it makes no sense for the data controller to delete the data
when appropriate in application of the principle of Article 5.1.d) of the GDPR, while
the data processor retains the data indefinitely until the end of the contract (which
could be longer than the data retention period).
The contractual provision indicating that, at the controller's discretion, the data processor
will delete or return all personal data once the provision of the processing services ends in no way alters this breach, since, as has been
stated, it would only apply at the end of the contract.
Therefore, in accordance with the evidence currently available
from the agreement to initiate sanctioning proceedings, it is considered that the known facts
could constitute an infringement, attributable to SAREB, for
violation of Article 28 of the GDPR, as transcribed above.
VIII. Classification of the violation of Article 28 of the GDPR and
classification for the purpose of limitation
Article 83.4 of the GDPR classifies the violation of the following articles as an administrative offense. In accordance with paragraph 2, the following shall be punishable by administrative fines of up to EUR 10,000,000 or, in the case of a company, an amount equivalent to a maximum of 2% of the total annual turnover of the preceding financial year, whichever is higher:
"a) the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39, 42, and 43;
b) the obligations of certification bodies pursuant to Articles 42 and 43;
c) the obligations of the supervisory authority pursuant to Article 41(4).
For its part, the LOPDGDD (Organic Law on the Protection of Personal Data) in its Article 71, "Infractions," states that:
"Infractions constitute the acts and conduct referred to in sections 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law."
For the sole purpose of the statute of limitations, Article 73 of the LOPDGDD establishes
the following:
"In accordance with the provisions of Article 83.4 of Regulation (EU) 2016/679, infringements that constitute a substantial violation of the articles mentioned therein, and in particular the following, are considered serious and will be subject to a two-year statute of limitations:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 26/34
violation:
k) Entrusting data processing to a third party without prior formalization of a contract or other written legal act with the content required by Article 28.3 of
Regulation (EU) 2016/679."
IX. Proposed sanction for non-compliance with Article 28 of the GDPR
In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR, as well as Article 76 of the LOPDGDD, must be observed, as set forth in the sixth legal basis of this initial agreement.
In the present case, considering the seriousness of the potential violation, paying particular attention to the consequences its commission has on those affected, a fine should be imposed, in addition to the adoption of measures, if appropriate.
The fine imposed must be, in each individual case, effective, proportionate, and dissuasive, in accordance with the provisions of Article 83.1 of the GDPR. To guarantee
these principles, SAREB's turnover of €2,118,629,000 in 2023 is considered as a preliminary matter.
For the purposes of deciding on the imposition of an administrative fine and its amount, in accordance with the evidence currently available in
the decision to initiate sanctioning proceedings, and without prejudice to the outcome of the investigation, it is considered appropriate to grade the sanction to be imposed according to
the following circumstances, contemplated in the aforementioned provisions.
As a preliminary matter, the following circumstances are deemed to be present:
• The nature, severity, and duration of the infringement, taking into account the
nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damages they have suffered (Article 83.2(a) of the GDPR).
(…)
• Negligence in the breach (Article 83.2, letter b) of the GDPR). The negligence must be
considered serious. Maintaining the data for very long periods of time (remember that the oldest data affected by the breach dated back to December 2013) created an unnecessary risk for data that could have been deleted had the deadlines been
determined. Thus, it is perfectly possible that much of the data held by the data controller would not have been affected by the cyberattack had a clear and effective data deletion policy been implemented after the deadlines had elapsed. And in this regard, it should be remembered that, although the data processor may be subject to compliance with the legal obligations
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 27/34
referred to in its responses, it seems more doubtful that the data processor is, as it does not establish the means and purposes.
• The categories of personal data affected by the
infringement (Article 83.2, letter g) of the GDPR). (…).
• The impact on the rights of minors (Article 76.2, letter f) of the
LOPDGDD): (…).
The balance of the circumstances contemplated in Article 83.2 of the GDPR and Article 76.2 of the LOPDGDD, with respect to the infringement committed by violating the provisions of Article 28 of the GDPR, allows for the initial imposition of an administrative fine of €50,000.00.
X. Corrective Measures
If the infringement is confirmed, the resolution issued may establish the corrective measures that the offending entity must adopt to put an end to the non-compliance with personal data protection legislation, in this case Article 28 of the GDPR and Article 5.1.f) of the GDPR, in accordance with the provisions of the aforementioned Article 58.2.d) of the GDPR, according to which each supervisory authority may "order the controller or processor to ensure that processing operations comply with the provisions of this Regulation, where appropriate, in a specified manner and within a specified period."
Thus, the responsible entity may be required to adapt its actions to the
personal data protection regulations, within the scope expressed in the
previous Legal Basis.
This act establishes the alleged violation committed and the facts
that could give rise to this potential violation of data protection regulations, from which it is clear what measures to be adopted, without prejudice
to the fact that the type of procedures, mechanisms, or specific instruments to
implement them corresponds to the sanctioned party, since it is the data controller who fully understands his or her organization and must decide, based on
proactive responsibility and a risk-based approach, how to comply with the GDPR and the LOPDGDD.
However, in this case, regardless of the foregoing, in accordance with the evidence currently available regarding the agreement to initiate sanctioning proceedings, the resolution adopted may require SAREB to adopt the following measures within three months from the date of the final resolution of this procedure:
- Prove the effective application of appropriate technical and organizational measures to ensure compliance with the principles of integrity and confidentiality, as well as the implementation of data processing security measures appropriate to the risks.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 28/34
- Prove the execution and validity of the corresponding data processing contract with whoever currently performs, where applicable, the functions assigned by SAREB that are the subject of this file, with the content adapted to article 28 of the GDPR.
The imposition of these measures is compatible with the sanction of an administrative fine, as provided in Article 83.2 of the GDPR.
Please note that failure to comply with the possible order to adopt measures imposed by this body in the resolution of this sanctioning procedure may be considered an administrative infraction pursuant to the provisions of the GDPR,
classified as an infraction in Articles 83.5 and 83.6 thereof, and such conduct may lead to the opening of a subsequent administrative sanctioning procedure.
Please also remember that neither the acknowledgment of the infraction committed nor, where applicable, the voluntary payment of the proposed amounts exempts you from the obligation to adopt the relevant measures to cease the conduct or correct the effects of the infraction committed, nor from the obligation to prove compliance with this obligation to this AEPD.
Therefore, in light of the foregoing, the President of the Spanish Data Protection Agency,
IT IS AGREED:
FIRST: Initiation of sanctioning proceedings
INITIATING SANCTIONING PROCEEDINGS against the COMPANY FOR THE MANAGEMENT OF ASSETS FROM BANK RESTRUCTURING, S.A., with NIF A86602158,
- For the alleged violation of Article 5.1.f) of the GDPR, as defined in Article
83.5 of the same Regulation
- For the alleged violation of Article 28 of the GDPR, as defined in Article
83.4 of the same Regulation
SECOND: Appointment of investigating officer
APPOINTING A.A.A. as investigating officer and, as secretary, B.B.B., indicating that
they may be challenged, if applicable, in accordance with the provisions of Articles 23 and 24
of Law 40/2015, of October 1, on the Legal Regime of the Public Sector (LRJSP).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 29/34
THIRD: Incorporation of documentation into the file
INCORPORATE into the file, for evidentiary purposes, the claim filed by the
complaining party and its documentation, as well as the documents obtained and
generated by the Subdirectorate General of Data Inspection in the actions prior to the initiation of this sanctioning procedure.
FOURTH: Possible sanction
THAT for the purposes set forth in art. 64.2 b) of Law 39/2015, of October 1, on the
Common Administrative Procedure of Public Administrations, the sanction that may be imposed would be:
- An administrative fine of 250,000 euros, for the violation of Article 5.1.f) of the
GDPR
- An administrative fine of 50,000 euros for the violation of Article 28 of the GDPR
This makes a total of THREE HUNDRED THOUSAND EUROS (€300,000).
All of this without prejudice to the outcome of the investigation.
FIFTH: Notification and Period for Objections
NOTIFY this agreement to SOCIEDAD DE GESTIÓN DE ACTIVOS PROCEDENTES DE LA REESTRUCTURACIÓN BANCARIA, S.A., granting it a hearing period of ten business days to formulate its objections and present any evidence it deems appropriate. In its written objections, it must provide its NIF (Tax Identification Number) and the procedure number shown in the heading of this document.
In accordance with the provisions of Article 85 of the LPACAP (Spanish Civil Code), it may acknowledge its liability within the period granted for the formulation of objections to this initiation agreement; this will entail a 20% reduction in the appropriate penalty imposed in this procedure. With the application of this reduction, the penalty would be set at €240,000.00, and the procedure would be resolved with the imposition of this penalty.
Likewise, at any time prior to the resolution of this procedure, the applicant may voluntarily pay the proposed fine, which will result in a 20% reduction in its amount. With the application of this reduction, the fine would be set at €240,000.00, and its payment will imply the termination of the procedure, without prejudice to the imposition of the corresponding measures.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 30/34
The reduction for voluntary payment of the fine is cumulative with the reduction applicable for acknowledgment of liability, provided that this acknowledgment of liability is made clear within the period granted for submitting allegations at the opening of the procedure. Voluntary payment of the amount referred to in the preceding paragraph may be made at any time prior to the resolution. In
this case, if both reductions were to be applied, the penalty would be set at €180,000.00.
In any case, the effectiveness of either of the aforementioned reductions will be subject to the withdrawal or waiver of any administrative action or appeal against the penalty.
If you choose to voluntarily pay any of the amounts indicated above (€240,000.00 or €180,000.00), you must do so by depositing it into account IBAN: ES00-0000-0000-0000-0000-0000
(BIC/SWIFT Code: CAIXESBBXXX) opened in the name of the Spanish Data Protection Agency at the bank CAIXABANK, S.A., indicating in the
item the reference number of the procedure shown in the heading of this document and the reason for the reduction in the amount you are applying for.
You must also send proof of payment to the Subdirectorate General of Inspection so that the procedure can continue in accordance with the amount
deposited.
In compliance with Articles 14, 41, and 43 of the LPACAP (Spanish Civil Procedure Act), you are hereby advised that, from now on, notifications sent to you will be sent exclusively electronically, through the Single Authorized Electronic Address (dehu.redsara.es) and the Electronic Office (sedeaepd.gob.es). If you do not access them, your rejection will be recorded in the file, deeming the process complete and following the procedure. You are hereby informed that you may provide this Agency with an email address to receive notification of the availability of notifications and that failure to provide this notification will not prevent the notification from being considered fully valid.
Finally, please note that, pursuant to Article 112.1 of the LPACAP, no administrative appeal may be filed against this act.
1479-110425
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency
>>
SECOND: On July 30, 2025, SAREB proceeded to pay the fine
in the amount of €180,000.00, making use of the two reductions provided for in
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 31/34
the initiation agreement transcribed above, which implies recognition of
responsibility in relation to the events referred to in the initiation agreement and
their legal classification.
THIRD: The initiation agreement transcribed above indicated that, if the infringement was confirmed, it could be agreed that the controller would be required to adopt appropriate measures to bring its actions into compliance with the regulations mentioned in this act, in accordance with the provisions of the aforementioned Article 58.2 d) of the GDPR, according to which each supervisory authority may "order the controller or processor to ensure that processing operations comply with the provisions of this Regulation, where appropriate, in a specific manner and within a specified period...".
Having acknowledged responsibility for the infringement, the imposition of the measures included in the initiation agreement is appropriate.
LEGAL BASIS
I
Jurisdiction
In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (the General Data Protection Regulation, hereinafter GDPR) and as established in Articles 47, 48.1, 64.2, and 68.1 of
Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), the President of the Spanish Data Protection Agency is competent to resolve this procedure.
Likewise, Article 63.2 of the LOPDGDD establishes that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development, and, insofar as they do not contradict them, in a subsidiary manner, by the general rules on administrative procedures."
II
Termination of the Procedure
Article 85 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), under the heading
"Termination of Sanctioning Procedures" provides the following:
"1. Once a sanctioning procedure has been initiated, if the offender acknowledges responsibility,
the procedure may be terminated with the imposition of the appropriate sanction.
2. When the sanction is solely pecuniary in nature, or when a pecuniary sanction and a non-pecuniary sanction may be imposed, but the inadmissibility of the second sanction has been justified, voluntary payment by the alleged responsible party, at any time prior to the resolution, will entail the termination of the procedure.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 32/34
except in matters relating to the restoration of the altered situation or the determination of compensation for damages caused by the commission of the violation.
3. In both cases, when the sanction is solely monetary in nature, the competent body responsible for resolving the procedure shall apply reductions of at least 20% on the amount of the proposed sanction, which may be combined.
These reductions must be specified in the notification of initiation of the procedure, and their effectiveness shall be conditional on the withdrawal or waiver of any administrative action or appeal against the sanction.
The percentage reduction provided for in this section may be increased by regulation.
III
Voluntary Payment and Acknowledgment of Liability
In accordance with the provisions of the aforementioned Article 85 of the LPACAP, the notified initiation agreement informed of the possibility of acknowledging liability and voluntarily paying the proposed penalty, which would entail two cumulative reductions of 20% each. With the application of these two reductions, the penalty would be set at €180,000.00, and its payment would imply the termination of the procedure, without prejudice to the imposition of the corresponding measures.
Following notification of the aforementioned initiation agreement, SAREB proceeded to acknowledge liability and voluntarily pay the penalty, availing itself of the two proposed reductions. In accordance with section 3 of Article 85 of the LPACAP, the effectiveness of the aforementioned reductions will be conditional on the withdrawal or waiver of any administrative action or appeal against the penalty.
It should be noted Please note that, in accordance with the provisions of the LPACAP, as well as the Supreme Court's jurisprudence on this matter, the exercise of voluntary payment by the alleged offender does not exempt the administration from its obligation to resolve and notify all proceedings, regardless of their form of initiation. Similarly, Article 88 of the aforementioned law establishes that the resolution that concludes the procedure will decide all issues raised by the interested parties and any other issues arising from it.
Therefore, in accordance with applicable legislation and having assessed the criteria for graduating sanctions, the Presidency of the Spanish Data Protection Agency RESOLVES:
FIRST: TO DECLARE the commission of the violations and CONFIRM the sanctions determined in the operative section of the initiation agreement transcribed in this
resolution.
The sum of the aforementioned amounts amounts to a total of 300,000.00 euros.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 33/34
After SOCIEDAD DE GESTIÓN DE ACTIVOS PROCEDENTES DE
LA REESTRUCTURACIÓN BANCARIA, S.A. has made prompt payment and acknowledged liability, pursuant to Article 85 of the LPACAP, the aforementioned reduction is carried out by
40% of the total, which represents the final amount of 180,000.00 euros.
The effectiveness of the aforementioned reductions is subject, in all cases, to the withdrawal or waiver of any action or appeal through administrative channels.
SECOND: DECLARE the termination of procedure EXP202318311, in accordance with the provisions of Article 85 of the LPACAP.
THIRD: ORDER SOCIEDAD DE GESTIÓN OF ASSETS FROM BANK RESTRUCTURING, S.A. to notify the Agency within 3 months
of this resolution becoming final and enforceable, of the adoption of the measures described in the legal grounds of the initiation agreement transcribed in this resolution.
FOURTH: NOTIFY this resolution to the MANAGEMENT COMPANY OF ASSETS FROM BANK RESTRUCTURING, S.A.
FIFTH: In accordance with the provisions of Article 85 of the LPACAP, which conditions the
reduction for voluntary payment and acknowledgment of liability on the withdrawal or waiver of any action or appeal in administrative proceedings, this resolution will become final in administrative proceedings and fully enforceable upon notification.
In accordance with the provisions of Article 50 of the LOPDGDD, this resolution will be made public. The publication will take place once the resolution becomes final. Administrative.
Against this resolution, which ends the administrative process as provided for in
Article 114.1.c) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, the interested parties may file an administrative appeal before the Contentious-Administrative Chamber of the National Court, in accordance with the provisions of Article 25 and Section 5 of the Fourth Additional Provision of Law 29/1998, of July 13, regulating the Contentious-Administrative Jurisdiction, within two months from the day following notification of this act, as provided for in Article 46.1 of the aforementioned Law.
However, in accordance with the provisions of Article 90.3.a) of the LPACAP, the final resolution may be provisionally suspended if the The interested party
expresses their intention to file an administrative appeal. If this is
the case, the interested party must formally notify this fact in writing
to the Spanish Data Protection Agency, submitting it through the
Agency's Electronic Registry [https://sedeaepd.gob.es/sede-electronica-web/], or
through one of the other registries provided for in Article 16.4 of the aforementioned Law
39/2015, of October 1. They must also send the Agency the documentation
that proves the effective filing of the administrative appeal. If the
Agency does not become aware of the filing of the administrative appeal within two months from the day following notification of this resolution, it will consider The precautionary suspension has ended.
1259-180725
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es




