AEPD (Spain) - EXP202402154

From GDPRhub
AEPD - EXP202402154
Authority: AEPD (Spain)
Jurisdiction: Spain
Relevant Law: Article 5(1)(f) GDPR
Type: Complaint
Outcome: Upheld
Started: 06.02.2024
Decided: 17.09.2025
Published: 20.10.2025
Fine: 1,500,000 EUR
Parties: SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A
National Case Number/Name: EXP202402154
European Case Law Identifier: n/a
Appeal: Not appealed
Original Language(s): Spanish
Original Source: AEPD (in ES)
Initial Contributor: ap

The DPA fined a financial service company €1,500,000 for failing to ensure security and confidentiality of processing in relation to a data breach. Many data subjects later received phishing emails containing their personal data.

English Summary

Facts

SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A (the controller) is a financial service provider supervised by the Spanish National Bank (Banco de España). One of the products it sells is related to the supermarket Carrefour. The controller informed the DPA of a data breach involving data subjects’ personal data (including payment methods, contact information and ID numbers).

The DPA began investigating as a result of the data breach, as well as 16 complaints from data subjects filed between December 2023 and September 2024. Several data subjects received phishing emails containing personal data obtained by unauthorised third parties. The controller informed the DPA that it had communicated the data breach to most data subjects, including those who filed a complaint.

Holding

The DPA found a violation of Article 5(1)(f) GDPR, for failing to ensure integrity and confidentiality of processing. Specifically, the DPA found that the controller did not have appropriate security measures in place to prevent unauthorised third parties from accessing data subjects’ accounts.

The fine was initially set at €2,500,000 but pursuant to Law 39/2015, a Spanish law concerning administrative proceedings, the DPA informed the controller that it may make a voluntary payment of the proposed fine and waive their right to appeal. This action reduces the imposed fine by 20%. The fine can be reduced by a further 20% if the controller acknowledges its liability. The controller opted for both and reduced the fine by 40%, paying the reduced sanction amount of €1,500,000.

The DPA considered it a serious violation of the GDPR, as third parties were able to access a large volume of data, as well as the fact that the data breach exposed the data subject to phishing attempts using their personal data. Finally, the DPA took into consideration the implications of third parties accessing ID information; this exposed data subjects to the risk of identity theft. The DPA also emphasised the sensitive nature of data subjects’ ID documents, as it identifies the data subject beyond doubt.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.

1/24

 File No.: EXP202402154

RESOLUTION TERMINATING THE PROCEDURE BY RECOGNITION OF LIABILITY AND VOLUNTARY PAYMENT

Regarding the procedure initiated by the Spanish Data Protection Agency and based on the following

BACKGROUND

FIRST: On August 6, 2025, the Presidency of the Spanish Data Protection Agency agreed to initiate sanctioning proceedings against SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A. (hereinafter, SFC), through the following agreement:

<<
AGREEMENT TO INITIATE SANCTIONING PROCEDURE

Regarding the actions taken by the Spanish Data Protection Agency and based on the following

FACTS

FIRST: On December 21, In 2023, this Agency was notified of a personal data breach involving SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A., with NIF A79456232 (hereinafter, S. F. CARREFOUR or SFC), related to a cyber incident,

with compromised user credentials and the exfiltration of clients' personal data, including payment method data.

The facts brought to the attention of this Authority are:

 Temporal information: The breach began on 12/17/2023. Date of detection:

12/19/2023.
 Type of breach: Confidentiality.

 Incident Type: Cyberincident: Phishing /

User or administrator account compromise, Cyberincident: Unauthorized access to data in an information system (corporate or online).

 Data Controller: None involved.
 Specifically referring to the data affected by the confidentiality breach.

Is the data securely encrypted, anonymized, or
protected in a way that makes it unintelligible to anyone who may have accessed it, or is it impossible to identify individuals? No

 Degree to which people will be affected: significant inconvenience

 Incident summary: “On 19/12 at 09:27, an abnormal volume of requests was detected (…). At 13:15, it was discovered that the attacker, using compromised credentials (exposed through a source outside of SFC),
(…). There were (…) successful requests to the affected service that corresponded
to (…) customers whose personal data was compromised. The breach affects: basic data, contact information, DNI number,
economic and financial information of the customer related to the contracted product, incomplete data on payment methods, customer ID, and El Club Carrefour membership number. The credentials were reset and the 19 affected customers were notified. At At 4:20 PM, a patch is implemented to prevent consumption of the affected service. On the 20th, the incident data is updated, resulting in a total of (...) affected. Following the measures implemented, the attack is confirmed to have been blocked.

 Data categories: (...)

 Number of affected data subjects: (...)

 Categories of affected parties: Customers / Citizens.

 Communication to affected parties: No, but they will be informed no later than
12/22/2023.

 Cross-border implications: No.

 Breach resolved: Yes.
 Breach detection method: Detection methods implemented

proactively by the data controller or processor.
 The incident has been reported to the police authorities: Yes.

SECOND: As a result of the reported events, on February 6,

2024, the Director of the Spanish Data Protection Agency requested the
Subdirectorate General of Data Inspection (SGID) to initiate the preliminary investigation procedures referred to in Article 67 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights
(hereinafter, LOPDGDD).

THIRD: The Subdirectorate General of Data Inspection carried out preliminary investigations to clarify the facts in question, pursuant to the functions assigned to supervisory authorities in Article 57.1 and the powers granted in Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VIII of the LOPDGDD.

The inspection report details the following information systems:

- Complaint 1:

o Entry date: December 22, 2023

o Complainant: A.A.A.

o Respondent: SERVICIOS FINANCIEROS CARREFOUR, E.F.C. S.A.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 3/24

o Facts according to statements by the complainant:

The complainant states that the respondent entity, on
December 22, 2023, informed them via email that they had suffered
a data breach in which their personal data was exposed.

In particular, the communication states that basic personal data, contact information, and ID number, among other data, were compromised.

o Relevant documentation provided by the complainant:

 Email received from the entity.

This complaint is the first received in relation to the security breach.

- Complaint 2:
o Date of entry: January 11, 2024

o Complainant: B.B.B.

o Respondent: SERVICIOS FINANCIEROS CARREFOUR, E.F.C. S.A.

o Facts according to statements by the complainant:

The complainant states that on January 10, 2024, they received a communication from the respondent entity via regular mail,
informing them that they have suffered a data breach in which their personal data has been exposed. In particular, the
communication states that basic personal data, contact information, and ID number, among other data, have been compromised.
o Relevant documentation provided by the complainant:

 Copy of the letter received from the entity.

- Claim 3:

o Date of entry: January 26, 2024

o Complainant: C.C.C.
o Respondent: SERVICIOS FINANCIEROS CARREFOUR, E.F.C. S.A.

o Facts according to the complainant's statements:

The complainant states that the respondent entity, on
December 22, 2023, informed them via email that they had suffered
a data breach in which their personal data

was exposed. In particular, the communication states that basic personal data, contact information, and ID number, among other information, were compromised.

o Relevant documentation provided by the complainant:
 Email received from the entity.

- Claim 4:

o Date of entry: February 6, 2024
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 4/24

o Complainant: D.D.D.

o Respondent: SERVICIOS FINANCIEROS CARREFOUR, E.F.C. S.A.

o Facts according to the complainant's statements:

The complainant states that they have received a communication from
the respondent entity via regular mail, informing them that

they have suffered a data breach in which
their personal data has been exposed. Specifically, the communication states that
basic personal data, contact information, and
DNI number, among other information, have been compromised.

o Relevant documentation provided by the complainant:

 Copy of the letter received from the entity.
- Claim 5:

o Date of entry: April 9, 2024

o Complainant: E.E.E.

o Respondent: SERVICIOS FINANCIEROS CARREFOUR, E.F.C. S.A.

o Facts according to the complainant's statements:
The complainant states that they received a letter from the

respondent informing them that they have suffered "unlawful access to our systems (...) basic personal data, contact information, ID number, among other data, has been accessed."

The complainant indicates that on April 5, 2024, they were the target of a vishing attempt (confirmed by telephone with the
respondent). The attackers provided them with "without fail a single piece of information: my full name
and surname, my full address, my ID number, and the last four
digit numbers of my bank account where payments are debited."

o Relevant documentation provided by the complainant:

 Copy of the letter received from the entity.

 Screenshots with the call log received.

- Complaint 6:
o Date of entry: May 10, 2024

o Complainant: F.F.F.

o Respondent: SERVICIOS FINANCIEROS CARREFOUR, E.F.C. S.A.

o Facts according to the complainant's statements:

The complainant states that, due to a data breach suffered by the respondent entity, they have begun receiving malicious emails with phishing attempts impersonating said entity, including their full name, physical address, customer registration code and date, and loyalty card number.

o Relevant documentation provided by the complainant:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 5/24

 Emails received.

- Complaint 7:
o Date of entry: May 10, 2024

o Complainant: G.G.G.

o Respondent: SERVICIOS FINANCIEROS CARREFOUR, E.F.C. S.A.

o Facts according to statements by the complainant:

The complainant states that they received an email from
the respondent entity warning them that they could receive spam
and that they should not click on the links.

The complainant received a malicious email with a phishing attempt impersonating said entity, which included their full name, physical address, customer registration code and date, and loyalty card number.

o Relevant documentation provided by the complainant:

 Warning email received from the entity.

 Malicious email received.
- Claim 8:

o Date of entry: May 10, 2024

o Complainant: H.H.H.

o Respondent: SERVICIOS FINANCIEROS CARREFOUR, E.F.C. S.A.

o Facts according to the complainant's statements:
The complainant states that they have begun receiving malicious emails

with phishing attempts impersonating said entity and which include their first and last name, physical address,
customer registration code and date, and loyalty card number.

o Relevant documentation provided by the complainant:
 Emails received.

- Claim 9:

o Date of Entry: May 11, 2024

o Claimant: I.I.I.

o Respondent: SERVICIOS FINANCIEROS CARREFOUR, E.F.C. S.A.

o Facts according to statements by the claimant:
The claimant states that on May 8 and 10, they received
three malicious emails with phishing attempts

impersonating said entity and including their first and last name,
physical address, customer registration code and date, and loyalty card number.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 6/24

o Relevant documentation provided by the claimant:

 Emails received.
- Claim 10:

o Date of entry: May 14, 2024

o Claimant: J.J.J.

o Respondent: SERVICIOS FINANCIEROS CARREFOUR, E.F.C. S.A.

o Facts according to statements by the complainant:
The complainant states that they have received a malicious email with

a phishing attempt impersonating said entity and which includes their first and last name, date of birth, physical address, customer code, and loyalty card number.

o Relevant documentation provided by the complainant:
 Email received.

- Claim 11:

o Date of entry: May 16, 2024

o Claimant: K.K.K.

o Respondent: SERVICIOS FINANCIEROS CARREFOUR, E.F.C. S.A.

o Facts according to the complainant's statements:
The complainant states that they have begun receiving malicious emails

with phishing attempts impersonating the respondent entity, including their first and last name, address, customer registration code and date, and loyalty card number.

o Relevant documentation provided by the complainant:
 Email received.

- Claim 12:

o Date of entry: June 11, 2024

o Claimant: L.L.L.

o Respondent: SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A.
o Facts according to the complainant's statements:

The complainant states that they have received malicious emails
with phishing attempts impersonating the respondent entity, including their first and last name, ID number, customer registration code, and loyalty card number.
o Relevant documentation provided by the complainant:

 Email received.

- Complaint 13:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 7/24

o Date of entry: June 12, 2024

o Complainant: M.M.M.
o Respondent: SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A.

o Facts according to the complainant's statements:

The complainant states that they have received a malicious email
with a phishing attempt impersonating the respondent entity,
which includes their first and last name, ID number, customer ID number, and

loyalty card number.
o Relevant documentation provided by the complainant:

 Email received.

- Claim 14:

o Date of entry: July 8, 2024, forwarded by the Catalan Data Protection Authority.

o Claimant: N.N.N.
o Respondent: SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A.

o Facts according to statements by the claimant:

The claimant states that they have received an email
from CarrefourPASS, which they understand has been sent impersonating said entity, in which their name, surname, ID number, customer code, and loyalty card number appear, and they understand that their personal data has been disclosed to third parties.

o Relevant documentation provided by the claimant:
 Email received.

- Claim 15:

o Date of entry: September 8, 2024

o Claimant: O.O.O.

o Respondent: SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A.
o Facts according to the complainant's statements:

The complainant states that he/she has received two
emails, apparently phishing, that use the image of

Carrefour Pass, a bank of which he/she is a customer, and include his/her personal
information (name, surname, ID number, telephone number, address, postal code, loyalty card number, and customer number).

o Relevant documentation provided by the complainant:
 Emails received on August 29 and September 7, 2024.

- Claim 16:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 8/24

o Date of entry: December 22, 2024

o Claimant: P.P.P.
o Respondent: SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A.

o Facts according to statements by the complainant:

The complainant alleges that they were the victim of an attempted fraud after receiving a phone call made by a
purported employee of the respondent, pretending to be made

from a legitimate phone number linked to the respondent. In the call, that person
stated that they knew the complainant's first name, last name, date of birth, email address, and former NIE (National Identity Document) number. They urged them to
provide a code sent to their device to supposedly
cancel a credit application.

o Relevant documentation provided by the complainant:

 Response from the respondent to the complainant,
confirming that this was a fraudulent attempt to capture
data that had already been detected and managed by the entity.

As a result of the actions taken, the following information has been obtained:

Regarding the service affected by the breach:

SFC is a financial credit institution classified as a hybrid payment institution, regulated and supervised by the Bank of Spain and classified as a "small and non-complex" entity. Among the products it sells are the Pass card, as well as other consumer credit products, such as personal loans or commercial loans (product financing).

The breach occurred in the backend service called (…).

(…).
(…).

Regarding the chronology of the events: Actions taken to minimize the adverse effects and measures adopted for its final resolution:

- 19/12/2023, 09:27: (…).

- 12/19/2023, 10:00 AM: Following an initial joint analysis by the IT
and Information Security teams, (…).

- 12/19/2023, 10:10 AM: The IT and Information Security teams blocked (…) and continued analyzing the incident and its potential impacts.

- 12/19/2023, 1:15 PM: After completing the second in-depth analysis, the following events were observed, and appropriate corrective measures were taken:

o (…).

(…).

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 9/24

o (…).

(…).
SFC developed and deployed a patch into production at 4:29 PM on
December 19th, remediating the detected vulnerability.

(…), the call volume to the service returned to within normal thresholds,
and no services other than the (…) were detected to be

affected by the incident.
(…).

- 12/19/2023 7:06 PM: (…).

- 12/19/2023, 7:10 PM: (…).
- 12/20/2023, 6:32 PM: (…).

- 12/21/2023 6:05 PM: The breach was reported to the AEPD.

- 12/21/2023, 6:49 PM: The corresponding report was filed with the
National Police Crimes Squad.

In summary, the immediate security measures adopted to stop the attack
were:

- (…).
- (…).

- (…).

Document 5 of entry with registration no. REGAGE24e00033575481.

Regarding the causes that led to the breach

(…).

(…).

(…).

(…). Document 1 of entry with registration no. REGAGE24e00063724654.
Regarding the vulnerability exploited during the breach

In the response to entry with registration no.
REGAGE25e00018954067, SFC indicates that the vulnerability exploited in the breach
is not identified in the NIST vulnerability database because it was not a

vulnerability detected in a market solution.
(…).

The SFC Vulnerability Management service provider ((…)),
based on the standard proposed by NIST in its CVSS (Common Vulnerability Score System) version 3.1 calculation, has obtained a CVSS Score
of 8.5, which corresponds to high severity. The supporting documentation for the calculation is provided as Document 1

of the entry with registration number REGAGE25e00018954067.

The criteria established in the Application Security Policy were applied. This policy classifies applications into three different levels:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 10/24

: low-sensitivity applications, medium-sensitivity applications,
and critical applications.

The asset affected by the breach is classified as critical based on
three criteria: the nature of the information, the type of service provided, and the asset's
exposure.

In turn, depending on the classification of the applications, certain controls will be applied.
(…).

Furthermore, when SFC became aware of the exploitation of the vulnerability, it implemented various measures, such as activating an emergency procedure and implementing a patch that was published in the production environment on the same day the breach was detected.

The Application Security Policy for entry with registration number REGAGE25e00018954067 is provided as Document 2.

Regarding technical audits,

SFC indicates that it conducts technical audits (pentests) of its assets periodically and describes the criteria for selecting the assets to be audited in the response to entry with registration number REGAGE24e00063724654:

a) (…).
b) (…).

c) (…).

d) (…).

(…).
(…).

(…).

(…).
The last pentest performed prior to the breach, which took place between November 9 and 17, 2023, is provided as Document 2 of the entry with registration no.

REGAGE24e00063724654.
A table certifying the status of the vulnerabilities in question is provided as Document 3 of the entry with registration no.

REGAGE24e00063724654.

(…).
Regarding the credentials compromised in the breach

As already described, on December 19, 2023, SFC detected an abnormal volume
of requests to the service that returns customer information on digital channels
from customers who have a PASS card:

Accesses occurred from 19 different user accounts and 10
IP addresses, as recorded in the access log of (...).

[…]

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 11/24

Most of the addresses correspond to the same internet service provider
and network range.

[…]
A total of 19 different user IDs were recorded, with which

an attempt was allegedly made to achieve some type of unauthorized access. The possible leak or exposure of these users' information has been investigated in various specialized forums and through various tools, taking into account the different user IDs and NIF numbers provided, without obtaining any related findings.

[…]

Document 2 of the entry with registration number REGAGE24e00033673364.
Regarding the compromised credentials, SFC indicates that these are customer accounts

whose registration process is carried out by the customer independently
through online channels without the assistance or personal intervention of SFC.

(…).
Regarding the affected data

(…).

(…).
SFC indicates that of the (…).

Types of data affected:

- (…).

- (…).
Regarding the communication sent to those affected

The communication sent to those affected is provided as Document 6 of the entry with registration no.
REGAGE24e00033575481. It is indicated that in those cases where the affected persons had an

email address, the communication was sent by email. In the
remaining cases, the communication was sent by postal mail.
Confirmation of the sending of the email is provided as Document 4 of the entry with registration no.

REGAGE24e00063724654 (...).
Of the (...), which are those affected who are holders of

SFC products.
Regarding the sending date, as evidenced by Document 4: the
emails were sent on December 22, 2023, and the

postal communications, due to their greater logistical burden and the presence of several
holidays due to the time of year, were sent on December 29, 2023, and January 2 and 3, 2024.

(…) after weighing the following factors:
o The more limited categories of personal data affected in relation

to the data subjects and the degree of risk posed to their rights and
freedoms.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 12/24

o The fact that the data subjects had been informed.

o The logistical difficulties in contacting the affected co-owners
(SFC does not have the postal addresses of the co-owners and, as we have explained, the email address is not mandatory for co-owners).

As part of the investigation, SFC is asked to explain whether the breach was communicated to the following claimants listed in this report: A.A.A., B.B.B., D.D.D., E.E.E., F.F.F., G.G.G., H.H.H., I.I.I., J.J.J., K.K.K., L.L.L., and M.M.M.. SFC confirms that it communicated the breach to all of them except for

M.M.M., who was not notified of the breach due to the fact that she was a co-owner. Document 5 of the
entry with registration no. REGAGE24e00063724654.

Regarding the security measures implemented
Security measures implemented prior to the data processing breach where it occurred.

- (…)

or (…).

or (…).

or (…).

or (…).

or (…).

or (…).

or (…):

 (…)
 (…).

 (…)

- (…)

or (…).

or (…).

(…).

or (…).

(…).

or (…).

The latest infographic sent to employees prior to the incident is provided,
as well as the latest phishing campaign launched in April 2023.
Document 4 of the entry with registration number REGAGE24e00033575481.

Reason why the security measures implemented did not prevent the
incident.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 13/24

(…).

(…).
Technical and organizational measures adopted to prevent, as far as possible, incidents
such as the one that occurred.

- Technical security measures

or (…).

or (…).
- Other measures

or (…).

or (…).

or (…).

or (…).

or (…).

or (…).

or (…).

or (…).

Document 5 of the entry with registration number REGAGE24e00033575481.

Information on the recurrence of these events and the number of similar events that have occurred over time.

SFC states that there has been no recurrence of similar events or facts either before or after the breach was reported.

LEGAL BASIS
I
Jurisdiction

In accordance with the powers granted to each supervisory authority by Article 58.2 of the GDPR and as established in Articles 47, 48.1, 64.2, and 68.1 of the LOPDGDD,
the President of the Spanish Data Protection Agency is competent to initiate and resolve this procedure.
II

Procedure

Likewise, Article 63.2 of the LOPDGDD establishes that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development, and, insofar as they do not contradict them, in a subsidiary manner, by the general rules on administrative procedures."

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 14/24

In accordance with Article 64 of the LOPDGDD, and taking into account the characteristics of the alleged violations committed, a sanctioning procedure shall be initiated.

The procedure will last a maximum of twelve months from the date of the initiation agreement. After this period, the proceedings will expire and, consequently, the proceedings will be archived, in accordance with the provisions of Article 64 of the LOPDGDD.

If no objections are made to this initial resolution within the stipulated period, it may be considered a proposed resolution, as established in Article 64.2.f) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP).
III

Preliminary Questions

Article 4(1) of the GDPR defines "personal data" as: "any information relating to an
identified or identifiable natural person ("data subject"); an identifiable natural person is any person whose identity can be determined, directly or

indirectly, in particular by reference to an identifier such as a name,
an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental,
economic, cultural or social identity of that natural person."

Article 4(2) of the GDPR defines “processing” as: “any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.”

Article 4(7) of the GDPR defines “controller” or “controller” as: “the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing; where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.”

In the present case, in accordance with the provisions of Articles 4.1 and 4.2 of the GDPR, personal data processing is established, since S.F.

CARREFOUR carries out, among other processing, the collection and storage of personal data of natural persons, including identification, documentary, contact, and related data regarding contracted services, as well as economic, financial, and payment data.

S.F. CARREFOUR carries out this activity in its capacity as data controller, as it determines the purposes and means of such activity, pursuant to Article 4.7 of the GDPR.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 15/24

IV
Breached obligation. Article 5.1.f) of the GDPR. Integrity and confidentiality.

Article 5.1(f) of the GDPR states:

"1. Personal data shall be:

(…)

f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, by applying appropriate technical or organizational measures ("integrity and confidentiality")."

The principle of confidentiality and integrity, set forth in Article 5.1(f) of the GDPR,
requires data controllers to ensure that personal data are

processed in a manner that ensures the confidentiality and integrity of the personal data, preventing unauthorized access, misuse, or disclosure to unauthorized third parties.
This includes implementing appropriate technical and organizational measures of all kinds to protect data against potential personal data breaches, both external and internal. These measures must be appropriate to prevent the materialization of risks to the rights and freedoms of natural persons that may arise from the processing, and must be reviewed and updated periodically to ensure their effectiveness.

In the present case, a personal data breach has occurred.
According to the information available, including in the notification to this AEPD by S.F. CARREFOUR of said breach, as well as that included in the information

obtained in the preliminary investigations carried out, it is clear that on December 19, 2023, following an anomalous volume of requests to the service (...), the service used by the mobile application, S.F. CARREFOUR detected the personal data breach.

As stated in the preliminary investigation report and in the same

breach notification sent to this Agency:

“On December 19 at 9:27 a.m., an abnormal volume of requests was detected (…),
mainly on December 18. At 10:00 a.m., it was identified that 94% of the requests
came from 10 IPs, and the attack was confirmed. At 10:10 a.m., the IPs were blocked. At
1:15 p.m., it was discovered that the attacker, using 19 compromised credentials

(exposed through a source other than SFC), had obtained (…). There were (…) successful
requests to the affected service that corresponded to (…) customers whose personal
data was compromised. (…).”

According to information sent to this Agency by S.F. During the investigation, CARREFOUR identified the following types of data that were compromised:

- (…).

- (…).

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 16/24

Regarding the compromised credentials, SFC indicates that these are customer accounts whose registration process is carried out by the customer independently
through online channels without the assistance or personal intervention of SFC.

(…).

The total number of customers results in a total of (…) affected.

The preliminary investigation report included in the file details the origin of the breach:

“(…).
(…).

(…).”

The preliminary investigation report states that (…).

Clear deficiencies can be observed in the measures established regarding improper access by a third party to customer accounts. The preliminary investigation report notes (…).

Regarding this aspect, S.F. CARREFOUR, in its response to the inspection by this Agency, notes that the service of (…).

In short, the deficiencies that led to the cyberattack being carried out and
succeeded were:

- Vulnerable configuration since the service was implemented (2017): (…).

- (…).

- Lack of proactive review of the service for years: (…).

All of these aspects provide sufficient evidence to consider that, at the time the breach occurred, S.F. CARREFOUR did not have appropriate technical or organizational measures in place to guarantee adequate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, through the application of ("integrity and confidentiality").

Therefore, based on the evidence available at this time, and the agreement to initiate sanctioning proceedings, it is considered that the known facts could constitute an infringement attributable to S.F. CARREFOUR
for violation of Article 5.1.f) of the GDPR, as transcribed above.

V

Classification of the violation of Article 5.1.f) of the GDPR and classification for the purposes of limitation

Article 83.5 of the GDPR classifies as an administrative violation the violation of the

following articles, which shall be punishable, in accordance with paragraph 2, with administrative fines of up to EUR 20,000,000 or, in the case of a company, an amount equivalent to a maximum of 4% of the total annual global turnover of the preceding financial year, whichever is higher:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 17/24

"a) the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9;"

For its part, the LOPDGDD (Organic Law on the Protection of Personal Data) in its Article 71, "Infractions," states that:

"The acts and conduct referred to in sections 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law, constitute infringements."

For the sole purpose of the statute of limitations, Article 72.1 of the LOPDGDD establishes the following:

"Based on the provisions of Article 83.5 of Regulation (EU) 2016/679, infringements that constitute a substantial violation of the articles mentioned therein, and in particular, the following, are considered very serious and will be subject to a three-year statute of limitations:

a) The processing of personal data in violation of the principles and guarantees established in Article 5 of Regulation (EU) 2016/679."

VI

Proposed sanction for non-compliance with Article 5.1.f) GDPR

In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR must be observed, which state:

“1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article for infringements of this Regulation referred to in paragraphs 4, 9, and 6 are, in each individual case, effective, proportionate, and dissuasive.

2. Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or as a substitute for the measures provided for in Article 58(2)(a) to (h) and (j). When deciding on the imposition of an administrative fine and its amount in each individual case, due account shall be taken of:
a) the nature, gravity, and duration of the infringement, taking into account taking into account the
nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage suffered by them;

b) the intentionality or negligence of the breach;
c) any measures taken by the controller or processor to mitigate the damage suffered by the data subjects;
d) the degree of responsibility of the controller or processor,

taking into account the technical or organizational measures they have implemented pursuant to Articles 25 and 32;
e) any previous breaches committed by the controller or processor;
f) the degree of cooperation with the supervisory authority to remedy the breach and mitigate the potential adverse effects of the breach;

g) the categories of personal data affected by the breach;
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 18/24

h) the manner in which the supervisory authority became aware of the infringement, in particular whether the controller or processor notified the infringement and, if so, to what extent;

(i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned in relation to the same matter, compliance with those measures;

(j) adherence to codes of conduct pursuant to Article 40 or certification mechanisms approved pursuant to Article 42; and
(k) any other aggravating or mitigating factors applicable to the circumstances of the case,

such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement.

For its part, Article 76 "Sanctions and Corrective Measures" of the LOPDGDD
provides:

"1. The sanctions provided for in sections 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the grading criteria established in section 2 of the aforementioned article.

2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679,

the following may also be taken into account:

a) The continuous nature of the infringement.
b) The connection between the offender's activity and the processing of personal data.

c) The benefits obtained as a result of the commission of the infringement.
d) The possibility that the affected party's conduct could have led to the commission of the infringement.
e) The existence of a merger by absorption process subsequent to the commission of the infringement, which cannot be attributed to the offender. to the acquiring entity.

f) The impact on the rights of minors.
g) Having a data protection officer, when not mandatory.
h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms in cases where there are disputes between them and any interested party.

The above implies that the amount of the fine must be based on three elements: turnover, the categorization of the violations according to their nature (i.e., whether it is a violation of Article 83.4, 83.5, or 83.6 of the GDPR), and the severity of the violation in each specific case (in accordance with Article 83.2 a), b), and g). In any case, the fine to be imposed must be, in each case, individual, effective, proportionate, and dissuasive, in accordance with the provisions of Article 83.1 of the GDPR.

First, for the purposes of determining the severity of the breach,
the following circumstances are considered to be present:

• The nature, severity, and duration of the breach, taking into account the
nature, scope, or purpose of the processing operation in question,

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 19/24

as well as the number of data subjects affected and the level of damages
they have suffered (Article 83.2, letter a) of the GDPR).

Regarding severity, it should be noted that this is a widespread breach in the service (…). In this regard, SFC indicates that the number of affected parties was (…). Furthermore, the known facts directly impact the control that data subjects have over their personal data. Furthermore, the large volume of data the attackers have accessed poses greater risks to the rights and freedoms of those affected. This broad impact amplifies the severity of the breach, given that each customer was at risk of phishing.
• Intentionality/Negligence in the breach (Article 83.2, letter b) of the GDPR):

Gross negligence is considered to exist, considering that the conduct of the data controller demonstrates a serious lack of due diligence, as it failed to apply the minimum operational controls required in the conduct of its activities. (…).

• The categories of personal data affected by the breach (Article 83.2, letter g) of the GDPR).

Data that could lead to identity theft attempts and the possibility of carrying out actions that could cause financial harm to those affected was involved: National Identity Document (DNI) number.

Regarding the DNI number, this involves processing sensitive data, as it allows for the direct and unequivocal identification of a natural person. As established by Royal Decree 255/2025, of April 1, which regulates the National Identity Document, the DNI is a general-purpose personal numeric identifier, with sufficient value to prove both the identity and nationality of the holder, making it a particularly sensitive element within the personal data ecosystem. Furthermore, its improper use entails a high risk of identity theft, property damage, or infringement of the right to honor, risks expressly contemplated in Recital 75 of the GDPR. Therefore, a systematic and concise interpretation of the GDPR—in accordance with Recitals 51 and 75—allows the DNI to be considered particularly sensitive data, given its potential to cause significant harm in the event of unauthorized use. In
this regard, according to Guidelines 04/2022 on the calculation of fines
under the GDPR, when assessing this circumstance, reference should be made not only to the "types of data covered by Articles 9 and 10 of the GDPR, but also to data outside the scope of these articles, the dissemination of which causes immediate harm or

difficulty to the data subject." Among these, it expressly mentions
identity document numbers.
Likewise, the following grading factors are considered as

aggravating factors:

• The connection between the offender's activity and the processing of personal data (Article 76.2, letter b) of the LOPDGDD.

On the one hand, the offender's main activity involves offering services to the general public and attracting a large number of clients who are natural persons.

Therefore, the continuous processing of its clients' personal data is an essential part of its activity. On the other hand, the systems targeted by the attack in this case
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 20/24

are related to the marketing of the services offered by the entity, and are therefore
specifically also linked to the regular processing of personal data.

The balance of the circumstances contemplated in Article 83.2 of the GDPR and 76.2 of the LOPDGDD regarding the infringement committed by violating the provisions of

Article 5.1.f) of the GDPR allows for the initial imposition of an administrative fine of €2,500,000.00, without prejudice to the outcome of the investigation.

Therefore, in light of the above, the President of the Spanish Data Protection Agency,

IT IS AGREED:

FIRST: TO INITIATE SANCTIONING PROCEEDINGS against SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A., with Tax Identification Number (NIF) A79456232,

- for the alleged violation of Article 5.1.f) of the GDPR, classified in accordance with the

provisions of Article 83.5 of the GDPR, classified as very serious for the purposes of the statute of limitations, in Article 72.1 a) of the LOPDGDD.

SECOND: TO APPOINT P.P.P. as investigating officer. and, as secretary, R.R.R., indicating
that they may be challenged, if appropriate, in accordance with the provisions of Articles 23 and
24 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector

(LRJSP).

THIRD: INCORPORATE into the file, for evidentiary purposes, the notification of the
personal data security breach, as well as the documents obtained
and generated by the Subdirectorate General of Data Inspection in the actions

prior to the initiation of this sanctioning procedure.

FOURTH: THAT for the purposes set forth in art. 64.2 b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, the applicable sanction would be an administrative fine of 2,500,000.00 euros, without prejudice to the outcome of the investigation.

FIFTH: NOTIFY this agreement to SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A., with Tax Identification Number (NIF) A79456232, granting it a hearing period of ten business days to formulate its allegations and present any evidence it deems appropriate. In its written allegations, it must provide its Tax Identification Number (NIF) and the procedure number shown in the heading of this document.

In accordance with the provisions of Article 85 of the LPACAP, it may acknowledge its liability within the period granted for the formulation of allegations to this initiation agreement; This will result in a 20% reduction in the appropriate penalty imposed in this proceeding. With the application of this reduction, the penalty would be set at €2,000,000.00.

With the imposition of this penalty.

Likewise, the court may, at any time prior to the resolution of this proceeding, voluntarily pay the proposed penalty, which
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 21/24

will result in a 20% reduction in its amount. With the application of this reduction,
the penalty would be set at €2,000,000.00, and its payment will imply the
termination of the proceeding, without prejudice to the imposition of the corresponding measures.

The reduction for voluntary payment of the fine is cumulative with the reduction applicable for acknowledgment of liability, provided that this acknowledgment of liability is made clear within the period granted for submitting allegations at the opening of the procedure. Voluntary payment of the amount referred to in the preceding paragraph may be made at any time prior to the resolution. In this case, if both reductions were to be applied, the amount of the fine would be set at €1,500,000.00.

In any case, the effectiveness of either of the two aforementioned reductions will be subject to the withdrawal or waiver of any administrative action or appeal against the fine.

If you choose to voluntarily pay any of the amounts indicated above (€2,000,000.00 or €1,500,000.00), you must do so by depositing it into account IBAN: ES00-0000-0000-0000-0000-0000

(BIC/SWIFT Code: CAIXESBBXXX) opened in the name of the Spanish Data Protection Agency at the bank CAIXABANK, S.A., indicating in the entry the reference number of the procedure shown in the heading of this document and the reason for the reduction in the amount you are applying for.

You must also send proof of payment to the Subdirectorate General of Inspection so that the procedure can continue in accordance with the amount paid.

Finally, it is noted that, in accordance with the provisions of Article 112.1 of the LPACAP,

there is no administrative appeal against this act."

Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency>>

SECOND: On August 27, 2025, SFC proceeded to pay the fine

in the amount of €1,500,000.00, making use of the two reductions provided for in
the initiation agreement transcribed above, which implies recognition of
responsibility in relation to the events referred to in the initiation agreement and
their legal classification. (...).

LEGAL BASIS

I
Jurisdiction

In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679
(General Data Protection Regulation, hereinafter GDPR) and as provided Pursuant to Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 22/24

the Guarantee of Digital Rights (hereinafter, LOPDGDD), the Presidency of the Spanish Data Protection Agency is competent to resolve this procedure.

Furthermore, Article 63.2 of the LOPDGDD establishes that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development, and, insofar as they do not contradict them, in a subsidiary capacity, by the general rules on administrative procedures."

II
Termination of the Procedure

Article 85 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), under the heading "Termination of Sanctioning Procedures," provides the following:

"1. Once a sanctioning procedure has been initiated, if the offender acknowledges responsibility, the procedure may be terminated with the imposition of the appropriate sanction.
2. When the sanction is solely monetary in nature, or when one monetary sanction and another non-monetary sanction may be imposed, but the inadmissibility of the second sanction has been justified, voluntary payment by the alleged offender, at any time prior to the resolution, will entail the termination of the procedure, except with regard to restoring the altered situation or determining compensation for damages caused by the commission of the violation.

3. In both cases, when the sanction is solely monetary in nature, the
body competent to resolve the procedure will apply reductions of at least 20% on the amount of the proposed sanction, which may be combined.
These reductions must be specified in the notification of initiation

of the procedure, and their effectiveness will be conditional on the withdrawal or waiver of any administrative action or appeal against the sanction.

The percentage reduction provided for in this section may be increased by regulation.

III

Voluntary Payment and Acknowledgment of Responsibility

In accordance with the provisions of the aforementioned Article 85 of the LPACAP (Spanish Civil Protection Act), the notified initiation agreement provided information on the possibility of acknowledging responsibility and voluntarily paying the proposed penalty, which would entail two cumulative reductions of 20% each. With the application of these two reductions, the penalty would be set at €1,500,000.00, and its payment would imply the termination of the procedure, without prejudice to the imposition of the corresponding measures.

Following notification of the aforementioned initiation agreement, SFC has proceeded to acknowledge responsibility and voluntarily pay the penalty, availing itself of the two reductions provided. In accordance with section 3 of Article 85 of the LPACAP (Spanish Civil Protection Act), the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 23/24

The effectiveness of the aforementioned reductions will be conditional on the withdrawal or waiver
of any administrative action or appeal against the sanction.

It should be noted that, in accordance with the provisions of the LPACAP, as well as the Supreme Court's jurisprudence on this matter, the exercise of voluntary payment by the alleged offender does not exempt the administration from the obligation to resolve and notify all proceedings, regardless of their form of initiation. Similarly, Article 88 of the aforementioned law establishes that the resolution that concludes the procedure will decide all issues raised by the interested parties and any other issues arising from it.

Therefore, in accordance with applicable legislation and having assessed the criteria for graduating sanctions, the Presidency of the Spanish Data Protection Agency RESOLVES:

FIRST: TO DECLARE the commission of the violations and CONFIRM the sanctions determined in the operative section of the initiation agreement transcribed in this resolution.

The sum of the aforementioned amounts results in a total of €2,500,000.00.

After SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A. made prompt payment and acknowledged liability, pursuant to Article 85 of the LPACAP, the aforementioned total has been reduced by 40%, resulting in a final amount of €1,500,000.00.

The effectiveness of the aforementioned reductions is subject, in all cases, to the withdrawal or waiver of any administrative action or appeal.

SECOND: DECLARE the termination of procedure EXP202402154, in

accordance with the provisions of Article 85 of the LPACAP.

THIRD: NOTIFY SERVICIOS FINANCIEROS
CARREFOUR, E.F.C., S.A. of this resolution.

FOURTH: In accordance with the provisions of Article 85 of the LPACAP, which conditions

the reduction for voluntary payment and acknowledgment of liability on the
withdrawal or waiver of any action or appeal in administrative proceedings, this resolution will be final in administrative proceedings and fully enforceable upon notification.

In accordance with the provisions of Article 76.4 of the LOPDGDD, and given that the
amount of the fine imposed exceeds one million euros, the information identifying the offender, the
infraction committed, and the amount of the fine will be published in the Official State Gazette.

In accordance with the provisions of Article 50 of the LOPDGDD, this resolution will be made public. The publication will take place once the resolution becomes final in administrative proceedings.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 24/24

Against this resolution, which ends the administrative process as provided for in

Art. 114.1.c) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, interested parties may file an administrative appeal before the Administrative Litigation Division of the National Court, in accordance with the provisions of Article 25 and Section 5 of the Fourth Additional Provision of Law 29/1998, of July 13, regulating the Administrative Litigation Jurisdiction, within two months from the day following notification of this action, as provided for in Article 46.1 of the aforementioned Law.

However, pursuant to Article 90.3.a) of the LPACAP, a final administrative decision may be provisionally suspended if the interested party expresses their intention to file an administrative appeal. If this is
the case, the interested party must formally notify this fact in writing

to the Spanish Data Protection Agency, submitting it through the
Agency's Electronic Registry [https://sedeaeps.gob.es/sede-electronica-web/], or
through one of the other registries provided for in Article 16.4 of the aforementioned Law
39/2015, of October 1. They must also forward to the Agency the documentation

that proves the effective filing of the contentious-administrative appeal. If the
Agency does not become aware of the filing of the contentious-administrative appeal within two months from the day following notification of this resolution, it will terminate the precautionary suspension.
936-180725
Lorenzo Cotino Hueso

President of the Spanish Data Protection Agency

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es