AEPD (Spain) - EXP202402612
| AEPD - EXP202402612 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 5(1)(f) GDPR |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | 09.12.2022 |
| Decided: | 14.02.2025 |
| Published: | 16.09.2025 |
| Fine: | 500,000 EUR |
| Parties: | SANTANDER CONSUMER FINANCE, S.A. |
| National Case Number/Name: | EXP202402612 |
| European Case Law Identifier: | n/a |
| Appeal: | n/a |
| Original Language(s): | Spanish |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | ap |
The DPA fined a bank €500,000 for a lack of technical security measures after a data breach led to the disclosure information such as contact information, IBANs and ID documents, affecting over 100,000 data subjects.
English Summary
Facts
SANTANDER CONSUMER FINANCE, S.A. (the controller) is a bank. In October and November 2022, two companies acting as a processor for the controller reported a data breach to the DPA. The DPA began investigating following two complaints by data subjects against the processors, however, the controller was also investigated. The DPA found that the data breach affected over 100,000 data subjects, with data such as names, contact information, IBAN and ID information being available on the dark web. Some of the DPA’s findings were also based on previous data breach reports from processors contracted by the controller. The controller informed affected data subjects of the data breach in December 2022.
The controller argued that it was not the controller in this case, as the data breach was targeted towards the processors.
Holding
The DPA first dismissed the arguments by the controller. The DPA emphasised that the controller was responsible for the processing of personal data of its customers, and the negligence of third parties does not completely exempt it from responsibility. The DPA noted that, for example, the controller gave the processors insufficient instructions regarding security measures when processing personal data.
The DPA found a violation of Article 5(1)(f) GDPR. During its investigations, the DPA found that until 2021 the controller stored data subjects’ IBAN without pseudonymising it. This meant there was a high risk of the data being accessed and misused by third parties. According to the DPA, the unauthorised access would have not occurred if the controller had pseudonymised or anonymised the data.
The DPA fined the controller €500,000. The DPA considered this a serious violation, taking into account the high number of data subjects affected. In addition, the DPA ordered the controller to implement appropriate security measures.
Comment
The controller filed an internal appeal with the DPA on 14 February 2025. The DPA dismissed the appeal on the grounds that the controller had not brought any new facts or legal arguments.
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.
1/60 File No.: EXP202402612 SANCTIONING PROCEDURE RESOLUTION From the procedure initiated by the Spanish Data Protection Agency and based on the following BACKGROUND FIRST: On October 5, 2022, and November 4, 2022, two notifications of security breaches were received from MARKTEL GLOBAL SERVICES S.A. (hereinafter MARKTEL) with entry registration numbers REGAGE22e00044254458 and REGAGE22e00049917967. The following relevant information can be extracted from the content of both notifications: - Description of the breach: “(…)” - Data affected: Basic data (e.g., first name, last name, date of birth), DNI, NIE, Passport and/or any other identification document, Economic or financial data (without payment methods), Contact information. - Individuals affected: 4,251. - Date of detection: October 3, 2022 (same as the start date). - Date of incident resolution: November 4, 2022. - A complaint has been filed with law enforcement. - 4,251 affected individuals have been informed on October 6, 2022. SECOND: On October 29, 2022, and entry record REGAGE22e00048731676, a notification of a security breach was received from the data controller, SANTANDER CONSUMER FINANCE S.A. (hereinafter SANTANDER CONSUMER or SCF) with the following associated information: - Description: “(…)” Affected data: Basic data (e.g., first name, last name, date of birth), DNI, NIE, Passport and/or any other identification document, contact information. Affected: 28120. Detection date: October 28, 2022. Start date: October 3, 2022. A report has been filed with the police authorities. They state that those affected will not be informed. THIRD: On October 22, 2022, and November 21, 2022, two data breach notifications were received from ORANGE ESPAGNE SAU (hereinafter ORANGE or ORANGE ESPAGNE). The following information is extracted from their contents: - Description: “(...)” - Number of affected parties: 742,852. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 2/60 - Detection date: October 20, 2022. - Date on which those affected were informed: November 4, 2022. FOURTH: On November 10, 2022, SANTANDER CONSUMER was ordered to communicate the personal data breach to those affected and to confirm, within 30 days, that it had been resolved. complied with the order. FIFTH: On November 18, 2022, A.A.A. (hereinafter, complainant one) filed a complaint with the Spanish Data Protection Agency. The complaint is directed against ORANGE and MARKTEL. The grounds for the claim are as follows: "The complainant is a JAZZTEL customer who was informed by the operator that his or her personal data (name, surname, address, telephone number, email address, ID number, date of birth, nationality, and IBAN code (international bank account number)) may have been exposed as a result of a security incident affecting one of the company's providers. The affected party requested clarification of the exposed data and received all the information listed above in response, except for the IBAN code." Date of the events complained of: November 11, 2022. Relevant documentation provided by the complainant: - A screenshot of the email received from JAZZTEL is attached, notifying them of the security breach and the impact on their personal data. This email is dated November 11, 2022. - A screenshot of the user's response to JAZZTEL is attached after receiving the previous email, requesting more information about the security incident and the impact on their personal data. - A screenshot of JAZZTEL's response to the previous email sent by the user is attached, offering the complainant more details about the breach. This email is dated November 17, 2022. SIXTH: On December 9, 2022, B.B.B. (hereinafter, complainant two) filed a complaint with the Spanish Data Protection Agency. The complaint is directed against ORANGE and MARKTEL. The grounds for the complaint are as follows: "The complainant is an ORANGE customer who was informed by the operator that their personal data (name, surname, address, telephone number, email address, ID number, date of birth, nationality, and IBAN code) may have been exposed." as a result of a security incident that affected a supplier of the company." Date on which the claimed events occurred: December 9, 2022. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 3/60 Relevant documentation provided by the complainant: - Attached are screenshots of the emails received from ORANGE reporting the breach of their personal data. The content of this email bears the signature of both the DPO of ORANGE and ORANGE BANK. The content states that both entities act as data controllers, as ORANGE BANK is responsible for the financing of the devices purchased by the customer whose personal data has been affected. SEVENTH: Following this Agency's order of November 10, 2022, to notify those affected, SANTANDEER CONSUMER proceeded to make said communication on the following dates and through the following means: - December 7, 2022: 67,268 affected people were informed by email. - December 9, 2022: 30,578 affected people were informed by email. - December 12, 2022: 9,956 affected people were informed by email. - December 13, 2022: 6,184 affected people were informed by email. - December 15, 2022: 9,571 affected people were informed by SMS with a link to the information. For the remaining affected people (1,038), SANTANDER CONSUMER informs that it does not have valid contact information. EIGHTH: On December 15, 2022, and entry record REGAGE22e00057522607, was received. New security breach notification letter from the data controller, SANTANDER CONSUMER, due to a substantial change in information regarding the breach reported on October 29, 2022, with registration number REGAGE22e00048731676. After further investigation, a larger number of people were affected. In some cases (105,401 cases), the stolen file contained the full IBAN code. Affected data: Basic data (e.g., first name, last name, date of birth), DNI (National Identity Document), Passport and/or any other identification document, payment method data (bank card, etc.), contact information. Affected: 124,595 Detection date: October 28, 2022. Start date: October 3, 2022. Number of people informed 123,557 NINTH: In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter LOPDGDD), on December 23, 2022, these complaints were forwarded, for the purposes of this document, to ORANGE and MARKTEL so that C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 4/60 they could analyze them and inform this Agency within one month of the actions taken to comply with the requirements set forth in the data protection regulations. The following information was requested in the complaint forwarding: - Detailed and chronological description of the events. - Causes that led to the incident. - Individuals and category of personal data affected. - Possible consequences for those affected. - Actions taken to resolve the incident. - Risk analyses and preventive security measures completed, as well as impact assessments, if applicable. - Copy of the Processing Activities Log where the incident occurred. - Information on possible communication to affected individuals. - Information on possible notification of the incident to this Agency. TENTH: On January 23, 2023, and entry records REGAGE23e00004620337 and REGAGE23e00004620561, a response was received from MARKTEL regarding the transfer of the first claim, attaching the following documents: - Internal document with the incident log, dated October 3, 2022. - Internal document with the technical report of the incident, dated November 2, 2022. - Excel document with a risk analysis of the processing activities affected by the data breach. Security. - Document proving ISO 27001 certification. - Document proving the contract for cybersecurity services with Sophos. The following information is extracted from the documentation provided to this AEPD: The incident was detected on October 3, 2022, at around 5:15 a.m. and was based on an intentional attack by the cybercriminal group known as Lockbit, which managed to penetrate the company's security systems, encrypting company data and stealing sensitive content. It is stated that the causes that led to the incident have not been determined, but the use of an outdated server, an attack through social engineering, or spam email are being considered as possible causes. More details will be investigated in a new information request. The attack was detected by the security elements of the Sophos anti-malware platform, and the malware detected was Lockbit 3.0 ransomware. Proof of this detection will be requested in a new information request. It is stated that following the incident, forensic analysis services were contracted through the company Entelgy, and MARKTEL's Data Protection Officer received a preliminary report on this analysis on October 17, 2022, which C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 5/60 identified personal data leaked on the Dark Web, confirming that this data came from the service contract with ORANGE ESPAGNE for the debt collection campaign. After several extortion attempts by the attacking group (unanswered by MARKTEL), a larger volume of personal data belonging to customers operated by MARKTEL was published on October 27, 2022. On October 30, 2022, MARKTEL's technology team obtained further evidence of this breach and communicated the scope of the breach to the Data Protection Officer. It is stated that on October 19, 2022, MARKTEL initially notified ORANGE ESPAGNE of the incident through its data protection office, and subsequently, on November 2, 2022, a second notification was issued, providing updated information and attaching the technical report of the incident. Proof of both notifications will be requested in a new information request. It is stated that a police report was filed and INCIBE was notified. Proof of this will be requested in a new information request. It is stated that a police report was filed and INCIBE was notified. Proof of this report will be requested in a new information request. The following relevant information is extracted from the attached technical incident report: )a The attack encrypted the ICS Production server serving ORANGE ESPAGNE and deleted the Signology NAS Backup machine that contained its backup. However, it is stated that the data files that existed on the SFTP file-sharing system, which were four months old, were recovered. A new information request will be requested to clarify this statement and confirm whether data was lost due to the lack of recent full copies of personal data. )b After detecting the incident, the following actions were taken: the production environments were shut down, the affected elements were isolated from the network, new production environments were created, backups were uploaded, and an analysis of the overall impact of the attack was performed. )c Regarding the information published on the Dark Web, it is stated that after analyzing the files, the following data was compromised: The "Customers" table of the database containing 1,027,969 records (with a total of 803,099 unique ID numbers) and the following fields was leaked: ID. First and last name. Phone number. Email. Address (Street, Number, City, Postcode). Date of birth. Unobfuscated IBAN account numbers for 517,326 records (the remaining records were obfuscated or did not include this data). )d It is stated that until November 2021, the IBAN data was stored openly in a database; however, at the end C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 6/60 of November 2021, this data was obfuscated, which is why among the leaked data are records with clear IBAN data. )e It is stated that after carrying out the corresponding verifications of the leaked data, it is concluded that there are data for 742,852 affected individuals. )f It is stated that on October 20, 2022, MARKTEL notified ORANGE of the incident, reporting the impact of the following personal customer data (certification will be requested in a new request): Identification data (name and surname, NIF/DNI/Credit Card, Residence/Passport, address, email, telephone number). Invoice data (current account/contract holder, invoice number, invoice amount, current and total debt). Personal characteristics data (date of birth and nationality) Product data: Packages, rate, start date, end date. )g The following list of preventive measures implemented by MARKTEL is confirmed (certification will be requested in a new information request): (…) The list of reactive measures adopted by MARKTEL following the incident is confirmed (certification will be requested in a new information request): (…) It is stated that they are awaiting the results of the audit contracted with Deloitte. However, based on internal analyses conducted, it is believed that the attack vector may have been caused by a brute-force attack against the SSH service, using a Command and Control server, followed by lateral movement. A copy of the audit report prepared by Deloitte will be requested in a new information request. The response to the transfer also includes a document containing the risk analysis, created in May 2018 and updated on October 20, 2022. The following relevant information is extracted from this document: A necessity and proportionality analysis of the processing and data lifecycle is performed. 19 risk factors are identified and analyzed, each assigned a quantitative value for probability and impact, resulting in an inherent risk value. This concludes with a list of mitigating control measures that result in a new residual risk value. A section is also specified with the new security measures included as a result of this breach and the resulting residual risk update. The risk factors identified and analyzed are: (…) C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 7/60 - Attached is the Register of Processing Activities (RAT) of MARKTEL, acting as the data processor for ORANGE/JAZZTEL, collecting the following information: )a The purpose of the processing (extrajudicial or pre-litigation management of debts and management of outstanding debts). )b The categories of data processed and the categories of data subjects affected. )c The deletion periods. )d Possible international transfers. )e Description of the security measures implemented to guarantee the processing. - Regarding the communication to those affected, it is stated that MARKTEL did not provide any notification, acting at all times as the data controller of the affected personal data. It is stated that MARKTEL merely followed the instructions of the affected data controller. ELEVENTH: On January 27, 2023, and through the entry records REGAGE23e00005596907 and REGAGE23e00005596460, a response was received to the transfer of the first claim from ORANGE. From an analysis of the documentation provided, the following information is obtained. - The data processor received notification of the breach on October 19, 2022, is hereby confirmed. - It is stated that the affected personal data includes customers of SANTANDER CONSUMER AND/OR ORANGE BANK SA (hereinafter ORANGE BANK), entities with which ORANGE has an agreement to finance terminals purchased by its customers and for which ORANGE itself acted as the data processor for the management of debt collection operations in the event of non-payment, a service for which MARKTEL was subcontracted. It is stated that these affected data processors were notified of the incident on October 25, 2022. Their accreditation will be requested in a new information request. - It is stated that after becoming aware of the incident, it was decided to suspend the service contracted with MARKTEL until security guarantees were in place. - It is stated that 742,852 customers were affected, with the following leaked data: First and last name, ID, address, email, date and place of birth, nationality, phone number, IBAN, current account holder, invoice amount, current and total debt. Regarding the IBAN data, it is stated that on November 23, 2021, this data was no longer provided to the sub-processor MARKTEL. - Regarding the possible consequences, it is stated that the affected individuals could encounter significant inconveniences, causing limited damage, which they will be able to overcome despite some difficulties. However, it is stated that there is no evidence of this possible consequence materializing for any affected customers. - It is stated that the affected individuals were notified of the security incident between November 4, 2022, and November 7, 2022. Their accreditation will be requested in a new information request. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 8/60 - It is stated that between December 7 and 9, 2022, a new communication was sent to the affected parties, identifying SANTANDER CONSUMER and ORANGE BANK as data controllers. Proof of this will be requested in a new information request. - Regarding the measures adopted by ORANGE to respond to the incident, the following list is attached: (…) - A document containing an analysis of the risk factors for the processing is provided. This document is the same as the one previously provided in the response given by the MARKTEL manager and referenced in the previous points. - Regarding the communication to the affected parties, it is stated that SMS and email were used, with the text sent varying depending on whether the IBAN was affected. Proof of all communications will be requested in a new information request. - A document is provided with the action plan, including the reactive measures adopted by MARKTEL and their implementation date: (…) TWELFTH: The responses given by MARKTEL and ORANGE to the transfer of the second claim, from which no additional information was obtained relevant to that already analyzed in the previous background, are also received. THIRTEENTH: In February 2023, both claims were admitted for processing. FOURTEENTH: The Subdirectorate General of Data Inspection proceeded to carry out preliminary investigative actions to clarify the facts in question, pursuant to the functions assigned to supervisory authorities in Article 57.1 and the powers granted in Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VII, Chapter I, Section Two, of the LOPDGDD (General Data Protection Act), having learned of the following: The inspector conducted an internet search for the existing data leak, detecting a single point of dissemination through the website of the Lockbit attack group on the Dark Web. It is confirmed that the group made an initial publication of data on October 12, 2022, and subsequently published a larger data file (43 GB) on October 30, 2022. During the inspection, the data was downloaded in a secure environment and the type of personal data contained in this leak was analyzed, yielding the following conclusions: - As stated in the technical incident report provided by MARKTEL, there is a folder ***REFERENCE.1 that stores the following relevant SQL files with personal data: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 9/60 )a ***REFERENCE.2: includes personal data of customers that match the information provided in the technical incident report by MARKTEL. )b ***REFERENCE.3: with identical information to that contained in the technical incident report provided by MARKTEL. - Folder ***REFERENCE.4 containing an export of the database table named ***REFERENCE.5, which includes the fields customer_id, age, sex, marital_status, employment_status, postal_code, city, province, children, children's age, and purchasing power. This information may not have been mentioned in the breach notifications or in the response to the transfer of the complaint by MARKTEL. Furthermore, the inspection detected that this Agency carried out the notification of an order to notify those affected by the breach notified by SANTANDER CONSUMER. This order was notified on November 8, 2022, requiring confirmation of compliance within 30 days. This order is complied with by this responsible party. Considering the information obtained at this point in the investigation, on May 29, 2023, it was decided to issue a new information request to MARKTEL, ORANGE ESPAGNE, and SANTANDER CONSUMER, marked by the following lines of investigation: - For MARKTEL: )a Investigate all potential data controllers affected by the data breach. )b Request the audit report prepared by Deloitte. )c Investigate the attack vector of the breach. )d Request accreditation of the listed and referenced preventive measures. - For ORANGE ESPAGNE: )a Investigate the correct formalization of data processing orders. )b Investigate the possible loss of data availability due to the breach. )c Investigate proper communication to those affected. - For SANTANDER CONSUMER: )a Investigate the adequacy of the contract with ORANGE ESPAGNE. )b Investigate the communication to those affected as the data controller. )c Investigate the existence of risk analyses for the rights and freedoms of those affected. On June 19, 2023, and with entry records REGAGE23e00039953302, REGAGE23e00039953372, REGAGE23e00039953646, REGAGE23e00039953646, REGAGE23e00039953771, and REGAGE23e00039953828, a response to the request was received from MARKTEL. The inspector's analysis revealed the following relevant information: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 10/60 - It is confirmed that the leaked personal data pertains to the orders formalized with ORANGE ESPAGNE. - They confirm the contract for processing. The inspector's analysis concludes: )a The contract for the provision of call center services with ORANGE ESPAGNE (identified in the contract as OSP) replaces the contract signed in 2018 for debt collection services and takes effect from January 1, 2022, and incorporates the purpose of the processing contract, the personal data affected, the categories of data subjects, the obligations assumed by the data processor, and the security measures. Regarding security measures, the following is set forth in Clause 17 "Data Protection," Section 2.6.d) of the contract: In cases where data is processed in the SUPPLIER's systems, the SUPPLIER undertakes to ensure, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the risks of varying probability and severity for the rights and freedoms of natural persons, the implementation of appropriate technical and organizational measures to ensure a level of security that, where appropriate and among others, includes: • Pseudonymization and encryption of personal data; • The ability to guarantee the confidentiality, integrity, and permanent availability and resilience of processing systems and services; • The ability to restore the availability of and access to personal data quickly in the event of a physical or technical incident; • A process of regular verification, evaluation, and assessment of the effectiveness of the technical and organizational measures to ensure the security of the processing. When assessing the adequacy of the security level, the PROVIDER will take into account the risks posed by data processing, in particular, as a result of the accidental or unlawful destruction, loss, or alteration of personal data transmitted, stored, or otherwise processed, as well as unauthorized communication or access to such data. The SUPPLIER must implement at least the technical and organizational measures described in the Information Security Annex attached to this Contract, as well as any other security measures that ORANGE determines from time to time and communicates to the SUPPLIER. Annex III of the Information Security Annex attached to the aforementioned Contract establishes the following: ANNEX III SPECIFIC MEASURES REGARDING INFORMATION SECURITY AND CODE OF CONDUCT FOR SUPPLIERS AND FRAUD CONTROL AND REVENUE ASSURANCE (…) C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 11/60 - They state that they detected the attack when they noticed, on the morning of October 3, 2022, that some applications presented access denial anomalies, From this moment on, the existence of encrypted elements was observed on the servers. Documentary evidence shows that the Sophos anti-malware protection system also detected and alerted to the attack and subsequent lateral movements on the servers. At this point, the incident was escalated to the cybersecurity team. - The complaint filed on October 7, 2022, with law enforcement is accredited. It includes the following statements made by MARKTEL: )a "The attack involves ransomware whose objective is to block access to the affected device, specifically the so-called Lockbit 3.0." )b "Following the incident, it was found that four internal servers were affected by the attack, affecting systems such as SAP, SAGE, and internal tools that affect the company's obligations to meet official obligations." )c "The measures and actions to minimize the damage consisted of suspending the group's services, that is, isolating them, as a precautionary measure to stop the spread. Once the attack was identified, cleanup work began. At the same time, the cybersecurity team established a permanent control and monitoring system." - They claim that it wasn't until October 17, 2022, that the company contracted for the forensic analysis reported the leak of personal data on the Dark Web. They affirm that on this date, the existence of a security breach related to data from the contract with ORANGE ESPAGNE and VODAFONE ESPAÑA became known with certainty. - The notifications issued by MARKTEL as the data processor to the two previous data controllers are confirmed. This notification was made on October 19, 2022. - Regarding the recovery of the encrypted personal data, it is stated that MARKTEL works with a copy of each data controller's personal data, and, therefore, the data remained available at all times, so there was no impact on availability. - Regarding our request for clarification as to why, among the leaked data, there was a database table named ***REFERENCE.5 containing a greater amount of personal data than that notified in the breach, they responded that this table does not belong to MARKTEL but to the company MIA ADVANCED SYSTEMS SL, and that it was located on MARKTEL's servers because it provides an information hosting service on its servers to this company. However, they state that the data contained in this table is anonymous and does not allow the identification of natural persons, and that it only contains data grouped by cluster of interest and used to improve operational efficiency. - A document is provided with the audit report conducted by Deloitte on December 1, 2022. It concludes that the entry vector for the breach could not be determined, indicating that the incident could have been C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 12/60 caused by an attack via a "Command and Control" server on one of MARKTEL's corporate servers through remote SSH login attempts. - Two reports from the companies Entelgy and Sophos on the causes of the incident are also certified. The inspector's analysis yields the following verbatim statements: (…) - It is stated that a "double backup policy" is in place that performs backups on the production servers and on four high-capacity NAS servers, two of which were compromised, with their disks encrypted and the operating system erased. Following the incident, (…) was implemented. - The following preventive measures, completed from the risk analysis, are documented: )a (…) - Regarding the verification of the communication from those affected, they state that MARKTEL only notified the affected data controllers, who subsequently communicated the incident to those affected. The notification made to ORANGE ESPAGNE and VODAFONE ESPAÑA via email on October 19, 2022, is confirmed. On June 20, 2023, and through the entry records REGAGE23e00040164903 and REGAGE23e00040165559, a response to the request was received from ORANGE ESPAGNE. The following relevant information is extracted from its analysis: - A copy of the order contract with SANTANDER CONSUMER is provided. From its analysis, it is concluded: Regarding the contract with SANTANDER CONSUMER, a document formalized on the date of signature on July 7, 2015, is provided, containing the following relevant information: Purpose of the contract: provision of billing, debt collection, after-sales, ARCO rights management, and debtor data management in the assignment of credits. Obligations of the data processor, including the need to apply medium-level measures, to manage ARCO rights, to communicate to those affected, and to notify unauthorized access (among other obligations). The registration of the affected files in the General Registry of the AEPD is included as an annex, in accordance with the old data protection regulations. Regarding subcontracting, it is established: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 13/60 “The DATA PROCESSOR may subcontract the services covered by the Service Provision Contract to a third party, provided that the following requirements are met: - That the DATA PROCESSOR communicates all data (company name, registered office, identification number, etc.) of the subcontractor to the FILE CONTROLLER, in writing, prior to contracting. That the processing of data by the subcontractor complies in all cases with the instructions of the FILE CONTROLLER. - That a written contract is formalized between the DATA PROCESSOR and the subcontracting company, under the same terms as this document, and in which it is stated that the The subcontractor will comply with the instructions of the FILE CONTROLLER. Once the contract has been signed, the DATA PROCESSOR is obliged to send a copy of it to the DATA CONTROLLER. The DATA PROCESSOR will monitor the quality and level of compliance of the obligations of the suppliers with whom it has subcontracted with the same diligence it must observe in the fulfillment of its own obligations, being personally responsible for them and exonerating the DATA CONTROLLER from any liability arising from its actions." - A copy of the contract signed between ORANGE ESPAGNE and MARKTEL, already analyzed in previous points, is provided. - Regarding proof of notification of the breach to each affected data controller, a screenshot is provided of the emails sent on October 25, 2022, addressed to SANTANDER CONSUMER, the content is as follows: "(...)". - The following relevant statements were made by ORANGE ESPAGNE: )a "Among those affected, it was determined that there were customers of Santander Consumer Finance and/or Orange Bank, entities with which Orange has an agreement to finance the terminals and equipment purchased by Orange/Jazztel customers, and for which Orange is also the data processor for managing debt collection operations in the event of non-payment on behalf of Santander Consumer Finance and/or Orange Bank. With respect to these customers, Orange Espagne S.A.U. therefore assumes the dual role of data controller and data processor. This is duly reflected in the attached RAT extract, in the 'data processor/subprocessor identification' column, along with the details of the processing." C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 14/60 )b “Regarding the number of affected individuals who were notified directly, 85,871 communications were sent via SMS; and 621,741 communications via email, depending on the contact channel available. It should be clarified that there were records for which no contact channel (email or contact number) was available or these were incorrect, for example, an email address with an incorrect format. For these purposes, since direct contact with the affected individuals is impossible, in accordance with the provisions of the Guide for the notification of personal data breaches issued by this Agency, the following entry was published on the Orange corporate blog (access to which remains available as of the date of this writing). Likewise, in order for the incident to be sufficiently disseminated so that it would not go unnoticed by any customer of Orange/Jazztel, Orange proceeded to report the incident to the National Cybersecurity Institute for publication." )c "The communications were sent between November 4, 2022, and November 7, 2022. Likewise, as previously reported, between December 7 and 9, 2022, a communication was sent in the same terms to those customers whose data was affected. Since they had a debt arising from the purchase of a terminal on installments, their data was also processed by the controllers, Orange Bank and/or Santander Consumer Finance." On October 19, 2022, and entry record REGAGE23e00039958979, a response to the request was received from SANTANDER CONSUMER. The inspector's analysis revealed the following relevant information: - Regarding the data processing assignment with ORANGE ESPAGNE, the following statement was made: )a "On July 7, 2015, the Parties entered into a Service Provision Agreement attached as Document No. 2 hereto, by which Orange would provide Santander Consumer with billing, collection, debt collection, and after-sales services to its customers, and which regulates Orange's data processing assignment." )b "That on January 2, 2020, Santander Consumer received notification from Orange indicating its intention not to extend the Service Contract. However, it is agreed that Orange will maintain the services in relation to the assigned credits at the maturity date until the full collection of the economic rights or the completion of the Collection services for said credits. This communication is attached as Document No. 2." Attached document No. 2 contains only an email sent by SANTANDER COSUMER to ORANGE ESPAGNE acknowledging the notification received with the intention of not extending the framework agreement for the sale of credits, also affirming the controller's willingness to achieve "mutual collaboration in good faith not only to facilitate an orderly resolution of the contractual relationship, but also for the purpose of maintaining the management of services related to the credits assigned to the maturity date until the full payment of the economic rights or the completion of the collection services for them." C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 15/60 - They provide a risk analysis for the rights and freedoms of the processing of the activities affected by the breach, concluding that one of them is high risk and providing the DPIA prepared accordingly. From the inspector's analysis of these documents, the following is obtained: )a The risk analysis was initially conducted in August 2020 and subsequently updated in April 2022 and May 2023. )b It includes an analysis of the suitability, necessity, and proportionality of the processing. )c It includes a description of the processing and the life cycle of the data. - Regarding the chronology and recording of the incident, it is stated: )a That on October 25, 2022, ORANGE ESPAGNE notified them of the breach. )b “In an initial analysis of the incident, the total number of affected customers rose to 28,120, and therefore, on October 29, 2022, it was decided to report the incident to the AEPD by Santander Consumer. Subsequently, and following investigations, the total number of affected customers rose to 124,595, as reported to the AEPD in the information with registration number REGAGE22e00057522607. On November 16, 2022, Santander Consumer received a request from the AEPD to notify interested parties about the incident, establishing a period of 30 days to respond to the Agency. Between December 7 and 16, 2022, and within the stipulated period, communications were sent to the interested parties and the Agency responded.” )c It states: "That, with the aim of providing greater transparency and generating a lesser impact on those affected, the communication has been made jointly by Orange Espagne S.A.U. and Santander Consumer, since (i) the affected data is the responsibility of both Orange Espagne S.A.U. (for processing arising from telecommunications services) and Santander Consumer (for processing arising from terminal financing), and (ii) Orange Espagne S.A.U. is also responsible for Santander Consumer, according to the Agreement signed by both parties on July 7, 2015, for processing arising from terminal financing, including communications with customers." - A screenshot is provided proving the communication sent via email to the affected individuals. The text is signed by the data protection officers of Orange Espagne and Santander Consumer and refers to the actions of both entities as data controllers of the affected data. FIFTEENTH: SANTANDER CONSUMER. is a commercial entity whose global parent company is Banco Santander, S.A., according to the information contained in its own "2022 Annual Report" of the Santander Group, which details the corporate structure of the Santander Group and its turnover. This report C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 16/60 records that the total global annual turnover of Banco Santander, S.A. and its subsidiaries (Santander Group) in the financial year prior to the commission of the infringement, 2021, was €52,117 million (see page 836 of the aforementioned "2022 Annual Report"). SIXTEENTH: On February 16, 2024, the Director of the Spanish Data Protection Agency agreed to initiate sanctioning proceedings against the respondent, in accordance with the provisions of Articles 63 and 64 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), for the alleged violation of Article 5.1.f) of the GDPR, classified as such in Article 83.5 of the GDPR. The initiation agreement was sent, in accordance with the rules established in the LPACAP, via electronic notification and was received on February 21, 2024, as evidenced by the certificate in the file. SEVENTEENTH: Having requested an extension of the period granted to submit allegations, as well as a copy of the file, pursuant to the provisions of Article 32.1 of the LPACAP, on February 23, 2024, it was agreed to extend said period up to a maximum of ten days, to be counted from the day following the day on which the copy of the file was received. On March 20, 2024, the requested copy was sent in accordance with the provisions of Article 53.1 a) of the LPACAP. EIGHTEENTH: After notification of the aforementioned initiation agreement in accordance with the rules established in the LPACAP, the investigated entity submitted a written statement of allegations. NINETEENTH: On December 20, 2024, a proposed resolution was formulated, proposing: <<That the Director of the Spanish Data Protection Agency sanction SANTANDER CONSUMER FINANCE, S.A., with NIF A28122570, for violating Article 5.1.f) of the GDPR, classified in accordance with the provisions of Article 83.5 of the GDPR, classified as very serious for the purposes of the statute of limitations, in Article 72.1 a) of the LOPDGDD, with a fine of 500,000 euros. That the Director of the Spanish Data Protection Agency order SANTANDER CONSUMER FINANCE, S.A., with Tax Identification Number (NIF) A28122570, pursuant to Article 58.2.d) of the GDPR, within six months of the finality of the resolution concluding this procedure, to certify that it has implemented the necessary measures to guarantee the confidentiality and integrity of the data on whose behalf it processes them, and to inform this Agency, within the same period, of the measures adopted.>> The aforementioned resolution proposal was sent, in accordance with the standards established in the LPACAP, by electronic notification, and was received on December 26, 2024, as evidenced by the certificate in the file. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 17/60 TWENTIETH: On December 26, 2024, SANTANDER CONSUMER submitted a document requesting an extension of the deadline for submitting objections, as well as access to the administrative file. On December 30, 2024, the investigating body agreed to an extension of the deadline up to a maximum of five days, to be counted from the day following the end of the first period for objections. A copy of the documents added to the file was attached, since the response to the last access request, dated March 21, 2024, the date on which the full copy was delivered by courier on a flash drive. The aforementioned agreement was notified on December 30, 2024, as recorded in the acknowledgment of receipt included in the file. TWENTY-FIRST: On January 20, 2025, SANTANDER CONSUMER submitted a written statement of objections to the Proposed Resolution, in which, in summary, it states that: FIRST. - VIOLATION OF THE PRINCIPLE OF THE PRESUMPTION OF INNOCENCE. It states that this principle has been clearly violated, since there is not a single investigative action that would allow it to be concluded that the cyberattack perpetrated was indeed caused by a lack of measures on the part of the data controller and not by acts of vandalism carried out by a third party, which is considered a criminal group, as recognized by the Ministry of the Interior on its website. It indicates that we are dealing with a pioneering criminal group in the exploitation of ransomware-as-a-service models. Therefore, it considers that the AEPD has not analyzed the specific factual situation, but has simply limited itself to requiring the implementation of certain security measures as an obligation of results and not of means. Therefore, there is a clear contradiction, given that the criterion established by the Supreme Court, in its Judgment 188/2022 of February 15, 2022, established that the obligation to adopt security measures is an obligation of means. Consequently, it states that there is a significant deprivation of the powers of proof and contradiction, resulting in a significant imbalance in the position occupied by SANTANDER CONSUMER in the proceedings and, as a result, a material lack of defense, incurring the defect of voidability of art. 48.2 of the LPACAP. It is, to say the least, striking that the AEPD has flatly failed to make any statement regarding the reason that led it to depart from the position held by the Supreme Court regarding the exclusion criterion for the objective imputation of the "prohibition of return," especially considering that the impact of the actions derived from the malicious action of an organized group, on the infringement being charged, stems from the decision not to accede to extortion by the data processor. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 18/60 In short, it alleges that this Agency bases its allegations on mere hypotheses and without any logical reasoning based on a coherent contradiction with respect to the allegations presented by this party in the written statement of allegations to the Agreement to Initiate Sanctioning Procedure. SECOND. - ADEQUATE SECURITY MEASURES AND THE ABSENCE OF INTENTIONALITY OR NEGLIGENCE GREATER OR GREATER THAN THE TYPE THAT COULD BE TAKEN INTO CONSIDERATION TO INCREASE THE SERIOUSNESS OF THE FACT. The Court emphasizes that the Company cannot be held liable for the alleged violation, given that the security breach that occurred on the Subprocessor's media was a direct consequence of an attack perpetrated by a criminal group that used advanced computer engineering techniques to compromise established security measures. Therefore, the Court considers that the Resolution does not assess the decisive influence of the actions of a third party, in this case, a criminal group with international reach that operates outside the legal framework. It is clear, as established above, that the orchestrated attack is aligned with the characteristics provided for in the criminal framework, having been carried out using advanced techniques that exceed security standards, which demonstrates its purpose. It is essential to emphasize that the Company cannot be held guilty of the alleged violation, since the security breach was not the result of a negligent act or omission on its part, but rather an external and extraordinary event. As recognized by case law, it argues that, in order to determine the sanction, as well as its amount, it is necessary to take into consideration the intentionality or negligence of the infringement, as well as the nature, severity, and duration of the infringement, the categories of personal data affected, and the manner in which knowledge of the infringement was obtained. Therefore, it considers that the AEPD—unilaterally—decided not to apply the fundamental criteria that govern the difference between misconduct and sanction, concluding in a discretionary action, once again violating the principle of proportionality. Furthermore, in accordance with preamble 146 of the GDPR, the imposition of sanctions, including administrative fines, must be subject to sufficient procedural guarantees in accordance with the general principles of EU law and the Charter, including the right to effective judicial protection and due process. THIRD. - OF THE OBLIGATIONS ASSUMED BY EACH OF THE PARTIES AND THE RESPONSIBILITIES ARISING THEREFROM. The Court states that the criminal acts that led to the notification of the security incident originated in the systems of the Subprocessor, which is why it cannot be ignored that the loss of confidentiality as a result of the data extraction is due to these circumstances. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 19/60 Therefore, it alleges that it was and is the data processor who should and must ensure that the guarantees established pursuant to Article 28 of the GDPR were complied with to the fullest extent. It is clearly stated that ORANGE, pursuant to the provisions of Article 28 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector (hereinafter, the "LRJSP"), is the company responsible for the act allegedly constituting an infringement committed by its Subprocessor and, therefore, the one who must bear the fine imposed by this Agency. In any case, any negligent or culpable action contrary to current and applicable data protection regulations falls upon the data processor, without it being considered that SANTANDER CONSUMER did not have adequate technical and organizational measures, as required by Article 32 of the GDPR. Thus, the Court argues that there is no doubt that the attribution of an infringement arising from the actions entrusted to the data controller calls into question the proper and/or correct application of European data protection regulations, in addition to the provisions of our national law. All of this, without forgetting the serious repercussions that systematic action against the data controller can entail, both reputationally and financially, especially considering that the Company acted with due diligence and in accordance with the law. FOURTH. - VIOLATION OF THE GUIDING PRINCIPLES OF THE ADMINISTRATIVE SANCTIONING PROCEDURE. It alleges that there is a more than evident lack of motivation and, therefore, the reason why this Agency, in this Sanctioning Procedure, deviates from the criteria followed in other proceedings has not been duly justified, see (i) the security breach suffered by Facebook in 2019, which affected 533 million users, including almost 11 million users in Spain; (ii) the cyberattack suffered by Decathlon, in which more than 123 million registered user data were exposed, several million of which were Spanish users; or (iii) the cyberattack on Iberdrola in 2022, in which the data of 1.3 million customers, coincidentally all of which were archived, was compromised. Furthermore, it states that, in addition to the aggravating circumstance of culpability and/or negligence—refuted in the Second Allegation—the fact that the Company's activity involves the handling of a large amount of personal data in each of the cases has also been established as an aggravating circumstance, without the competent body being limited to resolving the specific facts. The fact that SANTANDER CONSUMER processes a large amount of personal data as a result of its activity cannot be used as a catch-all to impose a fine due to the unlawful actions of third parties, despite the adoption of strict measures to ensure the proper processing of personal data. It considers that, however, in determining the sanction to be imposed for the alleged breach of Article 5.1 f) GDPR, the AEPD relies on Article 83.5 GDPR, but it self-servingly seeks to extrapolate facts that have not been taken into account in applying the criteria established in Article 83 GDPR, which have not been fully observed, but are simply taken into account in applying aggravating factors, but in no case mitigating factors. To this end, it states that, as described throughout the written statement, in no case has SANTANDER CONSUMER been found guilty or negligent, nor have any losses or damages suffered by its customers been reported. This is crucial, given that the claims filed and which led to the initiation of the investigations are completely unrelated to this entity. It is also completely incorrect to indicate that the violation was committed by failing to maintain obfuscated IBAN data—a criterion distinct from encryption, with all the implications this may entail. It is understood that proactivity, the response throughout the communication phase of the incident and answers to the questions posed by the AEPD, as well as the fact that it was this same party that informed the Agency about the security breach, must be taken into consideration, as well as the lack of benefit as a consequence of the alleged violation, in order to quantify the penalty. Thus, the Court considers that not only is the Agency's actions reprehensible for failing to take into consideration the actual facts—the nature, severity, duration of the violation, scope, number of affected parties, level of damage or harm suffered—but also ignoring the fact that mens rea is generally required to impose a criminal sanction and that, therefore, strict liability constitutes a kind of "exception" to this general rule, insofar as it must be justified in light of the objectives pursued by the Regulation. This sanction is, in turn, incompatible with the principle of legal certainty arising from Article 25.1 of the EC, since an ad hoc grading of the sanction leaves broad limits for the sanctioning body. In light of the foregoing, the Court requests that the present proceedings be closed, rendering the Initiation Agreement null and void. However, in the event that the AEPD does not consider all of the claims raised by SANTANDER CONSUMER, it requests that this supervisory authority proceed with the correct quantification of the penalty, taking into account all the facts described in the document. In light of all the actions taken by the Spanish Data Protection Agency in this proceeding, the following facts are considered proven: PROVEN FACTS FIRST: It has been confirmed that, on October 3, 2022, the MARKTEL team detected that some applications were experiencing access problems, and from that moment on, encrypted elements were observed on the servers. It is noted that anti-malware protection equipment was in place that detected the existence of lateral movement on servers, but was unable to contain the attack. It has also been confirmed that the attackers were inside MARKTEL's systems at least since September 11, 2022. However, it was not until October 17, 2022, that the personal data leak became known after publication was detected on the attacker's Dark Web website. The information published on the Dark Web came from the "Customers" table of the database, with some open data, which contained 1,027,969 records (with a total of 803,099 unique ID numbers) and the following fields: • ID. • First and Last Name. • Telephone. • Email. • Address (Street, Number, Town, Postcode). • Date of Birth. • Unobfuscated IBAN account numbers for 517,326 records (the remaining records were obfuscated or did not include this information). SECOND: On October 5, 2022, and November 4, 2022, two security breach notifications were received from MARKTEL with entry registration numbers REGAGE22e00044254458 and REGAGE22e00049917967. The following relevant information can be extracted from the content of both notifications: - Description of the breach: “(...)” - Data affected: Basic data (e.g., first name, last name, date of birth), DNI, NIE, Passport and/or any other identification document, Economic or financial data (without payment methods), Contact information. - Affected individuals: 4,251. - Detection date: October 3, 2022 (same as the start date). - Incident resolution date: November 4, 2022. - A complaint has been filed with law enforcement. - 4,251 affected individuals have been informed on October 6, 2022. THIRD: On October 29, 2022, and with the entry record REGAGE22e00048731676, a security breach notification was received from the data controller, SANTANDER CONSUMER, with the following associated information: Description: "(...)" Affected data: Basic data (e.g., first name, last name, date of birth), DNI (National Identity Document), Passport and/or any other identification document, contact information. Affected individuals: 28,120. Detection date: October 28, 2022. Start date: October 3, 2022. A report has been filed with the police authorities. They state that those affected will not be informed. FOURTH: It is recorded in the letter dated June 19, 2023, registration EGAGE23e00039958979, from SANTANDER CONSUMER that, following the order of this C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 22/60 Agency to communicate with those affected, said communication was made on the following dates and by the following means: - December 7, 2022: 67,268 affected people informed by email. - December 9, 2022: 30,578 affected people informed by email. - December 12, 2022: 9,956 affected individuals were informed by email. - December 13, 2022: 6,184 affected individuals were informed by email. - December 15, 2022: 9,571 affected individuals were informed by SMS with a link to the information. For the remaining affected individuals (1,038), valid contact information was not available. FIFTH: On December 15, 2022, and with entry registration number REGAGE22e00057522607, a security breach notification was received from the data controller, SANTANDER CONSUMER, due to a substantial change in the information regarding the breach reported on October 29, 2022, with registration number REGAGE22e00048731676. After further investigation, a larger number of affected individuals has been identified. In some cases (105,401 cases), the stolen file contained the full IBAN code. Affected data: Basic information (e.g., first name, last name, date of birth), DNI (National Identity Document), Passport and/or any other identification document, Payment method information (bank card, etc.), Contact information. Affected: 124,595 Detection date: October 28, 2022. Start date: October 3, 2022. Number of people reported: 123,557 SIXTH: A leak has been confirmed in the "Customers" table of the database, with some open data, containing 1,027,969 records, with a total of 803,099 unique ID numbers (124,595 people affected by SANDANDER CONSUMER) and the following fields: ID number. First and last name. Telephone number. Email address. Address (Street, Number, Town, Postcode). Date of birth. Unobfuscated IBAN account numbers from 517,326 records related to SANTANDER CONSUMER C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 23/60 105,401 cases (the remaining records were either obfuscated or did not include this data). The technical report on the incident, dated November 2, 2022, provided by MARKTEL, states that "Until last November 2021, the bank account number was openly displayed in the database fields sent for daily production. Starting at the end of November 2021, Orange obfuscated this field, and the bank account number is no longer openly displayed in the production files sent to us." SEVENTH: Regarding liability for the leaked personal data, it has been established that MAKTEL acted as a sub-processor, subcontracted by ORANGE ESPAGNE to provide debt collection services for customers who acquired debts for the purchase of terminals on installment payments. ORANGE ESPAGNE acted in a dual role with respect to this data: on the one hand, as the data controller of the personal data provided during the purchase, and on the other, as the data processor for SANTANDER CONSUMER FINANCE, as there was a transfer of credit rights for the debts incurred in the installment purchase of the terminals. SANTANDER CONSUMER and ORANGE ESPAGNE were responsible for managing the collection operations in the event of non-payment. EIGHTH: It is established that on July 7, 2015, ORANGE ESPAGNE. and SANTANDER CONSUMER formalized a Service Provision Agreement, through which Orange would provide Santander Consumer with billing, collection, debt collection, and after-sales services to its customers, and which regulates Orange's data processing assignment. The data processor agreement, in relation to security measures, indicates that medium-level measures must be applied. Regarding subcontracting, it establishes: "The DATA PROCESSOR may subcontract the services covered by the Service Provision Agreement to a third party, provided that the following requirements are met: - That the DATA PROCESSOR communicates all data (company name, registered office, identification number, etc.) of the subcontractor to the DATA CONTROLLER, in writing, prior to contracting." - That the processing of data by the subcontractor complies in all cases with the instructions of the FILE CONTROLLER. - That a written contract be formalized between the DATA PROCESSOR and the subcontractor, under the same terms as this document, and in which it is stated that the subcontractor will comply with the instructions of the FILE CONTROLLER. Once the contract is signed, the DATA PROCESSOR is obliged to send a copy of it to the FILE CONTROLLER. The DATA PROCESSOR will monitor the quality and level of compliance with the obligations of the subcontracted suppliers with the same diligence that it must observe in the fulfillment of its own obligations, being personally responsible for them and exonerating the DATA CONTROLLER from any liability arising from its actions. Regarding its validity, it is indicated that its duration is linked to the execution of the Service Provision Contract and, therefore, would have the same duration as said service contract, which was valid until July 1, 2017, although it could be tacitly extended for two-year periods. NINTH: SANTANDER CONSUMER has informed this Agency that on January 2, 2020, Santander Consumer received notification from Orange announcing its intention not to renew the Service Contract. However, it was agreed that Orange would maintain the services in relation to the credits assigned at the maturity date until full collection of the economic rights or completion of the collection services for these. Document No. 2 is provided, which contains only an email sent by SANTANDER CONSUMER to ORANGE ESPAGNE acknowledging the notification received with the intention of not renewing the master purchase agreement. credits, also affirming the controller's willingness to achieve "mutual collaboration in good faith not only for the purpose of facilitating an orderly resolution of the contractual relationships, but also for the sake of maintaining the management of services related to the credits assigned at the maturity date until the full payment of the economic rights or the completion of the collection services for them." TENTH: ORANGE ESPAGNE signed a processor contract with MARKEL with retroactive effect from January 1, 2022, which includes the purpose of the processing assignment, the personal data affected, the categories of data subjects, the obligations assumed by the processor, and the security measures. In said contract, Clause 17 regarding data protection establishes, regarding security measures, in section 2.6.d), that: d. In cases where the data is processed in the systems of the PROVIDER, this is obliged to guarantee, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the implementation of appropriate technical and organizational measures to ensure a level of security at risk, which, where appropriate and among others, includes: Pseudonymization and encryption of personal data; The ability to guarantee the permanent confidentiality, integrity, availability, and resilience of processing systems and services; The ability to restore the availability of and access to personal data quickly in the event of a physical or technical incident; C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 25/60 A process of regular verification, evaluation, and assessment of the effectiveness of the technical and organizational measures to ensure the security of the processing. When assessing the adequacy of the security level, the SUPPLIER will take into account the risks posed by data processing, in particular, as a result of the accidental or unlawful destruction, loss, or alteration of personal data transmitted, stored, or otherwise processed, as well as unauthorized communication or access to such data. The SUPPLIER must implement, at a minimum, the technical and organizational measures described in the Information Security Annex attached to this Agreement, as well as any other security measures that Orange determines from time to time and communicates to the SUPPLIER. ANNEX III SPECIFIC MEASURES REGARDING INFORMATION SECURITY AND SUPPLIER CODE OF CONDUCT AND FRAUD CONTROL AND REVENUE ASSURANCE (…) ELEVENTH: In relation to compliance with the obligations of Notification of the breach to both this Agency and those affected has confirmed the following chronology of events: - On October 17, 2022, MARKTEL first learned of the data breach and notified its customers of the breach. - On October 22, 2022, ORANGE ESPAGNE notified the AEPD of the breach. - On October 24, 2022, ORANGE ESPAGNE learned of the personal data breach of SANTANDER CONSUMER and notified the AEPD of the breach on October 25, 2022. - On October 29, 2022, SANTANDER CONSUMER notified the AEPD of the breach. - On November 4, 2022, ORANGE SPAGNE sent an initial communication of the breach to those affected. It did not mention SANTANDER CONSUMER as the data controller. - On On November 10, 2022, this Agency sent an order to notify those affected without undue delay, addressed to the data controller, SANTANDER CONSUMER. - Between December 7 and 16, 2022, SANTANDER CONSUMER FINANCE notified the customers affected by the breach. This communication was carried out by ORANGE ESPAGNE as the data processor. However, it has been confirmed that SANTANDER CONSUMER learned of the breach on October 25, 2022. TWELFTH: The implementation of the following list of preventive measures by MARKTEL prior to the incident has been confirmed: (…) C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 26/60 THIRTEENTH: The implementation and deployment of the following list of reactive measures adopted by MARKTEL: - (…) FOURTEENTH: Regarding the customers affected by the breach whose data were the responsibility of SANTANDER CONSUMER (following the transfer of credit rights from ORANGE ESPAGNE), it has been confirmed that these customers were informed of this transfer of credits on the purchase invoice itself, including a text in the invoice footer with the following information: - That SANTANDER CONSUMER is responsible for the credit rights of the debt incurred and their personal data. - That SANTANDER CONSUMER had delegated collection management to ORANGE ESPAGNE itself. - The existence of data protection rights and how to exercise them. - An email address for additional information. LEGAL BASIS I Jurisdiction In accordance with the powers provided for in Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), grants each supervisory authority, and in accordance with the provisions of Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), the President of the Spanish Data Protection Agency is competent to resolve this procedure. Likewise, Article 63.2 of the LOPDGDD establishes that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development, and, insofar as they do not contradict them, in a subsidiary capacity, by the general rules on administrative procedures." II Preliminary Questions SANTANDER CONSUMER is a large company in the financial sector, specializing in consumer finance. For this purpose, it processes personal data, meaning personal data: “any information relating to an identified or identifiable natural person.” It carries out this activity in its capacity as data controller, given that it is the party that determines the purposes and means of such activity, pursuant to Article 4.7 of the GDPR: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 27/60 “controller” or “controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of such processing; if Union or Member State law determines the purposes and means of such processing, the controller or the specific criteria for its appointment may be laid down by Union or Member State law. Member States. An identifiable natural person is one whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Processing shall also be understood as "any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction." Article 4(12) of the GDPR defines a "personal data breach" as any breach of security leading to the accidental or unlawful destruction, loss, or alteration of personal data transmitted, stored, or otherwise processed, or to unauthorized disclosure of or access to such data. In the present case, following the investigation conducted as a result of the notification of the personal data breach in the circumstances indicated above, potential violations of data protection regulations have been detected. The breach is categorized as a confidentiality and availability breach, as unauthorized access to the personal data processed was observed. Marktel suffered an attack in which personal data was compromised. (…) Regarding the liability for the leaked personal data, it has been established that MARKTEL acted as the data processor for ORANGE ESPAGNE when providing debt collection services to customers who acquired debts for the installment purchase of handsets. ORANGE ESPAGNE, in turn, acted as the data processor for SANTANDER CONSUMER. ORANGE ESPAGNE and SANTANDER CONSUMER signed an assignment of credit rights in favor of SANTANDER CONSUMER for the debts incurred in the installment purchase of the handsets. Santander Consumer, through a contract dated July 7, 2015, entrusted Orange ESPAGNE SAU with the debt collection services. Orange ESPAGNE, in turn, subcontracted Marktel to manage the collection operations in the event of non-payment. III Allegations to the Initiation Agreement C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 28/60 In relation to the allegations raised regarding the initiation agreement of this sanctioning procedure, the following are addressed, in the order set forth: 1. CLAIMS FILED THAT GAVE RISE TO THE OPENING OF THIS INITIATIVE AGREEMENT. SANTANDER CONSUMER alleges that this AEPD has violated the principles of legal certainty, good faith, and legitimate expectations established in Article 3.2 e) of the LRJSP, since, in a letter dated December 28, 2022, from the AEPD's Technological Innovation Division, it states that "After analyzing the additional information provided, the breach has been updated in the registry of personal data breach notifications and, without prejudice to the course of other procedures, no further action is planned by this Division in relation to this personal data breach notification." Well, contrary to what SANTANDER CONSUMER claims, this letter is not decisive in nature, not even due to its content. Rather, it is an "acknowledgment of receipt" of the notified breach and in no way can it be understood as if this AEPD had determined that no liability existed for an alleged breach of the regulations. data protection agency and that it had proceeded to archive certain actions—as SANTANDER CONSUMER has sought to understand—nor by its form, since it does not even formally reflect a decision, much less a resolution to archive any action that had not even been initiated. This letter is intended to inform SANTANDER CONSUMER of the receipt of notification of the breach that occurred and its inclusion in the registry of breach notifications, in accordance with the provisions of Article 31.d) of the Agency's Statute, approved by Royal Decree 389/2021, of June 1. It cannot be inferred from this that the AEPD assessed and decided that there was no liability for an alleged breach of data protection regulations. Thus, Article 13 of the AEPD Statute establishes the functions of the Presidency: 1. The Presidency of the Spanish Data Protection Agency is responsible for: d) Issuing the resolutions and directives required to exercise the Agency's functions, particularly those arising from the exercise of the powers provided for in Article 57 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, and the exercise of the investigative and corrective powers provided for in Article 58 of the aforementioned Regulation. Article 57, Functions, of the GDPR, in its letter h) establishes that: “1. Without prejudice to other functions under this Regulation, each supervisory authority shall, within its territory: (…) C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 29/60 h) carry out investigations into the application of this Regulation, in particular based on information received from another supervisory authority or another public authority; (…) Regarding the functions of the Subdirectorate General for Data Inspection of the AEPD, Article 27 of the Agency's Statute states, in its section 1, that “The Subdirectorate General for Data Inspection is the administrative body, reporting to the Presidency of the Spanish Data Protection Agency, which carries out the powers provided for in Article 57.1, letters f), g), h). i) and u) of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, and performs the inspection and investigation functions necessary for the exercise of the investigative powers established in Article 58.1, letters a), b), d), e) and f) and the corrective powers provided for in Article 58.2, letters a), b), c), d), f), g), i) and j), both of the aforementioned Regulation." And section 2 of this Article 27 lists the functions corresponding to the Subdirectorate General for Data Inspection, among which are, for what is of interest here, the following: "a) The permanent supervision of compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, of Organic Law 3/2018, of 5 December, and the provisions implementing it, by those responsible for and in charge of processing. (…) b) The exercise of the investigative powers defined in Article 51 of Organic Law 3/2018, of December 5. (…) d) The processing of procedures in the event of a potential violation of data protection regulations in accordance with the provisions of Title VIII of Organic Law 3/2018, of December 5, including complaints from citizens due to a lack of attention to their requests to exercise the rights provided for in Articles 15 to 22 of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016. The Deputy Directorate General for Data Inspection is responsible for informing the complainant about the progress and outcome of the complaint filed with the Spanish Data Protection Agency, in accordance with the provisions of Article 77.2 of the aforementioned Regulation. (…)” Therefore, in order to archive investigation proceedings, it is necessary, first, that they have been initiated (either by admitting a complaint for processing, or on its own initiative, which in both cases requires an express resolution C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 30/60 signed by the Director), which had not occurred at the time the aforementioned letter from the Technological Innovation Division was issued. Secondly, an express resolution by the Director is again required to archive said proceedings, because it is now understood that, based on the information gathered in said investigations, no violation of data protection regulations has been concluded, which had not occurred. In the present case, two complaints were filed by individuals affected by the breach, both of which were admitted for processing by the AEPD. In February 2023, in compliance with Article 64 of the Organic Law on Personal Data Protection (LOPDGDD). Article 64. Method of initiating the procedure and its duration. 1. When the procedure relates exclusively to the failure to address a request to exercise the rights established in Articles 15 to 22 of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, it shall be initiated by an agreement on admission to processing, which shall be adopted in accordance with the provisions of Article 65 of this Organic Law. In this case, the deadline for resolving the procedure will be six months from the date on which the claimant was notified of the decision admissibility for processing. After this period, the interested party may consider their claim to have been granted. 2. When the procedure aims to determine the possible existence of a violation of the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, and this Organic Law, it will be initiated by means of an initiation agreement, adopted on its own initiative or as a result of a complaint, which will be notified to the interested party. If the procedure is based on a complaint filed with the Spanish Data Protection Agency, the latter will decide beforehand on its admissibility, in accordance with the provisions of Article 65 of this Organic Law. Once the claim has been admitted for processing, as well as in cases where the Spanish Data Protection Agency acts on its own initiative, prior to the initiation agreement, there may be a phase of preliminary investigation procedures, which will be governed by the provisions of Article 67 of this Organic Law. The procedure will last a maximum of twelve months from the date of the initiation agreement. After this period, the procedure will expire and, consequently, the proceedings will be archived. Regarding preliminary investigation procedures, Article 67 of the LOPDGDD provides as follows: Article 67. Preliminary investigation procedures. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 31/60 1. Before adopting the agreement to initiate the procedure, and once the claim has been admitted for processing, if any, the Spanish Data Protection Agency may carry out preliminary investigations in order to better determine the facts and circumstances that justify the processing of the procedure. The Spanish Data Protection Agency will act in all cases when it is necessary to investigate processing involving massive amounts of personal data. 2. Preliminary investigation procedures shall be subject to the provisions of Section 2 of Chapter I of Title VII of this Organic Law and may not last longer than eighteen months from the date of the agreement admitting them for processing or from the date of the agreement initiating them when the Spanish Data Protection Agency acts on its own initiative. This regulation does not in any way imply that the AEPD must justify the initiation of preliminary investigations in the manner required by SANTANDER CONSUMER. SANTANDER CONSUMER argues that the AEPD has included two complaints from two interested parties in the procedure, without them even being SANTANDER CONSUMER customers or having referenced that entity in their complaints, and all of this without conducting any type of investigation to that effect. However, contrary to what has been stated, the AEPD did carry out preliminary investigations in this case to clarify the facts and circumstances of the incident, gathering more information in order to determine whether or not there was a potential violation of data protection regulations. In this sense, the initiation and execution of preliminary investigations, a power of the AEPD, whether with or without complaints, does not prejudge anything, but rather allows for the gathering of the necessary information to determine whether or not there is evidence of a violation. Even after such an investigation, the proceedings may be closed because, in light of the information gathered, it is understood that the necessary elements for the opening of a sanctioning procedure are not present. This has not happened in the present case. What the regulations do indicate is that, after complaints are submitted, this Agency must decide whether to admit them for processing or not. Once the claim has been admitted for processing, as indicated in the aforementioned Article 67.2 of the LOPDGDD, the AEPD may conduct preliminary investigations to better determine the facts and circumstances, which is what happened in this case. This power is granted to the AEPD by the GDPR and the LOPDGDD. Furthermore, and even if the complaints had not existed, the Technological Innovation Division's letter would not have been an obstacle to the exercise of the investigative powers of the AEPD, in accordance with the aforementioned Article 64.2, which states that "Once the complaint is admitted, C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 32/60 and in cases where the Spanish Data Protection Agency acts on its own initiative, prior to the initiation agreement, there may be a phase of preliminary investigations." Therefore, this sanctioning procedure has not been initiated due to the content or any new information provided in the two complaints filed with this AEPD, but rather due to the information and documentation obtained after the preliminary investigation period, as it inferred potential violations of data protection regulations. In this regard, it is once again recalled that these complaints are only admissible for processing, and that the documentation and everything collected during the investigation is the sole reason for the initiation of this sanctioning procedure, not the aforementioned complaints. Furthermore, it is reported that no action has been taken with respect to the complainants beyond notifying them (but not notifying them) of the initiation, in this case, of a sanctioning procedure. Once the procedure is completed, they will only be informed of its completion and the publication of the resolution on the AEPD website. 2. OMISSION OF THE AEPD REGARDING SANTANDER CONSUMER'S ASSESSMENT AS AN INJURED PARTY. In this section, SANTANDER CONSUMER focuses on its status as a victim of a cybercrime (a third-party cyberattack) and extortion (demand for payment under the threat of publishing the exfiltrated data), both of which are becoming increasingly sophisticated. It explains that it was a victim of the ransomware cyberattack suffered by MARKTEL called Lockbit 3.0, developed by a sophisticated cybercrime organization that represents a significant threat to businesses and organizations worldwide. In 2022 alone, the year in which the breach was reported, the Lockbit group carried out more successful cyberattacks than any other ransomware group, with the LockBit 3.0 application considered the most active version to date. Given the nature of the attack and the number of such attacks, it is considered diabolical to hold companies accountable simply because their security systems (even if they are advanced and robust) cannot repel the most sophisticated and damaging attacks, when, in fact, not even the specialized law enforcement agencies are capable of containing their criminal activity. In light of this, it should be noted that the plaintiff's culpability cannot be excluded or attenuated by the fact that a third party acted fraudulently, since the plaintiff's liability does not stem from the third party's actions, but from its own. In no case has total infallibility been required for the measures that can be adopted to ensure adequate protection in the processing of personal data. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 33/60 data. The fact that the data controller was found to have some security measures in place does not prevent this sanctioning procedure from verifying that, in relation to the information published on the Dark Web, the "Clients" table of the database was leaked, with some open data, containing 1,027,969 records (with a total of 803,099 unique ID numbers) and the following fields: ID number. First and last name. Telephone number. Email address. Address (Street, Number, Town, Postcode). Date of birth. Unobfuscated IBAN account numbers for 517,326 records (the remaining records were obfuscated or did not include this data). Of the exfiltrated data, according to the personal data breach notification from SANTANDDR CONSUMER, dated December 15, 2022, and entry record REGAGE22e00057522607, 124,595 of the entity's customers were affected by the breach, and in 105,401 cases, the stolen file contained the full IBAN code data of the entity's customers. The compromised data would include: Basic information (e.g., first name, last name, date of birth), DNI (National Identity Document), NIE (Foreigner Identification Number), Passport and/or any other identification document, Payment method information (bank card, etc.), and Contact information. It is stated that until November 2021, the IBAN data was stored openly in a database. However, at the end of November 2021, this data was obfuscated. This is why the leaked data included records with the IBAN data in clear text. Therefore, anyone anywhere in the world, without the consent of the data owners, could have access to it. This means that the risk of loss of confidentiality has materialized, leading to a total and absolute loss of control over said data. Furthermore, since it is irremediably accessible to anyone, it poses a very high risk of fraudulent use or of its use for any other purpose that, under certain circumstances, could constitute a threat to its owners. However, not only can the IBAN data of some customers be seen, but also the rest of the data included in the "Customers" table, including the DNI, since it was not encrypted, which increases the risk that the owners of the compromised data could suffer negative effects and harm as a result of the personal data breach. SANTANDER CONSUMER is responsible for the processing of this data and, consequently, is responsible for ensuring that the data processed on its behalf has the appropriate security guarantees that prevent or hinder a loss of confidentiality, integrity, or availability of the data, which did not occur in this case as the data was unencrypted. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 34/60 3. ON ORANGE'S LIABILITY AS SANTANDER CONSUMER'S DATA PROCESSOR. SANTANDER CONSUMER claims that MARKTEL was ORANGE'S data processor and that, therefore, SANTANDER CONSUMER cannot assume any liability. However, SANTANDER CONSUMER forgets that it is the data controller of its exfiltrated customer data. SANTANDER CONSUMER is responsible for the credit rights of the debt incurred by customers and is responsible for the processing of their personal data. This is regardless of the actions and liability that third parties may have incurred, since the negligence or illegal actions of third parties do not exclude its own liability. The data controller must comply with the processing principles set out in Article 5 of the GDPR, including confidentiality and integrity, and must be able to demonstrate compliance, in accordance with the principle of proactive accountability set out in paragraph 2 of that article. Among the obligations that the GDPR imposes on data controllers for compliance with the principle of proactive accountability is the obligation to sign a contract or other legal instrument with the data processor that establishes, among other stipulations, that the data processor will take all necessary measures in accordance with Article 32. On July 7, 2015, ORANGE ESPAGNE and SANTANDER CONSUMER, in connection with the service provision contract signed on that date, entered into a contract for access to the data for which SANTANDER CONSUMER is the data controller. This contract was incorporated into the service provision contract in ANNEX 3 thereof. Through this contract, ORANGE would provide SANTANDER CONSUMER with billing, collection, debt collection, and after-sales services to its customers. Regarding security measures, the data access contract indicates that medium-level measures must be applied, which does not meet the requirements set forth in Article 32 of the GDPR. Let us remember that Article 32 of the GDPR provides that “1. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, which, where appropriate, includes, among others: a) the pseudonymization and encryption of personal data; b) the ability to guarantee the ongoing confidentiality, integrity, availability, and resilience of processing systems and services; C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 35/60 c) the ability to restore the availability of and access to personal data quickly in the event of a physical or technical incident; d) a process for regular verification, evaluation, and assessment of the effectiveness of the technical and organizational measures to ensure the security of the processing. 2. When assessing the adequacy of the level of security, particular account shall be taken of the risks posed by the processing of data, in particular as a result of the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to personal data transmitted, stored or otherwise processed. 3. Adherence to a code of conduct approved pursuant to Article 40 or a certification mechanism approved pursuant to Article 42 may serve as an element to demonstrate compliance with the requirements set out in paragraph 1 of this Article. 4. The controller and the processor shall take measures to ensure that any person acting under the authority of the controller or the processor who has access to personal data only processes those data on instructions from the controller, unless required to do so by Union or Member State law. It should be noted that the GDPR, in the aforementioned provision, does not establish a list of security measures that must be applied according to the data being processed. Furthermore, compliance with Article 5.1.f) of the GDPR requires that the data controller implement technical and organizational measures, of any kind, and not just security measures, that are appropriate to the risk posed by the processing, taking into account the likelihood and severity of the risks to the rights and freedoms of data subjects. Furthermore, appropriate technical and organizational security measures must be adequate and proportionate to the risk identified. It should be noted that the determination of the technical and organizational measures must take into account: pseudonymization and encryption, the ability to guarantee confidentiality, integrity, availability, and resilience, the ability to restore the availability and access to data after an incident, a verification process (not an audit), and an evaluation and assessment of the effectiveness of the measures. In any case, when assessing the adequacy of the level of technical and organizational security measures, particular consideration will be given to the risks posed by data processing, such as the accidental or unlawful destruction, loss, or alteration of personal data transmitted, stored, or otherwise processed, or the unauthorized communication or access to such data, which could cause physical, material, or immaterial damage. In this same sense, Recital 83 of the GDPR states that: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 36/60 “(83) In order to maintain security and prevent processing infringing the provisions of this Regulation, the controller or processor should assess the risks inherent in the processing and implement measures to mitigate them, such as encryption. These measures should ensure an appropriate level of security, including confidentiality, taking into account the state of the art and the cost of their implementation, in relation to the risks and the nature of the personal data to be protected. When assessing the risk related to data security, the risks arising from the processing of personal data should be taken into account, such as the accidental or unlawful destruction, loss, alteration of personal data transmitted, stored or otherwise processed, or unauthorized disclosure of or access to such data. likely in particular to cause physical, material, or immaterial damage." Therefore, the instructions given by SANTANDER CONSUMER to its data controller were clearly insufficient to guarantee data protection adequate to the risk. Security measures must be periodically evaluated in order to implement effective measures appropriate to the risk. However, SANTANDER CONSUMER did not even renew the data processor contract signed with ORANGE ESPAÑA. It should be noted that Article 5.1.f) of the GDPR imposes on the data controller the obligation to adopt appropriate technical and organizational measures to guarantee the rights and freedoms of data subjects, without this obligation being limited to implementing security measures exclusively. Adequate risk management for the rights and freedoms of individuals must allow for the adoption of all measures, not just security measures, that are necessary to ensure that a personal data breach does not occur. In this regard, it should be noted that the fifth transitional provision, "Data Processor Contracts" of the LOPDGDD (Spanish Data Protection Act), establishes that: "Data processor contracts signed prior to May 25, 2018, under the provisions of Article 12 of Organic Law 15/1999, of December 13, on the Protection of Personal Data, will remain in effect until the expiration date indicated therein and, if agreed indefinitely, until May 25, 2022." During these periods, either party may require the other to modify the contract so that it complies with the provisions of Article 28 of Regulation (EU) 2016/679 and Chapter II of Title V of this Organic Law. The service contract was valid until July 1, 2017, although it could be tacitly extended for two-year periods. The data access contract states that its duration was linked to the execution of the Service Provision Contract and, therefore, would have the same duration as said service contract. Ultimately, SANTANDER CONSUMER should have renewed the data processor contract or terminated it, which it failed to do by extending C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 37/60 a contract that should have ended on July 1, 2019, after the first extension. It did not even terminate it on May 25, 2022. From all of the above, it can be inferred that SANTANDER CONSUMER displayed a lack of diligence in implementing technical and organizational measures to guarantee the confidentiality and integrity of personal data, as it maintained a contract that did not reflect the need for its data processor to implement risk-appropriate measures to prevent a personal data breach or reduce the impact should one occur. 4. A SECURITY INCIDENT DOES NOT IMPLY THAT SUFFICIENT SECURITY MEASURES HAVE NOT BEEN IMPLEMENTED. In this regard, it should be noted that Article 5.1.f) of the GDPR does not refer only to information security or cybersecurity measures aimed at preventing cyberattacks, but also to the obligation to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, which includes, among others, the ability to guarantee confidentiality, integrity, and availability, for which the risks of varying probability and severity to the rights and freedoms of natural persons will be taken into account, as required by Article 24 of the GDPR. In other words, the GDPR establishes the obligation to process personal data in such a way that their confidentiality, integrity, and availability are guaranteed. To this end, it is necessary to assess the risks and, based on them, adopt appropriate measures to avoid them or mitigate their impact on the rights and freedoms of individuals. In the present case, as previously noted, MARKTEL suffered a ransomware attack, causing a security breach consisting of a breach of confidentiality and availability, as unauthorized access to the personal data processed was detected, which was also encrypted by the attacker. Therefore, considering that attacks are foreseeable (and not all of them inevitable), mechanisms must be in place to guarantee data confidentiality. Therefore, it is important to be aware that prevention mechanisms can hardly guarantee data security completely against certain sophisticated attacks and, consequently, must be based on the assessment of measures that can mitigate the impact and allow for an adequate response in the event that the risk materializes. The loss of confidentiality was observed as a result of the exfiltration of the data. It should not be forgotten, in this regard, that there are measures specifically aimed at ensuring the confidentiality of personal data, such as encryption or the application of pseudonymization or anonymization techniques. These measures, if applied, would have prevented unauthorized third party access to the personal data and, subsequently, its subsequent publication, as the criminals would have obtained unintelligible information. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 38/60 5. CONSEQUENCES ARISING FROM ANY SECURITY ATTACK CARRIED OUT BY AN ORGANIZED GANG. SANTANDER CONSUMER alleges here that under no circumstances can it be held responsible for the criminal's subsequent publication on the Deep Web, understanding that this loss of control over personal data by those affected is a loss of confidentiality resulting from malicious intervention by a third party and not from a lack of diligence or regulatory non-compliance on the part of SANTANDER CONSUMER. In this regard, it is understood that the breach of confidentiality attributed to is the one that corresponds to it, that is, for failing to comply with the obligation imposed in Article 5.1.f) to process data in such a way as to ensure adequate security, including protection against unauthorized or unlawful processing, through the application of appropriate technical or organizational measures. The loss of control over one's own personal data occurs from the moment the personal data breach materializes, that is, from the moment that unauthorized third party accesses the personal data. This is the loss of confidentiality attributed to it. As mentioned above, there are measures specifically aimed at guaranteeing the confidentiality of personal data, such as encryption or the application of pseudonymization or anonymization techniques. These measures, if applied, would not have resulted in unauthorized third-party access to the personal data and, consequently, their subsequent publication. In this regard, it is worth referring to the judgment of June 22, 2021, Rec. 1210/2018, and the judgment of November 5, 2011, Rec. 1796/2019, in which the Court assessed the subjective or culpability element, "…insisting that the plaintiff's culpability cannot be considered excluded or attenuated by the fact that a third party may have acted fraudulently, since the plaintiff's liability does not arise from the latter's actions, but from its own." Regarding the fact that other entities have suffered similar attacks, and therefore, it is not consistent, proportionate, or even coherent with how this Agency has interpreted these types of cases to date, that in similar cases of ransomware security breaches that objectively represented the materialization of a greater risk for those affected, the Agency opted to close the proceedings, while in the Initiation Agreement it proposes a fine of five hundred thousand euros (€500,000). This means that, in addition to highlighting that these types of attacks are commonplace and therefore largely foreseeable, each attack is different because, even if the attack were similar, the companies that suffer it are different in each case, with different and specific processing of personal data, and in each case, the existing technical and organizational measures must be analyzed (if they existed, if they were adequate to guarantee a level of security appropriate to the specific risk in each case, if were efficient, whether they were observed, etc.) C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 39/60 6. LACK OF INTENTIONALITY OR NEGLIGENCE ON THE PART OF SANTANDER CONSUMER THAT AUTHORIZES THE IMPOSITION OF AN ADMINISTRATIVE FINE. Regarding SANTANDER CONSUMER's status as a victim of a crime, it is emphasized that the plaintiff's culpability cannot be considered excluded or attenuated by the fact that a third party acted fraudulently, since the plaintiff's liability does not arise from the latter's actions, but from its own. SANTANDER CONSUMER understands that the existence of any culpable, intentional, or negligent conduct on its part has not been proven, and therefore, it cannot identify a violation of personal data protection regulations in its conduct simply because it was the victim of a cyberattack. Consequently, no sanction is appropriate. This is taking into account the recent case law of the Court of Justice of the European Union (CJEU) regarding cases C-683/21 (Nacionalinis visuomenėssveikatos centras) and C-807/21 (Deutsche Wohnen). In light of this, it is noted that, in relation to the information published on the Dark Web, the "Customers" table of the database was leaked, with some data open, which contained 1,027,969 records (with a total of 803,099 unique DNI numbers) and the following fields: DNI. First and Last Name. Telephone Number. Email. Address (Street, Number, City, Postcode). Date of Birth. Unobfuscated IBAN account numbers for 517,326 records (for the remaining records, they were obfuscated or did not include this information). Regarding SANTANDER CONSUMER customers, the breach affected 124,595 of the bank's customers, and in 105,401 cases, the stolen file contained the full IBAN code data for the bank's customers. The compromised data would include: Basic information (e.g., first name, last name, date of birth), DNI (National Identity Document), Passport, and/or any other identification document, Payment method information (bank card, etc.), and Contact information. Until November 2021, the IBAN data was stored openly in a database. However, at the end of November 2021, this data was obfuscated. This is why the leaked data included records with the IBAN data in clear text. Therefore, any attacker anywhere in the world who accessed the systems could, without the consent of the owners, gain access to it. This is what happened in this case, and this means that the risk of loss of confidentiality has materialized, leading to a total and absolute loss of control by the owners of their data. Furthermore, since the data is not encrypted and is stored in clear text, it can be accessed by any unauthorized attacker. The failure to implement encryption measures poses a very high risk of fraudulent use of the same or of their use for any other purpose that, under certain circumstances, constitutes a threat to their holders. However, not only were the IBAN data of some customers visible, but the rest of the data included in the "Customers" table could also be seen, including the data subjects' ID numbers, since they were not encrypted. This reflects negligence on the part of SANTANDER CONSUMER, thus incurring the alleged violation. This negligence is what the aforementioned ruling requires in order to sanction those responsible for processing personal data for non-compliance with the obligations established by the GDPR. 7. VIOLATION OF THE PRINCIPLE OF PROPORTIONALITY REGARDING THE PROPOSED FINANCIAL PENALTY. It should be noted that complete infallibility of the measures that can be adopted to ensure adequate protection in the processing of personal data has not been required. However, once an attack has occurred, the diligence of controllers and processors in applying appropriate technical and organizational measures to ensure a level of security appropriate to the risk must be assessed, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of the processing. In the present case, the loss of confidentiality was observed as a result of the exfiltration of the data. In this regard, it should be noted, on the one hand, that in terms of data protection, the technical and organizational security measures to be adopted by data controllers and other obligations to be fulfilled required by the GDPR must be appropriate in relation to the specific risks posed by the specific processing operations carried out by each controller. Therefore, when analyzing the diligence of each party in complying with the regulations, the circumstances of each specific case must be considered, taking into account the nature, scope, context, and purposes of each processing. Therefore, there are no identical cases. In the present case, the following circumstances have been taken into account: the severity of the violation, its consequences, the lack of diligence shown, the specific processing carried out, the type of personal data and the number of people affected, the circumstances of the company (size, turnover, etc.), all of which were highlighted and justified in the Agreement to Initiate this sanctioning procedure and are reproduced in this proposal. These circumstances allow us to conclude that the principle of proportionality has been respected when determining the amount of the fine finally imposed. Consequently, the allegations must be dismissed, meaning that the arguments presented do not undermine the essential content of the violations declared to have been committed nor do they constitute sufficient justification or exculpation. IV Allegations to the Proposed Resolution C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 41/60 In relation to the allegations presented to the Proposed Resolution of this sanctioning procedure, the following are addressed, in the order set forth: FIRST. - VIOLATION OF THE PRINCIPLE OF THE PRESUMPTION OF INNOCENCE. SANTANDER CONSUMER once again reiterates this argument it already raised against the Initiation Agreement, the response to which was duly argued in the Draft Resolution and which is transcribed in Legal Basis III of this Resolution, to which, for the sake of procedural economy, reference should be made. In this argument, the existence of negligence in the Company's actions was already indicated. Thus, it was indicated that the breach of confidentiality attributed to SANTANDER CONSUMER is due to its failure to comply with the obligation imposed in Article 5.1.f to process data in such a way as to guarantee adequate security, including protection against unauthorized or unlawful processing, through the application of appropriate technical or organizational measures. It should not be forgotten, in this regard, that there are measures specifically aimed at ensuring the confidentiality of personal data, such as data encryption. However, as indicated in the Proven Facts, at the time of the security incident, it led to a personal data breach that affected the confidentiality of the data, as the Company had not implemented measures that, had they been implemented, would not have resulted in access to, exfiltration of, or publication of the personal data, as ultimately occurred. Therefore, in the case examined, as evidenced by the proven facts, there is a clear loss of confidentiality, as an unauthorized third party accessed the personal data processed by SANTANDER CONSUMER. This is an objective result, not a matter of strict liability. It should not be forgotten that the Supreme Court, in its ruling 188/2022, Legal Basis, Fourth, states in relation to the liability of legal entities that: "The fact that it was the negligent act of an employee does not exempt the employee from his/her responsibility as the party responsible for the correct use of the security measures that should have guaranteed the proper use of the designed data recording system. As we already stated in Supreme Court Ruling No. 196/2020, of February 15, 2021 (rec. 1916/2020), the data processor is also responsible for the actions of its employees and cannot excuse its diligent actions separately from those of its employees. Rather, it is the "culpable" actions of the employees, resulting from the violation of existing security measures, that underpin the company's liability in the area of sanctions for acts "own" to its employees. or charges, not of third parties.” And the CJEU ruled in the same vein in its judgment of December 5, 2023, in Case C-807/21, C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 42/60 24 Indeed, according to the aforementioned court, this case law, like the majority of national doctrine, gives special importance to the concept of "undertaking," within the meaning of Articles 101 TFEU and 102 TFEU, and, therefore, to the idea that liability is attributed to the economic entity in which the undesirable behavior has been adopted, for example, anti-competitive behavior. In their view, according to this "functional" conception, all acts of all employees authorized to act on behalf of a company are attributable to the company, including in the context of an administrative procedure. 44 With regard to legal persons, this implies, on the one hand, as the Advocate General essentially pointed out in points 57 to 59 of his Opinion, that they are liable not only for infringements committed by their representatives, directors, or managers, but also by any other person acting within the scope of the business activity of those legal persons and on their behalf. On the other hand, the administrative fines provided for in Article 83 of the GDPR in the event of such infringements should be able to be imposed directly on legal persons where they can be classified as controllers of the data in question. And according to the ECJ, issued on December 5, 2023, in Case C-683/21: 83 As regards, secondly, the question of whether an administrative fine under Article 83 of the GDPR may be imposed on a controller in relation to processing operations carried out by a processor, it should be recalled that, according to the definition in Article 4(8) of the GDPR, a processor is defined as "a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller." 84 Since, as indicated in paragraph 36 of this judgment, a controller is liable not only for any processing of personal data that it carries out itself, but also for processing carried out on its own behalf, that controller may be imposed an administrative fine under Article 83 of the GDPR in a situation where personal data are subject to unlawful processing and where it is not it, but a processor it has engaged, who carried out the processing on its behalf. This claim is therefore refuted. Regarding the claim that the applicable regulations do not establish an obligation of results regarding security measures, but only of means, referring to the Supreme Court Judgment STS 188/2022 of February 15, 2022, it is meant that this judgment declares “The obligation to adopt the necessary measures to guarantee the security of personal data cannot be considered an obligation of results. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 43/60 (…) In obligations of means, the commitment acquired is to adopt the technical and organizational means, as well as to carry out diligent activity in their implementation and use that tends to achieve the expected result with means that can reasonably be described as suitable and sufficient for its achievement. This is why they are called obligations of diligence" or "conduct" (…) it is not enough to design the The necessary technical and organizational means must also be correctly implemented and used appropriately, so that the Agency will also be liable for any lack of due diligence in their use, understood as reasonable diligence, taking into account the circumstances of the case. Well, the new regulation provided for in the GDPR significantly expands the obligations of the data controller and their scope of action and responsibility, now clearly extending them to the actions carried out by their data processors, which fall within their scope of responsibility. In this regard, this Agency wishes to point out that it in no way considers the obligation to implement measures imposed by data protection regulations to be an obligation of results rather than an obligation of means. However, it is no less true that, before the incident occurred, the Company did not have measures in place that "in accordance with the state of the art and in relation to the nature of the processing carried out and the personal data in question, would reasonably prevent its alteration, loss, unauthorized processing, or access," since it must not be forgotten that the data was not encrypted or subject to any other technique to prevent access to the information. SECOND. - ADEQUATE SECURITY MEASURES AND THE ABSENCE OF INTENTIONALITY OR NEGLIGENCE GREATER OR GREATER THAN THE TYPE THAT MIGHT BE TAKEN INTO CONSIDERATION TO INCREASE THE SEVERITY OF THE INCIDENT. The fact that SANTANDER CONSUMER is a large company whose activity involves constant and extensive processing of personal data requires greater diligence in the processing of personal data than can be required of a small company that performs sporadic or incidental processing. In this regard, it is important to note that there was negligence in compliance with and observance of the appropriate measures to ensure the security necessary for the protection of personal data, specifically to guarantee the confidentiality of personal data, as it did not adopt measures aimed at this end, especially those consisting of encryption, pseudonymization, or anonymization measures. Precisely because of the large number of processing operations it carries out and the number of clients who have been affected, SANTANDER CONSUMER is obliged to act with the special diligence that must be required of an entity of these characteristics, which carries out numerous processing operations of personal data. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 44/60 That said, the considerable number of those affected cannot be ignored. The investigative actions carried out have confirmed that the number of affected individuals whose integrity and/or confidentiality of their personal data was compromised was 1,027,969 records (with a total of 803,099 unique DNI numbers) due to unlawful access to personal data by an unauthorized third party, which resulted in the loss of confidentiality and control over numerous personal data and affected all those whose data was known. It is true that SANTANDER CONSUMER suffered a third-party attack, but a lack of diligence is observed in complying with the obligations imposed by data protection regulations, allowing cybercriminals to access personal data, thus violating its confidentiality. In this regard, we can cite the SAN of 10/17/2007, which, although issued before the GDPR came into force, its ruling is perfectly applicable to the case we are analyzing. The ruling, after alluding to the fact that entities whose activities involve continuous processing of client and third-party data must observe an adequate level of due diligence, specified that "(...) the Supreme Court has considered that negligence exists whenever a legal duty of care is disregarded, that is, when the offender fails to behave with the required due diligence. In assessing the degree of due diligence, the professionalism of the individual must be especially considered. There is no doubt that, in the case under consideration, when the appellant's activity involves constant and extensive handling of personal data, rigor and exquisite care must be emphasized to comply with the legal provisions in this regard" (Article 83.2(b) of the GDPR). In the case at hand, the type of data processed and affected by the personal data breach, which SANTANDER CONSUMER appears to disregard, poses a high risk of fraudulent use if its confidentiality is breached: identity theft, phishing, financial fraud, etc. Furthermore, the lack of due diligence demonstrated in the infringing conduct for which it is held responsible must be classified as very serious; SANTANDER CONSUMER is obliged under Article 5.2 of the GDPR to implement appropriate measures to comply with the data protection principles, and, for the purposes of this article, confidentiality, and to be able to demonstrate compliance. In this regard, the CJEU, in its judgment of December 14, 2023, Case C- 340/21 (VB), recalls that "Article 5(2) of the GDPR establishes a principle of accountability under which the controller is responsible for compliance with the principles relating to the processing of personal data set out in paragraph 1 of that article and stipulates that the controller must be able to demonstrate compliance with those principles" (paragraph 49). THIRD. - THE OBLIGATIONS ASSUMED BY EACH OF THE PARTIES AND THE LIABILITIES ARISING THEREFORE. It states that the criminal acts that led to the notification of the security incident originated in the systems of the subprocessor, which is why it cannot be ignored that the loss of confidentiality as a result of the data extraction is due to these circumstances. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 45/60 Consequently, it was and is the data processor who should and must ensure that the guarantees established pursuant to Article 28 of the GDPR were fully complied with. Please note that on July 7, 2015, ORANGE ESPAGNE and SANTANDER CONSUMER, in connection with the service provision contract signed on that date, formalized a data access agreement for which SANTANDER CONSUMER is responsible. This agreement was incorporated into the service provision contract in ANNEX 3 thereof. This agreement would allow ORANGE to provide billing, collection, debt collection, and after-sales services to its customers. Regarding security measures, the data access agreement indicates that medium-level measures must be applied, which does not meet the requirements set forth in Article 5.1.f) of the GDPR. This is SANTANDER CONSUMER's responsibility, as it is the data controller and is obligated to integrate and implement data protection measures throughout its organization, in all areas of its operations, whether affecting its employees or its data processors. It must be kept in mind that, ultimately, the determining objective is to guarantee the protection of the data subject, as the focus is on the risks to the rights and freedoms of data subjects arising from the processing of personal data by the data controller. Consequently, the data controller must carry out an assessment of the risks to the rights and freedoms of individuals in data processing, implementing appropriate technical and organizational measures to apply the principles of data protection and integrating the necessary safeguards into the processing, in order to comply with the requirements of the GDPR. The controller must be able to demonstrate that the processing complies with the provisions of the aforementioned regulation. And in light of the principle of proactive accountability (Article 5.2 GDPR), the data controller must be able to demonstrate that it has taken into account all the elements provided for in the GDPR. The system provided for in the LOPD was a compliance system, and today, it has moved from a system with standard, static security measures for any data controller to security measures tailored to each organization (adapted to its characteristics and idiosyncrasies), which consider the specific risks of the entity in question. Furthermore, they are now dynamic, so that they do not end with the implementation of risk-appropriate measures at the start of processing, but must be adapted to emerging risks. Establishing compliance with medium-level measures does not imply compliance with this obligation, which requires the implementation of the measures that are necessary in each case. Therefore, all of this merely reflects a lack of diligence on the part of the entity under investigation when it comes to ensuring security appropriate to the risk of the data processing it carries out. In this regard, it should not be forgotten that the affected database contains the personal data of thousands of customers, which entails large-scale processing, requiring appropriate technical and organizational measures of all kinds, including security measures, specifically aimed at ensuring that said personal data does not become unlawful. As has been demonstrated and argued throughout this sanctioning procedure, it is considered that appropriate measures were not in place to guarantee the security of the customers' personal data, which, in this case, led to unlawful access to the personal data of SANTANDER CONSUMER customers. Therefore, strict liability is not being demanded as a result exclusively of a cyberattack. What's more, it constitutes a breach of the obligations imposed by the GDPR. Therefore, it is essential that the data controller establish, in its relationship with the data processor, clear modalities for such assistance and provide precise instructions to the data processor on how to properly comply with them. Document this in advance through a contract or other (binding) agreement, as well as subsequently during the term of the agreement. Verify compliance with the contract at all times in the manner established therein. However, the instructions given by SANTANDER CONSUMER to its data processor were clearly insufficient to guarantee data protection adequate to the risk. Security measures must be periodically evaluated to implement effective measures appropriate to the risk. However, SANTANDER CONSUMER did not even renew the data processor contract signed with ORANGE ESPAÑA. It is enough to refer to the content of Supreme Court Judgment 1562/2020, of June 15, 2020, rec. 601/2019, which states the following: "In this regard, the Supreme Court's ruling of June 5, 2004, which confirmed, in cassation for the Unification of Doctrine, the ruling of this National Court of October 16, 2003, echoing the arguments of this Court, refers to the differentiation of two controllers depending on whether the decision-making power is directed to the file or to the data processing itself. Thus, the controller of the file is the one who decides the creation of the file and its application, as well as its purpose, content, and use, that is, the one who has the decision-making capacity over all the data recorded in said file. The controller of the data processing, however, is the subject to whom decisions regarding the specific activities of a specific data processing activity can be attributed, that is, regarding a specific application. This would apply to all those cases in which the decision-making power must be distinguished from the material execution of the activity that constitutes the processing. Thus, as also argued The Supreme Court Judgment of April 26, 2005 (cassation for unification of doctrine 217/2004), the Spanish legislator intends to adapt to the requirements of Directive 95/46/EC, which aims to provide a legal response to the increasingly frequent phenomenon of the so-called outsourcing of IT services, where multiple operators operate, many of them insolvent, C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 47/60 created with the aim of seeking impunity or irresponsibility for those who follow them in the following links in the chain. Currently, the new Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data (repealing Directive 95/46/EC, and directly applicable as of May 25, 2018) also distinguishes between the figures of the controller and the processor. The former is defined in section 7 of Article 4 as "a natural or legal person (...) who determines the purposes and means of the processing." And the processor in section 8 of the same Article 4 as the one who "processes personal data on behalf of the controller." This is in relation to Articles 24 and 28 of the same European Data Protection Regulation. The controller and processor of data are, without a doubt, also responsible for data protection violations, in this new regulatory framework, in accordance with the provisions of Article 82.2 of the aforementioned Regulation (EU) 2016/679, which states: Any controller involved in the processing operation shall be liable for the damages caused if said operation does not comply with the provisions of This Regulation. A data processor shall only be liable for damages caused by processing when it has not complied with the obligations of this Regulation directed specifically to data processors or has acted outside or contrary to the legal instructions of the controller. It follows from all of the foregoing that the presence, in the present case, of a data processor ZZZZ in no way exempts the now appellant entity XXXX from liability, and this despite the forcefulness of the clauses contained in the contract and annex thereto signed by both companies (proven facts 9 and 10) in that the personal data processed was for the purpose of carrying out an advertising campaign regarding car and motorcycle insurance that (XXXX) marketed, ultimately for the benefit of said XXXX, with the plaintiff entity being the one that ultimately determines the purposes and means of the repeated data processing, and therefore cannot be exonerated from liability." The Supreme Court continues, in relation to the alleged possible exemption from liability regarding the provisions of the "data processor" contract, as follows: "The sanctioned conduct of obstructing or impeding XXXX's exercise by its client of the right to object to the processing of their data is evident in that said company did not adopt any type of measure or precaution to prevent the sending of advertising to its client's email addresses by the companies it entrusted with carrying out the advertising campaigns. The adoption of the necessary measures or precautions to ensure the effectiveness of the right to object to the processing of their data by XXXX, as the data controller, persists even if the advertising campaigns are not carried out using data from its own files, but rather using databases from other companies contracted by XXXX. In this case, it was proven that C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 48/60 that the appellant did not inform the companies with which it contracted the provision of advertising services of the complainant's objection to receiving advertising from the Mutual Society, nor did it adopt any measures to ensure the exclusion of its client from the advertising mailings contracted with third-party entities." Consequently, the allegations must be dismissed since the entity under investigation has violated the obligations imposed by the GDPR as the controller of the processing carried out on its behalf and on its behalf, in relation to the responsibilities required of all data controllers by Article 5.1.f) of the GDPR. FOURTH. - VIOLATION OF THE GUIDING PRINCIPLES OF THE ADMINISTRATIVE SANCTIONING PROCEDURE. It alleges that there is a more than evident lack of motivation and, therefore, the reason why this Agency, in this Sanctioning Procedure, deviates from the criteria followed in other cases, all of which, coincidentally, have been archived, has not been duly justified. In light of this, it should be noted that this Agency does not have a filing criterion in the event of cyberattacks of any kind, nor, therefore, for those affected by ransomware. Rather, in terms of data protection, the technical and organizational measures to be adopted by data controllers and other obligations to be fulfilled by the GDPR must be appropriate in relation to the specific risks posed by the specific processing carried out by each controller. Therefore, when analyzing the diligence of each party in complying with the regulations, the circumstances of each case must be taken into account, taking into account the nature, scope, context, and purposes of each processing, as no two cases are identical. Thus, an attack carried out with the same ransomware at the same time and on different companies would have disparate results, as the circumstances are different. Even this same attack against the same company at different times could lead to a different situation. Of the three cases cited by SANTANDER CONSUMER (the personal data breach suffered by Facebook, the cyberattack on Decathlon, and the cyberattack on Iberdrola), two relate to cross-border processing in which the AEPD would not have been responsible for acting as the primary authority, and the third is a local case. Regarding the company with its main establishment in Spain, it is worth noting that the Resolutions published on the Agency's website omit everything related to specific measures that are confidential in order to protect the security of the entities. Therefore, if SANTANDER CONSUMER has obtained the information regarding the archiving of the aforementioned actions, it will not have been possible to obtain the circumstances taken into account in each case. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 49/60 Furthermore, SANTANDER CONSUMER does not justify that, in the three cases it mentions, the proceedings were filed, nor does it even indicate the source from which it obtained this information. The decisions made by the supervisory authorities in each case are not comparable, as they refer to different organizations that can be very different, either due to their size, the processing they perform, the type of data, the personal data involved, the risks involved, the systems affected, and the technological stage in which each cyber incident operates. Therefore, this Agency does not have a criterion for closing cases in cases of ransomware attacks, nor for imposing the same specific amounts of fines in cases of cyberattacks. In the case of cyberattacks, whether ransomware or other types, the specific case must be taken into account, especially the prior security measures in place and those adopted to address the incident. It should be noted that Article 83.1 of the GDPR provides that "Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article for the infringements of this Regulation indicated in paragraphs 4, 5, and 6 are, in each individual case, effective, proportionate, and dissuasive." The fines, therefore, as can be deduced from the aforementioned provision, must be effective, proportionate, and dissuasive to achieve the purpose intended by the GDPR. It is true that for this system to function with all its guarantees, several elements must be fully and completely implemented. The application of rules outside the GDPR regarding the determination of fines in each of the Member States applying their national law, whether due to aggravating or mitigating circumstances not provided for in the GDPR—or in the LOPDGDD in the Spanish case, as permitted by the GDPR itself—would render the system ineffective, losing its meaning, its teleological purpose, and the legislator's will. The result would be that the fines imposed for various violations would no longer be effective, proportionate, and dissuasive. This would also deprive data subjects of the effective guarantee of their rights and freedoms, weakening the uniform application of the GDPR. This would diminish the mechanisms for protecting citizens' rights and freedoms and would be contrary to the spirit of the GDPR. The GDPR is endowed with its own principle of proportionality, which must be applied strictly. Regarding the principle of proportionality of sanctions, the National Court has stated in numerous rulings that the principle of proportionality cannot be exempt from judicial review, since the margin of appreciation granted to the Administration in imposing sanctions within the legally established limits must be developed by weighing, in all cases, the concurrent circumstances in order to achieve the necessary and proper proportion between the alleged acts and the liability required, given that any sanction must be determined in accordance with the magnitude of the violation committed and according to a criterion of proportionality in relation to the circumstances of the act. Therefore, C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 50/60 proportionality constitutes a regulatory principle imposed on the Administration and which reduces the scope of its sanctioning powers. Well, in accordance with the circumstances of this case, which have been meticulously and appropriately evaluated, this resolution does not violate the principle of proportionality in determining the sanction imposed, and is considered balanced and proportionate to the seriousness of the violation committed, the importance of the facts, as well as the circumstances taken into account in graduating the sanction. No reasons are found to further justify the reduction, especially considering the amount that such sanctions can amount to in accordance with art. 83.5 of the GDPR, which provides for violations of Article 5.1.f) of the GDPR, "with administrative fines of a maximum of €20,000,000 or, in the case of a company, an amount equivalent to a maximum of 4% of the total global annual turnover of the previous financial year, whichever is higher." In the present case, SANTANDER CONSUMER. is a commercial entity, whose global parent company is Banco Santander, S.A., which, according to the information contained in its own "2022 Annual Report" of the Santander Group, which includes the corporate structure of the Santander Group and its turnover. This report states that the total global annual turnover of Banco Santander, S.A. and subsidiaries (Santander Group) in the financial year prior to the commission of the infringement, fiscal year 2021, was €52.117 billion (see page 836 of the aforementioned "2022 Annual Report"), resulting in the fine imposed for the infringement of Article 5.1.f) of the GDPR amounting to €500,000, which would be at the lower end of the possible administrative fine that could be imposed on the data controller and far from the maximum of 4% of the total annual global turnover of the previous financial year, taking into account the turnover. What is being highlighted is that the violation of Article 5.1.f) affects one of the basic principles on which personal data protection regulations are based: confidentiality. This violation is exacerbated and aggravated by the number of people affected by the incident, the damages and losses caused (irreversible loss of power and control over personal data by clients), and its duration. Until November 2021, the IBAN data was stored openly in a database. However, at the end of November 2021, this data was obfuscated, which is why records with the IBAN data in plain text are among the leaked data. Considering that the conduct includes an element of culpability, which is essential to enforce liability, in this case it also involves a very serious lack of diligence in complying with the principle of confidentiality of personal data, as has been demonstrated throughout the proceedings. Furthermore, the lack of diligence demonstrated in the infringing conduct for which it is held responsible must be classified as very serious. SANTANDER CONSUMER is obliged by Article 5.2 of the GDPR to implement appropriate measures to comply with the data protection principles, and, for the purposes of this matter, the principle of confidentiality, and to be able to demonstrate compliance. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 51/60 It considers that considering its banking activity as an aggravating circumstance is a kind of objective aggravating circumstance; firstly, it is not a matter related to the specific activity carried out by a particular entity, but rather the aggravating circumstance provided for in Article 76.2.b) of the LOPDGDD (Organic Law on the Protection of Personal Data) operates when the offender's activity, in which the infringement occurred, is linked to the processing of personal data. It is obvious that, in relation to the current data controller, the infringement occurred in the context of its banking activity and that this activity is clearly directly linked to multiple processing operations of personal data affecting thousands of customers. In this regard, the National Court has ruled that it is correct to consider the aggravating circumstance provided for in art. 76.2.b) of the LOPDGDD (General Data Protection Act) provided that the aforementioned connection exists, and this has been considered in numerous rulings, including one dated July 4, 2024 (Recital No. 382/2022), which states in relation to the aforementioned circumstance that: "It is also possible to appreciate the aggravating circumstance of the continuous nature of the infringement, as set out in Article 76.2.a) of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights, referring to this when we analyze the application of the GDPR to the infringement at hand. Likewise, the assessment of the connection between the infringer's activity and the processing of personal data (Article 72.2.b) of Organic Law 3/2018, of December 5), due to the fact that the appellant's activity is linked with the processing of data from both clients and third parties; this connection is known, since the entity, due to its activity, is in constant contact with clients and third parties, processing a large volume of data, which imposes a greater duty of diligence" (emphasis added). Finally, it considers that the AEPD, in regulating its liability, has not taken into account elements to mitigate it, such as proactivity, response throughout the entire phase of reporting the incident and answering the questions posed by the AEPD, as well as the fact that it notified the AEPD of the security breach. In this regard, it should be noted, first, that notifying supervisory authorities and informing data subjects of a personal data breach are obligations imposed on the data controller by the GDPR (Articles 33 and 34, respectively). That is, compliance with these obligations is required by law. It is a mandate that must be fulfilled, and therefore, failure by the data controller, in accordance with the requirements of these provisions, may constitute a violation of the GDPR. Second, the requirements of the AEPD are mandatory. Therefore, in this case, the degree of cooperation with the Agency cannot be assessed, and the mitigating circumstance is not applicable, since the consideration of cooperation with the Agency as a mitigating circumstance, as the entity claims, is not linked to any of the cases in which collaboration or cooperation is legally provided for, or responding to a request pursuant to a legal mandate. Therefore, when the actions are due and required by law, as in the case at hand, its application is not applicable. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 52/60 Finally, regarding the absence of profit as a result of the alleged infringement, it should be noted that, regarding this criterion, Article 76.2 of the LOPDGDD, in its letter c), includes among the criteria that must be considered when setting the amount of the fine, "the profits obtained as a result of the commission of the infringement" and not the absence of these profits. The ruling of the National Court, dated May 5, 2021, refers to the need for the factual "condition" contemplated in the law to be met for a specific grading criterion to be applied, and, as stated, the absence of profits is not among the circumstances regulated in the aforementioned article. This grading criterion is established in the LOPDGDD in accordance with the provisions of Article 83.2.k) of the GDPR, according to which administrative fines will be imposed taking into account any "aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement." It is understood that avoiding a loss has the same nature for these purposes as obtaining benefits. If we add to this the fact that sanctions must be effective, proportionate, and dissuasive "in each individual case," in accordance with the provisions of Article 83.1 of the GDPR, accepting the absence of benefits as a mitigating factor is not only contrary to the factual assumptions contemplated in Article 76.2.c), but also contrary to the provisions of Article 83.2.k) of the GDPR and the aforementioned principles. Thus, considering the absence of benefits as a mitigating factor would nullify the deterrent effect of the fine, to the extent that it lessens the effect of the circumstances that actually affect its quantification, giving the offender a benefit that they have not deserved. This would be an artificial reduction of the penalty, which could lead to the understanding that violating the law without obtaining benefits, financial or otherwise, will not have a negative effect proportional to the seriousness of the offending act. In any case, the administrative fines established in the GDPR, in accordance with Article 83.2, are imposed based on the circumstances of each individual case, and at present, the absence of benefits is not considered to be an appropriate and determining factor for assessing the seriousness of the offending conduct. Consequently, the allegations must be dismissed, meaning that the arguments presented do not distort the essential content of the alleged violation nor do they constitute sufficient justification or exculpation. V Integrity and Confidentiality Article 5.1.f) “Principles relating to processing” of the GDPR establishes: “1. Personal data shall be: (…) f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, by applying C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 53/60 appropriate technical or organizational measures (“integrity and confidentiality”).” In the same vein, Recital 39 of the GDPR provides that: “Personal data must be processed in a manner that ensures appropriate security and confidentiality of personal data, including to prevent unauthorized access to or use of such data and of the equipment used in the processing.” The principle of data integrity and confidentiality requires a guarantee of security in the application of technical or organizational measures to prevent the alteration of personal data, its loss, unauthorized or unlawful processing or access. This fundamental right cannot exist if its confidentiality, integrity, and availability are not guaranteed. Hence, the integrity and confidentiality of personal data are considered essential to prevent data subjects from suffering negative effects. Therefore, they must be processed in a manner that ensures adequate integrity and confidentiality of personal data, especially to prevent unauthorized access, processing, or use of such data. Ultimately, it is the data controller who has the obligation to integrate the necessary safeguards into the processing, in order to, pursuant to the principle of proactive accountability, comply and be able to demonstrate compliance, while respecting the fundamental right to data protection. In this regard, it should be remembered that the confidentiality of personal data is regulated in Article 5 of the GDPR and is therefore one of the principles relating to processing. The principles relating to processing are, on the one hand, the starting point and the closing clause of the data protection legal system, constituting true rules that inform the system with an intense expansive force; on the other hand, due to their high level of specificity, they are mandatory rules that are susceptible to being violated. Therefore, the principle of confidentiality must inform all aspects, rights, and obligations that come with the processing of personal data. This is because a breach of confidentiality entails the loss of control over the data subjects, which can pose serious risks to their rights and freedoms. Article 5.1.f) of the GDPR establishes a clear obligation to comply with the conditions of preventing unauthorized or unlawful processing by implementing appropriate technical and organizational measures. Consequently, data controllers must be able to guarantee the confidentiality of personal data to prevent a third party from accessing data that is not theirs, as it is precisely their responsibility to process personal data in accordance with the GDPR and LOPDGDD. For this reason, the due diligence exercised by data controllers is essential to prevent this type of unauthorized access. In the present case, the principle of confidentiality has been violated, as it is clear that following a ransomware attack, there was unauthorized access to C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 54/60 personal data, resulting in the loss of confidentiality and control over said data. The fact that the data controller was found to have some security measures in place does not prevent this sanctioning procedure from verifying that, in relation to the information published on the Dark Web, the "Clients" table of the database was leaked, with some open data, which contained 1,027,969 records (with a total of 803,099 unique ID numbers) and the following fields in clear text: ID number. First and last name. Telephone number. Email address. Address (Street, Number, Town, Postcode). Date of birth. Unobfuscated IBAN account numbers of 517,326 records (for the remaining records, it was obfuscated or did not include this data). Unobfuscated IBAN account numbers for 517,326 records (the remaining records were obfuscated or did not include this information). The breach affected 124,595 SANTANDER CONSUMER customers, and in 105,401 cases, the stolen file contained the full IBAN code of the company's customers. The compromised data included: Basic information (e.g., first name, last name, date of birth), DNI (National Identity Number), NIE (Foreigner Identification Number), Passport and/or any other identification document, Payment method information (bank card, etc.), Contact information. It is stated that until November 2021, the IBAN data was stored openly in a database. However, at the end of November 2021, this data was obfuscated. This is why the leaked data includes records with the IBAN data in clear text. Therefore, anyone anywhere in the world, without the consent of the data owners, could have access to it. This means that the risk of loss of confidentiality has materialized, leading to a total and absolute loss of control over said data. Furthermore, since the data is irremediably accessible to any attacker, it poses a very high risk of fraudulent use or any other use that, under certain circumstances, could constitute a threat to its owners. But not only can you see the IBAN data of some customers, but you can also see the rest of the data included in the "Customers" table since it was not encrypted. This loss of control over one's personal data results in a violation of the fundamental right to data protection recognized in Article 18 of the Spanish Constitution. As the Constitutional Court has stated (Judgment 292/2000, of November 30, 2000), "the fundamental right to data protection seeks to guarantee individuals the power to control their personal data, their use, and their destination, with the aim of preventing illicit trafficking that is harmful to the dignity and rights of the data subject (...) The right to data protection guarantees individuals the power to dispose of such data." In this same vein, and as already stated, there are measures specifically aimed at ensuring the confidentiality of personal data, such as encrypting the data or applying pseudonymization or anonymization techniques to it. These measures, if applied, would have made it much more difficult for an unauthorized third party to access the personal data and, consequently, its subsequent publication. This is because the loss of confidentiality was observed as a result of the exfiltration of the data; a loss of confidentiality, caused by unauthorized third-party access to the personal data, would not have occurred if the data had been encrypted, pseudonymized, or anonymized, as the criminals would have obtained unintelligible information. Consequently, the proven facts are considered to constitute an infraction, attributable to the entity under investigation, for violation of Article 5.1.f) of the GDPR. VI Classification of the violation of Article 5.1.f) of the GDPR The aforementioned violation of Article 5.1.f) of the GDPR entails the commission of the violations classified in Article 83.5 of the GDPR, which, under the heading "General conditions for the imposition of administrative fines," provides: "Violations of the following provisions shall be punished, in accordance with paragraph 2, with administrative fines of a maximum of EUR 20,000,000 or, in the case of a company, an amount equivalent to a maximum of 4% of the total global annual turnover of the preceding financial year, whichever is higher: a) the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9; (...)" In this regard, the LOPDGDD, in its Article 71 "Infractions" establishes that "Infractions are the acts and conduct referred to in sections 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law." For the purposes of the statute of limitations, Article 72, "Very Serious Violations" of the LOPDGDD states: "1. Pursuant to the provisions of Article 83.5 of Regulation (EU) 2016/679, violations that constitute a substantial violation of the articles mentioned therein, and in particular the following, are considered very serious and will be subject to a three-year statute of limitations: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 56/60 a) The processing of personal data in violation of the principles and guarantees established in Article 5 of Regulation (EU) 2016/679. (…)" VII Sanction In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR must be observed. provisions that state: “1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article for infringements of this Regulation referred to in paragraphs 4, 5 and 6 are, in each individual case, effective, proportionate, and dissuasive. 2. Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or as a substitute for the measures referred to in Article 58(2)(a) to (h) and (j). When deciding whether to impose an administrative fine and its amount in each individual case, due account shall be taken of: a) the nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation concerned, as well as the number of data subjects affected and the level of damage they have suffered; b) the intentionality or negligence of the infringement; c) any measures taken by the controller or processor to mitigate the damage suffered by data subjects; d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures they have implemented pursuant to Articles 25 and 32; e) any previous breaches committed by the controller or processor; f) the degree of cooperation with the supervisory authority to remedy the breach and mitigate the potential adverse effects of the breach; g) the categories of personal data affected by the breach; h) how the supervisory authority became aware of the breach, in particular whether the controller or processor notified the breach and, if so, to what extent; i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned in relation to the same matter, compliance with those measures; j) adherence to codes of conduct pursuant to Article 40 or mechanisms of certification approved pursuant to Article 42, k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement." For its part, Article 76 "Sanctions and Corrective Measures" of the LOPDGDD provides: "1. The sanctions provided for in sections 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the grading criteria established in section 2 of the aforementioned article. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 57/60 2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account: a) The continuous nature of the infringement. b) The connection between the offender's activity and the processing of personal data. c) The benefits obtained as a result of committing the infringement. d) The possibility that the affected party's conduct could have led to the commission of the violation. e) The existence of a merger by absorption process subsequent to the commission of the violation, which cannot be attributed to the acquiring entity. f) The violation of the rights of minors. g) Having, when not mandatory, a data protection officer. h) Voluntary submission by the controller or processor to alternative dispute resolution mechanisms in those cases where there are disputes between them and any interested party. Penalty for violation of Article 5.1.f) of the GDPR In accordance with the provisions transcribed, for the purposes of setting the amount of the penalty for violation of Article 5.1.f) of the GDPR, the fine must be graded taking into account: As aggravating factors: - Article 83.2.a) GDPR: Nature, severity, and duration of the violation. The nature of the violation is considered serious since it entails a loss of confidentiality and, therefore, irremediable loss of access and control over personal data. - Number of data subjects affected: the "Customers" table of the database containing 1,027,969 records was leaked, of which 124,595 were SANTANDER CONSUMER customers. - Level of damages suffered: High. Numerous personal data of SANTANDER customers were stolen. CONSUMER: DNI, First and Last Name, Telephone, Email, Address (Street, Number, City, Postcode), Date of Birth 105,401 records with unobfuscated IBAN account numbers (for the rest of the records, it was obfuscated or did not include this data). C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 58/60 - Duration of the violation: It is stated that, until November 2021, the IBAN data was stored openly in a database. However, at the end of November 2021, this data was obfuscated, which is why among the leaked data, there are records with the IBAN data in clear text. - Article 83.2.b) GDPR. Intentionality or negligence in the violation: In this case, it is a matter of gross negligence. The Supreme Court has held that negligence exists whenever a legal duty of care is disregarded, that is, when the offender fails to behave with the required diligence. In assessing the degree of diligence, the professionalism of the individual must be especially considered. There is no doubt that, in the case now under review, when the activity of the entity under investigation involves constant and extensive handling of personal data, rigor and exquisite care must be emphasized to comply with the legal provisions in this regard. [Judgment of the National Court of 17/10/2007 (rec. 63/2006)]. Furthermore, it is considered appropriate to graduate the sanction to be imposed according to the following criteria established in section 2 of the article. 76 “Sanctions and corrective measures” of the LOPDGDD: As aggravating circumstances: - Article 76.2.b) LOPDGDD. Link between the offender's activity and the processing of personal data: It is known that the entity under investigation is an entity that processes a large volume of its clients' personal data, and that this data is systematically processed in the exercise of its banking activity, which is the activity affected by the personal data breach. Consequently, and for the purposes of complying with the legally established requirements, the exercise of said activity necessarily implies knowledge and application of current regulations on personal data protection. This circumstance determines a higher level of rigor and professionalism and, consequently, of responsibility of the entity, in relation to the processing of personal data. Considering the factors set forth, the amount of the fine is €500,000 (five hundred thousand euros) for violation of Article 5.1.f) of the GDPR. VIII Adoption of Measures The text of the resolution establishes the violations committed and the facts that led to the breach of data protection regulations. From this, it is clear what measures to be adopted, without prejudice to the specific type of procedures, mechanisms, or instruments to implement them being the responsibility of the sanctioned party, since the data controller is fully familiar with their organization and must decide, based on proactive responsibility and a risk-based approach, how to comply with the GDPR and the LOPDGDD. Therefore, it is considered appropriate to order the data controller to, within six months from of the finality of the resolution concluding this procedure, adopt the necessary measures to guarantee the confidentiality of the data subject to its processing and notify this body. Please note that failure to comply with the order to adopt measures imposed by this body in the sanctioning resolution may be considered an administrative violation pursuant to the provisions of the GDPR, classified as a violation in Articles 83.5 and 83.6, and such conduct may lead to the opening of a subsequent administrative sanctioning procedure. Therefore, in accordance with applicable legislation and having assessed the criteria for graduating the sanctions whose existence has been proven, the Presidency of the Spanish Data Protection Agency RESOLVES: FIRST: TO IMPOSE SANTANDER CONSUMER FINANCE, S.A., with NIF A28122570, - for the violation of Article 5.1.f) of the GDPR, classified as a violation In accordance with the provisions of Article 83.5 of the GDPR, classified as very serious for the purposes of the statute of limitations, in Article 72.1 a) of the LOPDGDD, with a fine of 500,000 euros. SECOND: ORDER SANTANDER CONSUMER FINANCE, S.A., with NIF A28122570, pursuant to Article 58.2.d) of the GDPR, within 6 months of this resolution becoming final and enforceable, to certify that it has implemented the necessary measures to guarantee the confidentiality and integrity of the data on whose behalf it processes them, as well as to inform this Agency, within the same period, of the measures adopted. THIRD: NOTIFY this resolution to SANTANDER CONSUMER FINANCE, S.A. with NIF A28122570. FOURTH: This resolution It will become enforceable once the deadline for filing an optional appeal for reconsideration expires (one month from the day following notification of this resolution) without the interested party having exercised this right. The sanctioned party is hereby notified that they must pay the imposed sanction once this resolution becomes enforceable, in accordance with the provisions of Article 98.1.b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), within the voluntary payment period established in Article 68 of the General Collection Regulations, approved by Royal Decree 939/2005, of July 29, in conjunction with Article 62 of Law 58/2003, of December 17, by making a payment, indicating the sanctioned party's NIF (Tax Identification Number) and the procedure number shown in the heading of this document. The restricted account IBAN number: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT code: CAIXESBBXXX), opened in the name of the Spanish Data Protection Agency at C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 60/60 the bank CAIXABANK, S.A. Otherwise, the collection will be carried out during the enforcement period. Once the notification has been received and enforced, if the enforcement date is between the 1st and 15th of each month, inclusive, the deadline to make the voluntary payment will be until the 20th of the following month or the next business day thereafter. If it is between the 16th and the last day of each month, inclusive, the payment deadline will be until the 5th of the second following month or the next business day thereafter. subsequent. In accordance with the provisions of Article 50 of the LOPDGDD, this Resolution will be made public once it has been notified to the interested parties. Against this resolution, which ends the administrative process in accordance with Article 48.6 of the LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, the interested parties may optionally file an appeal for reconsideration before the Presidency of the Spanish Data Protection Agency within one month from the day following notification of this resolution, or directly file an administrative appeal before the Administrative Litigation Division of the National Court, in accordance with the provisions of Article 25 and section 5 of the fourth additional provision of Law 29/1998, of July 13, regulating the Administrative Litigation Jurisdiction, within two months from the day following notification of this act, as provided for in Article 46.1 of the aforementioned Law. Finally, it is noted that in accordance with the provisions of Article 90.3 a) of the LPACAP, the final decision may be provisionally suspended in administrative proceedings if the interested party expresses their intention to file an administrative appeal. If this is the case, the interested party must formally notify this fact in writing to the Spanish Data Protection Agency, submitting it through the Agency's Electronic Registry [https://sedeagpd.gob.es/sede-electronica- web/], or through one of the other registries provided for in Article 16.4 of the aforementioned Law 39/2015, of October 1. They must also forward to the Agency the documentation proving the effective filing of the administrative appeal. If the Agency is not aware of the Filing of the administrative appeal within two months from the day following notification of this resolution would terminate the precautionary suspension. 938-101224 Olga Pérez Sanjuán The Deputy Director General of Data Inspection, in accordance with Article 48.2 of the LOPDGDD (Spanish Data Protection Act), due to a vacancy in the position of President and Deputy President C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es




