AEPD (Spain) - EXP202400905
| AEPD - EXP202400905 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 6(1) GDPR |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | 06.06.2024 |
| Decided: | 03.06.2025 |
| Published: | 16.10.2025 |
| Fine: | 100,000 EUR |
| Parties: | GOLDCAR SPAIN, S.L. |
| National Case Number/Name: | EXP202400905 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Spanish |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | ap |
The DPA fined a car rental company €100,000 for processing information about customers’ previous incidents in blacklists without a legal basis. Being blacklisted led to the denial of services by the rental company.
English Summary
Facts
GOLDCAR SPAIN, S.L. (the controller) is a car rental company. A data subject made a reservation on the controller’s website to rent a car, and was later denied due to an entry in the controller’s database for a previous rental contract signed three years earlier. According to the controller, the data subject gave the keys to a third person, and as a result, the car disappeared and was later found in Poland.
The data subject brought a complaint to the DPA on the grounds that the controller linked their data from a previous incident through an alert system without their consent. This also prevented the data subject from accessing the controller’s services. The controller therefore processed data without a legal basis.
The controller argued that it complied with data protection laws at the time, as the incident occurred before the GDPR came into force. According to the controller, it did not need to inform the data subject of the legal basis. In addition, the controller argued that processing data in the alert system was based on its legitimate interest, and necessary to offset the risk of fraud and damages to the rental cars.
Holding
The DPA found a violation of Article 6(1) GDPR, as the controller processed data without a legal basis. The DPA stated that the controller could not rely on legitimate interest (Article 6(1)(f) GDPR) or contract (Article 6(1)(b) GDPR) to process the data. The controller could not rely on contractual necessity to process data in relation to blacklists, according to the Working Party 29.[1]
In terms of legitimate interest, the DPA stated that fraud prevention could be a valid legitimate interest. However, the DPA considered that the rights and freedoms of data subjects prevail in this case. The DPA also noted that the controller had not carried out a balance test of the interests involved. In addition, the controller had deprived the data subject of their right to know the legal basis and legitimate interests pursued by the controller, as well as the fact that the controller is processing their data in that manner. This meant the only available legal basis was consent of the data subject (Article 6(1)(a) GDPR); given the circumstances of the case, the DPA concluded that the controller did not receive consent to process the data.
The DPA fined the controller €100,000. The DPA considered it a serious violation of the GDPR, as the controller processed data without a legal basis for several years. In addition, the DPA ordered the controller to demonstrate a legal basis for the processing activities, and cease to process data to exclude possible data subjects.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.
1/40
File No.: EXP202400905
RESOLUTION TERMINATING THE PROCEDURE DUE TO VOLUNTARY PAYMENT
From the procedure initiated by the Spanish Data Protection Agency and based on the following
BACKGROUND
FIRST: On June 6, 2024, the Director of the Spanish Data Protection Agency
agreed to initiate sanctioning proceedings against GOLDCAR SPAIN, S.L. (hereinafter, GOLDCAR). After notification of the initiation agreement and after analyzing the allegations presented, the following draft resolution was issued on May 16, 2025:
<<
File No.: EXP202400905
PROPOSED RESOLUTION FOR SANCTIONING PROCEDURE
From the procedure initiated by the Spanish Data Protection Agency and based on the following:
BACKGROUND
FIRST: A.A.A. (hereinafter, A.A.A.) filed a complaint with the Spanish Data Protection Agency on December 25, 2023. The complaint is directed against GOLDCAR SPAIN, S.L., with NIF B03403169 (hereinafter, GOLDCAR).
The grounds for the complaint are as follows:
A.A.A. He stated that he made a reservation for a vehicle with GOLDCAR between June 9, 2021, and June 16, 2021, through a website. When he went to pick up the vehicle, he was denied access due to a notice in the entity's database for a contract signed in Madrid in 2018. He believes that his data has been
linked, without his consent, to a previous incident, and has been incorporated into an alert system to prevent him, as a customer, from contracting GOLDCAR's services.
The following were provided along with the complaint:
- A copy of the rental contract with the contracted rate "***REFERENCE.1" and
reservation number ***REFERENCE.2, listing the customer as the complainant, and
which states the following: "(...)" (sic). The contract bears the seal of
GOLDCAR SPAIN SLU and a handwritten signature. This document includes a
section on "Specific Conditions" with the following text: "The vehicle may not be driven outside the Spanish mainland, or in the case of rentals
contracted in the Balearic or Canary Islands, the vehicle may not be left on the island where it was
delivered, unless expressly authorized and signed by the company in both cases and the corresponding additional extraordinary coverage is contracted and paid for."
- Copy of the general rental conditions.
SECOND: In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), on January 17, 2024, the complainant was notified of this complaint so that it could analyze it and inform this Agency within one month of the actions taken to comply with the requirements set forth in the data protection regulations.
The notification, which was carried out in accordance with the regulations established in Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), was recorded on January 17, 2024, as recorded in the acknowledgment of receipt included in the file.
On February 15, 2024, the respondent requested an extension of the deadline to respond, which was extended for an additional ten days.
GOLDCAR responded to the notice on February 29, 2024, stating that it had requested information from the customer service department regarding the contracts signed
by the customer and any potential claims, stating: "According to the report, A.A.A. reserved a rental car and the reservation was referenced with the number ***REFERENCE.2. The car was reserved for pickup at the airport in
***LOCATION.1 on June 9, 2021, and returned to GOLDCAR on June 16, 2021. Indeed,
the car was not delivered; we understand this was due to a reservation error."
Attach the document "Car Rental Denial Incident" with the following
information:
"Our customer database shows that A.A.A. booked a car with
number ***REFERENCE.2 at the airport in ***LOCATION.1 between
June 9, 2021 and June 16, 2021.
We have consulted our customer service department to determine if
there are any complaints related to this reservation or issues with the delivery
of the vehicle.
According to our internal information, the reservation was not executed because the car was not
delivered to the customer.
Additionally, we are not aware of A.A.A.'s complaint or any
data protection rights requests submitted by this customer in relation to this reservation."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 3/40
THIRD: On March 25, 2024, in accordance with Article 65 of the LOPDGDD, the claim filed by A.A.A. was admitted for processing.
FOURTH: The Subdirectorate General of Data Inspection proceeded to carry out preliminary investigative actions to clarify the facts in question, pursuant to the functions assigned to the supervisory authorities in Article 57.1 and the powers granted in Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VII, Chapter I, Section Two, of the LOPDGDD, having learned of the following:
A) On April 2, 2024, a request for information was sent to GOLDCAR, requesting:
- The reason for rejecting the vehicle contract based on the entry written on the reservation document: "(...)"
- Type of data, whether proprietary or third-party, that was consulted to make that entry.
- If the data is not yours, please indicate the legal basis for this.
On April 8, 2024, GOLDCAR received a written response, stating the following:
1. GOLDCAR has verified the information related to the aforementioned contract
signed in April 2018 and states that:
“(…) According to our information, there was an incident with the return
of the vehicle rented by the complainant on April 28, 2018, since the
client breached GOLDCAR's general terms and conditions. In
particular, they breached clause 10 by allowing a third party to drive the
vehicle without informing GOLDCAR of the existence of a second driver. In
this regard, said clause expressly states:
“Likewise, it is the client's obligation not to allow the vehicle to be driven
by any person other than those authorized in accordance with this contract,
the client being directly responsible for any damage or harm caused to the
vehicle or to third parties in such a case."
As a result of access by a third party The vehicle
was stolen or at least disappeared, with the customer unable to return it during the
rental period. The vehicle was recovered by the police in August 2018
in Poland, and GOLCAR had to assume the costs of repatriating the vehicle, the
services of the vehicle recovery and claims management company, the
payment of the fines imposed on the vehicle during this period, as well as its
cleaning.
In response to this incident, our insurance department could have
written an internal note on the customer file to manage the breach
of contract, the recovery of the vehicle, and the costs arising from the incident.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 4/40
Currently, there is no note on the customer file, probably due to the
time that has elapsed since the incident, but it is possible that the agent, at the
time of processing the reservation and delivery of the vehicle, could have seen this
information on the file customer and, upon verifying that there was a breach of contract, decided not to deliver the car, in accordance with clause 10, paragraph 11 of GOLDCAR's specific terms and conditions, which establish:
"Goldcar reserves the right to cancel the delivery of the vehicle in the event of
well-founded doubts about the customer's financial capacity or due to a history of
non-payments or serious incidents with Goldcar." (...)"
2. "The personal data used to provide the customer with an explanation were
those included in the customer file, necessary for formalizing the
contract and monitoring its execution, collected and processed in accordance
with GOLDCAR's general contracting conditions and its privacy policy. All personal information consulted is internal and obtained
directly from the customer, except for the vehicle recovery report
issued by the police, which does not provide additional information about the customer."
3. As mentioned above, GOLDCAR states that it does not access personal data
provided by third parties; the data is processed within the framework of the contractual relationship.
B) On April 10, 2024, the claimant and GOLDCAR were requested to provide a copy of the contract signed in 2018.
On that date, the claimant's response was received. Two documents were provided:
- Rental_Contract__***REFERENCE.3__1.pdf: Vehicle rental contract for the period April 27-29, 2018.
- Rental_Contract__***REFERENCE.3__2.pdf: Vehicle rental contract for the period April 27-30, 2018.
Both documents include a section on "Specific Conditions," the content of which is detailed in the First Proven Fact.
On April 16, 2024, GOLDCAR received a response. Provide the
following documents:
- Doc_1.pdf: Vehicle rental contract no. ***REFERENCE.4, from
04/27/2018 to 04/29/2018, for an amount of ***AMOUNT.1 €.
- Goldcar_Contestacion_requerimiento.pdf: written response to the request for information.
The contract provided includes the same "Specific Conditions" as those in the
copy of the contract provided by the claimant. In addition, GOLDCAR includes the
details of the stipulated "General Rental Conditions." Part of what is stated in
this document is noted in the First Proven Fact.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 5/40
FIFTH: According to the report collected from the AXESOR tool, the respondent is a large company established in 1988, with a turnover of €203,880,000 in 2022.
SIXTH: On June 6, 2024, the Director of the Spanish Data Protection Agency agreed to initiate sanctioning proceedings against GOLDCAR, in accordance with the provisions of Articles 63 and 64 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), for the alleged violation of Article 6.1 of the GDPR, classified as follows: Article
83.5.a) of the GDPR.
SEVENTH: Having received notification of the aforementioned initiation agreement in accordance with the rules established
in Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), GOLDCAR requested on June 10, 2024, an extension of the deadline to respond and a copy of the file; this extension was granted, and a copy was sent to it on June 12, 2024.
GOLDCAR submitted a written statement of allegations on June 27, 2024, requesting the closing of this sanctioning procedure. After reiterating the details regarding
its relationship with the complainant, already stated in its previous briefs,
it makes the following considerations as the basis for its claim:
1. GOLDCAR has at all times engaged in legitimate data processing;
2. GOLDCAR considers the processing of the data to be lawful in accordance with its legitimate interest;
3. The initiation of sanctioning proceedings is not appropriate, as there is no intentional or negligent performance of GOLDCAR's duties as data controller;
4. The circumstances leading to the imposition of the sanction have not been properly assessed;
5. GOLDCAR considers that it complies with the provisions of the GDPR and that it is not necessary to adopt measures to bring the processing into compliance with the regulations.
With its letter, it provided a copy of the following documents:
1. Copy of the weighing of GOLDCAR's legitimate interest and the freedoms and rights of its clients (document in English and undated).
2. Copy of GOLDCAR's privacy policy, prepared, according to this entity, "as a result of the GDPR adaptation process." The
current version of this Privacy Policy, updated as of May 1,
2024, is provided. Part of the content of this document is outlined in Proven Fact Five.
3. Copy of the "internal protocol" or "procedure for managing incidents and including notices in customer files" which, according to GOLDCAR, "establishes the
specified cases in which a notice could be included, the consequences, and the
duration of the measure depending on the severity of the events or the potential harm to GOLDCAR and the personnel authorized to manage incidents" (in English and undated).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 6/40
Sigger Incident Procedure (Alert System)
This procedure will define the management and use of the incident types found in SIGGER. This procedure defines:
1. The guidelines for adding incidents
2. The consequences of incidents for customers and the company
3. Who is authorized to add incidents in Sigger
The purpose of this protocol is to keep our databases up-to-date and reduce the risk of non-payments and accidents, as well as to prevent fraudulent vehicle rentals.
Sigger incident types can be found in the customer file as follows:
Positive incidents will be identified with a blue line in the customer file
Negative incidents will be identified with a red line in the customer file
Incident Types
Sigger Incident Types and Restrictions
Positive
This incident only provides information about the customer.
The customer may continue renting without restrictions.
Negative
Minor (Low): These are comments/warnings that the customer may consider when renting a vehicle with the company for their next reservation. The customer may rent without restrictions.
Serious (Serious): These are comments/warnings based on alleged behavior from customers who have previously rented with us. Additionally, if there is a police warning, a warning from a company with debts, or if the customer has a history of debts with the company, they will not be able to rent again until the incident is resolved.
Very Serious: The customer will not be able to rent again until the incident is resolved.
Low Incidents and Reasons:
Low incidents justify why the customer was not given the vehicle on a previous rental. The office manager may use this type of incident to explain why a vehicle was denied on a reservation.
A vehicle cannot be denied to A customer with this level of incident will not be eligible for future bookings.
Reasons for Low Incidents
Any type of insult or provocation (without physical aggression) toward company employees.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 7/40
History of already settled debts. In these cases, the incidents must be removed from the customer's file.
Video recordings or photos of employees.
Customer who has not complied with cross-border regulations.
If a customer shows signs of being incapacitated by drugs or alcohol, the vehicle will not be released to them for public safety reasons. If the customer insists on taking the vehicle, the rental company or office manager must call the police.
Reasons for Serious Incidents:
When a customer experiences a serious incident, they will not be able to rent a vehicle with our company until to be resolved.
These incidents can only be resolved by designated individuals at Headquarters.
Internal Audit: History of unpaid or unsettled payments within the Company or use of fraudulent cards.
Claims: Police reports or warnings from theft or debt prevention companies.
Claims: Serious accidents.
Claims: Theft or misappropriation.
Office Manager: Clients with a prior police report for various reasons.
Very Serious Incidents:
When a client experiences a very serious incident, they will not be able to rent a vehicle
with our Company.
These incidents can only be submitted by the Legal Department if
there is a final court ruling against the client.
(For each type, the following is indicated: Office Manager,
Internal Audit Department, Legal and Customer Service Department,
Insurance and Claims Department. Very serious incidents can only be
added by the Legal Department if there is a Final Court Resolution against the client.)
EIGHTH: On January 17, 2025, the investigating officer agreed
to perform the following tests on GOLDCAR:
- To reproduce for evidentiary purposes the claim filed by the
claimant and its documentation, the documents obtained and generated
during the claim admission phase, and the report of the
preliminary investigation.
- In the written statement of allegations to the initial agreement, GODLCAR stated
in relation to the incident of denial of the rental vehicle to the complainant
that: "the Complainant was unable to return the vehicle, since he
had lent it to a third driver not affiliated with the contract with GOLDCAR, and
the driver disappeared or was stolen, so the vehicle was recovered
by the police in Poland months after the end of the rental period" and that "As explained, in the present case, there was unauthorized
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 8/40
use of the vehicle rented by the Complainant, since during the
rental of the vehicle, he lent it to a third party not authorized in the
rental contract, which led to the disappearance of the vehicle and the
filing of a police report with a police report ***REFERENCE 5. The
vehicle was subsequently located and recovered by the National Police. of the
Police in Poland. For this reason, in order to comply with the provisions of
the contract in cases of breach of contract, a notice or note may be
inserted in the client's file by our
insurance department."
The respondent was asked to provide documentary evidence and justification for the aforementioned statements and the handwritten note included in the rental agreement provided.
On January 27, 2025, GOLDCAR provided the following documentation:
- As Document No. 1, it provided a copy of the form completed and signed by the
claimant, dated April 30, 2018, in which GOLDCAR was informed of the
disappearance of the vehicle ***REFERENCE.3, after leaving the keys to a person not authorized under the rental agreement, who in turn left the
keys hidden in the vehicle's wheel well for the claimant to collect. The claimant accompanied the form with the police report filed on April 30, 2018, which is provided.
- Regarding the statement that the vehicle was recovered by the police
in Poland, please provide as Document No. 2 a copy of the email received
dated August 28, 2018, from the Criminal Investigation Police - (...), forwarding
information on the recovery of the reported vehicle.
- Regarding the statement regarding the internal notice from the insurance department, GOLDCAR states the following: "It is possible that it was issued, but at the date the proceedings were initiated, there is no evidence that any notice was posted on the customer file, since if it had been posted at the time, it would have been removed over time. In any case, the breach of the General Contract Conditions arises from the statement made by the complainant when submitting the form to GOLDCAR. Regarding the handwritten note on the rental contract, as already stated, no such note exists in the copy of the contract held by GOLDCAR and provided in response to the information requests made by the AEPD." Provide a copy of the
rental agreement no. ***REFERENCE.4 dated April 27, 2018.
NINTH: On January 17, 2025, the investigating judge agreed to conduct the following tests on the claimant:
- On April 10, 2024, the claimant provided two copies of the same vehicle rental agreement
signed with GOLDCAR:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 9/40
1) Vehicle rental agreement no. ***REFERENCE.4, start and end of rental
(...), to be exercised from April 27, 2018 to April 29, 2018, the client being the claimant, signed by both parties, and amount ***AMOUNT.1 €.
2) Vehicle rental agreement No. ***REFERENCE.4, start and end of rental
(...), to be exercised from April 27, 2018 to April 30, 2018, client, the complaining party, signed by both parties, and amount ***AMOUNT.2.
The complainant was asked to explain the reason and purpose of the existence
of these two copies of the agreement with different terms.
On January 17, 2025, the claimant provided the following requested information:
“- Vehicle rental agreement No. ***REFERENCE.4, from April 27, 2018
to April 29, 2018, for an amount of ***AMOUNT.1 €. This is an initial agreement
linked to the rental of vehicle ***REFERENCE.3, justifying the start and
payment of the rental, delivered at the start of the rental.
- Vehicle rental agreement No. ***REFERENCE.4, from April 27, 2018
to April 30, 2018, for an amount of ***AMOUNT.2. This agreement includes
the one-day extension of the initial rental, and also includes
expenses after the end of the rental, as shown, a traffic fine, delivered after the end of the rental.”
TENTH: A list of documents included in the proceedings is attached as an annex.
From the actions taken in this proceeding and from the documentation
in the file, the following have been established:
PROVEN FACTS
FIRST: On April 27, 2018, at 12:58 p.m., A.A.A. and GOLDCAR signed the
rental contract for vehicle no. ***REFERENCE.4, to be used from April 27, 2018, to April 29, 2018, for an amount of ***AMOUNT.1 €, with the rental contract starting and
ending on (...). Said contract, number ***REFERENCE.4, was
later extended until April 30, as shown on the payment invoice for
the vehicle rental ***REFERENCE.3, dated June 22,
2018, at 4:51 p.m.
These contracts include a section on "Specific Conditions" with the following content:
"This contract is subject to a mileage limit according to the following values: contracts of 1 to 3 days duration: 350 km/day; 4 to 6 days: 250 km/day; 7 to 14 days: 150 km/day; and 15 days or more: 100 km/day. Only one of the above limits applies to each contract: the one that corresponds
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 10/40
depending on its duration. €0.15 per km will be charged on the total kilometers that exceed the limit. The vehicle may not be driven outside the Spanish mainland,
or, in the case of rentals contracted in the Balearic or Canary Islands, it may not be
left to leave the island where the vehicle was delivered. vehicle, unless there is
express and signed authorization from the company in both cases and the corresponding extraordinary ADDITIONAL COVERAGE is contracted and
paid for. It is not permitted to take the vehicle from mainland Spain to Africa. If the vehicle receives
a fine during the validity period of this contract, you will be
responsible for the amount of the fine, and a €45 charge will also be made for
fine management. The Premium Office Charge is 8.00%.
These contracts also include details of the stipulated "General Rental Conditions." Of the information stated in this document, it is important to highlight the following:
“10. Unauthorized use.
The customer shall be obligated to use the vehicle with due diligence, in accordance
with its characteristics, respecting current motor vehicle traffic regulations and avoiding, in any case, any situation
that could cause damage to the vehicle or to third parties.
Furthermore, it is the customer's obligation not to allow
anyone other than those authorized in accordance with this contract to drive the vehicle.
The customer shall be directly liable for any damage or harm caused to
the vehicle or to third parties in such a case....”
“16. Computer processing of personal data.
For the purposes of current regulations regarding the protection of
personal data and information society services and
electronic commerce, Goldcar informs you that your personal data will be
incorporated into an automated personal data file
created and under the responsibility of this company, with registered office at..., in order
to manage the contracted vehicle rental services, as well as to keep you promptly informed of all offers,
products, and promotions, whether its own or those of third parties, that may be of interest to you,
either by email or by any other equivalent means. In the
case of commercial communications via email or equivalent means, you expressly consent to the sending of
advertising through said means. This consent may be revoked
at any time by written request addressed to the address..., or
by email to the address...
Likewise, your data may be transferred to other companies in the
transport and tourism sectors that collaborate now or in the future in the... activities carried out by Goldcar, so that they can carry out promotional activities.
Finally, we inform you that you may exercise your rights of access,
modification, or cancellation by written request addressed to…”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 11/40
SECOND: On April 30, 2018, at 11:21 a.m., A.A.A. He filed a report with the Judicial Police - (...), report no. ***REFERENCE.5, for the disappearance of the rental vehicle with license plate ***REFERENCE.3, in which he states the following:
“That the complainant presents himself to this investigation as the driver of the rental vehicle with license plate..., property of the company GOLDCAR.
That he left the vehicle perfectly parked and locked, in the area near Neptuno...
That the complainant gave the keys to his girlfriend to keep at the hostel while he went to work... and that they would be left later so that he could take her to the airport and leave the rental car in the company's parking lot.
That because the complainant couldn't pick up his girlfriend to take her to the
airport and because she wasn't authorized to drive the car and would miss her flight if she waited, the woman left the keys
hidden in the vehicle's wheel well, later notifying the complainant so
he could pick up the vehicle and deliver it.
That the complainant showed up in the area and couldn't find the vehicle... he began
driving around the surrounding areas... but couldn't find it.
That the complainant notified national and municipal police patrols, who
conducted sweeps of the area, all efforts being unsuccessful...
That the complainant notified GOLDCAR by telephone,
informing them to file a report with the police authorities and
subsequently go to the rental office..."
This report was submitted by the complainant to GOLDCAR along with a form
entitled "BREAKDOWN INFORMATION," which includes the car and customer information
and an explanation of how the complainant lost the vehicle.
He stated that he left the vehicle keys with a third party, who in turn
hidden them in the vehicle's wheel well for the complainant to collect
the vehicle, which disappeared before the complainant could collect it.
THIRD: On August 28, 2018, the rented vehicle with license plate
***REFERENCE.3 was recovered by the police in Poland, as confirmed in The
email sent by the police to GOLDCAR read as follows: "As indicated by a GOLD CAR employee, following a call, we are proceeding to communicate the details of the Polish Police service that recovered the vehicle ***MAKE 1, white, with license plate
***REFERENCE 3. ** Polish Police: *(...)"
FOURTH: The claimant reserved a vehicle from GOLDCAR with number
***REFERENCE.2 to be used from June 9, 2021, to June 16, 2021. However, the vehicle rental was denied for the reason stated in the handwritten note included in the vehicle reservation document, validated with a stamp bearing the name, address, and CIF (Tax ID Number) of GOLDCAR. The text of this note reads: "(...)" (sic). GOLDCAR acknowledged the refusal to rent said vehicle in its response to the request made by the AEPD on April 8, 2024 (emphasis added):
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 12/40
"(...) According to our information, there was An incident occurred with the return of the vehicle rented by the claimant on April 28, 2018, as the client breached GOLDCAR's general terms and conditions. In particular, he breached Clause 10 by allowing a third party to drive the vehicle without informing GOLDCAR of the existence of a second driver. In this regard, this clause expressly states: "Furthermore, it is the client's obligation not to allow the vehicle to be driven by any person other than those authorized in accordance with this contract. The client shall be directly liable for any damage or harm caused to the vehicle or to third parties in such a case."
As a result of a third party gaining access to the vehicle, the vehicle was stolen or at least disappeared, and the client was unable to return it during the rental period. The vehicle was recovered by the police in August 2018 in Poland, and
GOLCAR was required to cover the costs of repatriating the vehicle, the services of the vehicle recovery and complaint management company, the payment of fines
imposed on the vehicle during this period, and the cost of cleaning the vehicle.
In response to this incident, our insurance department could have
written an internal note in the customer file to address the breach of contract, the recovery of the vehicle, and the costs arising from the incident.
Currently, there is no note on the customer file, likely due to the
time elapsed since the incident, but it is possible that the agent, at the time of processing the reservation and delivery of the vehicle, could have seen this information on the customer file and, upon verifying that there was a breach of contract, decided not to deliver the car..."
FIFTH: GOLDCAR provided the proceedings with a copy of its Privacy Policy, in its current version updated as of May 1, 2024. According to GOLDCAR, this Privacy Policy was developed "as a result of the process of adapting to the GDPR." The following are highlighted from the content of this document:
"3. For what purposes do we process your personal data?
" We collect and process your personal data for various purposes and on the following legal grounds:
Purposes of processing:
Management and maintenance of account freezes for customers with contractual risks based on:
Payment incidents that have given rise to legal proceedings;
Vehicle accidents or repeated damage or offenses against our employees;
Use of our vehicles in violation of the general vehicle rental conditions.
Legal grounds:
This processing is based on our legitimate interest, in particular, the defense
of our rights, to prevent risks and fraud related to the
execution of your rental contract, and to prevent and manage offenses against our employees.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 13/40
In this regard, we try to maintain a fair balance between the need to process your personal data and respect for your rights and freedoms, in particular the protection of privacy. If you appear in our customer alert system, your booking request will be rejected. You can object to this decision by sending an email to the following address: dpo@goldcar.com.
5. How long will we retain your personal data? Your personal data is retained for different periods, depending on the purposes of the processing:
Purpose: The management and maintenance of a list of customers with contractual risks based on:
Payment incidents that have given rise to legal proceedings;
Vehicle accidents or repeated damage or offenses to our employees;
Use of our vehicles in violation of the general vehicle rental conditions
Retention period
3 or 5 years from the date of creation or modification of the last rental and
depending on the nature of the incident."
"6. What rights can you exercise regarding the processing of your personal data?
Within the limits and conditions permitted by current regulations,
you can:
(…)
object to the processing of your personal data based on a legitimate interest,
which you can verify by reviewing the table in the section "For what
purposes do we process your personal data?" and particularly in the section "Legitimation
Basis."
LEGAL BASIS
I
Jurisdiction
In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (the General Data Protection Regulation, hereinafter GDPR) and as established in Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), the President of the Spanish Data Protection Agency is competent to resolve this procedure.
Likewise, Article 63.2 of the LOPDGDD establishes that: "The procedures
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 14/40
processed by the Spanish Data Protection Agency shall be governed by the provisions
of Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development, and, insofar as they do not contradict them,
subsidiarily, by the general rules on administrative procedures."
II
Preliminary Questions
Article 4(1) of the GDPR defines "personal data" as:
"any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is any person whose identity can be determined, directly or indirectly, in particular by reference to an identifier,
such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person."
Article 4(2) of the GDPR defines “processing” as:
“any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.”
Article 4(7) of the GDPR defines “controller” or “controller” as:
“the natural or legal person, public authority, agency or other body which, alone or
jointly with others, determines the purposes and means of processing; where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be
laid down by Union or Member State law.”
Article 4.7 of the GDPR defines "processor" or "processor":
"the natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller."
In the present case, in accordance with the provisions of Articles 4.1 and 4.2 of the GDPR,
personal data processing is established, since GOLDCAR
carries out, among other processing operations, the collection and storage of personal data of natural persons, such as: name and surname, telephone number, and address, among others.
GOLDCAR carries out this activity in its capacity as data controller, given
that it determines the purposes and means of such activity, pursuant to Article 4.7 of the GDPR.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 15/40
III
Allegations to the Initiation Agreement
In relation to the allegations made to the initiation agreement of this sanctioning procedure, the following are addressed in the order
set forth by GOLDCAR:
FIRST: Based on the legitimacy of data processing.
In the present case, the processing of the complainant's personal data by GOLDCAR originates from the vehicle rental contracts that both parties signed on April 27 and 30, 2018.
During the period of use contracted by the complainant, the rented vehicle was
stolen by a third party and was finally located and recovered by the Police in
Poland on August 28, 2018.
The case records show that, prior to the theft of the vehicle in question, the complainant gave his partner the keys, who then hid them in the car's wheel well for him to retrieve.
This never happened due to the theft.
These events were assessed by GOLDCAR as a serious precedent and
determined that said entity made the appropriate note in the complainant's customer file to deny future rentals of vehicles from its fleet, as
occurred in June 2021 when the complainant attempted to reserve
a GOLDCAR vehicle, as described in the Fourth Proven Fact.
The disputed data processing, which gave rise to this sanctioning procedure, relates to the recording of the incident that occurred with the return
of the vehicle rented in 2018 and the negative note made in the customer file,
as well as the use of this personal data in June 2021 to
deny the complainant the reservation they requested from GOLDCAR for a new vehicle rental.
The controversy surrounding this processing relates to its legality, not to the certainty
of its implementation, which has been conclusively proven and even admitted by GOLDCAR.
This and no other is the purpose of this procedure, so this act does not constitute
any pronouncement on other aspects revealed in the proceedings,
such as GOLDCAR's new Privacy Policy or the record of "positive" annotations
in customer files provided by this entity, among others.
a) In this regard, firstly, GOLDCAR considers that at all times it has
conducted legitimate processing of the data in accordance with the regulations in force at each occasion. It is noteworthy that a first vehicle rental contract was signed with the
claimant for the period between April 27 and 29, 2018, that is, prior to the GDPR coming into force on May 25, 2018. The law in force at the time was Organic Law 15/1999 on the Protection of Personal Data (LOPD), which established what information should be provided to data subjects regarding the processing of their data in Article 5. Under this article, data subjects should be informed of the existence of the file, the purposes of its collection, and the recipients, as well as the possibility of exercising the data subject's rights and the contact information of the data controller. Consequently, it was not necessary to provide information about the legal basis for processing the data, nor about its retention period.
The company points out that Section 16 of the General Rental Conditions applicable at the time of the contract included a data protection clause, which
informed the parties of the requirements of the aforementioned Article 5 of the LOPD: "For the purposes of the provisions of current regulations […] GOLDCAR informs you that your personal data will be incorporated into an automated personal data file created and under the responsibility of this company […] in order to manage the contracted vehicle rental services (…)".
Thus, the data was collected and processed for the management of the contracted vehicle rental services without obtaining consent in accordance with Article 6.2 of the LOPD (Spanish Data Protection Act), according to which processing for contractual purposes was limited to the parties to a contract when the processing was necessary for the maintenance or fulfillment of the contractual relationship. The General Conditions of Contract established in Clause 10 that the use of the vehicle by unauthorized persons constituted a breach of the contractual relationship. Clause 10, paragraph 11 of the specific conditions established: "Goldcar reserves the right to cancel delivery of the vehicle in the event of well-founded doubts regarding the customer's financial capacity or due to a history of non-payments or serious incidents with Goldcar."
GOLDCAR thus explains that, at the time the complainant's data was collected, it was collecting and processing the customer's personal data within the scope of the contract and could decide to include an incident report in the event of a breach of its terms and conditions. It adds that the management of the incident and potential future risks arising from non-compliance are processed in accordance with the legitimate interest to prevent the risks associated with the provision of vehicle rental services, particularly those related to fraud, personal injury resulting from traffic accidents, damage to GOLDCAR's fleet, and illegal activities carried out with stolen or lost vehicles.
As GOLDCAR points out, Organic Law 15/1999 on the Protection of Personal Data required the responsible entity to inform data subjects at the time of data collection about the purpose for which the data would be processed. However, the information provided to the complainant at the time of
formalizing the vehicle rental contracts signed in April 2018, which
is reproduced in full in the First Proven Fact, was limited to informing
the complainant about the use of data to manage vehicle rental services and
for promotional purposes, without warning about the possibility of recording records that
would lead to the blocking of the customer account so that GOLDCAR could
reject future vehicle reservations.
This data processing, which, as indicated, constitutes the subject of this
procedure, has a purpose other than the execution of the contract. Nothing was included
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 17/40
in that information clause regarding this data processing, so the complainant had no opportunity to know that their personal data would be recorded in GOLDCAR's systems for this purpose.
Furthermore, although this AEPD is not responsible for deciding on compliance or non-compliance with the stipulations agreed by the parties in the vehicle rental contract, it is important to note, for the purposes of this matter, that it has not been proven that the complainant breached the obligation not to transfer use of the vehicle to an unauthorized person. The proceedings do not contain any evidence, beyond the fact that
the complainant handed the car keys to his partner, that this person drove the vehicle.
Nor has it been proven that the "specific conditions" stipulated in
those vehicle rental contracts signed in April 2018 authorized
GOLDCAR to cancel the delivery of rental vehicles in the event of serious incidents or risks. The "specific conditions" stated in said
contracts are detailed in the First Proven Fact, and nothing indicated therein is related to the data processing in question.
b) In any case, it is noted that the data recorded by GOLDCAR, which
includes all the details regarding the circumstances described in the Second and Third Proven Facts, including the theft of the vehicle while it was
being used by the claimant, as well as the "alert" regarding the blocking of future contracts, remained in the responsible entity's systems, at least until the complaint that gave rise to the proceedings was known.
Despite this, GOLDCAR did not establish the appropriate measures to adapt this data processing to the requirements of the GDPR.
GOLDCAR emphasizes that, during the GDPR adaptation process, the personal data retention policies are reviewed, and this information is included in the privacy policy in accordance with the information and transparency requirements set forth in Article 13 of the GDPR. A balance is also made between its legitimate interest and that of third parties in preventing risks and fraud related to rental contracts, as well as preventing and managing offensive behavior toward its employees and the freedoms and rights of those affected (customers). For this reason, GOLDCAR carried out an Impact Assessment and currently has a procedure for managing incidents and including notifications in customer files. This procedure
establishes the specific circumstances in which a notice could be included, the
consequences, and the duration of the measure depending on the severity of the
events or the potential harm to GOLDCAR and the personnel authorized to handle
the incidents. GOLDCAR therefore considers that, had it occurred,
maintaining the incident note in the customer's file was legitimate based
on the existing contractual relationship with the customer and, subsequently, on the entity's legitimate interest. However, it notes that at the date of the various requests for
information, no incident notice existed in the customer's file.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 18/40
It is important to reiterate that GOLDCAR may be processing data beyond its initial contractual purpose by maintaining internal notes or notices about non-compliance without having previously reported this additional use.
Furthermore, with the entry into force of the GDPR on May 25, 2018, GOLDCAR was required to comply with the broader information requirements established in Article 13, including detailing the legal basis and retention period, as well as conducting an impact assessment and properly weighing its legitimate interest against the rights of the data subjects.
GOLDCAR has stated that it has made this adjustment and has provided
some of the documents prepared for this purpose, although it has not proven when this adjustment was made and, more importantly for the resolution of this case, it has not proven that it properly informed the
complainant about this processing so that they could understand how their data was being
used and exercise their rights, such as the right to object to data processing based on the controller's legitimate interest, given that such internal notices could have a future impact on the complainant.
Even if GOLDCAR had provided the complainant with the information provided,
this information does not guarantee that the complainant would have been fully aware
of the use of their personal data to exclude them from future contracts based
on the events that occurred in 2018.
GOLDCAR's current Privacy Policy, dated May 1, 2024, well after the events analyzed, contemplates "The management and
maintenance of the account freeze for customers with contractual risks based
on:
. payment incidents that have given rise to legal proceedings;
. vehicle accidents or repeated damage or offenses to our employees;
. use of our vehicles in violation of the general vehicle rental conditions.
It has already been stated previously that there is no certainty regarding the
complainant's breach of the general or specific conditions.
Likewise, the facts established in relation to the incidents that occurred in 2018 They do not allow for establishing a direct, cause-and-effect relationship between the complainant's conduct and the theft of the vehicle that would justify attributing any responsibility to him for this theft. It can be concluded that GOLDCAR's recording of these incidents and the entry made in the complainant's customer file to prevent or avoid future risks, which led to the rejection of the vehicle rental in 2021, is the result of GOLDCAR's subjective assessment of the facts, which makes it difficult for the complainant to even intuit that his personal data would be processed for this purpose and that, based on this, he would be subject to this exclusion.
These facts also do not comply with the statements contained in this Privacy Policy. There are no records of non-payments, accidents, or damage to the vehicle that are
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 19/40
attributable to the complainant, nor Offenses against GOLDCAR employees or proven breaches of the general vehicle rental conditions.
SECOND: Regarding the weighing of GOLDCAR's legitimate interest and the rights of its customers.
Regarding the accreditation of legitimate interest, GOLDCAR considers the processing of data in accordance with its legitimate interest to be lawful, noting that the GDPR itself, in its recital 47, provides the following: "The processing of personal data strictly necessary for the prevention of fraud also constitutes a legitimate interest of the data controller in question." Thus, it would pursue fraud prevention and the protection of its employees, including the interests of third parties in the event of an accident involving a stolen or lost car resulting in material or personal injury to third parties, since insurance companies and policies do not cover damages without limitations.
GOLDCAR argues that this need arises from the risk of the vehicle rental business, in which fraud can occur. and even
the commission of other types of crimes, resulting from false information provided by customers, damage caused to vehicles, property or personal injury caused
in accidents involving stolen or missing vehicles, theft of vehicles with the
possibility of them being used to commit crimes. It reports that
vehicle rental is subject to the documentary registration obligations provided
for in Organic Law 4/2015, of March 30, on the protection of public safety.
GOLDCAR continues by noting that the following measures were adopted to
minimize potential risks:
"In order to avoid a possible violation of the rights of those affected, the handling of incidents was limited to specific
cases that posed serious harm to the entity, either by
possibly causing serious economic harm, the possibility that customers
could commit fraud or a crime, or that could pose a risk to the
physical or moral integrity of GOLDCAR staff.
" In all cases, it is verified and ensured that the data collected or
used to include a note is not related to or collected
due to birth, race, sex, religion, opinion, or any other
personal or social condition or circumstance, in accordance with Article
14 of the EC.
Those affected are informed of the consequences of the processing and that
they have the right to expressly appeal this decision to the
entity's DPO.
An internal protocol is established for the management of these situations,
which expressly indicates the cases in which incidents may be reported.
That is, this data may only be processed in
cases of (i) payment incidents that have given rise to legal proceedings;
(ii) vehicle accidents or repeated damage or offenses to
our employees; and (iii) use of our vehicles in violation of the
general vehicle rental conditions. Likewise, it is expected that
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 20/40
Depending on the severity of the incident, the recording period will be adjusted between 3 and 5 years.
This possibility is reported in the privacy policy, as well as the
data retention period and the possibility of appealing the
decision.
The data must be processed by personnel expressly authorized
for this purpose.
Any incident must be documented; if it is not possible
to document it, the processing of this data will not be possible.
If it is decided to include a notice or alert in the customer record,
it is entered manually by authorized personnel with the minimum information so that counter staff cannot access the complete incident information; they are only aware
of the existence of the note or notice in the record and the severity rating of the incident.
Furthermore, under no circumstances is this data shared with third parties,
unless it is necessary to inform the State Security Forces and/or the competent courts and tribunals.
No data is collected from external sources in relation to incidents.
The only information that may be included from third parties will be that
provided by the courts and tribunals or the security forces in cases where the incident is the subject of judicial proceedings or an investigation by the competent authorities. In any case, this information is not included in the customer file, but is processed by the relevant departments within the company.
The complainant points out that, on the date of the second contract, all this information was provided
in GOLDCAR's General Terms and Conditions and in its privacy policy, without the complainant contacting our customer service or the DPO, as stated in the privacy policy.
The complainant also points out that, by analogy, one could speak of a "reservation of the right of admission" with respect to future rentals that the customer may make and
mentions that case law requires that the rules on the conditions of admission must be publicized, arguing that the privacy policy informs of the existence of the processing, the specific cases in which it may occur, and the consequences of the processing. Additionally, the General Terms and Conditions establish, in the present case, that lending the vehicle to third parties without the lessor's authorization is a breach of the vehicle's conditions of use. Likewise, the specific conditions specify that, In the event of non-compliance, the entity reserves the right to refuse delivery of the vehicle.
a) Regarding all these statements, we can refer to what was expressed in the previous section, which provides a sufficient answer to them. However, it should be emphasized that the complaining party had no reason to know about the notes that
existed in its customer file and their purpose, so it is not understood that GOLDCAR
justifies its conduct by attributing to the complainant responsibility for having
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 21/40
contacted its customer service or not after it published its new privacy policy, which, furthermore, is unknown whether it occurred prior to or subsequent to the
rejection of the car rental reservation requested by the complainant in June
2021.
b) Likewise, this Agency wishes to point out that GOLDCAR claims that its legitimate interest
protects the processing of personal data, relying on recital 47 of the
GDPR, which indeed mentions that fraud prevention may constitute a
legitimate interest of the controller, although in this case there is no certain evidence that
the complaining party committed any fraud as a result of the rental contracts
of April 2018, beyond GOLDCAR's own assessment of the facts in this regard.
Furthermore, Article 6.1.f) of the GDPR requires that the legitimate interest invoked by the
responsible entity does not prevail over the interests, rights, and fundamental freedoms of the data subjects that require the protection of personal data, without
sufficiently proving the legal basis for its processing of customers' personal data when it includes internal alerts for prior incidents.
Regarding the legal basis for legitimate interest, Article 6 of the GDPR states:
“1. Processing shall only be lawful if at least one of the following conditions is met:
f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child…”
Recital 47 of the GDPR specifies the content and scope of this legitimate basis for processing:
“(47) The legitimate interest of a controller, including that of a controller to which personal data may be disclosed, or of a third party, may provide a legal basis for processing, provided that the interests or rights and freedoms of the data subject are not overridden, taking into account the data subjects’ reasonable expectations based on their relationship with the controller. Such a legitimate interest could arise, for example, where there is a relevant and appropriate relationship between the data subject and the controller, such as in situations where the data subject is a client or employee of the controller. In any case, the existence of a legitimate interest would require a careful assessment, including whether a data subject could reasonably foresee, at the time and in the context of the collection of personal data, that processing for such purposes might take place. In particular, the interests and fundamental rights of the data subject could prevail. over the interests of the data controller when personal data are processed in circumstances where the data subject does not
reasonably expect further processing to take place. Since it is for the legislator to establish by law the legal basis for the processing of personal data by public authorities, this legal basis should not apply to processing carried out by public authorities in the exercise of their functions.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 22/40
The processing of personal data strictly necessary for the prevention of fraud also constitutes a legitimate interest of the data controller in question. The processing of personal data for direct marketing purposes
may be considered to be carried out on the basis of legitimate interest.
The interpretative criteria drawn from this Recital are, among others, (i) that the legitimate interest of the controller prevails over the interests or fundamental rights and freedoms of the data subject, in light of the data subject's reasonable expectations based on the relationship he or she maintains with the controller; (ii) a "meticulous assessment" of the rights and interests at stake will be essential, also in cases where the data subject can reasonably foresee, at the time and in the context of data collection, that processing for this purpose may take place; (iii) the interests and fundamental rights of the personal data subject could prevail over the legitimate interests of the controller when the data processing is carried out in circumstances where the data subject "does not reasonably expect" that further processing of his or her personal data will take place. GOLDCAR has not sufficiently substantiated this legitimate interest to allow the necessary balancing test between the controller's interest and the data subject's rights to be carried out.
In this case, furthermore, there is no evidence that the aforementioned entity had carried out this balancing test
prior to collecting the complainant's data and making the entries in his customer file, nor that it duly informed the complainant
of this legitimate basis, at that time or at a later time.
The respondent entity did not carry out this prior analysis and at no time informed the
complainant about this legal basis for the processing.
In the absence of information regarding the balancing test, the data subject is deprived
of his right to know the legal basis for the processing claimed by the controller, and
specifically, by referring to legitimate interest, he is deprived of his right to know
what legitimate interests are claimed by the controller or a third party that
would justify the processing without taking his consent into account.
Similarly, the data subject is deprived of his or her right to allege the reasons why
the legitimate interest claimed by the controller could be outweighed by the data subject's
rights or interests. Since the data subject has not been given the opportunity
to assert these rights to the controller, any assessment carried out by the controller
without taking into account the circumstances that the data subject could allege, who has not been
allowed to do so, would be flawed, as it would be contrary to a mandatory
law.
It is difficult to accept that processing is based on the legitimate interest of the controller
when that processing is carried out in a hidden manner.
Therefore, it is not possible to invoke this legal basis of legitimate interest "a posteriori"
in the course of administrative proceedings. Accepting this would be tantamount to admitting a legitimate interest that arose, regarding which the requirements set forth in personal data protection regulations have not been respected.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 23/40
and about which the complainant was not informed.
However, although it is clear that legitimate interest is not applicable in the present case,
it is important to analyze the terms under which the balancing provided for in
Article 6.1.f) of the GDPR between the legitimate interest of the data controller and the
protection of the personal data of the data subject should be carried out, that is, how said legitimate interest plays out, if applicable.
The CJEU, in its judgment of 04/05/2017, C-13/16, Rigas Satskime, paragraphs 28 to 34,
determined the requirements for processing to be lawful on the basis of legitimate interest. The CJEU judgment of 29/07/2019, C-40/17, Fashion ID, echoing the aforementioned judgment, includes these requirements.
28. In this regard, Article 7(f) of Directive 95/46 (currently Article 6.1.f) of the GDPR)
sets three cumulative requirements for the lawfulness of processing personal data:
first, the controller or the third party or parties to whom the data are disclosed must pursue a legitimate interest; Second, the processing must be necessary to satisfy that legitimate interest, and third, the fundamental rights and freedoms of the data subject do not prevail in relation to data protection.
This legal basis requires the existence of real, non-speculative, and legitimate interests. The existence of that legitimate interest does not simply mean that those processing operations can be carried out. It is also necessary that these processing operations be necessary to satisfy that interest and that the impact on the data subject, the level of intrusion into their privacy, and the effects that may negatively impact them, must be considered.
Regarding the first requirement, that is, that the data controller or third parties pursue a legitimate interest, such as preventing fraud, we are faced with an interest that could be considered legitimate in itself, although this interest must be weighed against that of individuals based on the processing of personal data that involves preventing fraud. That is,
even if the controller has such a legitimate interest, this does not mean, in itself, that this legal basis can simply be invoked as the basis for processing.
The legitimacy of this interest is merely a starting point, just one of the
elements that must be considered.
Regarding the second requirement, however, it is considered that the processing of personal data carried out by GOLDCAR is not necessary or strictly necessary for the satisfaction of the legitimate interest claimed (the aforementioned judgment of 04/05/2017, C-
13/16, Rigas Satskime, in paragraph 30, states: "With regard to the requirement that data processing be necessary, it should be recalled that exceptions and restrictions to the principle of protection of personal data must be established without exceeding the limits of what is strictly necessary").
Thus, less invasive means should always be preferred to serve the same purpose. Necessity here means that the processing is essential for the satisfaction of the aforementioned interest, so that, if this objective can be reasonably achieved in another way that produces less impact or is less intrusive, the legitimate interest cannot be invoked.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 24/40
The term "necessity" used in Article 6.1 f) of the GDPR has, in the opinion of the CJEU, a
distinct and independent meaning in Community law. It is an "autonomous concept of Community law" (CJEU, 16/12/2008, case C-
524/2006, paragraph 52). Furthermore, the European Court of Human Rights (ECtHR) has also offered guidelines for interpreting the concept of necessity. In its judgment of March 25, 1983, it clarified that, without prejudice to whether the processing of the complainants' data is "useful," "desirable," or "reasonable," as the ECHR clarified in its judgment of March 25, 1983, the term "necessary" does not have the flexibility implied in these expressions.
The more "negative" or "uncertain" the impact of the processing may be, the more unlikely it is that the processing as a whole can be considered legitimate.
As can be seen, the above is in line with the Constitutional Court's doctrine regarding the proportionality assessment that must be made regarding a measure restricting a fundamental right. According to this doctrine, three requirements must be met: suitability (whether the measure allows the proposed objective to be achieved); necessity (whether there is no other, more moderate measure); and proportionality in the strict sense (more benefits or advantages than harm).
In short, leaving aside the fact that the data subject does not know for what purposes or on what legal basis their data was collected, nor does they even know how it was processed, it is understood that the collection and use of the complainant's data by GOLDCAR constitutes disproportionate processing of personal data.
It is especially noted that the information retained by GOLDCAR does not
conclusively refer to fraud committed by the complainant and the harm or discriminatory effects that the processing has caused them.
The result of the actions taken by GOLDCAR is the creation of a "customer blacklist," a data processing that, as stated, is not
covered by the contractual relationship, to the extent that this processing does not end
with the expiration of the contractual relationship, but rather continues for a different purpose; and requires another legal basis to legitimize it, as well as compliance with all the principles and guarantees provided for in the GDPR (transparency, purpose limitation, data minimization, retention period limitation, etc.).
The Legal Office of this AEPD has had the opportunity to comment on this issue regarding "blacklists." Report 0201/2010, whose conclusions are perfectly valid, states the following:
"The first question arising from the consultation is what should be understood by a blacklist, given that there is no legal concept to which we can turn in our law. In this regard, the Article 29 Working Party, the EU's independent advisory body on data protection and privacy, established pursuant to the provisions of the aforementioned article of Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data, in its working document on blacklists of October 3, 2002, addressed in general terms a possible basic concept of a blacklist, defining it as "the collection and dissemination of certain information relating to a specific group of persons, compiled in accordance with the provisions of the aforementioned article of Directive 95/46/EC." www.aepd.es
28001 – Madrid sedeaepd.gob.es 25/40
compliance with certain criteria depending on the type of blacklist in question, which generally entails adverse and harmful effects for the people included in it, which may consist of discriminating against a group of people by
excluding them from accessing a certain service or damaging their reputation.
This document states that, since any operation or set of operations
applied to personal data constitutes processing of personal data subject to
Directive 95/46 EEC and the respective data protection regulations
in each Member State, for blacklists to legally exist,
they must be subject to the principles of legitimacy set forth in said Directive and
respect the rights conferred on citizens by it, unless they can avail themselves of any of the exceptions provided therein.
The translation of these principles into Spanish law is found in Article 6 of
Organic Law 15/1999, of December 13, on the Protection of Personal Data, according to which "1. The processing of personal data shall require
the unequivocal consent of the data subject, unless otherwise provided by law.
2. Consent will not be required when personal data is collected
for the exercise of the functions of public administrations within the scope of their powers; when it relates to the parties to a contract or pre-contract of a business, employment, or administrative relationship and is necessary for its maintenance or fulfillment; when the processing of the data is intended to protect a vital interest of the data subject under the terms of Article 7, section 6, of this Law; or when the data is contained in publicly accessible sources and its processing is necessary to satisfy the legitimate interest pursued by the data controller or by the third party to whom the data is communicated, provided that the fundamental rights and freedoms of the data subject are not violated.
Thus, except for those cases in which blacklists have some legal basis, as is the case in Spanish law with the financial solvency and credit files regulated by Organic Law 15/1999 and whose basis is the legitimate interest in preserving and stabilizing the financial system, or are legitimized in any of the cases provided for in Article 6.2 of Organic Law 15/1999, the inclusion of personal data in a blacklist would require the consent of the data subject to comply with the provisions of data protection regulations.
As this report clearly indicates, a clear example of these lists is credit reporting systems, whose regulations expressly establish the objective factual circumstances that determine the recording of personal data in said system, as well as the need, as a determining requirement for the legality of data processing, to provide prior information about the possibility of recording the data if the factual circumstances that determine the recording objectively occur.
Ultimately, the legitimate interest invoked by GOLDCAR does not prevail over the claimant's fundamental rights and freedoms in the protection of their personal data, so the processing of personal data it carries out cannot be considered to be protected by the legitimate interest provided for in Article 6.1.f) of the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 26/40
GDPR.
Nor does the data subject provide consent for such data processing.
As will be explained below, in accordance with the provisions outlined above, the processing of personal data that is the subject of the claim requires the existence of a legitimate legal basis, such as the valid consent of the data subject, which is necessary when no other legal basis exists as mentioned in Article 6.1 of the GDPR, or when the processing pursues a purpose compatible with the purpose for which the data was collected.
c) GOLDCAR mentions that vehicle rentals are subject to certain documentary obligations under Organic Law 4/2015, of March 30, on the protection of public safety. However, this regulation does not generally allow the prolonged storage of incidents or the inclusion of internal alerts about customers for alleged breaches of contract, damages, or future risks assessed by GOLDCAR itself. The legal obligation set forth in this regulation refers to providing specific data to the authorities when requested, not to maintaining internal databases to anticipate non-compliance. Therefore, this argument does not justify the widespread or permanent processing of problematic customer data within the framework of Article 6 of the GDPR.
d) Furthermore, GOLDCAR lists several internal measures that do not replace or compensate for the lack of a valid legal basis under Article 6 of the GDPR regarding the processing of the complainant's personal data analyzed in this case. Thus, the safeguards adopted are relevant, but they still require compliance with the requirement that a valid legal basis exists for the processing.
e) Finally, this Agency wishes to point out that the claim regarding the right of admission does not fall within the scope of data protection, but rather under contract and commercial law. The GDPR does not regulate whether a company may or may not admit a client, but rather how it processes personal data in that context. Therefore, this argument is not relevant to justify processing under Article 6 of the GDPR.
THIRD: Regarding the culpability principle of the administrative sanctioning procedure.
GOLDCAR considers that the initiation of sanctioning proceedings is not appropriate, as there is no intentionality or negligence in the fulfillment of its duties as data controller, since, at all times, it has intended to process the data collected from its client in accordance with the regulations in force at all times and in compliance with the requirements of data protection regulations for the collection and processing of data.
In this regard, this Agency considers that the necessary measures to ensure compliance with the GDPR have not been effectively adopted. Thus, negligence is defined as omission, willful carelessness, and, in general, acting without the due level of care required according to the level of responsibility inherent to its position and the applicable regulations.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 27/40
FOURTH: Regarding the provisions of Articles 83.1 and 83.2 of the GDPR to be taken into account when calculating the fine.
Regarding the nature, severity, and duration of the violation, GOLDCAR reiterates that the data was collected and processed under the existing contractual relationship with the client, i.e., to manage the provision of the service and its fulfillment. It notes that the vehicle was picked up in 2018, and any violation related to the information provided to the client would have expired at that time. Additionally, without prejudice to any other considerations, there is a legitimate basis for processing data related to incidents based on the legitimate interest of GOLDCAR and third parties, the interest in preventing risks for GOLDCAR, its employees, and third parties.
GOLDCAR states that the data retention period it has been monitoring
is five years after the contract was signed, that is, at least until the statute of limitations for contractual liability claims expires, which is why the data
remained in its system in 2021. Since a new contract was signed on that date,
the data is again retained for a period of five years from the last contract. It goes on to explain that the notes on incidents in the customer record are also subject to a time limit and may be kept for a
period of between 3 and 5 years, depending on the severity of the incidents. In this regard,
due to the time elapsed, there is no incident note in the customer record. However,
documentation regarding contracts and incidents is available,
because there was a second contract and an incident with the delivery of the vehicle in 2021, but this information is only available to personnel
who need access to it.
Regarding the aggravating factor that "the activity of the allegedly infringing entity is linked to the processing of customer and third-party data," GOLDCAR reiterates that the only information taken into account to reflect an
incident in a customer file is that obtained from the contractual relationship.
Finally, GOLDCAR considers that no reference is made to other circumstances that
could, if applicable, mitigate liability, such as the fact that it has not been previously sanctioned by the AEPD, that it has not obtained any type of
benefit from the commission of the infringement, or that no serious harm was caused to the
interested party.
Regarding the allegation that the collection of personal data occurred in 2018 and that, therefore, any violation related to that time would be subject to a statute of limitations, this
Agency considers that the events subject to this sanctioning procedure
occurred on June 9, 2021, when delivery of the rented vehicle was denied due to an internal note relating to the events that occurred in 2018.
Consequently, data processing continued throughout this period, so that the three-year period established in Article 72 of the LOPDGDD for the
statute of limitations for the violation due to lack of standing provided for in Article 6 had not been
met at the time GOLDCAR was notified of the opening of this sanctioning procedure.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 28/40
Regarding the five-year retention period for records referred to by GOLDCAR, this Agency warns that this is a matter beyond the scope of the proceedings.
Regarding whether the fact that GOLDCAR's activity is linked to the processing of personal data is considered an aggravating factor, this Agency wishes to point out that Article 83.2 of the GDPR provides that "When deciding on the imposition of an administrative fine and its amount in each individual case, due account shall be taken of: (…) k) any other aggravating or mitigating factors applicable to the circumstances of the case…"
In this regard, the Spanish legislator has considered including in Article 76 of the LOPDGDD the following: "2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account:
(…)
b) The connection between the offender's activity and the processing of personal data."
This Agency simply takes into consideration this circumstance, provided for by the legislator, when deciding whether to impose an administrative fine.
It should be noted, of course, that for the purposes of deciding whether to impose an administrative fine, an infringement committed by an individual or a small company not accustomed to processing personal data cannot be considered in the same way as a company like GOLDCAR, which is accustomed to processing the personal data of hundreds of clients. Of course, the violation is considered more serious for the purposes of imposing a fine if the data controller is among the latter, as is the case with GOLDCAR. This was stated by the National Court in its SAN 65/2017, dated February 7, 2017, when it adopted the doctrine of the Supreme Court, stating that "in assessing the degree of diligence, the professionalism of the data subject must be given special consideration.
There is no doubt that, in the case examined, when the appellant's activity involves constant and extensive handling of personal data, rigor and exquisite care must be taken to comply with the legal provisions in this regard."
Finally, regarding GOLDCAR's statement that no reference is made
to other circumstances that could mitigate liability, such as the fact that it has not been previously sanctioned by the AEPD, that it has not obtained
any type of benefit from the commission of the infringement, or that no serious harm was caused to the interested party, this Agency wishes to point out that these circumstances cannot be considered
as mitigating factors. This is in accordance with the ruling of the
National Court, of 05/05/2021, rec. 1437/2020, which states: "It also considers that the non-commission of a prior violation should be considered as a mitigating factor.
Well, Article 83.2 of the GDPR establishes that, for the imposition of the administrative fine, circumstance "e) any prior violation committed by the controller or processor must be taken into account, among others. This is an
aggravating circumstance; the fact that the grounds for its application are not met means that it cannot be taken into consideration, but it does not imply or allow, as the plaintiff claims, its application as a mitigating factor."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 29/40
Penalties must be "in each individual case" effective, proportionate, and dissuasive, in accordance with the provisions of Article 83.1 of the GDPR. Thus, considering the fact that GOLDCAR has not been previously sanctioned by the AEPD, has not
obtained any type of benefit from the commission of the violation, or has not caused
serious harm to the interested party as mitigating factors would nullify the deterrent effect of the fine, to the extent that it lessens the effect of the circumstances that actually affect its quantification, giving the person responsible a benefit that they have not deserved. This would be an artificial reduction of the penalty that could lead to
the understanding that violating the rule without obtaining benefits, financial or otherwise,
will not produce a negative effect proportional to the seriousness of the violation.
In any case, the administrative fines established in the GDPR, in accordance with Article 83.2, are imposed based on the circumstances of each individual case, and the absence of benefits is not considered an appropriate and determining factor in assessing the seriousness of the infringing conduct.
Furthermore, in this case, it cannot be said that no harm has been caused to the claimant.
For all the reasons stated above, this claim is dismissed.
FIFTH: Regarding the adoption of measures.
GOLDCAR considers that it complies with the provisions of the GDPR and that it is not necessary to adopt measures to bring the processing into compliance with the regulations. It also notes that GOLDCAR welcomes any suggestions for improving internal procedures or data processing by the AEPD.
In this regard, this Agency positively assesses the measures implemented regarding the modification of the privacy policy and internal protocols to mitigate the risk that a case like this complaint could occur again.
However, regarding the adoption of measures, GOLDCAR is responsible for proactively ensuring compliance with data protection regulations, for which it remains obliged to prove the legitimacy for processing data in accordance with Article 6 of the GDPR.
IV
Obligation breached: Violation of Article 6.1 of the GDPR
Article 6.1 of the GDPR establishes the conditions that allow the processing of personal data to be considered lawful:
“1. Processing shall only be lawful if at least one of the following conditions is met:
a) the data subject has given his or her consent to the processing of his or her personal data for one or more specific purposes;
b) processing is necessary for the performance of a contract to which the data subject is a party or for the implementation, at the request of the data subject, of pre-contractual measures;
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 30/40
c) processing is necessary for compliance with a legal obligation applicable to the controller;
d) processing is necessary to protect the vital interests of the data subject or of another natural person.
e) processing is necessary for the performance of a task carried out in public interest or in the exercise of official authority vested in the controller;
f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
The provisions of point (f) of the first paragraph shall not apply to processing carried out by public authorities in the exercise of their tasks.
Likewise, Recital 40 of the aforementioned GDPR provides that "For processing to be lawful, personal data must be processed with the consent of the data subject or on another legitimate ground established by law, whether in this Regulation or under other Union or Member State law to which this Regulation refers, including the need to comply with a legal obligation applicable to the controller or the need to perform a contract with which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract."
Article 6 of the GDPR, on the "Lawfulness of Processing," determines in its paragraph
1 the situations in which the regulations permit the processing of personal data of a third party, which are referred to as "lawful grounds." If any of these situations or conditions are not met, the processing will not be legitimate, or considered lawful, under the GDPR.
Pursuant to this article, in addition to consent, there are other possible grounds that legitimize data processing without the need for the data subject's authorization. In particular, when it is necessary for the performance of a contract to which the data subject is a party or for the implementation, at the data subject's request, of pre-contractual measures, or when it is necessary for the protection of legitimate interests pursued by the data controller or a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject that require protection of such data. Processing is also considered lawful when it is necessary for compliance with a legal obligation applicable to the data controller, to protect the vital interests of the data subject or another natural person, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller. The complainant stated that the vehicle he had reserved through the respondent's website was not delivered to him because the signed contract included the
notation "The vehicle was not delivered to the customer due to a very serious warning from a 2018 Madrid contract."
GOLDCAR, for its part, has stated that:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 31/40
“According to our information, there was an incident with the return of the
vehicle rented by the claimant on April 28, 2018, since the
client breached GOLDCAR's general terms and conditions. In
particular, they breached clause 10 by allowing a third party to drive the
vehicle without informing GOLDCAR of the existence of a second driver.
In this regard, said clause expressly states:
“Likewise, it is the client's obligation not to allow the vehicle to be driven by
any person other than those authorized in accordance with this contract,
the client being directly liable for any damage or harm caused to
the vehicle or to third parties in such a case.”
As a result of a third party accessing the vehicle, the
vehicle was stolen or at least disappeared, without the client's knowledge. could
return it during the rental period. The vehicle was recovered by the
police in August 2018 in Poland, and GOLCAR had to assume the costs of
repatriating the vehicle, the services of the claims management company
and vehicle recovery, payment of the fines imposed on the vehicle
during this period, as well as cleaning the vehicle.
In response to this incident, our insurance department could have
written an internal note in the customer file to manage the
breach of contract, the recovery of the vehicle, and the costs arising
from the incident.
Currently, there is no note in the customer file, probably due
to the time elapsed since the incident, but it is possible that the agent, at
the time of processing the reservation and delivery of the vehicle, could have seen
this information in the customer file and, upon verifying that there was a
breach of contract, decided not to return the car, in accordance with
Clause 10, paragraph 11 of GOLDCAR's specific terms and conditions, which
state:
"Goldcar reserves the right to cancel the delivery of the vehicle in the event of well-founded doubts about the customer's financial capacity or due to a history of non-payments or serious incidents with Goldcar."
It can be concluded that the data processed comes from GOLDCAR itself and was retained as a result of an incident that occurred in 2018.
In the present case, GOLDCAR processed the complainant's personal data without legal grounds, as it was linked to an alert arising from a contract signed in 2018, which constitutes a violation of personal data protection regulations.
All the arguments expressed in the previous Legal Grounds serve to support this conclusion, according to which this processing of the complainant's data, carried out to block potential vehicle rentals from GOLDCAR, is not covered by the contractual relationship or the legitimate interest of GOLDCAR. The only basis for legal grounds in this case is the processing of the complainant's data. It can only result from
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 32/40
the consent of the interested party, validly given, although GOLDCAR has not proven that it has this basis for legitimacy, which, moreover, has not even been invoked by said entity.
Therefore, in accordance with the evidence currently available
in the proposed resolution of the sanctioning procedure, it is considered that the known facts constitute an infringement, attributable to GOLDCAR, for violation of Article 6 of the GDPR.
V
Classification of the infringement of Article 6.1 of the GDPR and qualification for the purposes of
limitation
Article 83.5 of the GDPR classifies the violation of the following articles as an administrative infringement, which shall be sanctioned, in accordance with section 2, with administrative fines of A maximum of EUR 20,000,000 or, in the case of a company, an amount equivalent to a maximum of 4% of the total annual global turnover of the previous financial year, whichever is higher:
"a) the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9;"
For its part, Article 71 of the LOPDGDD, "Infractions," states that:
"The acts and conduct referred to in sections 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law, constitute infringements."
For the sole purposes of the statute of limitations, Article 72.1 of the LOPDGDD
establishes the following:
"In accordance with the provisions of Article 83.5 of Regulation (EU) 2016/679, infringements that constitute a substantial violation of the articles mentioned therein, and in particular the following, are considered very serious and will be subject to a three-year statute of limitations:
b) The processing of personal data without any of the conditions for the lawfulness of processing established in Article 6 of Regulation (EU) 2016/679."
VI
Proposed sanction for infringement of Article 6 of the GDPR
In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR must be observed, which state:
“1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article for infringements of this Regulation indicated in paragraphs 4, 9, and 6 are, in each individual case, effective, proportionate, and dissuasive.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 33/40
2. Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or as a substitute for the measures provided for in
Article 58, paragraph 2, letters a) to h) and j). When deciding to impose a The administrative fine and its amount in each individual case shall duly take into account:
a) the nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage suffered by them;
b) the intentionality or negligence of the infringement;
c) any measures taken by the controller or processor to mitigate the damage suffered by data subjects;
d) the degree of responsibility of the controller or processor, taking into account any technical or organizational measures they have implemented pursuant to
Articles 25 and 32;
e) any previous infringements committed by the controller or processor;
f) the degree of cooperation with the supervisory authority in remedying the infringement and mitigating any adverse effects of the infringement;
g) the categories of personal data affected by the infringement;
h) the manner in which the supervisory authority became aware of the infringement, in
particular whether the controller or processor notified the infringement and, if so, to what extent;
(i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned in relation to the same matter, compliance with those measures;
(j) adherence to codes of conduct pursuant to Article 40 or certification mechanisms approved pursuant to Article 42; and
(k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement.
For its part, Article 76 "Sanctions and Corrective Measures" of the LOPDGDD
provides:
"1. The sanctions provided for in sections 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the grading criteria
established in section 2 of the aforementioned article.
2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account:
a) The continuous nature of the infringement.
b) The connection between the offender's activity and the processing of personal data.
c) The benefits obtained as a result of the commission of the infringement.
d) The possibility that the affected party's conduct could have led to the commission of the infringement.
e) The existence of a merger by absorption process subsequent to the commission of the infringement, which cannot be attributed to the offender. to the acquiring entity.
f) The impact on the rights of minors.
g) Having a data protection officer, when not mandatory, available.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 34/40
h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms in cases where there are disputes between them and any interested party.
In the present case, considering the seriousness of the potential violation, paying special attention to the consequences its commission has on those affected, a fine would be imposed, in addition to the adoption of measures, if appropriate.
The fine imposed must be, in each individual case, effective, proportionate, and dissuasive, in accordance with the provisions of Article 83.1 of the GDPR; and that to
guarantee these principles, the respondent's business volume, which amounted to €203,880,000 in fiscal year 2022, is taken into account as a preliminary matter.
For the purposes of deciding on the imposition of an administrative fine and its amount, in accordance with the evidence currently available in the proposed resolution of the sanctioning procedure, it is considered appropriate to grade the sanction to be imposed according to the following circumstances, contemplated in the aforementioned provisions.
First, it is deemed that the following circumstances exist:
- The nature, severity, and duration of the breach, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damages suffered.
(Article 83.2, letter a) of the GDPR): The facts revealed seriously affect a fundamental issue in data protection, such as the principle of lawfulness, which the law penalizes with the greatest severity. The defendant party lacks legal standing to process personal data that remained in its systems linked to an alert in 2021, resulting from an incident that occurred in connection with a contract concluded in 2018. It is also taken into account that the purpose of the processing is linked to the creation of a customer exclusion list, with the resulting effects.
- Intentionality/Negligence in the infringement (Article 83.2, letter b) of the GDPR):
GOLDCAR acted with serious lack of due diligence in its actions. In connection with the
degree of due diligence that the data controller is obliged to display in
compliance with the obligations imposed by data protection regulations,
the SAN of 10/17/2007 can be cited. Although it was issued before the GDPR came into force, its ruling is perfectly applicable to the situation we are analyzing. The ruling, after alluding to the fact that entities whose activities involve the continuous processing of client and third-party data must observe an adequate level of due diligence, specified that "(...) the
Supreme Court has held that negligence exists whenever a legal duty of care is disregarded, that is, when the offender fails to behave with the required due diligence. In assessing the degree of due diligence, the professionalism of the individual must be especially considered.
There is no doubt that, in the case now under consideration, when the appellant's activity involves constant and extensive handling of personal data, rigor and exquisite care must be emphasized to comply with the legal provisions in this regard."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 35/40
Furthermore, the following grading factors are considered aggravating factors:
- The connection between the offender's activity and the processing of personal data (Article 76.2, letter b) of the LOPDGDD): In the activity of the entity being sued, the processing of personal data is essential for the provision of the service. Thus, GOLDCAR has been continuously processing identification, contact, financial, and driver's license data since 1988.
No mitigating circumstances are found.
The balance of the circumstances contemplated in Article 83.2 of the GDPR and 76.2 of the LOPDGDD, with respect to the infringement committed by violating the provisions of Article 6.1 of the GDPR, allows for the proposal of an administrative fine of €100,000.00.
VII
Adoption of Measures
If the infringement is confirmed, it is proposed to require the controller to adopt appropriate measures to bring its actions into compliance with the regulations mentioned in this act, in accordance with the provisions of the aforementioned Article 58.2 d) of the GDPR, according to which each supervisory authority may "order the controller or processor to ensure that processing operations comply with the provisions of this Regulation, where appropriate, in a specified manner and within a specified period..."
Thus, the responsible entity may be required to adapt its actions to personal data protection regulations, within the scope expressed in the previous Legal Basis.
This document establishes the alleged violation committed and the facts that could lead to this potential breach of data protection regulations.
From this, it is clear what measures to be adopted, without prejudice to the specific procedures, mechanisms, or instruments to implement them being the responsibility of the sanctioned party. The data controller is fully familiar with their organization and must decide, based on proactive responsibility and a risk-based approach, how to comply with the GDPR and the LOPDGDD.
However, in this case, regardless of the foregoing, in accordance with the evidence currently available regarding the proposed resolution of the sanctioning procedure, it is proposed that the resolution adopted require GOLDCAR to adopt the following measures within 6 months from the date of the final resolution of this procedure:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 36/40
- Prove the legitimacy for processing the data subject to the actions, in accordance with Article 6.1 of the GDPR, with the consequent elimination of any processing of personal data that entails the exclusion of individuals as potential customers, to the extent expressed in this act.
Please be advised that failure to comply with the possible order to adopt measures imposed by
this body in the sanctioning resolution may be considered an
administrative violation under the provisions of the GDPR, classified as a
violation in Articles 83.5 and 83.6, and such conduct may lead to the opening of a
subsequent administrative sanctioning procedure.
In light of the above, the following
PROPOSED RESOLUTION
That the Presidency of the Spanish Data Protection Agency sanction
GOLDCAR SPAIN, S.L., with NIF B03403169, for a violation of Article 6.1 of the GDPR, classified in Article 83.5.a) of the GDPR, with a fine of 100,000 euros.
That the Presidency of the Spanish Data Protection Agency orders
GOLDCAR SPAIN, S.L., with NIF B03403169, pursuant to Article 58.2.d) of the GDPR, to demonstrate within a period of 6 months that it has adopted the measures required in
Legal Basis VI, in relation to the accreditation of legitimacy for the
processing of data in accordance with Article 6.1 of the GDPR.
Furthermore, in accordance with the provisions of Article 85.2 of the LPACAP, you are informed that you may, at any time prior to the resolution of this procedure, voluntarily pay the proposed fine, which
will entail a 20% reduction in the amount of the fine. With the application of this reduction, the fine would be set at €80,000, and its payment would imply the termination of the proceedings, without prejudice to the imposition of the corresponding measures. The effectiveness of this reduction will be conditional on the withdrawal or waiver of any administrative action or appeal against the fine.
If you choose to voluntarily pay the amount specified above, in accordance with the provisions of the aforementioned Article 85.2, you must make such payment by depositing it into the restricted account IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX) opened in the name of the Spanish Data Protection Agency at the banking entity CAIXABANK, S.A., indicating in the account the reference number of the procedure shown in the heading of this document and the reason, due to voluntary payment, for reducing the amount of the fine. You must also send proof of payment to the Subdirectorate General of Inspection to close the file.
By virtue of this, you are hereby notified of the foregoing, and the procedure is made clear to you
so that within TEN DAYS you may present any arguments you deem necessary in your defense and
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 37/40
submit the documents and information you deem relevant, in accordance with
Article 89.2 of the LPACAP.
926-100325
R.R.R.
INSPECTOR/INSTRUCTOR
ANNEX
Index of file EXP202400905
(…)
>>
SECOND: On June 2, 2025, GOLDCAR proceeded to pay the
fine in the amount of €80,000.00, making use of the reduction provided for in the
proposed resolution transcribed above.
THIRD: In the draft resolution transcribed above, the facts constituting an infringement were established, and it was proposed that the Presidency require the controller to adopt appropriate measures to bring its actions into compliance with the regulations, in accordance with the provisions of the aforementioned Article 58.2 d) of the GDPR, according to which each supervisory authority may "order the controller or processor to ensure that processing operations comply with the provisions of this Regulation, where appropriate, in a specific manner and within a specified period...".
LEGAL BASIS
I
Jurisdiction
In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (the General Data Protection Regulation, hereinafter GDPR) and as established in Articles 47, 48.1, 64.2, and 68.1 of
Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), the President of the Spanish Data Protection Agency is competent to resolve this procedure.
Likewise, Article 63.2 of the LOPDGDD establishes that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development, and, insofar as they do not contradict them, in a subsidiary manner, by the general rules on administrative procedures."
II
Termination of the Procedure
Article 85 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), under the heading "Termination of Sanctioning Procedures," provides the following:
"1. Once a sanctioning procedure has been initiated, if the offender acknowledges responsibility,
the procedure may be terminated with the imposition of the appropriate sanction.
2. When the sanction is solely pecuniary in nature, or when a pecuniary sanction and a non-pecuniary sanction may be imposed, but the inadmissibility of the latter has been justified, voluntary payment by the alleged responsible party, at
any time prior to the resolution, will entail the termination of the procedure,
except with regard to restoring the altered situation or determining compensation for damages caused by the commission of the offense. Infraction.
3. In both cases, when the penalty is solely monetary in nature, the competent body resolving the procedure shall apply reductions of at least
20% of the proposed penalty, with these reductions being cumulative.
These reductions must be specified in the notification of initiation
of the procedure, and their effectiveness shall be conditional on the withdrawal or waiver of
any administrative action or appeal against the penalty.
The percentage reduction provided for in this section may be increased
by regulation."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 39/40
III
Voluntary payment
In accordance with the provisions of the aforementioned Article 85 of the LPACAP, the notified draft resolution allowed the applicant to voluntarily pay the proposed penalty, which would entail a 20% reduction in its amount. With the
application of this reduction, the fine would be set at €80,000.00, and its
payment would terminate the proceedings, without prejudice to the imposition of the
corresponding measures.
Following the aforementioned resolution proposal, and before the resolution was issued by
this authority, GOLDCAR, on June 2, 2025, proceeded to make the voluntary
payment, availing itself of the 20% reduction. In accordance with section 3 of
Article 85 of the LPACAP (Spanish Civil Protection Act), the effectiveness of the aforementioned reduction will be conditioned on the
withdrawal or waiver of any administrative action or appeal against the
fine.
It should be noted that, in accordance with the provisions of the LPACAP, as well as the Supreme Court's jurisprudence on this matter, the exercise of voluntary payment by the alleged liable party does not exempt the administration from its obligation to resolve and notify all proceedings, regardless of their initiation. Similarly, Article 88 of the aforementioned law establishes that the resolution that concludes the proceedings will decide all issues raised by the interested parties and any other issues arising from them.
Therefore, in accordance with applicable legislation and having assessed the criteria for graduating sanctions, the Presidency of the Spanish Data Protection Agency RESOLVES:
FIRST: TO DECLARE the commission of the violations and CONFIRM the sanctions
determined in the operative section of the proposed resolution transcribed in this resolution.
The sum of the aforementioned amounts amounts to a total of €100,000.00.
After GOLDCAR SPAIN, S.L. made voluntary payment, although without
acknowledgment of liability, pursuant to Article 85 of the LPCAP,
the aforementioned total is reduced by 20%, which represents the final amount of
€80,000.00.
The effectiveness of the aforementioned reduction is, in all cases, subject to the withdrawal
or waiver of any action or appeal through administrative channels.
SECOND: DECLARE the termination of procedure EXP202400905, in accordance with the provisions of Article 85 of the LPACAP.
THIRD: ORDER GOLDCAR SPAIN, S.L. to notify the Agency within 6 months of this resolution becoming final and enforceable, of the adoption of the measures described in the legal grounds of the proposed resolution transcribed in this resolution.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 40/40
FOURTH: NOTIFY GOLDCAR SPAIN, S.L. of this resolution.
FIFTH: In accordance with the provisions of Article 85 of the LPACAP (Spanish Civil Code), which conditions the
voluntary payment reduction on the withdrawal or waiver of any action or appeal
in administrative proceedings, this resolution will become final in administrative proceedings and
fully enforceable upon notification.
In accordance with the provisions of Article 50 of the LOPDGDD (Spanish Civil Code), this
Resolution will be made public once it has been notified to the interested parties.
Any appeal against this resolution, which terminates the administrative proceedings as provided for in
Art. 114.1.c) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, interested parties may file an administrative appeal before the Administrative Litigation Division of the National Court, in accordance with the provisions of Article 25 and Section 5 of the Fourth Additional Provision of Law 29/1998, of July 13, regulating the Administrative Litigation Jurisdiction, within two months from the day following notification of this action, as provided for in Article 46.1 of the aforementioned Law.
However, pursuant to Article 90.3 a) of the LPACAP, a final administrative decision may be provisionally suspended if the interested party expresses their intention to file an administrative appeal. If this is
the case, the interested party must formally notify this fact in writing
to the Spanish Data Protection Agency, submitting it through the
Agency's Electronic Registry [https://sedeaepd.gob.es/sede-electronica-web/], or
through one of the other registries provided for in Article 16.4 of the aforementioned Law
39/2015, of October 1. They must also forward to the Agency the documentation
that proves the effective filing of the contentious-administrative appeal. If the
Agency does not become aware of the filing of the contentious-administrative appeal within two months from the day following notification of this resolution, it will terminate the precautionary suspension.
1331-200325
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
- ↑ Working Party 29, Working Document on Blacklists, 3 October 2002. Available here: https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2002/wp65_en.pdf




