AEPD (Spain) - EXP202402590
| AEPD - EXP202402590 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 6(1) GDPR Art. 66.1.b. LGTEL |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | 25.01.2024 |
| Decided: | 28.08.2025 |
| Published: | 15.10.2025 |
| Fine: | 5,000 EUR |
| Parties: | AECORP 005, S.L. |
| National Case Number/Name: | EXP202402590 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Spanish |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | ricardo |
The DPA fined a company €5,000 for calling a data subject for direct marketing purposes without their consent, in violation of national telecommunication laws.
English Summary
Facts
On January 24, 2024, a data subject received a direct marketing call from AECORP 005 S.L. (a marketing company, the controller) falsely claiming to represent NATURGY (an energy company), and requesting a change in the data subject's electricity billing. During the call, they received an SMS with a link containing their phone number. NATURGY denied involvement, and the data subject refused the transaction. The controller acknowledged it conducted a marketing campaign through third party data providers, and the DPA confirmed the controller made the call without consent.
Holding
The DPA found a violation of Article 66(1)(b) of the national communications law (LGTEL), as the controller carried out direct marketing calls without the consent of the data subject. The DPA stressed that users have the right to privacy in electronic communications and that companies must respect individuals’ control over their personal data. The purpose of Article 66 LGTEL is to protect users from intrusive commercial practices that disregard their privacy and control over commercial communications, ensuring that companies respect data subjects' rights.
The DPA highlighted that a valid legal basis in accordance with Article 6(1) GDPR is essential for direct marketing calls to comply with Article 66(1)(b) LGTEL. In this case, the fact that a data subject had registered on the controller's website and accepted the privacy policy does not mean they provided the data or consented to the direct marketing calls. The DPA referred to EDPB Guidelines[1] and stated that controllers must demonstrate valid consent before processing personal data for marketing purposes, in accordance with the principle of accountability (Article 5(2) GDPR). Controllers must also continuously verify this consent throughout the entire data processing lifecycle, and ensure the data subject is fully informed. Therefore, the DPA considered that the controller carried out the direct marketing calls without valid consent, and could also not rely on any other legal basis under Article 6(1) GDPR.
The DPA fined the controller €5,000, and considered it a serious violation under Article 107(30) LGTEL.
Comment
This case reflects increasing scrutiny by the DPA over aggressive marketing practices involving third-party data brokers and lead generators. The resolution underscores that companies cannot rely on vague or unilateral records to justify commercial communications. Even when data is acquired through intermediaries, the responsibility for ensuring lawful consent and GDPR compliance remains with the entity initiating the contact.
The DPA’s reasoning reinforces its established doctrine: consent must be explicit, informed, and demonstrable. The agency rejected the claimed entity’s defense based on a registration record, noting that such evidence does not prove the data subject’s awareness or agreement to receive marketing calls. This decision aligns with prior rulings that emphasize accountability and transparency in data sourcing and commercial outreach.
Further Resources
The DPA fined the controller €5,000 for a similar violation of the LGTEL. You can read the decision here (in Spanish).
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.
1/14
File No.: EXP202402590, (PS/00521/2024)
SANCTIONING PROCEDURE RESOLUTION
From the procedure initiated by the Spanish Data Protection Agency and based on the following
BACKGROUND
FIRST: On January 25, 2024, a complaint was filed against the entity
AECORP 005, S.L., (AECORP) with CIF: B05470380 (hereinafter, the defendant), for the alleged violation of Law 11/2022, of June 28, General Telecommunications Law (LGTEL), Regulation (EU) 2016/679 of the European Parliament and of the Council of 04/27/2021, on the Protection of Natural Persons with regard to the Protection of Personal Data. that
regards the Processing of Personal Data and the Free Circulation of Such Data
(GDPR), and Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD).
The complainant states in his letter that, on January 24, 2024, he received a commercial call on his mobile line
***TELÉFONO.1, from line ***TELÉFONO.2 (11:32 a.m.)
in which the caller identified himself as a company representing NATURGY,
indicating that the reason for the call was to change the billing province for the contracted electricity service, since, otherwise, the service would be cut off.
He states that the caller knew his personal details (address, name, and
telephone number).
During the phone call, she received an initial SMS that included a link to the website www.servenergia.com, and verified that the link included her phone number: (https://servenergia.com/?numero=***TELÉFONO.1). She indicated that, before carrying out any transaction, she contacted her supplier (NATURGY), where they denied responsibility for the call, so she refused to process it. She received a second SMS indicating that they would send her a communication confirming the electricity termination process.
The following documentation is attached to the complaint:
- Screenshot proving the call received from phone number ***TELÉFONO.2 on January 24, 2024, and the outgoing call to ***TELÉFONO.3.
- Screenshot with the text of two SMS messages received on January 24, 2024, in the name of
NATURGY: the first SMS during the disputed call with
the text: https://servenergia.com/?numero=***TELÉFONO.1, and a second
SMS informing you of the electricity supply termination process.
SECOND: On February 15, 2024, the Director of the Spanish Data Protection Agency issued an agreement admissible for processing the
claim, in accordance with Article 65 of the LOPDGDD (Spanish Data Protection Act).
THIRD: The Subdirectorate General of Data Inspection proceeded to carry out preliminary investigative actions to clarify the facts in
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 2/14
this matter, pursuant to the investigative powers granted to the supervisory authorities in Article 58.1 of the GDPR and in accordance with the provisions of Title VII, Chapter I, Section Two, of the LOPDGDD, carrying out, among others, the
following actions and having knowledge of, among others, the following
points:
a.- The following is provided as evidence found by this AEPD on 01/31/2024:
- The content of the Legal Notice of www.servenergia.com, which indicates the
details of the domain controller: - ***EMPRESA.1, with address in
Colombia and contact email address and DPO (...), which will process the personal data
as the data controller for all websites linked to said company, for the purpose of presenting services related
to the promotion of offers and services related to electricity and gas supplies that
exist on the market.
- The existence of a complaint before the Organization of Consumers and
Users (OCU) dated 11/21/23, similar to this complaint in its modus operandi, directed against the entity AECORP 005, S.L. regarding a call and an
SMS received from the entity ***COMPANY.1.
b.- During these proceedings, the following entities have been investigated:
- AECORP 005, S.L. with NIF B05470380, domiciled at (...)
- ***COMPANY.1. with (...) domiciled at (...)
- ***COMPANY.2. with (…) with address (…)
c.- Result of the investigation:
c.1.- Regarding the existence of the call:
- ORANGE ESPAGNE, S.A.U., operator of the ***TELÉFONO.2 line, from
which the call was made on 01/24/2024 to the complainant's telephone number, confirms to this Agency that the owner of said line on that
date was AECORP 005 S.L. Tax ID No.: B05470380.
c.2.- Regarding the circumstances of the telephone call, AECORP 005, S.L.
In its letter sent to this Agency on May 16, 2024, it states the following regarding the call made to the complainant on January 24, 2024:
- "The communications were made as part of a marketing campaign to offer changes in electricity and gas services.
These actions were carried out under a collaboration agreement with our partner company, ***EMPRESA.3, and with the consent of the recipient by accepting the policies and methods of interacting with it. Attached hereto as Document No. 1 is a screenshot of the customer's record reflecting this interaction. The customer personally indicates that they have read and accepted the Privacy Policy and consequently authorizes contacting the company by email or any other means for commercial purposes.
Regarding the commercial communications made to the customer of the line Recipient ***TELEPHONE.1, we wish to clarify specifically the
situation regarding ***COMPANY.1. A lead transfer was signed with this company, but it does not perform sales management. The information about the client
comes exclusively from our collaboration with ***COMPANY.3,
a company that is dedicated to lead acquisition, as detailed in the
attached collaboration agreement. This entity provided us with the
client's data via an email, which is also attached
as proof of the communication received and the origin of the data used
for the telephone marketing campaign.
The collaboration agreement with
***COMPANY.3 is attached as Document No. 1, and the collaboration agreement with
***COMPANY.1 is attached as Document No. 2. The client was limited to a single interaction in which they were
offered a change of electricity and gas company. After informing us that they were not
interested, we have not made any further contact with
said client. The company has stipulated its quality parameters for
any type of acquisition (acquisition call, verification, sending SMS, etc.)
In this regard, and in order to demonstrate our collaboration in clarifying the
facts, we report the activity this company carries out as a commercial intermediary. This activity entails hiring several collaborators who are in charge of acquiring clients. These collaborators offer them access to our website so that, through a security check
guaranteed by the company ***COMPANY.4, they can provide their information, requesting that we contact them to manage the sale. The clients ultimately contract the service with the company that hires us, in
this case, electricity and gas supply. That is, we are in charge of conducting audits and managing the sale with those clients provided by our collaborators, for the contract with the company that hires us, offering that protection and security in the contract. Attached hereto is Document No. 3, the Commercial Agency Contract that binds you
to (...).”
Along with the response, ACORP 005 attaches the following documentation:
- Document No. 1, "Collaboration Agreement" dated 10/01/22, between, on the one hand, AECORP 005, S.L., and on the other, ***COMPANY.3, which states, among other things, the following:
o (…) Purpose.- In accordance with the terms of this agreement,
the company ***COMPANY.3 will promote, on a continuous and stable basis,
commercial acts or transactions on behalf of AECORP 005, S.L., with
the sole purpose of GAINING LEADS.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 4/14
or (…) Company ***COMPANY.3 will promote the commercial operations mentioned above in the object on behalf of AECORP
005, S.L. in the territory of Valencia.
- Document No. 2, "DATA TRANSFER AGREEMENT," dated 12/04/23,
between ***COMPANY.1, a Colombian company domiciled at
(…), "Transferor," and, on the other hand, Aecorp 005, S.L. "Transferee," where the following can be read, among other things:
or (…) That, as a result of its activity, the Transferor generates and is the owner
of personal data files, which it collects from users for the purpose, among others, of making commercial offers on products
and services in the energy and telecommunications sectors (the
"Databases"). The Transferor is responsible for the processing of the
personal data included in the Databases.
or (…) 1.2. Under this Agreement, the Assignor sells and the
Assignee acquires all Database records ("leads") that the Assignor obtains through its activity through the contact form
on the website www.servenergia.com, from today onwards during the term of the Agreement and with a maximum limit of
15,000 records per week, at the price established in Annex I.
or (…) 2.1. The transfer of the Databases will occur through the Assignor's communication to the Assignee of the personal data
included in the data files owned by the Assignor. The Assignor
will be obliged, prior to communicating the data
transferred to the Assignee, to obtain the consent of the data owners
to the transfer, by the legally established means, for the
conditions and purposes of the processing.
or (…) 2.6. Pursuant to the provisions of clause 1.2, in order to facilitate the Assignee's
activity, the parties expressly establish that the transfer of the records in the Database subject to transfer will be carried out as soon as possible from the moment in which the Assignor obtains each record through the aforementioned website www.servenergia.com. To this end, the parties will enable the communications and/or platform specifically designated for this purpose, which must have the corresponding security measures. - Screenshot of the customer record where the following information can be seen:
o Validation record (...) From Grupo Aecorp on 2023-08-11 15:19
o Contact from: www.grupoaecorp.com
o Mobile phone: ***TELÉFONO.1
o Registration code: (...)-
o IP: (...)
o I have read and accepted the Privacy Policy: 1
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 5/14
o I authorize contact by email or any other means for commercial purposes: Yes
c.2.- Regarding the collection of the complainant's data by ***COMPANY.3
- No evidence could be collected from ***COMPANY.3 since it does not respond to the requests of this Agency. The termination of collaboration is recorded
with AECORP 005, S.L. with ***COMPANY.3 signed on 11/20/2023 in another
file, EXP202312469 (AI/00122/2024).
c.3.- Regarding the existence of the SMS and its circumstances:
- The complainant states that during the call they were sent two SMS and provides a screenshot of the text of two SMS received in the name of NATURGY:
- The first SMS at 10:45 a.m. during the course of the complained call with the text: "https://servenergia.com/?numero=***TELÉFONO.1" and the second SMS at
11:40 a.m. reporting the termination of the electricity supply.
- The complainant's telephone line operator (Vodafone) states that:
o There is no record of an SMS being received during the requested period
from line ***TELÉFONO.2 to the complainant's line. There is no record of any SMS being sent in Vodafone's internal systems.
o There are two SMS messages sent to the complainant's line at
11:40 a.m. on January 24, 2024 from a number owned by NATURGY.
(These are Naturgy SMS messages for cancellation of the marketing company).
- ***COMPANY.4 does not confirm receipt of any SMS messages from the complaining party
on 01/24/2024.
- A response to file EXP202401777 (AI/00067/2024) from ***COMPANY.4 regarding the commercial relationship with
***COMPANY.1 and AECORP is included in this file, stating and attaching the following
to the entry:
o On 05/19/2021, ***COMPANY.4 signed a contract with AECORP 005, SL
for the provision of electronic notification and contracting services,
according to the contract signed by both parties. Attach the contract.
o On 01/16/2024, ***COMPANY.4 signed a contract with ***COMPANY.1
with NIT (...), a company based in Colombia for the provision of
electronic notification and contracting services. According to the contract
signed by both parties. Contract attached.
o It is verified that this AECORP contract predates the date of the
claimed SMS of 01/24/2024.
c.4.- Regarding the link in the SMS to the address https://www.servenergia.com:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 6/14
- Through due diligence, it was verified as of 11/08/2024 that the website
www.servenergia.com is accessible, but its privacy policy does not
indicate the name of the controller, only the name of the website provider and
processor, which is a German entity. Said domain expired on 10/30/2024 and was
updated on 11/01/2024. Its servers are located in Singapore.
- Through due diligence, information about the domain owner has been incorporated
www.servenergia.com provided in file EXP202401777
(AI/00067/2024): Owner: A.A.A. Tax ID: ***Tax ID.1 Contact email: (…) Phone:
***PHONE.1 Address: ***ADDRESS.1. Domain registration (Date) 2023-
10-30 Updated on (Date) 2024-04-23
c.5.- Regarding contractual relationships in the context of service promotion.
- The contracting line would be ***COMPANY.3 -> AECORP 005 S.L.->(...)
- AECORP provides the database transfer contract with ***COMPANY.1
dated 12/04/23. It is verified that this contract is in force on the date of the
claimed call of 01/24/24.
- It is verified that AECORP's contract with (...) is an Assignment Agreement
with subrogation of the Agency Agreement (Telemarketing modality) dated 07/29/21
between (...) (assignor), AECORP 005 S.L. (assignee or agent), and (...) (company).
In this Agreement, AECORP is subrogated from the Agency Agreement (Telemarketing) dated
03/04/20 between (...) (agent) and (...) (company).
- It is verified that the administrator signing on behalf of (...) SERVICES S.L.
in both documents, the Assignment Agreement and the Agency Agreement,
is the owner of the domain www.servenergia.com.
- Through a formality, the response is incorporated into file EXP202317140
of (...) in which it states that: "It has not authorized at any time the
subcontracting of sales agents or other subprocessors by
the company AECORP 005 S.L.”
This Agency requires entity ***COMPANY.4 to certify the record of the transactions carried out on August 11, 2023, linked to the telephone number ***TELÉFONO.1, B.B.B. and identify the sender of the transactions with their name/company name and tax identification number, if applicable, by replying, on November 28, 2024, that "After conducting an exhaustive search in our systems,
we have not found any SMS sent on August 11, 2023 related to the following identifying data: ***TELÉFONO.1, B.B.B.".
FOURTH: On March 19, 2025, the Presidency of the Spanish Data Protection Agency agreed to initiate sanctioning proceedings against the respondent,
for the alleged violation of Article 66.1.b) of the LGTEL, classified in Article
107.30 of the same regulation as a serious infraction.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 7/14
The aforementioned initiation agreement was notified in accordance with the regulations established in Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP) on March 21, 2025, the recipient being:
***NIF.1 A.A.A. and after the period granted for the formulation of allegations has elapsed, it has been determined that no allegations have been received from the respondent.
Article 64.2.f) of the LPACAP—a provision of which the respondent was informed
in the agreement opening the procedure—establishes that if no allegations are made within the established period regarding the content of the initiation agreement, when
it contains a A precise statement regarding the imputed liability may be considered a proposed resolution. In the present case, the agreement to initiate the sanctioning procedure determined the facts that specified the imputation, the GDPR violation attributed to the respondent, and the sanction that could be imposed. Therefore, taking into account that the respondent has not submitted any allegations to the agreement to initiate the procedure and in accordance with the provisions of Article 64.2.f) of the LPACAP, the aforementioned agreement to initiate the procedure is considered a proposed resolution in the present case.
In light of all the actions taken, the Spanish Data Protection Agency considers the following facts to be proven in this procedure:
PROVEN FACTS
First.- The entity AECORP 005, S.L., with NIF B05470380, is listed as the owner of the telephone line ***TELÉFONO.2, from which the 24th On January 1, 2024, a call was made to the complaining party's ***TELÉFONO.1 line. This circumstance has been confirmed by the telecommunications operator ORANGE ESPAGNE, S.A.U.
Second.- During the aforementioned call, the caller, according to the complainant,
claimed to represent NATURGY and indicated that the purpose of the call was to arrange a change in the electricity supply service. The complainant has
provided a screenshot of the call, made at 11:32 a.m.
on January 24, 2024, as well as a subsequent outgoing call to the number
***TELÉFONO.3.
Third.- The complainant has provided a screenshot of the content of two
SMS messages received on the same day. The first, received during the call,
contained the following link: https://servenergia.com/?numero=***TELÉFONO.1. The
second message, received at 11:40 a.m., reported the processing of a cancellation of the electricity supply. Both messages are identified as sent by
NATURGY.
Fourth.- Vodafone España, S.A.U., the provider of the complainant's line, has reported that its systems do not record any SMS messages being sent
from line ***TELÉFONO.2 to line ***TELÉFONO.1 on the aforementioned date.
However, there are two SMS messages sent at 11:40 a.m. on January 24, 2024, from a number owned by NATURGY GROUP, S.A., related to the cancellation of the marketing company.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 8/14
Fifth.- In the proceedings carried out by this Agency, it has been verified that the domain www.servenergia.com, included in the aforementioned SMS, was accessible at least until 11/08/2024, and that it was registered by A.A.A., with NIF
***NIF.1, and its contact email address (…).
Sixth.- The content of the legal notice of the website www.servenergia.com, accessed on
01/31/2024, identifies the entity ***EMPRESA.1, with registered office at (…), and NIT (…), as the data controller of the personal data collected through said website.
Seventh.- The entity AECORP 005, S.L. has sent a letter to this Agency indicating that the call was made in the context of a telephone marketing campaign based on a collaboration agreement with ***COMPANY.3, which, according to AECORP, provided the complainant's contact information via email.
Eighth.- There is no record in this proceeding that ***COMPANY.3 has responded to this Agency's requests. However, it is clear that its contractual relationship with AECORP 005, S.L. was terminated by document dated 11/20/2023.
Ninth.- There is an agency agreement between AECORP 005, S.L. and (…), S.A., arising
from the contractual subrogation of the entity (…), formalized on 07/29/2021, and the latter's prior agency contract with (…), dated 03/04/2020. The signatory administrator of (…) is the owner of the domain www.servenergia.com.
Tenth.- The entity (…), in a letter sent to this Agency, has stated that it has not authorized AECORP 005, S.L. to subcontract sales agents or subcontractors.
Eleventh.- According to a contract signed on 01/16/2024, ***COMPANY.1 maintains a
business relationship with ***COMPANY.4 for the provision of electronic notification and contracting services. A previous contract signed between the latter entity and AECORP 005, S.L. is also recorded. May 19, 2021, also in effect on the date the complained-about SMS was sent.
Twelfth.- Entity ***COMPANY.4 has reported that there is no record of
any SMS received or sent by the complainant on August 11, 2023, associated with the
number ***TELÉFONO.1.
LEGAL BASIS
I
Jurisdiction
In accordance with the provisions of Article 114.1.b) of the LGTEL and as established in
Articles 47, 48.1, 64.2, and 68.1 of the LOPDGDD, the Presidency of the Spanish Data Protection Agency is competent to
resolve this procedure.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 9/14
Likewise, Article 63.2 of the LOPDGDD establishes that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development, and, insofar as they do not contradict them, in a subsidiary manner, by the general rules on administrative procedures."
Finally, the Fourth Additional Provision, "Procedure in relation to the powers conferred on the Spanish Data Protection Agency by other laws," establishes that: "The provisions of Title VIII and its implementing regulations shall apply to the procedures that the Spanish Data Protection Agency may process in the exercise of the powers conferred on it by other laws."
II
Summary of the Facts
According to the complainant, the present case involves the receipt of a sales call on January 24, 2024, with the intention of proposing a change of electricity supplier. According to the complainant, the caller knew his personal information (address, name, account number ending, and telephone number, among others). He also indicates that, during the sales call, he received an SMS with a link to the website www.servenergia.com and then a second SMS informing him of the cancellation of his electricity supply.
For its part, the respondent entity (AECORP) states, in the letter sent to this
Agency on 05/16/2024, regarding the commercial communications made to the
complainant, that the information about him comes from the entity "***EMPRESA.3",
a company dedicated to lead acquisition, and this entity was the one that provided them
with the complainant's data via email (an email address that does not
appear in the documentation provided by the respondent).
III
Breach of Article 66.1 of the LGTEL
The making of unwanted calls for commercial communication purposes, without prior consent or without other legal grounds, may be subject to a violation of the provisions of Article 66.1.b) of the LGTEL, relating to the "Right to the protection of personal data and privacy in relation to unsolicited communications, traffic and location data, and subscriber directories," as it provides the following:
"1. With regard to the protection of personal data and privacy in relation to unsolicited communications, end users of publicly available interpersonal communications services based on numbering shall have the following rights: a) not to receive automated calls without human intervention or fax messages for commercial communication purposes without prior consent;
b) not to receive unwanted calls for commercial communication purposes, unless prior consent has been obtained. of the user himself/herself to receive this type of commercial communications, or unless the communication can be protected
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 10/14
by another legal basis as provided for in Article 6.1 of Regulation
(EU) 2016/679 on the processing of personal data."
This provision regulates the protection of users against unwanted communications, establishing as an essential requirement the existence of a valid legal basis, such as the prior consent of the data subject, or any other of those listed in Article 6.1 of the GDPR.
Its purpose is to protect users from intrusive commercial practices that do not respect their privacy and control over commercial communications. By requiring prior consent or a valid legal basis, this provision ensures that companies respect users' rights, avoiding unwanted commercial communications. In this way, it reinforces the protection framework established
by the GDPR, ensuring a balance between legitimate commercial activities and
the fundamental rights of users.
In this case, it is established that the call was made after the customer registered
through the AECORP website. This entity affirms that this registration would be
secure and guaranteed by the entity ***COMPANY.4, with which it has signed
an electronic notification and contracting agreement.
This is the data provided from the registration:
Validation registration (...)
From Grupo Aecorp on 2023-08-11 15:19
Contact from: www.grupoaecorp.com
Mobile phone: ***TELÉPHONE.1
Registration code: (...)
IP: (...)
I have read and accepted the Privacy Policy: 1
I authorize contact by email or any other means for commercial purposes: Yes
This registration was allegedly made in August 2023. The call was reported in January 2024. According to this registration, the complainant provided their data after accessing the privacy policy and consenting to the marketing actions. However, this registration alone, as a unilateral declaration, does not prove the complainant provided their data, nor their access to the information available on the website, much less that they consented to the commercial calls.
Additionally, as indicated in the preliminary investigation, entity ***COMPANY.4 was
required to report on the transactions carried out on
August 11, 2023, linked to the identifying details of the complainant's phone number and name, as well as the sender's identification and whether they were carried out on behalf of another entity. The response was: "After an exhaustive search of our systems, we have not found any SMS sent on
August 11, 2023 related to the following identifying details: ***PHONE.1,
B.B.B.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 11/14
In this regard, we must also take into account, regarding the authorization or
consent that the user gives to the data controller for the sending of commercial communications, the provisions of Directive 5/2020 on consent within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27/04/2016 on the Protection of Natural Persons with regard to the Processing of Personal Data and on the Free Movement of Such Data
(GDPR), as it establishes, in points 105 to 108, the following:
105. Recital 42 establishes that: "When processing is carried out
with the consent of the data subject, the controller must be able to demonstrate that the data subject has given his or her consent." to the processing operation."
106. Controllers are free to develop methods
to comply with this provision tailored to their daily operations. At the
same time, the obligation to demonstrate that a controller
has obtained valid consent should not in itself lead to
excessive additional data processing. This means that controllers
should have sufficient data to show a link to the processing (to
show that consent was obtained), but should not collect more
information than necessary.
107. It is the responsibility of the controller to demonstrate that it has obtained valid
consent from the data subject. The GDPR does not prescribe how this should be done
exactly. However, the controller must be able to demonstrate that, in a
specific case, a data subject has given consent. The obligation to
demonstrate consent will exist for the duration of the data processing activity
regarding the data in question.
Once such activity has been completed, evidence of consent should not be retained
longer than strictly necessary to comply with a legal obligation or for the establishment, exercise, or defense of legal claims, in accordance
with Article 17(3)(b) and (e).
108. For example, the controller should keep a record of the
declarations of consent received, so that it can demonstrate
how and when the consent was obtained, and the information provided to the data subject at that time must also be demonstrated.
The controller must also be able to demonstrate that the data subject was informed and that the controller's workflow met all relevant criteria for valid consent.
The underlying logic of the above is that the controller responsible for commercial communications must be accountable for obtaining the data subject's authorization or consent for the sending of commercial communications and for the mechanisms used to obtain it.
The regulation does not establish a specific mechanism for how the data controller must be able to prove that the user has requested or expressly authorized commercial communications. The controller is free to implement the method and record that best suits the organization's processes. However, at the very least, the controller must be able to prove who authorized the commercial communications, when, how, and for what purpose, as well as the information provided to the user at the time of obtaining it.
This obligation remains in place as long as the personal data continues to be processed under the initial conditions under which the data was collected and must be verifiable in the event of an audit or inspection.
For all these reasons, in the present case, AECORP 005, S.L. has violated the aforementioned Article
66.1.b) of the LGTEL by making the commercial call to the complainant without their consent and/or the valid legal basis provided for in Article 6.1 of the GDPR.
IV
Classification and classification of the violation
The behavior described in the previous points, when making the commercial call
without the consent of the interested party or any other legitimate basis that makes it possible,
involves a violation of the aforementioned Article 66.1.b), classified as "serious" according to Article 107.30 of the aforementioned law:
"30. Violation of the rights of consumers and end users,
as established in Title III and its implementing regulations, including the
rights to number retention, roaming within the European Union and
internationally, in matters of regulated intra-community communications and
open internet access."
V
Sanction
In accordance with the provisions of Article 109.1.c) of LGTEL, this violation may be punished with a fine of up to 2 million euros.
For its part, Article 110.1 of the aforementioned regulation establishes the criteria for determining the amount of the sanction:
“a) the severity of the violations previously committed by the subject being sanctioned;
b) the damage caused, such as interference with authorized third parties, and its remediation; c) voluntary compliance with the precautionary measures that, where applicable, are imposed in the sanctioning procedure;
d) the refusal or obstruction of access to the facilities or the provision of the required information or documentation; e) the cessation of the infringing activity,
prior to or during the processing of the sanctioning procedure; f)
the impact on protected legal rights related to the use of the public radioelectric domain, public order, public safety, national security, or
the rights of users; g) active and effective collaboration with the competent authority in detecting or proving the infringing activity.”
Based on these criteria, and taking into account the impact on users' rights under the LGTEL, it is deemed appropriate to impose a fine of 5,000 euros (five thousand euros) on the entity in question for violating Article 66.1.b) of the LGTEL, as defined in Article 107.30 of the aforementioned law.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 13/14
Therefore, in accordance with applicable legislation and having assessed the criteria for graduating the sanctions whose existence has been proven, the Presidency of
the Spanish Data Protection Agency RESOLVES:
FIRST: TO IMPOSE on the entity AECORP 005, S.L., with CIF: B05470380, with NIF B01983576, for a violation of Article 66.1.b) of the LGTEL, classified in Article 107.30 of the aforementioned law, a fine of 5,000 euros (five thousand euros).
SECOND: TO NOTIFY this resolution to the entity AECORP 005, S.L.
FIFTH: This resolution will become enforceable once the deadline for filing a complaint has expired. The
optional appeal for reconsideration (one month from the day following notification of this resolution) without the interested party having exercised this right.
The sanctioned party is hereby notified that they must pay the imposed sanction once this resolution becomes enforceable, in accordance with the provisions of Article 98.1.b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), within the voluntary payment period established in Article 68 of the General Collection Regulations, approved by Royal Decree 939/2005, of July 29, in relation to Article 68. 62 of Law 58/2003, of December 17, by depositing the fine, indicating the sanctioned party's NIF (Tax Identification Number) and the procedure number shown in the heading of this document, into the restricted account IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX), opened in the name of the Spanish Data Protection Agency at CAIXABANK, S.A. Otherwise, the fine will be collected during the enforcement period.
Once the notification is received and enforced, if the enforcement date is between the 1st and 15th of each month, inclusive, the deadline for making the voluntary payment will be the 20th of the following month or the next business day after, and if it is between the 16th and last day of each month, inclusive, the payment deadline will be the 5th of the second following month or the next business day after.
In accordance with Article 50 of the LOPDGDD (Spanish Organic Law on the Protection of Personal Data), this Resolution will be made public once it becomes final in the administrative proceedings.
Any appeal against this resolution, which terminates the administrative proceedings pursuant to Article 48.6 of the LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, interested parties may optionally file an appeal for reconsideration before the President of the Spanish Data Protection Agency within one month from the day following notification of this resolution, or directly file an administrative appeal before the Administrative Litigation Division of the National Court, in accordance with the provisions of Article 25 and Section 5 of the Fourth Additional Provision of Law 29/1998, of July 13, regulating the Administrative Litigation Jurisdiction, within two months from the day following notification of this decision, as provided for in Article 46.1 of the aforementioned Law.
Finally, it is noted that pursuant to the provisions of Art. 90.3 a) of the LPACAP, a final administrative decision may be provisionally suspended if the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 14/14
interested party expresses their intention to file an administrative appeal.
If this is the case, the interested party must formally notify this fact in writing to the Spanish Data Protection Agency, submitting it through
the Agency's Electronic Registry [https://sedeaepd.gob.es/sede-electronica-
web/], or through any of the other registries provided for in Article 16.4 of the aforementioned Law 39/2015, of October 1. They must also submit to the Agency the
documentation proving the effective filing of the administrative appeal. If the Agency does not become aware of the filing of the administrative appeal within two months from the day following notification of this resolution, it will terminate the precautionary suspension.
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
- ↑ EDPB, Guidelines 05/2020 on consent under Regulation 2016/679 (version 1.1), 4 May 2020. https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_202005_consent_en.pdf. See margins 105-108.




