AEPD (Spain) - EXP202404641

From GDPRhub
AEPD - EXP202404641
Authority: AEPD (Spain)
Jurisdiction: Spain
Relevant Law: Article 4(5) GDPR
Article 5(1)(c) GDPR
Article 6(1)(f) GDPR
Article 14 GDPR
Article 28(3) GDPR
Art. 19.2 LOPDGDD
Type: Complaint
Outcome: Upheld
Started: 27.12.2022
Decided: 15.04.2025
Published: 05.08.2025
Fine: 260,000 EUR
Parties: CAMERDATA
National Case Number/Name: EXP202404641
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Spanish
Original Source: AEPD (in ES)
Initial Contributor: ap

The DPA fined a company operating a database of financial information of Spanish enterprises €260,000 for processing data related to self-employed people. The data was processed without a legal basis and the data subjects were not informed of the processing.

English Summary

Facts

Institut per a la Cultura Democratica a L’era Digital (Institute for Democratic Culture in the Digital Era, also known as Xnet) is a digital rights non-profit organisation. Xnet brought a complaint to the DPA on 27 December 2022, regarding the processing of personal data of self-employed people by public authorities as well as private companies such as CAMERDATA (the controller). The controller is a company that provides commercial and financial information on Spanish enterprises. Their database is sourced mainly from the Chamber of Commerce (who receives the data from the Tax Authority) based on a contract. This includes data subjects’ Tax Identification Number (NIF), which is decrypted by the controller. The Chamber of Commerce, therefore, argued that the Tax Identification Number is not publicly available.

According to Xnet, once someone registers as self-employed with the Tax Agency their personal data is treated as information of professional interest. This means that if someone works from home, their personal address is easily accessible on the Internet. Financial information and legal incidents (including their credit scores and likelihood of nonpayment) are also available in some cases. This personal data can be processed and sold on the Internet by private companies, such as the controller.

The controller argued that their legal basis of processing data from the Chamber of Commerce for third parties is legitimate interest (Article 6(1)(f) GDPR). This legal basis is presumed to be met in accordance with Article 19(2) of the national data protection law (LOPDGDD). This article applies if the controller processes data of individual entrepreneurs in their professional rather than private capacity. In addition, the data is obtained from public sources.

Holding

The DPA first clarified that the GDPR does not exclude self-employed people in its scope. In addition, the Chamber of Commerce has the legal obligation under national law[1] to maintain a public census of enterprises. This database, however, does not contain the data subjects’ NIF and meets the requirements of data minimisation under Article 5(1)(c) GDPR. The DPA stated that the database transferred between the Chamber of Commerce and the controller contained more personal data than the publicly available census. Disclosing this information did not comply with the Chamber of Commerce’s agreement with the Tax Authority, as this agreement prohibits the disclosure of the NIF to third parties.

In terms of national law, the DPA stated that Article 19(2) LOPDGDD establishes a presumption of a legitimate interests legal basis limited to the contact information of individual entrepreneurs. Article 19(2) must be interpreted strictly, as it allows the controller to process data without the consent of the data subject and without involving an analysis of the interests involved. A broad interpretation allowing all personal data of a self-employed person would be “radically contrary to the spirit of the GDPR”.[2]

The DPA found a violation of Article 6(1) GDPR, as the controller processed self employed persons’ personal data without a legal basis. Not all data falls under the presumption of lawfulness in Article 19(2) LOPDGDD, meaning the controller needed to meet the requirements under Article 6(1)(f) GDPR to process data subjects’ data such as their NIF. The DPA also dismissed the argument that the controller accessed the information from publicly available sources, as the NIF was not available in the public census. Furthermore, encrypted data was still personal data within the meaning of Article 4(5) GDPR; the Chamber of Commerce provided the controller with data subjects’ NIF regardless of the format (encrypted or in plain text).

The DPA found a violation of Article 14 GDPR. The controller did not obtain the personal data directly from data subjects, however, it still had the obligation to provide information related to the processing. This allows the data subject to exercise their rights under the GDPR. The DPA dismissed the controller’s argument on disproportionate effort (Article 14(5)(b) GDPR). The controller is not exempt from providing any information under this Article, as it also requires the controller to take appropriate measures including making the information publicly available. The DPA noted that the controller had provided incomplete information in its website.

Finally, the DPA investigated a potential violation of Article 28 GDPR in relation to the controller’s contract with its processor, but did not find a violation. This is because the documentation met the requirements for Article 28(3) GDPR, even if the conditions of processing were dispersed in three separate documents.

The DPA fined the controller €260,000 in total: €200,000 for the violation of Article 6(1) GDPR and €60,000 for the violation of Article 14 GDPR. The DPA considered this a serious lack of diligence of the controller in processing without a legal basis. The DPA also noted that data such as the NIF is particularly sensitive, and processing this data without proper safeguards increases the risk of identity theft and fraud. Finally, the DPA ordered the controller to delete all personal data related to self-employed persons obtained from the Chamber of Commerce, and to cease processing this data without a legal basis. The DPA also ordered the controller to inform the self employed persons whose data was processed.

Comment

The DPA investigated several organisations following the complaint from Xnet. You can read the DPA's press release here. You can also read the GDPRhub summary of the fine against the Chamber of Commerce, against INFORMA D&B, and against DEYDE DATACENTRIC.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.

1/164

 File No.: EXP202404641

SANCTIONING PROCEDURE RESOLUTION

From the procedure initiated by the Spanish Data Protection Agency and based on the following

BACKGROUND

FIRST: The Spanish Data Protection Agency has learned, through a complaint from the association Institut per a la Cultura Democratica a L'era Digital (Institute for Democratic Culture in the Digital Age), received on
12/27/2022, of certain facts that could violate personal data protection legislation.

In order to clarify the facts brought to the attention of this Agency, on April 13, 2023, through an internal note, the Director of the Spanish Data Protection Agency urged the Subdirectorate General of Inspection to initiate preliminary investigations—provided for in Article 67 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter, LOPDGDD)—with various entities, including CAMERDATA, S.A., with NIF A78035896 (hereinafter, CAMERDATA), the entity against whom this sanctioning procedure is directed.

The internal note ordering the Subdirectorate General of Inspection to open preliminary investigations reflects, among others, the following issues:

“[…] Specifically, it is reported that, from the moment someone registers as self-employed by registering in the census of economic activities of the State Tax Administration Agency, the name, ID number, telephone number, email address, and address that are reported are treated as information of professional interest.
As a result of this processing, if the data coincides with private data,

for example, in the case of those who work from their personal home, this information on self-employed workers is exposed on the internet, easily
accessible from search engines. In addition to the above, in some cases, the data that appears when accessing some of the links, in addition to the name and surname,
ID number, address, email address, telephone number, and commercial activity, refers to

financial information or legal incidents and probability of default, having been obtained from the Commercial Registry, Bulletin State officials, chambers of commerce,
etc.
[…]”

The complaint received by the Agency explains that individuals interested in
registering as self-employed entrepreneurs provide the Tax Authority
with their name, ID number, telephone number, email address, and address. This data is processed by the
State Tax Administration Agency (AEAT), the Chamber of Commerce,
Industry, Services and Navigation of Spain (CDE), the company CAMERDATA, and

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 2/164

various private consulting firms. It is noted that the processing chains carried out
between the AEAT, the CDE, CAMERDATA, and private consulting firms lead to
the data of self-employed entrepreneurs that coincide with their personal data

being exposed and even sold online, potentially leading to
several breaches of personal data protection regulations.

The complaint includes as an attachment a document entitled "The Sale of Data of Self-Employed Individuals" which, as indicated on its first page, corresponds to "Section 5 of the report: Privacy, Data Protection vs. Institutionalized Abuse: https://xnet-x.net/es/datos-por-liebre-xnet-abusos-reforma-ley-proteccion-datos/". The attached document includes, among others, the following screenshots:

(i) Screenshot of the results obtained, according to the document, after a Google search for the first and last name of a self-employed entrepreneur.
It shows the results corresponding to the websites www.expansion.com and https://autonomos.axesor.es. The data of the individual is illegible because it is shaded and supposedly corresponds to the first and last name of the self-employed entrepreneur. The document indicates that clicking on any of these links provides access

to first and last names, including information such as ID, address, email, telephone number, business activity, and even financial information,
legal incidents, and probability of default.

(ii) Screenshot of information supposedly associated with the same person

as mentioned above, whose personal data is illegible because it is shaded, obtained by
viewing a rating page. The document states:

“[…] is a self-employed person whose business is registered in ***LOCALITY.1, the CNAE activity of the business is wholesale trade of food products, beverages, and

tobacco, and its SIC activity is groceries in general. Our reports will
provide you with the most complete information on the business activity, such as the
NIF (Tax Identification Number), telephone number, address in ***LOCALITY.1, credit scoring and rating,
probability of default and maximum solvency capacity, legal incidents […].

Furthermore, our researched reports on the commercial activity of […] are

especially indicated for high-risk transactions and/or for delinquent clients […] The information contained in this form is only an excerpt of all the
information on self-employed persons and professionals available on Axesor […] You can also
access the reports of executives or directors whose name matches
[…] (if they exist according to the publications in the Official Gazette of the Commercial Registry).”

(iii) Screenshot of the result of a search carried out, the document states, through the CDE website, in the Public Business Registry. It states that "If you wish to obtain more information, consult the Camerdata Online Business File."

SECOND: The Subdirectorate General of Inspection proceeds to carry out preliminary investigative actions to clarify the facts in question pursuant to the functions assigned to the supervisory authorities in Article 57.1 and the powers granted in Article 58.1, both of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VII, Chapter I, Section Two, of the LOPDGDD (General Data Protection Act). We are aware, among others, of the following details included in the Report signed by the acting inspector, from which these excerpts are transcribed:

<< […]
RESULTS OF THE INVESTIGATION ACTIONS

On 17/10/2023, it was verified that:
1. Within the AEAT's processing activity log, section 5.42

"Census of Economic Activities" states:
"Description of the activity
Tax control: management, settlement, and collection of the tax on economic activities.
Purpose

Effective application of the state tax and customs system.
Interested parties
Businesspeople, professionals, and artists
Data
NIF/DNI, Name and Surname, Address
Information Commercial

Processing
Collection
Recording
Storage
Structuring
Modification

Updating
Copying
Analysis
Consultation
Extraction
Dissemination

Interconnection
Limitation
Deletion
Destruction
Other
Recipients

INE
Other Autonomous Community bodies
Provincial Councils
Other Local Government bodies
Chambers of Commerce, Industry, and Navigation

Basque Provincial Councils, Chartered Community of Navarre
[…]”

2. Within the information on data protection published online by the
AEAT, section 3.6 “Recipients” states:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 4/164

“In accordance with article 95 of the General Tax Law, all data, reports, or background information obtained by the Tax Administration in the performance of its duties Their functions are confidential and may only be used for the effective application of the taxes or resources entrusted to them and for the imposition of appropriate sanctions. They may not be transferred or communicated to third parties. However, Article 95 of the General Tax Law also establishes a series of specific cases where the Tax Agency may transfer or communicate data to third parties. These cases may be of two types:
- Transfers or communications of data in cases such as collaboration in the fulfillment of tax obligations with other public administrations, the fight against tax crime and fraud in various areas, collaboration with investigations by judicial bodies and the public prosecutor's office, and the monitoring of the Tax Agency's own activities.
In these cases, in accordance with Article 6 of EU Regulation 2016/679, it will not be necessary to obtain the citizen's express consent for these transfers or communications to be carried out. Communications. Furthermore, in accordance with Article 14
of Regulation EU 2016/670, if a transfer or communication occurs, it will not be necessary to inform the citizen.
- Other transfers and communications not expressly contemplated in
Article 95, which are necessary within the scope of collaboration between
public administrations to facilitate the provision of public services to

citizens.
In these cases, the Administration requesting the data will always be required to obtain the citizen's express consent.
[…]”

3. That the URL https://sede.agenciatributaria.gob.es/Sede/condiciones-uso-

sede-electronica/datos-personales.html contains a first section with a hyperlink
with the text “Data Protection Information” that redirects to the URL of the following point. Further down in the “Help” section, there is another hyperlink with the text
“Data Protection Information for the interested party.”

4. That the URL https://sede.agenciatributaria.gob.es/Sede/condiciones-uso-

sede-electronica/datos-personales/informacion-sobre-proteccion-datos.html states:
“Data Protection Information
The State Tax Administration Agency (hereinafter “Tax Agency”) is responsible for all personal data processing carried out in the course of its activities, unless otherwise indicated in a specific processing.

These processing operations will be carried out on the personal data of individuals
who use the services it offers in the course of their activities, who may be
taxpayers, their representatives, public employees, or
any other person who uses its services. Hereinafter, we will refer to them
as data subjects.

In relation to the use of the Tax Agency's website by data subjects, you are hereby informed that your personal data may only be obtained
for processing when it is adequate, relevant, and not excessive, in relation
to the scope and the specific, explicit, and legitimate purposes for which it was obtained.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 5/164

The Tax Agency carries out these processing operations in accordance with current regulations regarding personal data protection, information security, and the specific regulations that govern its activities, which include all aspects related to the conditions under which data processing of interested parties may be carried out.

In this regard, the necessary technical and organizational measures have been adopted to prevent the accidental or unlawful destruction, loss, or alteration of personal data transmitted, stored, or otherwise processed, or unauthorized communication or access to such data, which could cause, in particular, physical, material, or immaterial damage. The measures adopted take into account the state of technology, the nature of the data, and the risks to which they are exposed, and are periodically reviewed to ensure their adaptation to new situations or risk scenarios.

The Tax Agency, as the controller of all processing of the personal data of data subjects and in accordance with the information requirements set forth in Article 14 of Regulation (EU) 2016/679,

indicates the following basic information regarding this processing:
"And also states:
a. Under "Purpose" it states exclusively:
"Effective application of the state tax and customs system"
b. Under "Recipients" it states exclusively:
"Other national and international public administrations"

c. Under "Source" it states exclusively:
"From the same data subject, from other Public Administrations, from other
individuals other than the data subject, from private entities, from public registries,
and from sources accessible to the public."

--As a result of the request for information made by the Data Inspectorate on 02/11/2023 to the AEAT, the Data Protection Officer The Tax Agency's Data Protection Department
remits the following information and documents to this agency:
<<1. Regarding the information on data protection related to the data provided to the census of entrepreneurs, professionals, and withholding agents (forms 036 and 037) and the transfer of this data to the Chamber, it states that it is provided:

a. Through the processing activities log "processing 5.1 Census" at the URL https://sede.agenciatributaria.gob.es/Sede/todas-gestiones/procedimientos-
notributarios/tratamiento-datos-personales/tratamiento-datos-
personales/informacioninteresado-sobre-proteccion-datos/5-registro-actividades-
tratamiento/5_1-censo.html
b. When completing forms 36 and 37, the following text appears on the "sign and send" screen:
"In accordance with Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, and Article 11 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights, you are hereby informed that the personal data you provide will be processed by the State Tax Administration Agency for the purpose of the effective application of the state tax and customs system. You can find more information on the possible processing, transfers, and the procedure for exercising the rights established in Articles 15 to 22 of the regulation at the following link:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 6/164

(https://sede.aqenciatributaria.qob.es/Sede/condiciones-uso-sede-electronica/datos-
personales.html)"
c. Furthermore, the record of the information provided is available on the electronic site at the following URL:
https://sede.agenciatributaria.gob.es/Sede/procedimientoini/ZA02.shtml

https://sede.agenciatributaria.gob.es/static_files/Sede/Procedimiento_ayuda/ZA02/drIA
E_CamCom08.pdf

2. Regarding the data provided, it is stated that it can be found in Annex I
of the Agreement signed between the AEAT (Tax Agency) and the CHAMBER of the Treasury, accessible at
https://www.boe.es/buscar/doc.php?id=BOE-A-2019-18316 .

It is verified, in accordance with said Agreement and Law 4/2014, that the data transferred
pursuant to Article 8 of Law 4/2014 are "Company census data" and "Economic Activities Tax Data."

3. That the transfer of company census data pursuant to Article 8 of Law 4/2014 does not

require the consent of the interested party, as it is carried out based on chamber regulations. It is carried out based on the legal obligation of Article 8 of Law 4/2014.

4. That in Article 22.3 of Royal Decree 669/2015, of July 17, which implements Law 4/2014, of April 1, Basic Law of the Official Chambers of Commerce, Industry, Services, and Navigation, in relation to the electoral register, states:
"3. The State Tax Administration Agency, as well as the other territorial administrations competent in tax matters, will collaborate with the governing bodies of the Chambers to provide them with the necessary information for the preparation and establishment of the registers, ensuring that only the employees of each Chamber determined by the plenary session will have access to said information, with the mandatory duty of confidentiality regarding said data. To this end, the State Tax Administration Agency will provide the information derived from the Economic Activities Tax register, along with the necessary company data included in other registers it prepares. and
manages, in particular, the Census of Business Owners, Professionals, and Withholding Taxes."

5. That "With respect to the information authorized for transfer related to the Tax on Economic Activities (IAE) and that of a census nature, understood as that contained in the Census of Business Owners, Professionals, and Withholding Taxes, the content of which is established in Article 5 of Royal Decree 1065/2007, of July 27, which approves the General Regulations for tax management and inspection actions and procedures and for the development of common rules for tax application procedures, this information is used only to compile the public business census."

6. That the IAE information exchange protocol located at
https://sede.agenciatributaria.gob.es/static_files/Sede/Procedimiento_ayuda/ZA02/pInt

ercambioIAE2006.pdf states that the transferred data may only be used for the purposes contemplated by the regulations and not for any other uses.>>

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 7/164

--As a result of the information request sent by the Data Inspectorate, on 14/11/2023, CAMERDATA provided this agency with the following information and statements:
<<1. That, in relation to self-employed workers, they process the following data, among others:
“NIF”:

Meaning:
tax identification number
Source of data:
Public business register published by CÁMARA in accordance with the provisions of Law 4/2014 (hereinafter Public Business Register).
It is transferred to:

Clients who request the business information services offered by CAMERDATA, including, on the one hand, entities in the sector known as infomediary or information reusing companies (AXESOR, CERVED, DATACENTRIC, EQUIFAX, IBERINFORM, MOODY'S) and, on the other hand, end-clients who request it
for their exclusive internal use.

“company name”
Meaning:
Method in which the company identifies itself with respect to its formal obligations,
normally with the agents with which it interacts, such as Social Security, the Treasury,
suppliers, or clients. Also known as the company name.
Data source:

Public business census.
Provided to:
Clients who request the business information services offered by CAMERDATA, including, on the one hand, entities in the sector known as infomediary or information reusing companies (AXESOR, CERVED, DATACENTRIC, EQUIFAX, IBERINFORM, MOODY'S) and, on the other hand, end-clients who request it

for their exclusive internal use.
"generic email"
Meaning:
General contact email address for the company.
Data source:
Kompass, through data enrichment from the public business census.

Provided to:
End-clients who request it for their exclusive internal use.
"address"
Meaning:
Company address consisting of street name, street number, and the remainder of the address.

Data source:
Public business census.
Provided to:
Clients who request the business information services offered by CAMERDATA, including, on the one hand, entities in the sector known as infomediaries or information reusers (AXESOR, CERVED, DATACENTRIC, EQUIFAX, IBERINFORM, MOODY'S) and, on the other hand, end-clients who request it
for their exclusive internal use.
"postal code"
Meaning:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 8/164

Postal code of the company's address.
Data source:
Public business census.
It is provided to:
Clients who request the business information services offered by
CAMERDATA, including, on the one hand, entities in the sector known as infomediary or information reusing companies (AXESOR, CERVED, DATACENTRIC,
EQUIFAX, IBERINFORM, MOODY'S) and, on the other hand, end-clients who request it
for their exclusive internal use.
To the company DMOVO to carry out the address normalization process.
"municipality"

Meaning:
City of the company's address.
Data source:
Public business census.
It is provided to:

Clients who request the business information services offered by CAMERDATA, including, on the one hand, entities in the sector known as infomediary or information reusing companies (AXESOR, CERVED, DATACENTRIC, EQUIFAX, IBERINFORM, MOODY'S) and, on the other hand, end-clients who request it
for their exclusive internal use.
To the company DMOVO to carry out the address normalization process.

"province"
Meaning:
Province of the company's address.
Data source:
DMOVO. Obtained during the address normalization process each time a new business census is uploaded.

It is provided to:
Clients who request the business information services offered by CAMERDATA, including, on the one hand, entities in the sector known as infomediary or information reusing companies (AXESOR, CERVED, DATACENTRIC, EQUIFAX, IBERINFORM, MOODY'S) and, on the other hand, end-clients who request it
for their exclusive internal use.

"Telephone"
Meaning:
General contact telephone number of the company.
Data source:
INFORMA and DATACENTRIC. Obtained during the data enrichment process of the business census.

It is provided to:
Clients who request the business information services offered by CAMERDATA, including, on the one hand, entities in the sector known as infomediary or information reusing companies (AXESOR, CERVED, DATACENTRIC, EQUIFAX, IBERINFORM, MOODY'S) and, on the other hand, end-clients who request it

for their exclusive internal use.
"Company type"
Meaning:
Legal form of the company.
Data source:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 9/164

Public business census.
It is provided to:
Clients who request the business information services offered by CAMERDATA, including, on the one hand, entities in the sector known as infomediary or information reusing companies (AXESOR, CERVED, DATACENTRIC,

EQUIFAX, IBERINFORM, MOODY'S) and, on the other hand, end-clients who request it
for their exclusive internal use.
"Company name"
Meaning:
Indicator of the type of company name.
Data source:

DMOVO. Obtained during the name standardization process each time a new business census is uploaded.

It is provided to:
Clients who request the business information services offered by CAMERDATA, including, on the one hand, entities in the sector known as infomediaries or information reusers (AXESOR, CERVED, DATACENTRIC, EQUIFAX, IBERINFORM, MOODY'S) and, on the other hand, end-clients who request it
for their exclusive internal use.
To the company DMOVO to carry out the address normalization process.

It provides an extract from its database relating to 500 records, where the "Company Name" column contains first and last names, the "Company Type" column contains "11 SELF-EMPLOYED", and the "Address" column contains what appears to be a street name and street number in all records, and floor and door numbers in some records. The "Company Gender" column also includes a "V" or "M" depending on whether the name in the "Company Name" column is considered male or female.

2. That they process data on a total of 1,665,049 self-employed workers, although not all registries have all the data reported.

3. Regarding the infomediary sector, it states:
a. They collect, analyze, transform, and process information from the public/private sector

to create value-added products for third-party companies or the general public, serving as a tool for effective decision-making.
b. That the entities that use its services and products are all IBEX 35 entities, all financial institutions, public administrations, including state security forces and bodies, SMEs and individual entrepreneurs for their commercial and business activities, any entity required to access information in compliance with various laws that require it, any citizen, or non-profit organizations.
c. “Companies in the infomediary sector have been operating in the market for more than two decades, and the reuse and distribution of information that can be freely obtained from various public sources in the broadest sense and context is vital to their performance. In a world where both access to and transparency of information are key to security in any commercial transaction, companies in this sector are the benchmark that provides the necessary security to global commercial traffic and acts as an essential element in boosting the general economy through the application of the best information processing techniques to ensure the quality, security, veracity, and reliability of information. The work of infomediary companies should therefore be considered of general public interest. Additionally, it is important to highlight the work carried out for SMEs. as an

essential part of the Spanish business fabric. Thus, on the one hand, it allows
individual entrepreneurs with limited resources to use high-value-added information systems without having to assume high individual costs
for direct consultation with the source of origin, with respect to their customers and suppliers.
On the other hand, it also makes their own business information accessible
to their suppliers and financial institutions in order to promote their activity and

business operations.
The infomediary sector is increasingly essential when it comes to streamlining and improving
business management, and the direct impact of the opportunities generated is greater both at the economic and political and/or social levels.
Furthermore, this sector interacts with other sectors, generating value in many

of its activities. Therefore, when assessing this sector, it must be taken into account
that it is growing both vertically, like other sectors, and also horizontally, making this undeniable transversality complex to assess.
The performance of the infomediary sector has a direct impact not only on community, but also very relevant to business activity and employment in the Spanish economy. According to data taken from the Infomediary Sector Report presented on April 14, 2023:
- As of December 31, 2019, there were 700 active infomediary companies identified
in Spain.
- The aggregate sales for fiscal year 2019 of the 591 infomediary companies for which financial data is available amounted to €2,543,042,052.
- The aggregate number of employees for fiscal year 2019 of the 588 companies for which employee data is available amounted to 21,998.
- The combined subscribed capital as of December 31, 2020, of the 700 companies
identified as infomediaries amounted to €311,911,961.
d. The main sources of data used by companies in the sector to create the services and products they provide to society are:
• Official Gazettes of the State, Autonomous Communities, and Provincial Governments.

• Official Gazette of the Commercial Registry and Intellectual Property.
• Public Census of Companies of the Chambers of Commerce, regulated by Law 4/2014,
of April 1, Basic Law of the Official Chambers of Commerce, Industry, Services, and Navigation.
• Open, unprotected information from the Real Estate Cadastre according to the Revised Text of the Real Estate Cadastre Law (TRLCI), approved by Royal Legislative Decree

1/2004, of March 5.
• Professional guides and directories.
• Telephone service subscriber guides.
• Any source referenced by the public administrations themselves in the opendata catalog under the Spanish Government's Open Data Initiative.

4. Regarding the information provided to data subjects pursuant to Article 14 of the GDPR,
it states:
a. It is considered a disproportionate effort pursuant to Article 14 of the GDPR. 14.5.b and Recital
62 GDPR and according to Report WP260.rev01 17/ES (last revised on April 11, 2018)

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 11/164

sending a communication to each data subject to notify them of the processing as a
self-employed person or individual entrepreneur.
i. That there are 1,665,049 self-employed persons in the CAMERDATA database who should be notified, which is an unaffordable cost.
ii. That according to the budget of MEYDIS S.L. and Sociedad Estatal de Correos y
Comunicaciones S.A., the handling, distribution, and materials costs for the communications amount to €9,409,000 and €4,266,900, respectively.
Provide a copy of the budgets from MEYDIS, S.L. dated July 1, 2021, which show the amount of "1,600,000." No total price is shown.
Provide a copy of the budgets from CORREOS, which do not show the aforementioned budget, but do show the text "CAMERDATA BUDGET, 2021 COMMUNICATION CAMPAIGN" and "TOTAL BUDGET FOR 1,650,000 SHIPMENTS."
iii. That CAMERDATA has annual revenues in 2019, 2020, 2021, and 2022 of €941,238.83, €836,093.46, €885,999.51, and €895,950.29, respectively.
Provide a copy of the audited annual accounts as of December 31, 2019, December 31, 2020,
fiscal year 2021, and December 31, 2022, with the aforementioned figures in the section "1. Net turnover."
a. That due to this disproportionate effort, they have initiated a process of publishing the following text on the websites of the chambers of commerce,
which is currently published in the Chambers of Commerce of Madrid, Valencia, Barcelona, Sabadell, Girona, Alicante, and Castellón.
“Information for self-employed workers regarding personal data protection

This communication informs all self-employed persons of the processing of their personal data by Camerdata and the ASEDIE partner companies that are subject to its code of conduct for the data protection intermediary sector, including: Axesor, Datacentric, Iberinform, Informa, and Equifax.
The data processed by CAMERDATA and related companies has been legitimately collected by CAMERDATA and obtained from an official census prepared by a public body. The data corresponds to the person who is the data subject (the self-employed person) in the exercise of an activity listed in Royal Decree 2007 (RD 475/2007).
The purpose of processing this data is to send commercial and marketing communications, offering various goods or services that may be of interest to them, as well as commercial information about them. the business activity carried out by the Self-Employed Person.
If you wish to exercise your rights of access, rectification, deletion, restriction of processing, or object to the processing of your contact information, you can send your request to the addresses indicated below. We remind you that you can exercise your right to object to receiving commercial communications centrally, using the services of the Robinson List at:
https://www.listarobinson.es/:
ASEDIE member companies that are subject to its Code of Conduct
CAMERDATA, S.A. Avda. Diagonal, 452, 3rd floor, 08006 Barcelona, or by sending an email to: informacion@camerdata.es. In all cases, please attach a copy of a document that proves your identity (ID, passport, or similar).
You can also contact CAMERDATA's Data Protection Officer using the same contact information provided to exercise your rights.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 12/164

You can also find additional information about the processing of your data by CAMERDATA at the following link:
https://www.camerdata.es/politica-privacidad
AXESOR CONOCER PARA DECIDIR S.A.
C/ Graham Bell, s/n, Edificio Axesor - 18100 Armilla, Granada

or by sending an email to: dpd@axesor.es. Always attach a copy of a document that proves your identity (DNI, passport, or similar).
You can also contact AXESOR's Data Protection Officer using the same contact information provided to exercise your rights.
You can also find additional information about the processing of your data by AXESOR at the following link: Link:
https://www.axesor.es/informacion-tratamientos-rgpd
DATACENTRIC S.A.
C/ José Echegaray 9, 28232 Las Rozas, Madrid
or by sending an email to: dpd@datacentric.es Always attaching a copy of a document that proves your identity (DNI, passport, or similar).
You can also contact DATACENTRIC's Data Protection Officer
using the same contact information provided to exercise your rights.
You can also consult additional information about the processing of your data by DATACENTRIC at the following link:

https://www.datacentric.es/politica-de-privacidad/
IBERINFORM S.A.
Calle Raimundo Fernández Villaverde, 57 Bis, Madrid 28003 (Madrid)
or by sending an email to: infogdpr@iberinform.es Always attaching a copy of a document. that proves your identity (DNI, passport, or similar).
You can also contact the IBERINFORM Data Protection Officer

using the same contact information provided to exercise your rights.
You can also consult additional information about the processing of your data by IBERINFORM at the following link:
https://www.iberinform.es/aviso-legal#section6
INFORMA S.A.

Avenida de la Industria, 32, 28108 - Alcobendas (Madrid)
or by sending an email to: clientes@informa.es. In all cases, please attach a copy of a document that proves your identity (DNI, passport, or similar).
You can also contact the INFORMA Data Protection Officer
using the same contact information provided to exercise your rights.

You can also consult additional information about the processing of your data by INFORMA at the following link: Link:
https://www.informa.es/textos-legales
Company not associated with ASEDIE
EQUIFAX S.A.

Paseo de la Castellana, 259D, 28046 Madrid,
or by sending an email to: sac@equifax.es. Always attach a copy of a document that proves your identity (DNI, passport, or similar).

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 13/164

You can also contact the EQUIFAX Data Protection Officer using the same contact information provided to exercise your rights.
You can also consult additional information about the processing of your data by EQUIFAX at the following link:

https://www2.equifax.es/ederechos/asnef_20024.html.”
c. Incorporate the above text into bulletins and newsletters that the Chambers publish periodically, thereby achieving greater dissemination of information.
d. That it is intended, beginning in 2024 and subsequently annually, to disseminate the informative text in several
largely circulated newspapers in Spain.

e. That it considers that these measures meet the criteria for validating the
exemption from the obligation to report individually.

5. Regarding ASEDIE's Code of Conduct, it states:
“[…]

In the performance of its statutory functions, ASEDIE has developed the Code of Conduct for the Infomediary Sector (hereinafter, the Code of Conduct or Code). In drafting the Code, it has taken into account the opinions of the main stakeholders involved in one way or another in the infomediary sector, especially members, both in the legal and business aspects, but also consultants and other individuals with knowledge of relevant aspects of the sector. The need for legal certainty and strengthening members' commitment to regulatory compliance regarding data protection, understood as an essential business requirement, have led ASEDIE's statutory bodies to consider it necessary to promote the Code of Conduct. The Code establishes a general framework that must be complied with by all ASEDIE member companies.

In any case, any action arising from compliance with the Code The Code of Conduct will be carried out in strict compliance with current regulations, especially competition law and regulations applicable to the protection of personal data.
In developing and improving the Code, ASEDIE has enjoyed significant collaboration and involvement from the AEPD, although there have been disagreements that have led the Association to challenge the denial of approval of the Code through legal proceedings.
[…]”

On January 22, 2024, the draft content of the ASEDIE Code of Conduct was obtained from the internet and incorporated into the file through a formality.

6. Regarding the processing of the business database in the case of self-employed individuals, it states that:

a. “The specific purpose of the processing is the development of a business information system or service

with quality data for the direct or indirect promotion of the goods or services of a company, organization, or person that
carries out a business or professional activity, whether on its own behalf or on behalf of
a third party.”
b. That they are based on legitimate interest, and states:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 14/164

"Camerdata processes the personal data of natural persons insofar as they relate to their status as sole proprietors or independent professionals, that is, exclusively related to their business activity.
In such cases, it is presumed to be covered by legitimate interest pursuant to Article 6.1 f) GDPR, unless proven otherwise, provided that the following requirements are met:

(i) That the processing relates solely to the data necessary for the purposes indicated in point b. of this response, which allows the controller's clients, or the controllers themselves, to maintain relationships with the data subject in the context of the business or professional development of the activity that the data subject operates or carries out, respectively, as a sole proprietor or independent professional.
" For these purposes, processing covered by Article 6.1 f) of the GDPR will be considered lawful, subject to the following considerations.
(ii) The processing is carried out in accordance with the provisions of Article 19 of the LOPDGDD, that is, provided that the following requirements are met:
- That the processing relates solely to the data necessary for professional identification.

- That the purpose of the processing is solely to maintain relations of any kind with the legal entity for which the data subject provides services, or with the business or professional activity carried out by the individual entrepreneur or liberal professional.
The legitimate interest provided for in the preceding sections extends, provided that these requirements are met, to the case where the data is processed to provide information

strictly about the economic activity carried out by individual entrepreneurs and independent professionals, and to assist third-party clients of the data controllers in their decision-making process for the purposes of contacting, initiating, and
maintaining business or professional relationships, thereby promoting business or economic promotion and development.
The presumption of legitimate interest established in cases

(i) and (ii) will not apply to the use of data for processing purposes intended to establish a relationship with the data subjects in their personal, non-business or professional capacity.
Outside of these two cases, in accordance with the provisions of Recital (47) and
Art. 6.1.f) of the GDPR, when these data are processed outside the scope, criteria, and/or purposes indicated, the data controller, or the third party on whose behalf the data controller acts, must have carried out a weighing of their own legitimate interest between their legitimate interests and the interests, rights, and freedoms of the data subjects, which determines that the intended processing does not violate those interests, rights, and freedoms of the data subject. They must, in all cases, apply the necessary security measures.
Legitimate interest of the data controller or third parties.
The existence of a legitimate interest on the part of Camerdata and its clients (to whom it provides services related to the purpose of the processing) in processing the personal data indicated is based on the need to know the identifying data of individual entrepreneurs and professionals, as necessary data within the total set of business or professional data offered in the various information products and services that Camerdata markets. Data that is relevant to the commercial or professional relationships of the data subjects and that may only be processed for those purposes, meaning that it may not be used for direct relationships with individuals.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 15/164

Camerdata's legitimate interest is twofold. On the one hand, it derives from its role as a source of funding, inherent to all business activities, and, on the other, it contributes to the development and promotion of business or professional relationships by offering a quality information system to stakeholders in the business community and individuals, providing the legal security required by the parties to any commercial or contractual relationship in their operations in the market, thereby satisfying a general economic and social interest.
Indeed, it should be noted that Camerdata obtains data from public sources and its processing of such data is intended to increase data quality and thus offer interested clients an information system on companies operating throughout the country, thereby fulfilling a general interest for the business sector.
Camerdata's data processing also underlies a legitimate interest of its clients and the data subjects themselves, who need to know this information, either to publicize their services and products, to offer them to third parties, to carry out commercial or professional transactions with third parties, or

even to be able to exercise the appropriate legal actions that may apply. Furthermore, access to, knowledge of, and evaluation of such business data is increasingly required by law, for example, by Law 10/2010 on the prevention of money laundering and the financing of terrorism. We are therefore faced with a business data processing that generally guarantees the legitimate interest of any third party in knowing this information.

It should be noted, once again, that the sources from which the information is obtained, which are processed for these purposes, are considered public in the broadest sense, either because the publication of the data responds to the requirement and application of a legal norm that requires such information to be known and accessible to everyone, or because it has been manifestly made public by the data subject.

Fundamental rights and freedoms of data subjects:
The fundamental rights and freedoms of data subjects are the general ones that require the protection of personal data, with none specifically highlighted in this particular situation.
In any case, they will not be violated by the processing described in this document, because:

1. The data subjects' information processed will be limited solely to the
type of business or professional data, and for the purposes and scope set forth in this document.
2. The data has been obtained from public sources.
3. The exercise of the rights of data subjects regulated in
Articles 15 to 22 of the GDPR is guaranteed.

Furthermore, the data subjects themselves have an interest in the processing of their business or professional data, as they can access the Camerdata database to contact third-party businesses or professionals to offer their services and products, and they have an interest in being located by third parties who access the Camerdata database to initiate commercial relationships.

Furthermore, and in compliance with the data minimization principle (Article 5.1.c of the EU GDPR), the data processed, listed in section 1 of this response, are relevant, adequate, and limited to what is strictly necessary for the purpose for which they are processed.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 16/164

Weighting:
1. - The processing of this information is lawful: The processing of the data is necessary to achieve the intended business and economic-social purposes.
2. - The sources from which the information is obtained are considered public sources in the broadest sense, either because the publication of the data responds to the requirement and application of a legal regulation that requires that such information be known and accessible to the general public. In this regard, data may be obtained from the following sources:
a) Public sources: Primarily those mentioned above.
b) Data that the data subject has manifestly made public. It will be understood

that this type of data may be subject to processing, based on the lawfulness of legitimate interest, to the extent that Article 9.2. e) of the GDPR allows the processing of special categories of data due to the fact that the data subject has manifestly made them public. Therefore, all the more reason for processing data that do not fall within these categories, as is the case with data processing carried out by data controllers, may be carried out.
c) Any other public sources, provided that their processing is not impeded by legal regulations or by the rights of the legitimate author or beneficiary of the data source, and the data controller has, prior to creating the file, weighed the legitimate interest of the data subject or the third party to whom the service is provided against the interests or fundamental rights and freedoms of the data subject that require the protection of personal data. In the processing of the public sources referred to in this paragraph, data controllers shall comply with the processing principles of Article 5 of the GDPR.
3. - The categories of data processed are minimally invasive of the data subject's right to privacy, as they are data limited to the performance of a business or professional activity, and at no time do they contain data from their family sphere, much less data from special categories of data (Article 9 of the GDPR).
Furthermore, the Camerdata business database does not include any credit or financial solvency information.
4. - Part of the legitimate interest considered for processing this information is the harm that would be caused to the general interest of commercial transactions by not processing this information, in the terms set forth, given the legal certainty that it provides in any market transaction. The lack of informative references regarding the business activity of these interested parties in the market would have a direct, clearly negative impact on economic activity, with consequent harm to general economic activity.
5. - The principle of the free circulation of data, established and protected by the European regulations on the matter (GDPR).

6. - The intended purposes for the processing of this data by Camerdata do not differ from those of the data sources, the official registry publications and the public business census of the Chambers of Commerce (the main sources for obtaining this information), as they seek to offer users the necessary transparency and legal certainty. This fact, together with the widespread and recognized existence of business information systems in the market and in society in general, directly influences the existence of a reasonable expectation on the part of the interested parties regarding the possibility that their business or professional performance data may be processed. Occasionally, the interested parties themselves directly make the information public or allow its dissemination because they are interested in having their contact information and business or professional activities known. 7. In the case of data that is public for any reason, the Judgment of the Court of Justice of the European Union of November 24, 2011 (Joined Cases C-468/10 and C-469/10) indicates, in its Recitals (44) and (45), that

when the data is contained in publicly accessible sources, the data controller and, where applicable, the third party or parties to whom the data is communicated, do not access data relating to the data subject's private life, given that the information is already public knowledge. As a result, there is a lesser impact on the data subject's rights, which must be assessed at its fair value in the weighing of the legitimate interest pursued by the data controller or

by the third party or parties to whom the data is communicated.

7. Regarding the processing involved in the transfer of the company database to third-party entities in the case of self-employed individuals, the Spanish Chamber of Commerce states that this is based on legitimate interest and the purpose indicated in the previous point.

Provides a copy of the contract dated February 15, 2016, signed between CAMERDATA and CHAMBER, which states (underlined):
a. CHAMBER is the transferor and CAMERDATA is the transferee.
b. “[…]
V. Based on the aforementioned data received from the collaborating public authorities

(currently the State Tax Administration Agency, the Provincial Council of Navarre, and the Chambers of Commerce of the Basque Country),
the Spanish Chamber of Commerce prepares the public business census under the name "Basic Business Census," guaranteeing confidentiality in the processing and the exclusive use of the information received.

[…]”

c. “That business information is one of the traditional areas where the
Chambers of Commerce, in accordance with their functions and purposes, have been
offering services to companies. With the primary purpose of properly and
coordinatingly managing these services, the now defunct High Council of Chambers of Commerce (now replaced by the Spanish Chamber of Commerce) and the Chambers of Commerce established in 1985 the commercial company CAMERDATA, S.A., a chamber-wide instrumental entity for the development of said activity.
According to Article 4 of the Bylaws of CAMERDATA, S.A., its corporate purpose is the development and operation of a business information system and the applications derived from it.”
d. “[…]CAMERDATA, S.A. It has been developing and commercially operating a
business information system called the "Spanish Business File,"

which is a separate database from the "Basic Business Census" prepared by the
Spanish Chamber of Commerce. However, in order to develop it, it is interested in obtaining
a copy of the business information from the "Basic Business Census."
e. “[…]
First. Purpose.

By this Agreement, the Assignor assigns and transfers to the Assignee, who, in turn, receives and acquires for itself a copy of all the business data contained in the Basic Business Census referred to in Exhibit V above (hereinafter the Assigned Database), updated as of January 2016, which

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 18/164

contains the information fields indicated in Annex 1 of 3,160,984
Business Registries.
For these purposes, the Business Registry is understood to be all the information fields
in Annex 1 relating to each of the companies listed in the Assigned Database, with the NIF (Tax Identification Number) of the companies being used as the identifier of said registry. The same.

[…]
Second. Purpose.
The Transferee will include the business data from the Transferred Database and its periodic updates in its Spanish Business File, and will process, complete, and enhance them under the terms agreed in this Agreement for the purpose of commercially offering it to interested companies and third parties as a database of information on companies operating in Spanish territory.
[…]”
f. The fields “Company NIF,” “Company name or corporate name,” “Main address,” “Business address,”

“IAE activity section,” “IAE activity” are listed in Annex 1.
g. “Second.- Purpose.
The Transferee will include the business data from the Transferred Database and its periodic updates in its Spanish Business File, and will process, complete, and enhance them under the terms agreed in this Agreement for the purpose of commercially offering it to interested companies and third parties as a database of information on companies operating in Spanish territory.”
h. “12.2.- The Transferor also declares that the Transferred Database and its updates contain data relating to individual entrepreneurs and data of natural persons who provide services to legal entities, relating solely to their first and last names, the functions or positions held, as well as their postal or email address, telephone number, and professional fax number, all in accordance with the provisions of Article 2 of the RLOPD.”
i. ANNEX 2 to the transfer agreement of February 15, 2016, with the "Conditions of the Transfer of the Transferred Database," states that:
i. "The data included in the Transferred Database and any updates thereto are obtained from the public business census regulated by Law 4/2014, prepared by the

Transferor under the name of the Basic Business Census."
ii. CAMERDATA Obligations:
“B) Obligations of the Transferee
b. 1) The Transferee undertakes to incorporate the information from the Transferred Database into the Spanish Company File and to process and market it under the terms agreed in the Contract and its Annexes.

b.2) The Transferee undertakes to always keep the business data in the Spanish Company File up to date and, to this end, undertakes to:
(i) Obtain from the Transferor all updates to the Transferred Database that the Transferor periodically makes within fifteen (15) business days following the date on which it receives written communication to this effect from the Transferor.

(ii) Not to transfer or market the Transferred Database or its updates, and not to make copies other than backup copies.
(iii) Incorporate the information from the Company Records of the Database into the Spanish Company File. Updated Transfer within thirty (30) business days

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 19/164

following the date on which it is received from the Transferor and to process it under the terms indicated in the following paragraph b.4).(iv) Carry out said update by overwriting the Spanish Company File with the information from the Transferred Database updated for each Administration Code submitted. Consequently, the Assignee will be obliged to delete the information from the Transferred Database previously submitted regarding said Administration Codes from the Spanish Company File. This information will be completely replaced and rendered ineffective. The Assignee will not be able to use said information for the purpose of the Contract or for any other purpose. It may only keep it blocked and available to public authorities, judges, and courts to address any potential liabilities that may arise from the processing and marketing of said information during the statute of limitations. b.3) The Assignee may only inform interested third parties that the
source of information in the Spanish Business File regarding the fields in
Annex I of the Contract corresponds to that of the Basic Business Census when

said file has incorporated information from the Assignor's most recently updated Assigned Database. Otherwise, it may not disclose said source.
b.4) Upon receipt of the Assigned Database or its update, the Assignee
will:
(i) Standardize names and addresses expressed in different elements (for example: street / rua / kale / carrer, standardizing all of them as a street) without this

implying a change in the essential content of the business information contained in
said Assigned Database.
(ii) Incorporate the information from the Assigned Database or its updates processed
in this way into the Spanish Business File owned by the Assignee.
b.5) The Spanish Company File that the Assignee develops and markets will have the following characteristics:

(i) The company registry and its fields in the Assigned Database indicated in Annex 1 of the Contract. The remaining fields in said File included by the Assignee will not modify, alter, or contradict the fields in the Assigned Database and its updates.
(ii) Fields developed by the Assignee based on algorithms created by it.

(iii) Fields provided by the Assignee: such as Legal Form, main activity, registered office, branches, and business activity.
(iv) Fields provided by other legitimate and up-to-date sources: Business name, telephone number, fax number, National Tax Code (CNAE), website, date of incorporation, number of employees, turnover, imports/exports, positions (up to 5 positions with first and last names), company type (to distinguish between self-employed individuals not included in Section 2 or 3), geodetic coordinates (in three universal systems), or others.
[…]

Provide a copy of the contract dated July 1, 2022, signed between CAMERDATA and INFORMA D&B S.A.U. (hereinafter INFORMA), which states:

a. CAMERDATA authorizes INFORMA to market its self-employed database through BUREAU VAN DIJK EDITIONS ELETRONIQUES SRL (hereinafter BVD), a MOODY'S ANALYTICS company.
b. INFORMA will be responsible and agrees that MOODY'S ANALYTICS may only use the information for:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 20/164

"Marketing services.
NIF enrichment (given a document, the requested fields from the database provided will be returned).
Preparation of commercial and business reports for the individual entrepreneur in their business aspect, never regarding their personal activity.

Segmentation in sales and pricing processes.
Provision of fraud prevention services related to the validation of information and identifiers.
Credit and asset solvency services (Analytics Scores services) in their business aspect."

Provides a copy of the contract dated 09/29/2022 and signed by CAMERDATA and INFORMA, which states that:
a. INFORMA provides CAMERDATA with company information in its database so that CAMERDATA can include it in its database and market it. This information includes, among other data, the CIF (Tax ID Number), company name, full address, company telephone number, and sales figures.
INFORMA also provides CAMERDATA with the FIBAEMP PRENORMALIZED file so that CAMERDATA can include it in its database and market it to its clients. The content of this file includes the CIF/NIF (Tax ID Number), company name or name, company status and date of the data, National Electoral Registry (CNAE), website, and date of the data.

b. CAMERDATA provides INFORMA with the Spanish company file (FIBAEMP) so that INFORMA can include this information in its file and market it to its clients. It is stated that this data includes the CIF/NIF (Tax Identification Number),
name or company name (for sole proprietors), IAE (Economic Activity), full address (street,
municipality, province), and telephone numbers.
Likewise, CAMERDATA provides INFORMA with the FIBAEMP PRENORM file so

that INFORMA can process it and return the FIBAEMP PRENORMALIZED file to CAMERDATA. The contents of this FIBAEMP PRENORM file include the CIF/NIF (Tax Identification Number), name or company name, IAE (economic activity).
c. CAMERDATA authorizes INFORMA to market its database of sole proprietors to the company BVD.

d. That BVD may only use the information for:
"Marketing services.
NIF enrichment (given a document, the requested fields from the submitted database will be returned).
Preparation of commercial and business reports for the individual entrepreneur in its business aspect, never regarding its personal activity.

Segmentation in sales and pricing processes.
Provision of fraud prevention services related to the validation of information and identifiers.
Providing financial solvency and credit services (Analytics Scores services) in its business aspect."

e. “SEVENTH. DATA PROTECTION
7.1 In the provision of information between the parties
Both parties expressly submit to Regulation (EU) 2016/679 of the
European Parliament and of the Council, of April 27, 2016 (hereinafter, GDPR), to Organic Law 3/2018, of December 5, on the Protection of Personal Data and

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 21/164

guarantee of digital rights (hereinafter, LOPDGDD), to Law 34/2002 of July 11, on information society services and electronic commerce (hereinafter, LSSI), and to other applicable regulations in this area.
For these purposes, CAMERDATA declares that the data it communicates under this Agreement (file CAMERDATA) contains personal data of individual entrepreneurs

(data subjects) related to their commercial activity, and never to their private sphere, and that this is lawful processing under the terms of Article 6.1.f) of the GDPR. To the extent that CAMERDATA guarantees that the data comes from what has been known as publicly accessible sources, CAMERDATA guarantees that the data may be used to establish a relationship with said data subjects in their capacity as individual entrepreneurs.

Similarly, INFORMA declares that the data it provides under this Agreement (Informa File) contains personal data of contact persons (data subjects), related to their professional location and for the purpose of maintaining relationships of any kind with the legal entity for which the data subject provides their services, and never to their private sphere, and that this is lawful processing under the terms of Article 6.1.f) of the GDPR and, to the extent that INFORMA guarantees that they come from what have been known as publicly available sources and telephone surveys of the companies themselves, INFORMA guarantees that they may be used to contact interested parties, provided that the purpose is to maintain relations of any kind with the legal entity for which the interested party provides their services.

That both INFORMA and CAMERDATA are responsible for their respective data privacy policies and will adapt them, where appropriate, to the requirements established in the regulations to ensure compliance with applicable legislation.
Likewise, as a result of CAMERDATA transferring the data contained in the Camerdata File to INFORMA, INFORMA will be considered the data controller, and undertakes to comply with all legal obligations applicable to it.
Additionally, as a result of the transfer by From INFORMA to CAMERDATA, if the data contained in the Informa File is transferred, CAMERDATA will become the controller of the data, and undertakes to comply with all legal obligations applicable to it as such.

[…]”

Provides a copy of the contracts dated 09/15/2009, 07/25/2012 (extension of the previous contract), 07/25/2014 (extension of the previous contract), and 05/24/2018, signed between CAMERDATA
and AXESOR CONOCER PARA DECIDIR S.A. (hereinafter AXESOR) or, in its
previous name, INFOTEL Información y Telecomunicaciones, S.A. (hereinafter INFOTEL), which state that:
a. The contract dated 09/15/2009 states that:
i. "l.- That INFOTEL, as a commercial company, is a provider of business and commercial information and maintains an extensive data warehouse with data on commercial and non-commercial entities, businesses, and self-employed entrepreneurs through its website, www.axesor.es.
ll.- CAMERDATA is a company created by the Chambers of Commerce to compile files on business activities carried out within its scope of activity, as well as to offer a public information service on the information contained, among others, in its file called Individual Entrepreneurs, of

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 22/164

in accordance with the provisions of Basic Law 3/1993 of March 22, on Official Chambers of Commerce, Industry, and Navigation, and in accordance with Organic Law 15/1999 on Data Protection.
III.- That INFOTEL is interested in accessing said public information,
obtaining a list of business activities of Self-Employed Business Owners for the

purpose of allowing it to enrich part of its file, specifically the Self-Employed Business Owners that INFOTEL obtains from various publicly accessible sources, and who are part of the Data Warehouse that INFOTEL or its Clients use in their commercial prospecting activities to carry out promotional and advertising marketing actions, in addition to providing said business and commercial information to their clients through the services and products of its website www.axesor.es."

ii. "FIRST: PURPOSE.
Through this document, CAMERDATA will provide INFOTEL with:
1. Information contained in the File it owns, called Individual Business Owners, in accordance with the details of services contained in the ANNEX to this contract, which is incorporated herein for all purposes. The

information to be provided comes from the file created by CAMERDATA based on the management and registration data of self-employed individuals with the Chambers of Commerce, as well as, insofar as the telephone number field is not originally provided, the telecommunications service subscriber lists.
iii. The ANNEX to the contract contains the identifying information, name
(company name and trade name, if available), full address (initials, street,

number, remainder of address, postal code, municipality, province, county), IAE (Economic Activities Tax), telephone number corresponding to the headquarters address, among other information.
iv. "In the use of the information in the CAMERDATA file covered by this contract to enrich the records of the INFOTEL Data Warehouse, so that the data subject provided may exercise the rights that are available to them by virtue of the provisions of Organic Law 15/1999, as the exception in art. 2.3 of Royal Decree 1720/2007, INFOTEL will proceed to inform its clients that in any advertising or commercial prospecting actions they carry out following consultation with this Data Warehouse, they must always include the following mandatory information: "In accordance with Article 2.3 of Royal Decree 1720/2007, of the Regulation implementing Law 15/1999, of December 13, on the Protection of Personal Data, the contact data of individual entrepreneurs used are outside the scope of said Law. However, if circumstances arise in the future that would make your data subject to the LOPD (Data Protection Act), you may exercise your rights of Access, Rectification, Cancellation, and Objection by contacting Infotel Información y Comunicaciones, attaching an official document proving your identity to buzoncliente@axesor.es or by fax. 902101062.
INFOTEL must inform its customers that they must use this information solely and exclusively to promote products or services directly related to the sector of activity to which the activities provided belong, and that they may not use it for any purpose other than those indicated above, nor may they communicate it to third parties, even for its storage.
b. The contract dated July 25, 2012 states that CAMERDATA will provide AXESOR with the data of legal entities and physical companies, including, among others:
i. "CIF" with the description "legal/physical sequential CIF"

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 23/164

ii. "company name"
iii. "street", "number", "other" with the description of "other address (staircase, floor, door, etc.)"
iv. For legal entities only: "postal code", "municipality", "province", "region", "telephone", "fax".

c. The contract dated 05/24/2018 contains the title "ADDENDUM TO THE DATA SUPPLY CONTRACT, SIGNED ON SEPTEMBER 15, 2009, BETWEEN CAMERDATA S.A. AND INFOTEL INFORMACIÓN Y TELECOMUNICACIONES S.A.
(CURRENTLY AXESOR CONOCER PARA DECIDIR S.A.)" and states that:
i. CAMERDATA (or THE OWNER) and AXESOR adapt the previous contract, signed
on 09/15/2009, to the GDPR.

ii. CAMERDATA is the transferor of the data and the controller thereof,
and AXESOR is the assignee.
iii. That CAMERDATA guarantees that it has a sufficient legal basis for the transfer that is the subject of the contract, as well as the legality of the creation of the file.
iv. That "For these purposes, CAMERDATA declares that the data contained in its

Companies and Entrepreneurs directory and provided under the aforementioned Contract (hereinafter the FILE) contains personal data of individuals
identified as individual entrepreneurs (hereinafter, the INTERESTED PARTIES or RECIPIENTS), considering that the processing carried out on them is solely related to this capacity, that is, strictly related to their commercial activity, never to their private sphere."

v. "AXESOR will directly and on its own behalf manage and respond to the rights
conferred by the GDPR that it receives directly on its behalf from the INTERESTED PARTIES,
in the manner and within the timeframes indicated in the regulations."
vi. “CAMERDATA will directly and on its own behalf manage and respond to the rights conferred by the GDPR that it receives directly on its behalf from the DATA SUBJECTS, in the manner and within the timeframes indicated in the regulations.”

vii. AXESOR's obligations state: “1. Use the personal data being processed, or the data it collects for inclusion, only for the provision of the services indicated in the Main Contract.”
AXESOR's role in relation to processing is not explicitly stated.
viii. The data protection obligations common to both parties state:

"FOURTH. DATA PROTECTION OBLIGATIONS COMMON TO THE PARTIES.
1. ASEDIE Code of Conduct: While both parties are members of the
Multisectoral Information Association (ASEDIE), they are subject to compliance
with the Code of Conduct on Data Protection approved by the
Association, and must extend the obligations imposed therein to the services

that CAMERDATA provides to AXESOR in the Original Contract, and AXESOR, for its part, to the services it provides to its clients, using the records in the FILE for this purpose,
in accordance with the provisions of Annex I of said Code of Conduct.
[…]
2. Management of the rights of the INTERESTED PARTIES:

The parties must communicate immediately and, in any case, at the latest,
every Friday and, failing that, on the last business day of the week, all
requests Effectively addressed the deletion, rectification, and objection of data of
those Self-Employed Persons who have proven the cessation of their business activity and therefore cease to be considered Individual Entrepreneurs, or who

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 24/164

find themselves in a special situation that means that the processing of their data by each party implies a potential violation of their fundamental rights.

Communications of the deletion of each party's data must be sent in a list that groups all the deletions carried out per week, by sending an email, including encrypted references or with any other equivalent security measure, to the following email addresses:
Send to Axesor: bcgestionrobinson@axesor.es
Send to Camerdata: informatica@camerdata.es

3rd. Notifications of Security Breaches:
Each party shall notify the other, using the information in the "Data Protection Notifications" section of this addendum, as soon as possible of any destruction, loss, alteration, disclosure, or access to Personal Data of which it becomes aware and which affects the processing of the other party ("Security Breach"), always within 24 hours of becoming aware of it.
The party that has suffered the security breach must collaborate with the other party to mitigate any effects that may affect the data it processes.
It shall be the responsibility of the party that suffers the security breach to notify the INTERESTED PARTIES and the supervisory authority, where necessary,

as indicated in the GDPR, as well as to respond to any damages suffered by the other party.
4. Security measures applicable to the data provided:
THE OWNER and AXESOR shall adopt appropriate measures. necessary technical and organizational measures that will guarantee the security, confidentiality, and integrity of personal data and prevent its alteration, loss, processing, or unauthorized access in accordance with the provisions of the GDPR, taking into account the state of technology, the nature of the data, and the risks to which they are exposed."

Provides a copy of the contract dated July 29, 2008, signed by CAMERDATA and

IBERINFORM INTERNACIONAL S.A. (hereinafter IBERINFORM or THE CLIENT)
which states that:
"l.- CAMERDATA is a company created by the Chambers of Commerce to
create files of the business activities carried out within its scope of operation (known as the Spanish Business File), as well as to offer the
public information service on the information contained in said file, in

accordance with the provisions of Basic Law 3/1993 of March 22, on Official Chambers of Commerce, Industry, and Navigation.
lI.- That THE CLIENT is interested in accessing said public information,
obtaining a list of business activities.
[…]

FIRST: PURPOSE.
The purpose of this contract is to regulate the conditions of supply to the CLIENT,
by CAMERDATA, of the information contained in the CAMERDATA Spanish Company File (hereinafter, the File), in accordance with the details of the services specified in the ANNEX to this contract, which is

incorporated herein for all purposes.
Second: Conditions of supply and use

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 25/164

CAMERDATA will provide the CLIENT with a list of company information,
according to the characteristics (search profile, information fields, format, and
technical support) specified in the ANNEX (point 1).
[…]
Fourth: Data Protection

Within the framework of this contract, both parties agree to comply with current legislation regarding the protection of personal data.
In particular, CAMERDATA, as the owner of the ETF, is responsible for it before any administrative or judicial body. However, all information contained in the ETF relates solely to commercial companies and individual entrepreneurs, and is outside the scope of data protection legislation, in accordance with Article 2 of the Implementing Regulations of Law 15/1999, of December 13.
The CLIENT will use the information provided to enrich its own files.
If the CLIENT carries out commercial prospecting campaigns with the information provided, they must inform CAMERDATA in advance and, in all cases, include the following mandatory information: "The list of commercial addresses used for this advertising campaign has been prepared by Camerdata, S.A. (Av. Diagonal, 452, 3rd floor, 08006 Barcelona, telephone 902 21 42 21, dptocalidad@camerdata.es), an entity owned by the Chambers of Commerce and responsible for the Spanish Business File.

You can inquire about the origin of the data from this entity.
In accordance with Article 2 of the Regulation implementing Law 15/1999, of December 13, on the Protection of Personal Data, these data are excluded from the scope of application of the LOPD. However, in accordance with the General Telecommunications Law, in its Article 38.3-h), you may cancel your electronic data when the requirements established in the aforementioned article are met.

Furthermore, in this case, when the information provided relates to individual entrepreneurs, the CLIENT must include their business activity codes, included in the list provided, on the shipping labels or media, in order to identify that we are addressing them in their commercial capacity (Example: Business Act: 1, 7). The CLIENT agrees to use said information to incorporate it into the reports it prepares for its clients, as well as to partially transmit it in the course of its commercial activities.
The CLIENT will not use said information for purposes other than those indicated above. […]”
And the ANNEX to the contract contains the following information: “Company name,”
“Full address,” “Available telephone and fax numbers,” “Tax ID Number,” among others.

Provides a copy of the contract dated April 25, 2017, May 24, 2018 (ADDENDUM TO THE INTERMEDIATION CONTRACT SIGNED ON APRIL 25, 2017, BETWEEN
CAMERDATA S.A. AND DATACENTRIC, PDM, S.A.), July 19, 2019, and signed between
CAMERDATA and DATACENTRIC PDM S.A. (hereinafter DATACENTRIC), which states

that:
a. The contract of April 25, 2017 states:
i. “FIRST. PURPOSE
The purpose of this contract is to regulate the terms of collaboration between CAMERDATA and DATACENTRIC regarding the provision of the following services:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 26/164

- The transfer of the Self-Employed Persons database by CAMERDATA to DATACENTRIC so that DATACENTRIC can use it in its business activities.
- The transfer of data or information fields by DATACENTRIC to CAMERDATA for computer processing.

The content of the services and products subject to transfer is regulated in the following
Stipulation.
SECOND. DATA SUPPLY CONDITIONS
CAMERDATA will transfer the Self-Employed Persons (individual entrepreneurs) database to DATACENTRIC in the Premium category. This modality includes the right: for internal use by DATACENTRIC to distribute and market the data to

third-party companies (with the exception of infomediary companies, such as Informa, Experian, Arvato, Equifax, Iberinform, Axesor, Ardan, etc.), with the
purpose that the recipients use it exclusively for internal use, never for subsequent distribution or sale.
ii. The information will contain, among other data, name or company name, NIF (Tax Identification Number),

full address, and telephone number.
iii. That the records comprising the files delivered to DATACENTRIC are those of individual entrepreneurs and are excluded from the applicable data protection regulations in accordance with Article 2 of Royal Decree 1720/2007.
b. The contract of May 24, 2018 states:
i. The purpose is to adapt the referenced contract to the GDPR. The referenced contract

remains in force as long as it is not modified.
ii. "For these purposes, CAMERDATA declares that the data it provides under the aforementioned Contract (hereinafter the FILE) contains personal data of individuals (hereinafter, the INTERESTED PARTIES or RECIPIENTS), considering that this is personal data related to the user's commercial activity, not to their private sphere, and that this processing is lawful in the terms of art. 6.1. f)

of the GDPR, in such a way that it allows us to send them advertising from the sectors included in
DATACENTRIC's privacy policy […]"
iii. DATACENTRIC is the data controller and processor, and CAMERDATA is the data controller.
iv. "[…] CAMERDATA, as the owner of the FILE and data controller, authorizes DATACENTRIC to market the file to CLIENTS who

contract the campaigns regulated in the corresponding contract with data processors who are not hosted in the EEA, provided that the clients, in their capacity as DATA EXPORTER, have the proper authorization from the Director of the Spanish Data Protection Agency to carry out the aforementioned international transfer […]"

And annexed to the contract is a "CONTRACT FOR THE PROVISION OF DATA PROCESSING SERVICES" which states that:
i. CAMERDATA is the data controller and DATACENTRIC is the data processor.
ii. DATACENTRIC will provide the processing services necessary for the

execution of advertising campaigns.
c. The contract of July 19, 2019, states that, in relation to the contract of April 25, 2017, CAMERDATA authorizes DATACENTRIC to distribute and market the database of self-employed workers owned by the former, to the infomediary company EQUIFAX IBÉRICA, S.L., and to the companies belonging to its group. The distribution of the file will be

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 27/164

carried out for the purpose of "marketing services" limited to the business sphere and
never private, to enrich the NIF (Tax Identification Number), and to identify whether the person is self-employed
for the purpose of locating them.

Provide a copy of the contract dated 23/08/2021 and signed between CAMERDATA and

CERVED GROUP S.p.A. (an entity located in Italy, hereinafter CERVED)
which states, in its unofficial English translation, that:
a. That CERVED is a company engaged in the exercise of commercial information activities.
b. CAMERDATA will transfer the database of companies and self-employed workers to CERVED for its business activity for internal use and that of its subsidiaries.

That CERVED will also use the information for distribution and marketing to third-party companies, except for the specified infomediary companies.
c. The information will contain, among other data, the name or company name, tax identification number,
full address, telephone number, and geographic coordinates.
d. That the records comprising the files delivered to CERVED include

information on self-employed workers and personal data related to their commercial activity, not related to their private sphere, and that this processing is lawful under the Art. 6.1.f. GDPR.

Provides general clauses used in the signing of contracts with between 500 and 900 clients per year to whom data is transferred for their exclusive use. These clauses state (underlined):

"GENERAL CONTRACTING CONDITIONS
First: Purpose
The purpose of these General Contracting Conditions is to regulate the conditions
of acquisition by the CLIENT and supply by CAMERDATA,
relating to the information on companies contained in CAMERDATA's Spanish Company File.

Second: Supply and Use of the File
CAMERDATA will provide the CLIENT with a file containing company information,
according to the characteristics (search profile, information fields, format, and
technical support) specified in the quote accepted by the CLIENT.
The CLIENT must use the information as provided, without manipulating the content of the information fields in the provided list.

The information provided by CAMERDATA may be used by the CLIENT for twelve months from the date of delivery.
The information provided to the CLIENT is the property of CAMERDATA; therefore, without the latter's consent, it may not be provided in whole or in part to a third party. The CLIENT will take the necessary measures to store, manipulate, and, where appropriate, destroy it, thereby eliminating the possibility of improper use by third parties.

The CLIENT is expressly prohibited from selling or transferring any or all of the information provided to third parties.
The CLIENT's failure to comply with the obligations contained in this clause may give rise to CAMERDATA taking the corresponding legal action and, in any case, to compensation for damages caused by the CLIENT. The damages, which both parties mutually agree upon, are set at a minimum amount consisting of five times the price of the information provided. CAMERDATA uses the advertising exclusion service provided by the Spanish Association of the Digital Economy (Adigital), also known as the list service.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 28/164

Robinson. Therefore, the information covered by this contract relating to individual entrepreneurs (if any) may be used in the field of personalized advertising within the time limits established by the regulations. Once this period has elapsed, the CLIENT must exclude from the information provided any new Robinson data that may have appeared before using it for personalized advertising.

Third: Information Sources
CAMERDATA certifies that this file only contains data from commercial companies and individual entrepreneurs engaged in commercial activities.
CAMERDATA guarantees the legality of the sources used to compile the file.

Furthermore, they are protected by Royal Legislative Decree 1/1996, of April 12, as amended by Law 5/1998, of March 6, incorporating into Spanish law European Community Directive 96/9 of March 11, 1996, on the legal protection of databases.
[…]

Sixth: Data Protection
The data covered by this contract may contain personal data that may constitute a personal data file. These data, in accordance with data protection regulations, have been collected and are distributed for the sole purpose of facilitating contact with the identified companies in relation to their business activities, in accordance with the restrictions established by the European Regulation (EU) 2016/679, General Data Protection Regulation. If the CLIENT stores the data contained in this file for future use, it will become the data controller under the terms of the European Regulation (EU) 2016/679, General Data Protection Regulation (hereinafter GDPR), assuming all the obligations that this regulation imposes on those responsible for the processing of personal data.

To comply with the principle of transparency and the obligations described in Articles 14.1 and 14.2 of the GDPR, the CLIENT must communicate individually to data subjects when the data has not been obtained directly from the data subject.
Since the data comes from publicly accessible sources, and if any of the legally established reasons exist, if the CLIENT does not communicate

individually to the data subjects, it will adopt the following appropriate measures to protect the rights, freedoms, and legitimate interests of the data subjects:
The CLIENT must provide the information indicated in sections 1 and 2 of Article 14 of the GDPR in clear and simple language, in a concise, transparent, intelligible, and easily accessible manner, no later than the time of the first communication
made to the data subjects. This communication may consist of the inclusion of the

following text, clearly incorporating it into the advertising communications
sent to the data subjects, or by means of a voiceover if the communication
is made by telephone.
"The contact information used to send this communication has been obtained by (the CLIENT) after being collected from (CAMERDATA).

The purpose of processing this data is to send commercial and marketing communications, offering you various goods or services that may be of interest to you.
If you wish to exercise your rights of access, rectification, erasure, restriction of processing, or object to processing, as well as the right to data portability of your

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 29/164

contact information, you can send your request to the following address: ________, or
by sending an email to __________, always attaching a copy of a document that proves your identity (DNI, passport, or similar)."
To learn all the information related to your data, please visit
our website: (Link to the CLIENT's website, where the rights related to the GDPR will be explained in detail)"
If the CLIENT is required to hire a Data Protection Officer,
they must add:
"You can also contact the Data Controller's Data Protection Officer at
the following address: ________, or by sending an email to __________."
In any case, this information must be retained in all other communications

made after the first.
The CLIENT agrees not to conduct telemarketing campaigns without a human operator,
with the information provided when it relates to telephone data.
[…]"

Provide a copy of the contract dated 06/29/2020 and signed between CAMERDATA and
KOMPASS S.A. (hereinafter KOMPASS), which states that:
“[…]
l. That KOMPASS Spain is a company founded in the early 1960s and is part of Kompass International, a French company with more than 65 years of experience as a B2B business information provider.

ll. That CAMERDATA is a company created by the Chambers of Commerce for the purpose of creating a database, called the Spanish Business File (hereinafter FEE), of which it is the owner, containing the data of all individuals and legal entities that carry out business activities, as well as to offer business information and advisory services to its members in relation to said database. All of this in accordance with the provisions of Basic Law 4/2014 of April 1, on Official Chambers of Commerce, Industry, and Navigation.
[…]
AGREEMENTS
First: Purpose
The purpose of this contract is regulate the terms of collaboration between

CAMERDATA and KOMPASS regarding the provision of the following services:
- The transfer of 107,897 CIFs from records contained in the Spanish Companies File (hereinafter FEE) database, for which CAMERDATA does not have the generic email field reported and partially the URL field reported, by CAMERDATA to KOMPASS for the purpose of KOMPASS performing "webcrawling" work.

- The transfer of the URL field of the 107,897 CIFs if KOMPASS has it reported (55,576 records counted) and the records from which the generic email address was obtained as a result of "webcrawling" work by KOMPASS, to CAMERDATA, so that it can use it in its business activities.
The content of the services and products subject to transfer is regulated in the following

sections.
Second: Data Supply Conditions
CAMERDATA will provide KOMPASS with the 107,897 CIFs resulting from a preliminary study, for use in the aforementioned webcrawling work.
KOMPASS will provide CAMERDATA with the URL field of the 55,576 records analyzed.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 30/164

KOMPASS will provide CAMERDATA with the generic email field of the records
resulting from the webcrawling work for which the generic email field has been obtained (as many as have been obtained per record), relating them to their corresponding CIFs.
Third: Webcrawling

KOMPASS will conduct webcrawling work on the database using its own resources. Provided by CAMERDATA, these consist of the application of Internet search and pattern recognition algorithms to attempt to obtain the generic email addresses associated with the URLs provided, using the URLs provided.
[…]
Fifth: Data Protection

KOMPASS and CAMERDATA undertake to comply with Spanish legislation on data protection and personal privacy. If this legislation cannot be complied with, you must refrain from receiving information or other services related to it, in accordance with the provisions of national legislation on the matter.

KOMPASS guarantees that the generic email addresses obtained do not contain personal data and may therefore be used as such.

Please provide a copy of the contract dated March 20, 2023, signed by CAMERDATA and KOMPASS, which states:
“[…]

AGREEMENTS
First: Purpose
The purpose of this contract is to regulate the terms of collaboration between CAMERDATA and KOMPASS regarding the provision of the following services:
- The transfer of records contained in the Spanish Companies File (hereinafter FEE) database that do not contain the generic email field provided,

by CAMERDATA to KOMPASS for the purpose of allowing KOMPASS to perform web crawling and subsequently use the database in its business activities.
- The transfer of records in the KOMPASS database containing the provided generic email field and the records from which the generic email address was obtained as a result of web crawling, along with their URLs, by KOMPASS to CAMERDATA, so that it can use them in its business activities.
The content of the services and products subject to transfer is regulated in the following sections.
Second: Data Supply Conditions
CAMERDATA will provide KOMPASS with the NIFs of the records contained in the FEE database

for which Kompass has the URL field provided and for which CAMERDATA does not have the generic email field (145,101 records): KOMPASS will provide CAMERDATA with the records resulting from the webcrawling work for which the generic email field has been obtained, the following fields:
NIF

URL used for the webcrawling (mainly the entire universe of 145,101 records)
Generic email obtained (as many as obtained per record)
Third: Webcrawling
KOMPASS will, using its own resources, perform webcrawling work on the database provided by CAMERDATA, consisting of the application of algorithms

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 31/164

Internet search and pattern recognition, to attempt to obtain generic email addresses associated with said URLs from the available URLs.
[…]”

Provides a copy of the contract dated 02/03/2020 and signed between CAMERDATA and

DMOVO ANALYTICS, S.L. (hereinafter DMOVO), which states:
“[…]
THEY STATE
l.- That Dmovo is an independent company dedicated to providing professional strategic, organizational, business, operational, and technological consulting services in the fields of Information Technology (ICT) and Marketing.

ll.- That THE CLIENT is interested in contracting Dmovo to provide technological development, information processing, and consulting services.
[…]
CLAUSES
FIRST.- PURPOSE OF THIS CONTRACT

This The purpose of this Agreement is to establish a collaborative framework for the provision of technological development, information processing, and consulting services by Dmovo.
The services consist of a periodic process of processing and adapting the name and address data from the company and self-employed registries for which THE CLIENT is the data controller.

The specifications and technical requirements of the services to be provided are detailed in ANNEX I (SmartAddress Offer) to this Agreement. These will consist of the specific services to be provided by Dmovo and accepted in all their terms by THE CLIENT, and which will be incorporated into this document as an integral part thereof for all purposes.
[…]

FIFTH.- SERVICES INCLUDED
The specific services regulated by this agreement are the following:
Batch normalization process for Camerdata
Dmovo will perform the data normalization processes four times a year with an estimated volume of 10 million records.
In addition, an annual process will be carried out for records belonging to the Basque Country

and Navarre. In this case, an approximate volume of 500,000 records is estimated.
Processes to be carried out.
Population Normalization (INE)
Route Normalization (INE)
Postal Code Assignment.
Census Section Assignment (INE)

Coordinate Assignment.
Grid Assignment (GRID 100>(100)).
Name Normalization.
Delivery of the file in the format defined by THE CLIENT.
SIXTH. - CONFIDENTIALITY

Dmovo undertakes to accept Confidential Information within a framework of trust for the proper execution of the agreed services and not to provide it to any third party or use it for its own benefit without obtaining the prior written consent of the other party.
[…]”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 32/164

--The Inspection Report states:

<<On 16/11/2023, it was verified that:

1. The URL https://sede.agenciatributaria.gob.es/Sede/todas-
gestiones/procedimientos-notributarios/tratamiento-datos-personales/tratamiento-
datos-personales/informacioninteresado-sobre-proteccion-datos/5-registro-actividades-
tratamiento/5_1-censo.html contains no content.

2. The URL

https://sede.agenciatributaria.gob.es/Sede/procedimientoini/ZA02.shtml and Information on the "Economic Activities Tax File Registration Design for Chambers of Commerce for the Annual File Submission for the 2008 and Subsequent Fiscal Year" can be found at
https://sede.agenciatributaria.gob.es/static_files/Sede/Procedimiento_ayuda/ZA02/drIA
E_CamCom08.pdf. This table describes the exchanged data, including, among others, the following data:
"NIF", "Surname and First Name or Company Name", "Current Tax Address", "Tax Address"
(which also includes "Telephone Number").

3. The Official State Gazette (BOE) of December 20, 2019, which can be accessed through the
link https://www.boe.es/boe/dias/2019/12/20/pdfs/BOE-A-2019-18316.pdf, It states

(underlined):
“AGREEMENT BETWEEN THE STATE TAX ADMINISTRATION AGENCY AND
THE OFFICIAL CHAMBER OF COMMERCE, INDUSTRY, SERVICES AND NAVIGATION
OF SPAIN FOR THE TRANSFER OF TAX INFORMATION TO THE OFFICIAL CHAMBERS FOR THE EXERCISE OF THEIR PUBLIC-ADMINISTRATIVE FUNCTIONS

[…]
First. Purpose of the Agreement.
1. The purpose of this Agreement is to establish a general framework for collaboration
on the conditions and procedures that must govern the transfer of information from the State Tax Administration Agency (hereinafter, the Tax Agency) to the Official Chambers of Commerce, Industry, Services and Navigation (hereinafter, the Chambers) and to the Official Chamber of Commerce, Industry, Services and Navigation of Spain (hereinafter, the Chamber of Commerce of Spain), preserving
in all cases the rights of the persons to whom it refers.
2. […]
Second. Purpose of the transfer of information.
The transfer of information from the Tax Agency will be for the exclusive purpose

of collaborating with the Spanish Chamber of Commerce and the Chambers
in the performance of the public functions assigned to them when, for the
exertion of these functions, the regulatory regulations require the provision of a
certification issued by the Tax Agency or the submission, in original, copy, or
certification, of the tax returns of the interested parties or any other
communication issued by the Tax Agency, particularly in the case of those not
required to file a tax return. In these cases, the information that must be included in such
documents will be requested directly from the Tax Agency, provided that it is
necessary for the performance of such functions and relates to a large number of interested parties or affected parties.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 33/164

Annex III of this Agreement sets out the public functions to be performed by the Chambers.
The transfer of data from the Tax on Economic Activities and the company census data will be for the exclusive purpose of preparing the public company census, fulfilling the public-administrative functions assigned to the Chambers by Law 4/2014

Basic Law of the Official Chambers of Commerce, Industry, Services and Navigation
assigns, as well as preparing the electoral census referred to in Article 17 of the same Law.
Third. Authorization of those interested in the information provided.
The transfer of tax information must have the prior express authorization of the interested parties, as established in Article 95.1.k) of the General Tax Law (LGT), under the terms and with the guarantees established in Article 2.4 of the Order of the Ministry of Economy and Treasury of November 18, 1999.
However, the transfer of data from the Tax on Economic Activities and company census data imposed by Article 8 of the aforementioned Law 4/2014 will not require the prior authorization of the interested parties.

Fourth. Recipients of the information provided.
The information provided by the Tax Agency may only be addressed to the bodies of the Spanish Chamber of Commerce and the Chambers assigned the public functions that justify the transfer, including the competent audit bodies to the extent that, pursuant to their own regulations, they participate in the procedures referred to in the second clause of this Agreement.

Under no circumstances may the recipients be bodies, agencies, or entities that perform functions other than those described in the second clause of this Agreement.
All of this is without prejudice to the strict allocation of the information sent by the Tax Agency to the purposes for which it is intended. Justified and for which it is requested. In any case, the recipient may not transfer the information sent by the Tax Agency to third parties.

[…]
Seventh. Transfer of information.
1. To fulfill the purposes described in the second clause, the information provided in Annex I to this Agreement is established.
[…]

Eighth. Control and security of the data provided.
[…]
2. The following controls are established over the custody and use of the information provided under this Agreement:
a) Internal control by the entity receiving the information.
The Chambers shall carry out controls over the custody and use of the data received

by the authorities, officials, or other personnel reporting to them, reporting to the Joint Coordination and Monitoring Committee provided for in
Clause Thirteen of this Agreement on the results of said monitoring.
They shall have an information security policy, risk analysis and management, and an explicit assignment of security responsibilities appropriate to their mission, objectives, and size, and shall apply these security mechanisms to the information provided by the Tax Agency. They will prevent unauthorized personnel from accessing the information provided, establishing traceability of access to the information provided and conducting audits of data access using random and risk criteria.
They will adopt specific measures to avoid the risk that the information may be used, even inadvertently, for other purposes or by personnel with a conflict of interest. They will also adopt measures to ensure compliance with the conditions underlying each transfer.
[…]
Ninth. Processing of personal data.
If the information includes personal data of the interested parties, both the transferor, the Tax Agency, the transferee, the Chamber of Commerce of Spain, and the Chambers will process the data in accordance with Regulation (EU) 2016/679

of the European Parliament and of the Council of April 27, 2016, and Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights.
The data processed in this Agreement is categorized as tax information.
In the case of the data transferor, the Tax Agency, the Data Controller for the purposes of the General Data Protection Regulation is the owner of the
General Directorate.
In the case of the data transferees, the Spanish Chamber of Commerce and the Chambers of Commerce, the Data Controller for the purposes of the General Data Protection Regulation will be the person designated by each Chamber.
Tenth. Obligation of confidentiality.

1. All authorities, officials, and other personnel who have knowledge of the data or information provided under this Agreement shall be bound to the strictest and complete confidentiality regarding them. Violation of this obligation will entail incurring the appropriate criminal, administrative, and civil liabilities, as well as subjection to the exercise of the powers that correspond to the Data Protection Agency.

[…]
ANNEX I TO THE AGREEMENT BETWEEN THE STATE TAX ADMINISTRATION AGENCY AND THE OFFICIAL CHAMBER OF COMMERCE, INDUSTRY, SERVICES AND NAVIGATION OF SPAIN FOR THE TRANSFER OF TAX INFORMATION TO THE OFFICIAL CHAMBERS FOR THE EXERCISE OF THEIR PUBLIC-ADMINISTRATIVE FUNCTIONS

[…]

ANNEX III
The basis for the conclusion and execution of this Agreement is the status of public administration, both of the Official Chamber of Commerce, Industry, Services and Navigation of Spain and of the Official Chambers themselves, with the provision of information to be provided by the State Tax Administration Agency, in all cases, being used for the exercise of public functions.
The public functions to be performed by the Official Chamber of Commerce, Industry, Services, and Navigation are listed directly and indirectly in letters d) to i) of Article 21.1 of Law 4/2014, of April 1, Basic Law of the Official Chambers of Commerce, Industry, Services, and Navigation:
[…]”

4. That the URL
https://sede.agenciatributaria.gob.es/static_files/Sede/Procedimiento_ayuda/ZA02/pInt

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 35/164

ercambioIAE2006.pdf contains the “PROTOCOL FOR THE EXCHANGE OF INFORMATION OF THE I. A. E. BETWEEN THE STATE TAX ADMINISTRATION AGENCY AND LOCAL ENTITIES / CHAMBERS OF COMMERCE" which states:
"[…]
Furthermore, information from the Economic Activities Tax census,

as well as any additions, deletions, or variations therein, is necessary for the Chambers of Commerce in managing the levies included in the Permanent Chamber Resource, which is why, starting in 2006, the same electronic procedure will be used to provide this information to the Chambers of Commerce.
[…]

5. REQUEST FOR I.A.E. FILES
Although the Tax Agency is obliged to provide I.A.E. information, To
all local entities with management and/or collection powers over this tax and to the Chambers of Commerce for the management and collection of the levies included in the Chamber Appeal, this procedure is based on a

prior request for the desired information. Although it may seem like an
obstacle, it provides several important advantages, such as:
• Local entities and Chambers of Commerce can request the type of information they
require, at any time, and as many times as they deem appropriate. Such requests are automatically recorded in the AEAT Data Entry Registry, which allows for subsequent monitoring of the request.

[…]
ANNEX II. Authorization template for the electronic exchange of information on the
IAE.
[…]
The requested information will be used exclusively for the purposes conferred by the regulations of the tax on economic activities to this

municipality/agency, and may not be used to the detriment of the interested party or affected party, nor may it be transferred to third parties, except in cases expressly provided for by law."
[…]">>

--The Investigation Report states that:
<<As of November 21, 2023, it was verified that:

1. That Royal Decree 1065/2007, of July 27, approving the
General Regulations on Tax Management and Inspection Actions and Procedures and the Development of Common Rules for Tax Application Procedures, in its Article 5, states that "In the Census of Business Owners, Professionals, and Withholders, in addition to the data mentioned in Article 4 of this regulation,
the following information will be included for each person or entity" and in Article 4 include

the following data:
"Article 4. Contents of the Census of Taxpayers.
1. The data to be included in the Census of Taxpayers will be the following for natural persons:
a) Name and surname, sex, date of birth, place of birth, marital status, and

date of marital status.
b) Spanish tax identification number.
c) Tax identification number of other countries, if applicable, for residents.
d) Tax identification code of the State of residence, if applicable, for non-residents.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 36/164

e) Passport number, if applicable.
f) Resident or non-resident status in Spanish territory.
g) Tax address in Spain and the property's cadastral reference number, unless not required to do so in accordance with the regulations. that applies.
h) If applicable, address abroad.
i) Full name and tax identification number of the legal representatives for persons who lack the capacity to act in tax matters.
[…]”>>

--The Investigation Report states:
<<As a result of the request for information made by the inspection,
on 11/21/2023, the Chamber of Commerce sent the following information and
statements to this agency […]

1. “The database of the public census of companies of the Chamber of Spain is comprised, in accordance with Article 8 of Law 4/2014, of April 1, Basic Law of the Official Chambers of Commerce, Industry, Services and Navigation (hereinafter, Law 4/2014),
of legal and natural persons, national or foreign, that carry out commercial, industrial, service, and shipping activities in the territory National.

Only those economic activities of companies, individuals, and legal entities whose activity falls under one of the headings of Divisions numbers 1 to 9, inclusive, of Section One of Annex I of Royal Legislative Decree 1174/1990, of September 28, approving the rates and instructions for the Tax on Economic Activities, and which have not been deregistered, are included.

The data comprising the public business census of the Spanish Chamber of Commerce are sourced from the Economic Activities Tax and the necessary company census data provided by the State Agency of the Tax Administration, pursuant to the Agreement of November 25, 2019, signed between the Tax Administration and the Spanish Chamber of Commerce for the transfer of tax information to the Official Spanish Chambers of Commerce, Industry, Services, and Navigation for compliance with its purposes and the exercise of its public-administrative functions, which has been extended by an addendum dated
December 19, 2023. Likewise, they also originate from the data on the
Economic Activities Tax provided by the Provincial Council of Navarre and

those provided by the Chambers of Commerce of the Basque Country. […]”

2. That the total number of self-employed or individual entrepreneurs or natural persons currently listed in the public business census is 1,459,498.

3. The data contained in the CHAMBER'S public business census are:
NIF/CIF (Tax Identification Number)
Name, first surname, second surname.
Mailing address of the business.
Postal code of the business.

Province of the business.
Municipality of the business.
Description of the business.
Provide an extract from the database containing this data, among other information.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 37/164

4. “[…] The fields listed above are provided solely to CAMERDATA, S.A., as a commercial entity established by multiple Spanish Chambers of Commerce and the Chamber of Spain, for inclusion in its Spanish Business File, for the purpose of processing, completing, and enriching them in a legitimate manner and to have a quality database of companies operating in Spanish territory so that it can be offered to interested companies and third parties.
[…]”

5. Regarding the obligation to provide information under Article 14 of the GDPR, it is not an obligation, pursuant to Article 14.5 c). The collection of data is expressly established by Law 4/2014 and the public-administrative functions that it assigns to the CHAMBER.

It states that Article 3 of Law 4/2014 establishes:
"The Official Chambers of Commerce, Industry, Services, and Navigation have the
purpose of representing, promoting, and defending the general interests of

commerce, industry, services, and navigation, as well as providing services to companies that carry out the aforementioned activities.
Likewise, they shall exercise the public powers attributed to them by this Law and
those that may be assigned to them by Public Administrations in accordance with the
instruments established by the legal system. […]"
That Article 5.1 Law 4/2014 establishes the public-administrative functions of the

CHAMBER:
“g) Manage, in accordance with Article 8 of this Law, a public census of all companies, as well as their establishments, branches, and agencies located within its district.
j) Promote actions aimed at increasing the competitiveness of small and medium-sized enterprises, and foster innovation and technology transfer to companies. (...)"
And that Article 8 of Law 4/2014 establishes in relation to the aforementioned census:
"The Official Chambers of Commerce, Industry, Services, and Navigation shall prepare a public census of companies, which shall include natural or legal persons, national or foreign, that carry out commercial, industrial, service, and shipping activities in national territory (...)."

That Article 21.1 Law 4/2014 establishes the following functions:
"[…]
a) Promote the general interests of commerce, industry, services, and navigation at the state level.
b) Represent all the Chambers of Commerce before various state and international bodies.

c) Coordinate and promote actions affecting all Spanish Chambers of Commerce.
d) Exercise, at the state level and in coordination with the Chambers of Commerce, Industry, Services, and Navigation, the functions referred to in section 1 of Article 5 of this Law. […]"

6. That "the collection of data comprising the public business census (listed in the previous point) and its processing for the preparation of a public census of all companies, whether natural or legal persons, constitutes the performance of a public-administrative function of the Chambers of Commerce.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 38/164

Spanish companies and which the Spanish Chamber exercises, at the state level and in coordination
with the Chambers of Commerce, to fulfill the chamber's purposes,
thus promoting the general interests of commerce, industry, services, and navigation, and promoting, in particular, actions aimed at increasing the competitiveness of small and medium-sized enterprises (largely self-employed)."

7. That the legitimacy for the processing implied by the public business census is the legal obligation, according to Article 5.1.g and 8 of Law 4/2014. That it is also the public interest.
And it states:
“[…]

Without prejudice to the exercise of its public-administrative function of preparing a public business census, through its management the Spanish Chamber also fulfills an objective or mission of public or general interest that (i), on the one hand, is inherent to its functions under Article 21.1.d) of Law 4/2014, in relation to the chamber purposes of Article 3 of the same Law, such as the promotion of the general interests of commerce, industry, services, and navigation, and of business and economic development, and the primary function of providing services to all companies that carry out these activities, including business information services, thus strengthening its role in supporting small and medium-sized enterprises in the area of increasing their competitiveness (paragraph 12, section l, of the Preamble to Law 4/2014), and that (ii), on the other hand, is implicit in the

public-administrative function consisting of promoting actions aimed at increasing the competitiveness of small and medium-sized enterprises (Article 5.1.j) of Law 4/2014).
In this sense, the Preamble to Law 4/2014 (paragraph 6, section l) highlights the public interest objective or mission of the purposes, functions, and activities of the Chambers of Commerce:

"Aware of their importance and necessity as basic institutions for the economic and business development of our country, their nature as public law corporations is maintained, guaranteeing the exercise of public-administrative functions that, in the current economic context, are especially relevant for the regeneration of the economic fabric and job creation, and enshrining their purpose of representing, promoting, and defending the general interests of commerce, industry, services, and navigation, as well as the provision of services to all businesses."
Law 4/2014 assigns to the Spanish Chamber the exercise and fulfillment of functions of public or general interest (i.e., functions of a public-administrative nature), among which is the preparation and management of a public census of companies, necessary for the fulfillment of its purposes and the exercise of the chamber's other public-administrative functions.
Thus, Law 4/2014 determines the purpose of the processing and its necessity for the fulfillment of a mission carried out in the public interest.
Thus, both the necessity of the data processing carried out, as well as the purposes of public interest, are imposed by a regulation with the rank of law.

8. Regarding the purpose of the processing, it states:
"The purpose of the processing carried out by the Spanish Chamber of Commerce is to promote
the general interests of commerce, industry, services, and navigation, as well as business and economic development, and its main function is to provide

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 39/164

services to all companies that carry out these activities, including business information services, thus strengthening its role in supporting small and medium-sized enterprises and promoting actions aimed at increasing their competitiveness.
Through the management of the public business register, a business information system or service is offered to the general public and to

businesses in particular, with the aim of providing greater transparency and security in commercial legal transactions, helping
economic and business development, and thereby fulfilling a general public interest for the business and professional sector and the creation of Employment.
This is the purpose of participating in this database, both for the interested parties themselves, the self-employed or individual entrepreneurs, who are interested in being part of this database, both to be

located by third parties interested in their products and services, and to access this database to offer them to third parties.

9. Regarding the transfer of data to CAMERDATA, the following statement is made:
"The Spanish Chamber of Commerce provides the data from the public business census to

Camerdata, S.A. for legitimate processing, completion, and enrichment, and to have a quality database of companies operating in Spanish territory, so that it can be offered to companies and interested third parties.
The legitimate basis for processing data from the public business census by Camerdata is that the processing is necessary for the satisfaction of legitimate interests pursued by the data controller or a third party,

provided that such interests are not overridden by the interests or fundamental rights and
freedoms of the data subject that require protection of personal data (Article 6.1. f) of the GDPR).
In this sense, it contributes to the development and promotion of commercial and industrial relations, thus providing a quality business information system for stakeholders in the business community, boosting the economic and business development, and providing greater security in commercial transactions, thereby satisfying a general interest.
The processing of data from the public business census by Camerdata also underlies a legitimate interest of the business owners themselves, who need to have this information either to learn about the services and products of other business owners or to make their own products known to third parties.

Fundamental rights and freedoms of data subjects:
The fundamental rights and freedoms of data subjects are the general ones that
require the protection of personal data, with none specifically highlighted in this particular situation.
In any case, they will not be violated by the processing of data from the public business census, because:

1. The category of personal data processed is limited to those in the public business census of the Chamber of Spain and for purposes consistent with its preparation.
2. The data processed is contained in the public business census, a publicly accessible database on the Chamber of Spain's website.

3. The easy exercise of the rights of data subjects regulated in Articles 15 to 22 of the EU GDPR is guaranteed at all times.
Result of the weighting:
1. - The processing is considered lawful.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 40/164

2nd - The data processed is public data, accessible to the general public on the corporate website of the Chamber of Spain.
3rd - The categories of data processed are minimally invasive of the data subject's right to privacy, as they are data limited to the data subject's performance of a business activity. At no time are data from their family spheres present, nor are there data belonging to special categories of data (Article 9 GDPR).
4th - The principle of the free movement of data, established and protected by the European regulations on the matter (GDPR).
5. - The purposes intended by Camerdata for data processing are consistent with and compatible with those of the Chambers of Commerce's public business census, as they seek to provide a quality business information system for stakeholders in the business community, promoting economic and business development and providing greater security in commercial transactions, thereby satisfying a general economic interest.

[…]”>>

-- The Preliminary Investigation Report states:
<<On March 22, 2024, it was verified, regarding a randomly selected self-employed person
from the lists provided by CAMARA and CAMERDATA, that:

1. A search was conducted on www.google.es for the first and last name of a self-employed person, yielding results from the website www.expansion.com.

2. That the website www.expansion.com contains data exclusively on the first and last name, postal code, province, municipality, year of commencement of activity, activity, SIC,

CNAE. It is stated that the data was obtained from public sources by AXESOR
CONOCER PARA DECIDIR S.A. It is also stated that for further information
about the self-employed person, a link to the website autonomos.axesor.es is provided. Clicking
on this link redirects you to the website autonomos.axesor.es and They show
exclusively the data on name and surname, postal code, municipality, province,

CNAE (National Tax Code), SIC (National Tax Code), and information about their activity.
The website autonomos.axesor.es also includes the text "Our reports will provide you
with the most complete information on the business activity of […]
such as the NIF (Tax Identification Number), telephone number, address in Molledo (Cantabria), credit rating,
probability of default, and maximum solvency capacity. Legal incidents....”

3. Searching the self-employed person's first and last name using www.google.com and restricting the search results to the einforma.es domain, search results are provided that, when clicked, redirect to the einforma.com website. These details include the name, surname, city, and province of the individual. More detailed information includes the name and surname, postal code, province, municipality, activity, SIC (National Tax Code), and CNAE (National Tax Code).
Furthermore, the einforma.com website contains a link with the words "Access the extended report for this company." It also includes the text "elnforma, a brand of INFORMA D&B S.A.U. (S.M.E.), is the market leader in Spanish business information and company reports. We have a business database with more than 500

million company records, where you can search for companies from around the world,
more than 7 million national economic agents, and access to Prospecta.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 41/164

4. Searching the first and last name of that self-employed person using the search engine www.google.com and restricting the search results to the domain axesor.es yields no results.

5. On the censo.camara.es website, performing a search using the name field

and entering the first and last name of the same self-employed person above, results are provided with the following data: first and last name, postal address, postal code, province, municipality, and activity. A link is also provided to the Camerdata Online business file (www.camerdata.es) for more information.>>

--The Preliminary Investigation Report states:

<<On 03/22/2024, it was verified that:

1. In section 5.1. "census" The AEAT's registry of processing activities located at https://sede.agenciatributaria.gob.es/Sede/todas-
gestiones/procedimientos-no-tributarios/tratamiento-datos-personales/tratamiento-

datos-personales/informacion-interesado-sobre-proteccion-datos/5-registro-actividades-tratamiento/5_1-censo.html states:
"Description of the activity:
Management and collection of information on taxpayers, whether individuals or legal entities. To this end, most census data are processed, including their history.

Purpose:
Effective application of the state tax and customs system.
Interested parties:
Taxpayers and taxpayers
Any Spaniard or foreigner with a DNI (National Identity Document), NIE (DGP), or NIF (AEAT).
Data.

DNI and associated information, name and surname, address, telephone number, email address, fax number, mobile phone number, marital status and, if applicable, spouse or ex-spouse, country of birth, province of birth, city of birth, date of birth, nationality, passport, sex, type of administration to which the taxpayer is assigned, tax identification number in a foreign tax authority, municipal identification number, electoral identification number, census number, father's name, mother's name.
Transactions involving goods and services.
Tax obligations.
[…]
Recipients.
Social Security Agencies

Regional Bodies
Regional Bodies
Administrative Bodies Local
Provincial Councils
Navarra Provincial Council

Tax Agency
Basque Provincial Councils
Chamber of Commerce
[…]”>>

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 42/164

THIRD: According to the report collected from the Axesor tool, CAMERDATA, S.A., is a microenterprise established in 1985 with a turnover in 2021—the last fiscal year in which it filed accounts—of €886,000.

FOURTH: On April 15, 2024, the Director of the Spanish Data Protection Agency agreed to initiate sanctioning proceedings against CAMERDATA, in accordance with the provisions of Articles 63 and 64 of Law 39/2015, October 1, of the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), for the alleged violation of the following provisions of Regulation

(EU) 2016/679, of April 27, on the Protection of Natural Persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter GDPR):
- Article 6.1 of the GDPR, defined in Article 83.5.a), specifically having collected

and processed in its file personal data of self-employed entrepreneurs
transmitted by the Official Chamber of Commerce, Industry, Services and Navigation of
Spain (CÁMARA), which obtained them from the tax authorities, without the processing being based on an adequate legal basis under the GDPR.

- Article 6.1 of the GDPR, classified in Article 83.5.a), specifically referring to having transferred to third-party entities for marketing purposes personal data of self-employed entrepreneurs, transmitted and collected by CÁMARA, which obtains them from the tax authorities, without the processing being based on an adequate legal basis under the GDPR.

-Article 6.1 of the GDPR, classified in Article 83.5.a), specifically referring to having transferred to KOMPASS, for the purpose of providing a feedback service for its "Spanish Business File" and for that company's own purposes, its database of personal data of self-employed entrepreneurs, transmitted and collected by CÁMARA, which obtains them from the tax authorities, without the processing being based on an adequate legal basis under the GDPR.

-Article 14 of the GDPR, classified in Article 83.5.b)

-Article 28 of the GDPR, defined in Article 83.4.a)

FIFTH: As evidenced in the documentation in the file (folios 1,722 and 1,723), the notification of the aforementioned initiation agreement is made electronically, with the date of availability being April 15, 2024, and the date of acceptance of the notification being April 25, 2024.

SIXTH: By letter submitted on May 7, 2024, CAMERDATA requests, pursuant to Article 32 of the LPACAP (General Action Plan), an extension of the deadline for submitting allegations and a review of the file (folios 1,724 and 1,725).

Provides a copy of the notarial deed granting power of attorney, dated

January 29, 2018, which shows that the natural person appearing as the company's attorney is authorized to intervene on its behalf in this administrative sanctioning procedure in all its steps and instances with full authority (folios 1,799 et seq.).

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 43/164

By letter dated May 10, 2024, served electronically on the same day and accepted on May 14, 2024 (folio 1,816), the investigating body agrees

to extend the period for submissions by five additional days and to forward a copy of the administrative file to the court. The documents proving the submission of the documentation are in the file (folios 1,811 to 1,813).

SEVENTH: CAMERDATA submitted its written arguments on May 16, 2024, in which it requested that the procedure be declared null and void and, alternatively, that it be closed.

1. As a preliminary allegation, it invokes the lack of defense suffered, which entails the violation of "the principles governing the sanctioning procedure and its rights of defense therein, in violation of the applicable legal provisions on the matter and Article

24 of the Constitution." It explains that the defenselessness that led to the
sought annulment of the procedure consisted of:

a) Having sent him a request for information, prior to the initiation of the
file, "without informing him of the reason for such a request," which has
seriously impaired his right to defense in the sanctioning procedure.

b) Having sent him a voluminous administrative file without granting him
additional time to adequately formulate his allegations and to
propose the appropriate evidence.

CAMERDATA adds that "Given the extensive length of said file (1,807 pages) and the time at which it was received (May 13), it has been materially
impossible for this company to review said file, which has therefore
seriously impaired its right to defense in this case."

2. Examination of the GDPR violations attributed to CAMERDATA in the initiation agreement.

2.1. Violations of Article 6.1 of the GDPR:

Allegation 1 of the statement of allegations examines the violations of Article 6.1 of the GDPR attributed to CAMERDATA.

a) Having collected and processed in its own information system the data transmitted by the CDE without a lawful basis.
b) Having transferred its Spanish Company File to third parties, without a lawful basis, the most relevant data, such as the NIF, obtained from the CDE.
c) Having transferred its File to KOMPASS for the dual purpose of providing a feedback service for the information collected therein and for use by this entity for its own activities.

The allegations dedicate a specific section to echoing the reasoning
on which the initiation agreement based the three alleged violations of Article 6.1 of the GDPR. It reads:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 44/164

“Under a “Business Database Transfer” contract signed in 2016 with the Chamber of Spain (CDE), Camerdata processes data on self-employed individuals or individual entrepreneurs from the public business census prepared and

managed by the CDE pursuant to the provisions of Articles 8 and 21.1, in conjunction with Article 5.1g), all of Law 4/2014.”

“The NIF data of individual entrepreneurs exceeds the data necessary for their professional identification. Therefore, the presumption of lawfulness established in

Article 19 of the LOPDGDD will not apply for the purposes of determining
the legal basis for processing this data. Therefore, Camerdata will be responsible for proving that
there is a legitimate basis for processing it.”

“In summary, the CDE transfers data to Camerdata on individual entrepreneurs who are not
listed in the public business census and for purposes not included in

Article 8 of Law 4/2014; it transfers the so-called “Basic Business Census.”

“With the data transferred by the CDE, Camerdata is developing and commercially
operating a business information system called the "Spanish Business File," which is a separate database from the "Basic Business Census" prepared by the CDE. In addition, Camerdata provides its Spanish Company File to other entities for the purpose, sometimes exclusively, of providing the services for providing feedback to its file.

The Court denies having committed any of the alleged violations of Article 6.1 of the GDPR, since, as follows:

A. With regard to the violations of Article 6.1 of the GDPR described in paragraphs a) and b), there is a "legal basis for legitimacy" for the processing and/or the element of culpability is lacking.

B. With regard to the violation of Article 6.1 described in the initiation agreement in letter c), the conduct consists of "processing of data exclusively from companies incorporated as legal entities."

Alternatively, in the event that any of the violations of Article 6.1.f) of the GDPR are found, the Court maintains that the conduct that falls under that type of violation does not contain any of the aggravating factors found in the initiation agreement.

A. With regard to the violations of Article 6.1 of the GDPR CAMERDATA denies their existence because it considers that the aforementioned conduct (A.1) is indeed covered by a legitimate basis or (A.2) lacks the element of culpability.

A.1. In explaining the reasons why it considers that it has not incurred in any of the violations of Article 6.1 of the GDPR described in the aforementioned sections a) and b), it makes an extensive argument focused on two

issues: I. Its objections to the statements made in the initiation agreement and II. The premises on which, in its opinion, we should start in the assessment of the facts at hand: One of them is that the data that are the subject of this procedure,
including the NIF of the business individuals, are "business data" and that,

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 45/164

As such, they are subject to a specific regime. Another is its particular interpretation of Article 19 of the LOPDGDD, from which it concludes that the data processing it has carried out is protected by a rebuttable presumption of lawfulness and, therefore, it is up to this Agency to overrule the presumption of lawfulness it has in its favor.

I. Objections to the considerations contained in the initiation agreement:

It states that the initiation agreement erroneously understood that "the purpose of processing the CDE's public business census is solely that expressly determined by Article 8 of Law 4/2014, from which it concludes that said purpose is incompatible with offering it commercially to companies and interested third parties."

It states that such an approach is erroneous because "the purpose of a census" Public

cannot be other than, as its name indicates, to be public, that is, to be shared publicly." It insists that "the purpose of the Chamber of Commerce's business census is not exhausted by its mere preparation for publicity, but rather that the publicity of the Chamber of Commerce's business census pursues an essential, ulterior purpose, specific to the Chambers of Commerce, which is to promote the competitiveness of our companies through policies that support commercial and business activity, especially for small and medium-sized enterprises, which primarily include self-employed individuals or sole proprietors."

It indicates that "There are multiple and unequivocal references in Law 4/2014 that assign the Chambers of Commerce the primary function of promoting business competitiveness, with the ultimate objective of actively promoting general economic growth and job creation in our country."

Among them, it mentions Section I of the Preamble to Law 4/2014 and Article 5.1.j) of Law 4/2014: “j) Promote actions aimed at increasing the competitiveness

of small and medium-sized enterprises, and encourage innovation and technology transfer to companies.”

It states that “the function of preparing and managing a public business census in Articles 5.1.g), 7, and 8 of Law 4/2014 cannot be correctly understood if it is not connected to the function of Article 5.1.j) of the same Law.” “In other words, the public business census is nothing more than an instrument for fulfilling one of the main purposes of the Chambers, which is to promote the competitiveness of small and medium-sized enterprises.”

Considering the business census a "mere instrument for the development of business competitiveness, economic growth, and job creation," CAMERDATA concludes that, since Law 4/2014 does not establish how the business census should be made public, it is "entirely legitimate" to give it "the widest possible dissemination." Therefore, it states, not only is it not incompatible, but it is "fully consistent" that the public business census not only be available

on the CDE website, "but also be marketed in digital format, thereby achieving its full potential for the public interest purpose it pursues."

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 46/164

It also indicates that, since the "business data in the public business census are, by definition, public, it fails to understand what duty of confidentiality or secrecy may apply to them."

It states that "the data published on the CDE's website are: (1) the company's name or corporate name; (2) main address; (3) business address;
(4) IAE activity section; and (5) IAE activity. It concludes that "Therefore, with respect to this data, there is no doubt that it does not affect the private sphere of self-employed workers or individual entrepreneurs and that the requirements of the GDPR are not violated, as it is public data and the disclosure of which is well known to the self-employed workers or entrepreneurs themselves, as is evident from Article 8 of Law 4/2014 and from the CDE's website."

Regarding the NIF (Tax Identification Number) of individual entrepreneurs, it acknowledges that "it is true

that this data does not appear in the public business registry" and states that the CDE "does not transfer it to Camerdata in accordance with agreement 12.2 of the contract signed between the CDE and Camerdata on February 15, 2016."

It states: "Camerdata receives from CDE the NIF (Tax Identification Number) of individual entrepreneurs
and self-employed persons encrypted with the MD5 algorithm (Message Digest Algorithm 5), commonly used

to securely store data. The algorithm used is a HASH or unique fingerprint, and its main characteristic is that it is not possible
to obtain the input value (NIF) corresponding to an output value (HASH or MD5 fingerprint), so it is Camerdata that obtains the NIF by its own means.

He argues that Law 4/2014 "does not define which business data are included in the public business register, so it could be understood to include the NIF."

He argues that the NIF is essential "for due compliance with the legal obligation to provide truthful and accurate data." "Only the NIF is unalterable, so only the NIF guarantees the true location and identification of the self-employed person or individual entrepreneur."

He rejects the idea that the NIF of self-employed workers can be considered sensitive data; he asserts that it is "business data" and, as such, "does not form part of the privacy and confidentiality of individual entrepreneurs." Thus, it states: “The NIF (Tax Identification Number) of self-employed persons or

individual entrepreneurs cannot be considered sensitive data, not only because it is not included among the special category data in Articles 9 and 10 of the GDPR,
but because it undoubtedly constitutes business data, since (i) without it they cannot
operate in commercial legal transactions nor issue invoices, (ii) it is registered in the
Commercial Registry for shipping companies and for all other

individual entrepreneurs who register in said Registry (Articles 81 et seq. and
Article 87 et seq., respectively, of the Commercial Registry Regulations), and (iii) it is
required for the provision of information society services (Article 10 of
Law 34/2002, of July 11, on information society services and electronic commerce).

As a summary of the position it defends, it states: “In Ultimately, the NIF, as business data, is not part of the privacy and confidentiality of individual entrepreneurs, but rather is essential information for operating in the market and for the security of commercial legal transactions.”

II. Premises for the assessment of these processing operations in CAMERDATA's opinion.

In referring to the premises that constitute the starting point for the assessment of the facts, CAMERDATA merely reiterates, using different expressions, the same idea already expressed.

a. The first premise, in its opinion, would be to establish that we are dealing with "business data."

In this regard, it states that "the data processed do not refer to the personal data of individuals as such, that is, in relation to their sphere or scope of private activity, but rather to data of individuals in their capacity as self-employed persons or individual entrepreneurs, that is, insofar as they carry out commercial, industrial, service, or shipping activities, as such is the configuration of the public registry of companies prepared and managed by the Chambers of Commerce in accordance with the provisions of Articles 5.g), 7, and 8 of Law 4/2014."

And it maintains that the applicable data protection regime is different from the general one: "Therefore, there is no doubt that the data of individual entrepreneurs, insofar as they act in such a capacity, enjoys completely different protection from the personal data of natural persons in relation to their private or particular sphere of activity."

b. Regarding Article 19 of the LOPDGDD, it mentions a paragraph in the initial agreement, page 45, which states that the LOPDGDD dedicates a provision, Article 19, to individual entrepreneurs. The paragraph in question reads as follows:

"For its part, the LOPDGDD dedicates a provision, Article 19, to the data of individual entrepreneurs - "Processing of contact data of individual entrepreneurs and independent professionals" - which is limited to establishing a rebuttable presumption of the lawfulness of the processing, based on section f) of Article 6.1 of the GDPR, with respect to contact data concerning individual entrepreneurs "when they refer to them solely in that capacity" and are not processed

to establish a relationship with them as natural persons."

The mere mention of this provision of the LOPDGDD in the initial agreement leads CAMERDATA to this conclusion: "Therefore, there is no doubt that the data of
individual entrepreneurs, insofar as they act in such a capacity, enjoys a protection that is completely different from the personal data of natural persons with regard to their particular or private sphere of activity."

And, regarding Article 19 of the LOPDGDD, it then makes a statement that is as categorical as it is erroneous, since it refers to the "data" of self-employed entrepreneurs without specifying what type of data it is: "Thus, Article 19 of the LOPDGDD establishes a legal presumption "iuris tantum" that the processing of the data of self-employed entrepreneurs or individual entrepreneurs is lawful under Article 6.1.f) of the GDPR when certain requirements are met."

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 48/164

This statement is erroneous in that it is incomplete: the requirements must indeed be met, and are set out in Article 19.2 of the GDPR. However, not all data of individual entrepreneurs are subject to the presumption of legality to which we are referring, but rather, exclusively, as stated in the initiation agreement (page 45, paragraph transcribed above), "contact data."

In line with CAMERDATA's erroneous interpretation of Article 19 of the LOPDGDD (the LOPDGDD)—because by including all data on individual entrepreneurs in it, it deviates from the legal provision—it maintains that the aforementioned provision exempts it from having to weigh whether the interests or fundamental rights and freedoms of the data subject that require the protection of personal data prevail over the interests of the data controller.

CAMERDATA attempts to justify its interpretation of Article 19 of the LOPDGDD with an argument that in no way supports its thesis: a fragment of the explanatory memorandum ("Preamble") of the LOPDGDD, which states that, in relation to specific processing operations, the legislator has established a rebuttable presumption of the prevalence of the controller's legitimate interest when the processing is "carried out with a series of requirements" (which the explanatory memorandum does not address). It adds—and this is the idea it seeks to convey—that nothing prevents the lawfulness of the processing from being based on the prevalence of the controller's legitimate interest when "the conditions provided for in the text" are not strictly met. However, the explanatory memorandum states that "the controller must carry out the legally required balancing, as the prevalence of legitimate interest is not presumed."

Subsequently, relying on an obvious error in the initiation agreement—since
on page 45 of the initiation agreement, it was clearly stated that the processing of data
of the business owners protected by the presumption of lawfulness was their contact information—including on page 50, where location data is mentioned instead of contact information—CAMERDATA reaches the biased conclusion that the requirements of section 1 of Article 19 of the LOPDGDD are being interpreted as equally extending to the different case regulated in section 2 of the same
Article 19 of the same Organic Law.

In addition to bringing up the comments contained in the Opinion of the Council of State on what was then Article 20 of the Draft Organic Law, it mentions that the Council of State, in its Opinion, "explains the different rationale for these two legal presumptions by connecting the provision of Article 20.1 of the Draft Law on the data of natural persons who provide services to legal entities (which corresponds to that of Article 19.1 of the LOPDGDD) with Article 88 of the GDPR, which regulates data processing in the workplace, since it logically considers that the case of natural persons who provide services to legal entities refers to workers in the workplace. Therefore, it recommends replacing the reference that Article 20.1 of the Draft Law makes to Article 6.1.f) of the GDPR with a reference to Article 88. of the GDPR:

“The provisions of paragraph 1 of this article could, however, be covered by Article 88 of the Regulation, to the extent that they refer to

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 49/164

workers. The aforementioned article of the European standard empowers Member States
to establish, through legislative provisions or collective agreements,
"more specific rules to guarantee the protection of rights and freedoms in

relation to the processing of workers' personal data in the workplace,
particularly for the purposes of hiring personnel, execution of employment contracts, […]"

Therefore, CAMERDATA adds, "Although this reference to Article 88 of the GDPR has not been transferred
to the current Article 19.1 of the LOPDGDD, what is undoubtedly true is that
this assessment by the Council of State highlights the different nature of workers' personal data in the workplace (the scope of Article 19.1), which is much more proprietary, and, consequently, the different degree of protection they deserve, since, unlike individual entrepreneurs, they do not openly expose themselves
to the market, offering their business activities and services to
all potential clients."

CAMERDATA concludes from its arguments that, in its opinion, the application of the rebuttable presumption of lawfulness protected by Article 6.1.f) of the GDPR has been established in relation to the data processing that was included in the initiation agreement as violations of Article 6.1 of the GDPR, as described in sections a) and b). And that, as long as this Agency has not refuted the presumption of lawfulness enjoyed by it, it is appropriate to order the closing of the proceedings with respect to the aforementioned violations.

The entity states the following: "It is appropriate to legally apply the presumption of
the prevailing legitimate interest of this company in its capacity as controller of the data of self-employed workers or individual entrepreneurs, as this presumption has not been overturned. Therefore, the actions described in letters a) and b) of Section I.1 above do not constitute a violation of Article 6.1.f) of the GDPR, but are protected by it pursuant to the provisions of Article 19.2 of the LOPDGDD."

Consequently, for this reason, this sanctioning procedure must be closed with regard to these actions.

A.2. Regarding the violations of Article 6.1 of the GDPR described in sections a) and b) of the initiation agreement, CAMERDATA denies their existence, based on the absence of the essential element of culpability.

The company CAMERDTA devotes an extensive discussion to examining the element of culpability, which is necessary for imposing liability for penalties, and cites several CJEU judgments to this effect, particularly those issued in Cases C-683/21 and C-807/21.

It then emphasizes that, in its opinion, it is striking that the initiation agreement did not mention "circumstances of relevance for the purposes of this procedure, known to the supervisory and control body, which directly impact the determination of whether or not there was intentionality or negligence on the part of Camerdata."

It cites the following relevant circumstances:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 50/164

-The AEPD Resolution of 27/02/2001 in the case initiated as a result of the complaint filed against a Chamber of Commerce for the transmission to third parties of data contained in the public business register regulated by

Law 3/1993.

-The query from the AEPD Legal Office, which states that it recovers the interpretation made in the aforementioned resolution (link to the resolution:
https://www.aepd.es/documento/2001-9901.pdf)

-The Legal Office's response to a query from ASEDIE, dated 09/30/2014,
reference number 383358/2014 (a query raised after the
approval of Law 4/2014), in which the Agency's Legal Office reported in
the following terms:
"Thus, provided that the data refer solely to legal entities, without

containing any personal data other than those mentioned in Article 2.2 of the implementing regulations of the Organic Law, or to individual entrepreneurs, in the terms that
have just been described and related solely and exclusively to the commercial activity of such entities. For entrepreneurs, data protection regulations will not apply,
therefore, without prejudice to the provisions of other regulations, their communication will not be
subject to the provisions of Organic Law 15/1999."

-The Resolution denying approval of the ASEDIE Code of Conduct
(File No. CC/0003/2018), in which neither the Subdirectorate General of the Central Data Protection Registry nor the Legal Office of the AEPD, in their
respective reports, found objections to the processing of personal data of

individual entrepreneurs and independent professionals. It transcribes this paragraph:

"Regarding the remaining content, the report of the Subdirectorate General of the General Data Protection Registry issues a positive overall assessment, considering
that it responds to the particular needs of the promoter, that it facilitates and specifies the

application of the GDPR, and that it provides sufficient guarantees."

-The report of the Legal Department of the AEPD (Spanish Data Protection Agency) No. REF 0089/2020, which specifies the processing operations in which the legitimate interest of the data controller is not found to prevail, specifically, data processing (i) for credit information systems related to the fulfillment of monetary, financial, or credit obligations and (ii) for solvency information systems with data obtained from public sources or that the data subject has made manifestly public, contained in sections 2 and 3 of Annex II, which should be deleted. "However, this Report does not raise any objection to Annex I of the Code of Conduct, which lists information services of economic relevance regarding commercial companies and other legal entities, individual entrepreneurs, and independent professionals."

-That the General Secretariat of the AEPD has agreed to initiate procurement file EX20240028 for "Economic-Financial and Commercial Information Analysis Services," the purpose of which is to contract a service for the AEPD providing economic-financial and commercial information for any entity, regardless of its legal form, including self-employed individuals, associations, and foundations.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 51/164

In light of the foregoing considerations, CAMERDATA states that "it is clearly established" that it has not acted at any time with intention or negligence in the processing of personal data of individual entrepreneurs and liberal professionals. This claim is based on the fact that:
(i) prior to the approval of the GDPR, there was no doubt about the legality of this company's processing of data of sole proprietors.
(ii) Since 2017, the AEPD has held working meetings and exchanged documents with the ASEDIE association, "has issued reports with statements favorable to the processing of personal data of sole proprietors that it now considers contrary to the GDPR, and is even going to hire a company, probably from the infomediary sector, specifically to process personal data of sole proprietors and independent professionals."

Without any justification, it claims that the "absence of culpability" it invokes is based "on the legitimate trust generated by the AEPD's own actions" in relation to the data of self-employed workers or sole proprietors.

It concludes from its reflections that, since the subjective element of culpability is not present (in any of its manifestations), it is appropriate to order the closing of the proceedings in relation to the violations of Article 6.1 of the GDPR referred to in the initiation agreement in cases a) and b) described therein.

B. Regarding the violation of Article 6.1 of the GDPR described in the initiation agreement

in letter c) – "c) Having transferred its File to the company KOMPASS for the dual purpose
of providing a feedback service for the information collected therein and for use by this entity for its own activities" – CAMERDATA alleges
that the conduct consists of "processing data exclusively from companies
incorporated as legal entities."

CAMERDATA asserts that the data provided does not violate the GDPR, as it is
exclusively data from companies incorporated as legal entities. For this reason, it rejects the violation of Article 6.1 of the GDPR noted in the initiation agreement, specifically in CAMERDATA's communication to KOMPASS, without a legal basis, of the personal data of self-employed entrepreneurs for the purpose of replenishing the file and subsequently using it in its business activity without a legal basis.

It mentions the two contracts signed with KOMPASS SPAIN, SLU, which are intended to perform "web crawling" work based on the data provided by CAMERDATA, consisting of the application of search algorithms and pattern recognition on the internet to, using the URLs of the company websites available, attempt to obtain the generic email addresses associated with these URLs.

Contract dated June 20, 2020:

- CAMERDATA transfers 107,807 CIFs from the records contained in the Spanish Companies File database, for which Camerdata does not have a generic email field reported and partially has a URL field reported.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 52/164

Contract of 03/20/2023:

- CAMERDATA transfers the NIFs of the records contained in the Spanish Companies File database, where KOMPASS has the URL field provided and that Camerdata does not have the generic email field (145.101).

In defense of the thesis that the data processed are exclusively those of legal entities, it invokes:

- That the universe of transferred records is completely different from the number of self-employed persons or individual entrepreneurs in the Spanish Companies File:
CAMERDATA processes data from a total of 1,665,049 self-employed persons or individual entrepreneurs, while the number of records transferred to KOMPASS is 107,807 (in the contract). 2020) and 145,101 (in the 2023 contract).

-That the 2020 contract expressly refers to Tax Identification Codes (CIFs), which clearly—although erroneously since 2008—indicates that these are data for companies incorporated as legal entities. This naming error is corrected in the 2023 contract since, strictly speaking, since 2008, the CIF has also been called the NIF, which was previously applicable only to natural persons.

-That the file contains, as document annex 5 to the allegations to the initiation agreement, a document signed by the CEO of KOMPASS stating that the records used to carry out its webcrawling work were exclusively those of legal entities, their tax identification numbers, URL addresses, and generic email addresses, and in no case those of individuals or sole proprietors.

It invokes Article 53.3 of the LPACAP (Spanish Civil Procedure Act), according to which, in administrative procedures of a sanctioning nature, a presumption of non-existence of administrative liability is established until proven otherwise.

It concludes that, since the data transferred under the contract signed with KOMPASS are not personal data—they are not data of self-employed entrepreneurs, but only of legal entities—such action does not violate Article 6.1 or any other provision of the GDPR, as the latter is not applicable to it according to Recital 14.

The procedure must be closed with regard to this violation.

In addition to the arguments set forth in sections A and B above, which address the violations of Article 6.1 of the GDPR attributed to it in the initiation agreement, it maintains that none of the elements of Article 83.2 of the GDPR that were taken into consideration in assessing the sanction can be found in the present case. The arguments put forward by CAMERDATA in this regard are merely a reiteration of those it has invoked in its allegations to deny the existence of the violations of Article 6.1 described in sections a) and b) above.

3. Allegation II of the written pleadings examines the violation of Article 28 of the GDPR attributed to it in the initiation agreement.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 53/164

CAMERDATA begins by stating that the initial agreement attributed to it an alleged
violation of Article 28 of the GDPR, considering that the contract signed between it and

DMOVO ANALITYCS, S.L., dated 03/02/2020, for the provision of certain
services, "although it contains a confidentiality clause, does not incorporate the other
provisions established by Article 28.3 of the GDPR, so this obligation must be deemed
to have been breached."

It rejects the alleged violation since, it says, the contract does comply with the provisions

of Article 28.3 of the GDPR.

In this regard, the company states that the contract that binds it as data controller
to DMOVO as data processor establishes the "object, duration,
nature, and purpose of the processing," "the type of personal data, categories of data subjects, and the obligations and rights of the data controller." It adds that it also makes express and repeated reference to observing and complying with the provisions of the GDPR and the LOPDGDD "regarding access, processing, and transfer of personal data."

It provides with its allegations (document no. 6) the "Confidentiality Agreement" that both parties signed on December 18, 2019. It explains that this document was not provided when the prior request for information was fulfilled by the AEPD, "because at that time no information was provided and, therefore, its scope was unknown."

In its defense, it has stated in which stipulations of the Confidentiality Agreement of December 18, 2019, and the Contract of February 3, 2020, each of the provisions of Article 28.3 of the GDPR, sections a) to h) are included (section b) is not mentioned, in order to demonstrate that all the requirements of Article 28.3 of the GDPR are documented in the Contract or the Confidentiality Agreement. It states in this regard:

1. The provision of Article 28.3.a) of the GDPR, according to which “the data processor shall process the data solely following the documented instructions of the controller,” is incorporated into Agreement 2.3.b) of the Confidentiality Agreement, which provides that “the information and data subject to processing shall be used solely and exclusively for the development and execution of the contractual relationship, in accordance with the agreements established between the parties and following Camerdata's instructions.” The agreement continues by stating that “under no circumstances may the data processor process, use, or apply them for a different purpose or in violation of said regulations.”

2. The provision of Article 28.3.c) of the GDPR, relating to "all necessary measures in accordance with Article 32 GDPR" on the "Security of processing", is incorporated through:

- Covenant 2.3.a) of the Convention, according to which the party receiving the information is obliged to have "the necessary technical and organizational means to ensure the security and confidentiality of any personal information provided."

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 54/164

-Covenant 2.3.e) of the Convention, according to which “personal data shall not be recorded in files that do not meet the legally required conditions regarding their integrity and security and that of the processing centers, premises, equipment, systems, and programs.”
-Covenants 2.3.g) and 2.3.k) of the Convention, according to which the confidentiality guarantees and criteria of the Convention shall extend to “any type of medium containing personal data (digital or non-digital) to which access is obtained” by reason of the development and execution of the contractual relationship.

3. Article 28.3.d) of the GDPR, according to which the first processor “shall respect the conditions indicated in paragraphs 2 and 4 for resorting to another Data processor,” is transferred to Pact 2.3.d) of the Convention, which prohibits subcontracting to third parties “any access to or processing of the personal data communicated without the prior express written authorization” of Camerdata.

4. Article 28.3.e) of the GDPR, under which “the processor shall assist the controller, taking into account the nature of the processing, through appropriate technical and organizational measures, whenever possible, to enable the controller to fulfill its obligation to respond to requests that aim to exercise the rights of data subjects set out in Chapter III,” is transferred

to Pacts 2.5 and 2.6 of the Convention.

Under the first, DMOVO is obliged to immediately inform Camerdata “of the content and scope of any right of access, rectification, erasure, and objection exercised by any data subject of personal data that is being processed as a data processor.” of its processing." And in accordance with
Agreement 2.6, DMOVO "will not directly process any response to data subjects, limiting its actions to keeping the controller informed at all times," who assumes responsibility for any exercise of data subjects' rights regarding personal data protection.

5. Article 28.3.f) of the GDPR, according to which the processor will assist the controller "in ensuring compliance with the obligations established in Articles 32 to 36, taking into account the nature of the processing and the information available to the processor," is incorporated through Agreement 2.3.f) of the Convention.

It establishes DMOVO's obligation both to comply with "the provisions of the LOPDGDD and the GDPR" and to monitor "the proper logical and physical protection of the personal data provided" by the controller and the implementation of "technical and organizational measures that are necessary, taking into account the state of the technology, the nature of the data stored and the risks to which they are exposed, whether caused by human action or by the physical or natural environment.”

6. Article 28.3.g) GDPR, according to which, at the controller’s discretion, the processor shall delete or return all personal data once the provision of processing services has ended, and shall delete existing copies unless the retention of the personal data is required under Union or Member State law,” is incorporated through:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 55/164

-Covenant 2.3.q) of the Convention. It provides that, upon termination or resolution of the contractual relationship, DMOVO "will return all confidential information and all personal data provided by... (Camerdata) and will not retain any copies thereof, immediately destroying any media or document containing any confidential information or personal data, without the need for an express request" from Camerdata.

-Pact 1.4 of the Agreement provides that, upon termination of the contractual relationship, both parties "will return all data, documentation, computer or electronic media, or any other type of media provided in the execution of the same, except in the event that there is a legal obligation to retain such media in accordance with and in the manner provided by applicable regulations."

7. Article 28.3.h) of the GDPR, relating to the provision to the controller of

all information necessary to demonstrate compliance with the obligations
set out in this Article, as well as to enable and contribute to the performance
of audits, including inspections, by the controller or another auditor
authorized by the controller, as well as, pursuant to its second paragraph, to the
obligation of the processor to immediately inform the controller if, in its opinion,
an instruction infringes this Regulation or other data protection provisions of the

Union or Member States, is incorporated through:

- Pact 2.3.ll) of the Convention, by virtue of which DMOVO allows Camerdata to
carry out "any type of control over the security and integrity of the data being processed, in compliance with the obligation of safeguards and oversight that the

controller has towards the processor." It also provides that Camerdata may "inspect, either itself or through technicians designated for this purpose, the premises, facilities, equipment, and measures implemented" by DMOVO, as well as DMOVO's obligation to keep Camerdata informed of "any type of incident that may impact the integrity or confidentiality of the data."

It concludes from its presentation that, through the 2020 Contract and the 2019 Confidentiality Agreement, the provisions of Article 28.3 of the GDPR were incorporated into the regulation of the contractual relationship, and therefore this obligation has been fulfilled and no violation of the provision has occurred. It is understood that it is appropriate to order the closing of the sanctioning procedure regarding this violation.

4. Allegation III of the statement of allegations examines the alleged violation of Article 14 of the GDPR attributed to it by the initiation agreement.

The allegations begin by indicating that the initiation agreement attributes to CAMERDATA an alleged violation of Article 14 of the GDPR, consisting in that it "has under no circumstances informed the data subjects of the processing it carries out."

CAMERDATA understands that the legal considerations and reasoning of the initial agreement

do not conform to the facts or the legal system for the following
reasons:
a. The conduct described does not constitute a violation of Article 14 of the GDPR because (i) the duty to inform data subjects under Article

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 56/164

14.5 of the GDPR has been fulfilled, due to the existence of a disproportionate effort, and (ii) it was not committed
through fault or negligence.

b. Alternatively, it considers that none of the factors used to determine the amount of the fine that could be imposed cannot be established: severity, fault or intentionality, category of sensitive data,
connection with the offender's activity.

(i) It states that it has complied with the duty to inform data subjects. It considers

Article 14.5.b) applicable, according to which:
“5. The provisions of paragraphs 1 to 4 shall not apply where and to the extent that:
a) […]
b) communication of such information proves impossible or involves a disproportionate effort, in particular for processing for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, subject to the conditions and safeguards referred to in Article 89(1), or to the extent that the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impede the achievement of the objectives of such processing. In such cases, the controller shall take appropriate measures to safeguard the rights,

freedoms and legitimate interests of the data subject, including by making the information public.”

It invokes Recital 62 of the GDPR. It mentions that "the Working Party on Personal Data Protection under Article 29, in its Report WP.rev01 17/ES (last revised on April 11, 2018), indicates, as does Recital 62 of the GDPR, that the reference to processing for archiving, historical, scientific or historical research, or statistical purposes is a reference to certain processing operations that are more likely to involve a disproportionate effort, but that they are not the only processing operations that may fall under this exception to the duty to provide individual information to data subjects."

It warns that both Recital 62 and the aforementioned Report refer to the number of data subjects, the age of the data, and adequate safeguards as criteria to be considered when assessing the existence of a disproportionate effort.

It explains that, in the present case, the number of data subjects exceeds one million and
adds that the criterion of adequate safeguards adopted is also met. It states
that, according to Article 14.5.b) of the GDPR, the criterion of adequate safeguards is an action that the data controller must take if a
disproportionate effort exists. The cited provision establishes that, "(…) In such

cases, the data controller shall adopt appropriate measures to protect the rights,
freedoms, and legitimate interests of the data subject, including making the
information public."

Regarding the safeguards adopted, it states that an informative text has been published on

the websites of the Chambers of Commerce of Madrid, Barcelona, Valencia, Castellón,
Alicante, Girona, and Sabadell. It adds that it has also been published on the Camerdata website.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 57/164

It indicates that the informative text on the processing of data of self-employed entrepreneurs will be "incorporated" (future action) into "the bulletins and newsletters" that the Chambers periodically publish. It indicates that it will be "disseminated" (future action) in several

largely circulated newspapers in Spain in paper and/or digital format on an annual basis.

It concludes that it "meets the criteria for validating the exemption from the obligation to provide individual information on processing." It specifies the following reasons:
a. "It clearly identifies the processing of personal data relating to […] individual entrepreneurs

included in the public business register." b. It provides the reasons that justify the disproportionate nature of compliance with the obligation to provide information. c. It sets out the compensatory measures adopted and agreed upon. d. It has prepared and disseminated on its website an informative text on data processing.

(ii) CAMERDATA denies the existence of a violation of Article 14 of the GDPR due to the absence of the necessary element of culpability. It refers to the discussion made on the element of culpability when examining the violation of Article 6.1 of the GDPR and cites to this effect some CJEU judgments, in particular those issued in Cases C-683/21 and C-807/21.

It maintains that the "absence of culpability" it invokes is based on the legitimate expectations generated by the AEPD's own actions in relation to the data of self-employed individuals or sole proprietors. And it goes on to say:

"Indeed, the actions carried out by the AEPD have created logical and reasonable expectations of legitimacy and lawfulness in the processing of personal data of individual entrepreneurs and professionals, such that Camerdata, as a company member of the ASEDIE association, has always acted in the legitimate belief that it is acting within the law, a belief based on the conduct and pronouncements of the AEPD itself."

It concludes that, since the subjective element of culpability is not present (in any of its manifestations), it is appropriate to order the closing of the proceedings in relation to the violation of Article 14 of the GDPR.

Alternatively, in order to justify that none of the elements used to fine-tune the sanction are present, it essentially resorts to the same arguments presented so far.

EIGHTH: Evidence Phase. Opening and List of Evidence to be Presented.

Pursuant to Article 77.2 of the LPACAP (Spanish Criminal Procedure Law), the investigating body agreed
on September 16, 2024, to open a thirty-day trial period.
This is stated in the Diligence signed on September 16, 2024 (folio 1,972), which details the

evidence it agrees to conduct:

1. To reproduce for evidentiary purposes:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 58/164

1.1. The complaint filed by the association Institut per a la Cultura Democratica a L'era Digital (Institute for Democratic Culture in the Digital Age) on December 27, 2022.
1.2. The internal note from the Director of the Spanish Data Protection Agency, dated

April 13, 2023, urging the Subdirectorate General of Inspection to initiate preliminary investigations, in accordance with Article 67 of the LOPDGDD.
1.3. All documentation generated and received during the preliminary investigations, as well as the Investigation Action Report signed by the acting inspector.
1.4. The allegations of CAMERDATA, S.A., regarding the agreement to initiate the sanctioning procedure and its attached documents.

2. Incorporate into the aforementioned file:
2.1. The following documents are part of the sanctioning file with
reference EXP202301678, which is being processed before the Spanish Chamber of Commerce,

Industry, Services and Navigation (CHAMBER or CDE): Your
allegations to the initiation agreement and the only attached document submitted with them, a
certificate signed by the General Manager of CAMERDATA, S.A.
2.2. Screenshots obtained from the census of Spanish companies accessible
from the CDE website.
2.3. Report of the Legal Department of the AEPD number 089/2020.

3. Request:
3.1. CAMERDATA, S.A., to send certain information and documentation to this Agency.
3.2. CDE to send certain information and documentation to this Agency.

NINTH: Trial Phase. Document incorporation procedures.

1. By means of a document signed by the investigating body on 09/16/2024 (pages 1,974 et seq.), the following documents obtained on 09/16/2024 from the website of the Spanish Chamber of Commerce (CDE) were incorporated into this administrative file, specifically from the Public Business Census accessible at https://www.camara.es/funcionconsultiva/consulta-del-censo-publico-de-empresas.

The attached screenshots demonstrate these details:

a. CDE provides information on its website under the heading "Public Business Census,"
"DESCRIPTION," in these terms: "We provide you with the data included in the Public Census, which contains all the legal and physical entities of the Official Chambers of Commerce, Industry, Services, and, where applicable, Navigation of Spain."

It indicates that the file "contains one record per activity (it does not accumulate several activities at the same address) and compiles the following data per record: Name,
Address, Postal Code, Municipality, Activity." Therefore, the NIF (Tax Identification Number) is not included among the data provided.

b. That, in relation to individual entrepreneurs, after a query is made to the public business census, the data provided is: first and last name, postal address (street name and number), postal code, province

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 59/164

and municipality, IAE code, and description of the activity. Therefore, the data provided does not include the NIF (Tax Identification Number).

c. That, after a query is made to the public business census by an individual entrepreneur, below the information indicated in the preceding point, the following legend is included with a direct link to CAMERDATA: "If you wish to obtain more information,
consult the Camerdata Online Business File."

2. By means of a diligence signed by the investigating body on 09/16/2024 (folios 1980 to 2005), the following are recorded in this administrative file:

- Statement of allegations regarding the agreement to initiate EXP202301678, submitted to this Agency by CÁMARA.
- The document attached to the statement of allegations submitted by CÁMARA in

EXP202301678: a certificate issued by the Director General of CAMERDATA.

3. By means of a diligence signed by the investigating body on 09/16/2024 (folios 2006 to 2180), the following are recorded in this sanctioning file:
Report of the Legal Department of the Spanish Data Protection Agency number
089/2020.

TENTH: Evidence phase. CAMERDATA requested tests and the entity's response.

By letter dated September 16, 2024, notified on the same day, and accepted by CAMERDATA on September 17, 2024, you are informed of the opening of a testing phase and are required to provide the information and documentation detailed in the letter (pages 1960 to 1968 and 1970).

On October 1, 2024, a letter was received requesting an extension of the deadline for the

maximum legally permitted period (pages 2181 to 2183 and 2193). The decision of the investigating body granting the requested extension, dated 10/01/2024, was communicated to CAMERDATA. The date of availability was 10/01/2024, and the acceptance of the notification was 10/09/2024 (pages 2193 to 2196).

CAMERDATA responded to the evidence process in a document submitted on

10/09/2024 (pages 2198 to 2422). The information and documentation requested by the investigating body during the evidence phase, along with CAMERDATA's response, are detailed below.

1.- Please provide the Record of Processing Activities related to the company database

related to self-employed entrepreneurs since 2021.

Response:
Please provide, as document 3, the "Record of Processing Activities.xlsx", "which records the record of processing activities related to self-employed entrepreneurs

since 2021."

2.- Please submit documentation demonstrating the assessment of the risks to the rights and freedoms of individuals resulting from the processing operations that CAMERDATA carries out in relation to the personal data of self-employed entrepreneurs obtained from CDE, as well as the appropriate technical and organizational measures implemented to effectively apply the principles of legality and transparency in the data processing operations it carries out.

Response:
"As Document 4, the document "Risk Assessment.xlsx" is provided, which
records the analysis and evaluation of the risks and the technical and organizational measures

that have been implemented in relation to self-employed entrepreneurs.

The documentation supporting the appropriate technical and organizational measures
implemented to effectively apply these principles is referenced as a response to section 5.10."

3.- Given that in your allegations to the agreement initiating the procedure, you have
invoked as a basis for the lawfulness of the data processing you carry out the
prevalence of the legitimate interest of CAMERDATA and/or the third parties with whom it contracts over the interests or fundamental rights and freedoms of the data subjects,
you are requested to provide documented information on the weighting

performed that justifies that the latter—the interests or fundamental rights and freedoms of the data subjects—do not prevail in the data processing you carry out.

Response:

“In our written submission of May 16 of this year, it was stated that the data of sole proprietors, insofar as they act in such a capacity, have a completely different protection from the personal data of individuals with regard to their particular or private sphere of activity, since Article 19.2 of the LOPDGDD establishes a legal presumption “iuris tantum” that the processing of the data of self-employed individuals or sole proprietors is lawful under Article 6.1.f) of the GDPR when certain requirements are met, specifically, when the data relates to them solely in that capacity and is not processed to establish a relationship with them as individuals.

Therefore, this company understands that this presumption of the prevalence of the legitimate interest of the data controller exempts it from having to weigh whether the interests of the controller do not prevail over said interest. or the fundamental rights and freedoms of the data subject that require the protection of personal data, as also stated in Section V of the Preamble of the LOPDGDD when referring to Title IV, which includes Article 19.

Thus, it can be understood that this legal presumption of the prevalence of the legitimate interest of the data controller, as a "iuris tantum" presumption, means that, in all cases, it must be rebutted by means of evidence to the contrary.

Notwithstanding the foregoing, and based on the presumption of Article 19 of the LOPDGDD, the weighing judgment has been carried out in the draft Code of Conduct of ASEDIE, an association of which CAMERDATA is a member. The following is provided as Document 5: "Weighing Judgment on the Legal Basis of Legitimate Interest

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 61/164

of Self-Employed Persons of Camerdata.pdf", the weighing judgment on economically relevant information services on commercial companies and other legal entities, individual entrepreneurs, and independent professionals, extracted from the aforementioned

ASEDIE Code of Conduct.

Since its scope of application is broader than the data processed by CAMERDATA (since, with respect to self-employed persons or entrepreneurs, only the data necessary for correct identification and location are processed, not including data of economic relevance), all the more reason for this weighing judgment to be extended to CAMERDATA."

4.- In your letter of 11/13/2023, in response to the information request from the Data Inspectorate, you stated regarding the NIF data of individual entrepreneurs

that such data was part of "the CAMERDATA business database related to self-employed workers," that its source was "the public business census published by
the Spanish Chamber of Commerce in accordance with the provisions of Law 4/2014 (hereinafter, the Public Business Census), and that it is obtained each time a new business census is uploaded […]" (page 2 of your letter).

In its submissions to the start-up agreement, it stated: <<Regarding the NIF (Tax Identification Number), it is true that this data does not appear in the public business registry, and the CDE does not transfer it to Camerdata in accordance with agreement 12.2 of the contract signed between the CDE and Camerdata on February 15, 2016. Camerdata receives from CDE the NIF (Tax Identification Number) of individual entrepreneurs and self-employed persons encrypted with the MD5 (Message Digest) algorithm, commonly used to securely store data. The algorithm used is a HASH or unique fingerprint, and its main characteristic is that it is not possible to obtain the input value (NIF) corresponding to an output value (HASH or MD5 fingerprint) […]>>

Please explain the reasons for this radical change in the information provided.

Response:
"The change in the information provided is due to a factual error that occurred in the preparation of the information and documentation necessary to respond to the AEPD's information request notified on October 20, 2023, due to the large volume of information requested. The correct information is that communicated in our written statement of objections to the agreement to initiate the sanctioning procedure dated May 16 of this year."

5. In view of the certificate issued by the General Manager of CAMERDATA, S.A., we request that you provide information, providing documentary evidence of your response, as of the date on which CAMERDATA stopped obtaining the NIF (Tax Identification Number) for self-employed entrepreneurs from the Chamber of Deputies in plain text.

Response:

“As far as has been verified with the historical data kept in compliance with legal obligations, CDE has always provided the NIF encrypted with the MD5 code, and there is no evidence that this data has been provided in plain text.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 62/164

6.-CAMERDATA states through the certificate issued by its Director General
(…).

You are requested to provide documentary evidence of your response, in accordance
with Article 5.2 of the GDPR, as to the "other means" through
which you obtained the NIF data. In particular, please provide information and evidence of the
origin of the NIF data for the 500 self-employed individuals included in the sample sent to
this AEPD in response to the information request, how it was obtained, and the date

on which it was obtained. You are also requested to provide information on the legal basis
of this processing.

Answer:
“(…)

As for the legality of this processing, this lies in the fact that the NIF (Tax Identification Number) of self-employed workers or individual entrepreneurs constitutes business data of undoubted general interest, as it is essential both for the legal security of commercial transactions and for the development of commercial relations, economic growth, and job creation.

Only through the NIF can the self-employed workers or individual entrepreneurs with whom a business relationship is to be established be uniquely and unalterably identified, thus avoiding identification errors and the inconvenience and harm that these could cause if only their first and last names were available.

Indeed, the first and last names of self-employed workers or individual entrepreneurs are not sufficient for their correct and unequivocal identification, since there are many

matching first and last names, the name can be changed, and the order of the Surnames and even last names can change. Only the NIF (Tax Identification Number) is unalterable, so only this information guarantees the true location and identification of the self-employed person or individual entrepreneur.

Thus, the NIF (Tax Identification Number) is also considered essential for proper

compliance with the legal obligation to provide truthful and accurate data.

Furthermore, the processing of the personal data of self-employed persons or individual entrepreneurs is considered legitimate under the legal presumption of Article 19.2 of the LOPDGDD (Spanish Data Protection Act), according to which it is lawful under Article 6.1.f) of the GDPR

when the data refers to the self-employed person or individual entrepreneur only
in that capacity and is not processed to establish a relationship with them as natural persons, as is the case with the processing carried out by CAMERDATA.

Furthermore, the NIF (Tax Identification Number) of self-employed persons or individual entrepreneurs cannot

be considered sensitive data. but rather a business data, since (i) without it, they cannot operate in commercial transactions or issue invoices, (ii) it is registered in the Commercial Registry for shipowners and for all other individual entrepreneurs who register in said Registry (Articles 81 et seq. and 87 et seq.,

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 63/164

respectively, of the Commercial Registry Regulations), and (iii) it is required for the provision of information society services (Article 10 of Law 34/2002, of July 11, on information society services and electronic commerce).

Finally, no actual harm has been proven in relation to the processing of this business data that would allow its processing to be considered serious, a process that has been carried out in a manner that is consistent with the law. This information has been publicly available for some time, but to date, no warning has been given of its possible illegality.

7.- You are requested to provide proof of the origin of the data of the 500 self-employed entrepreneurs
registered in the sample provided (a list of 500 self-employed entrepreneurs corresponding
to the records resulting from having ordered them alphabetically by first surname,
beginning with the letter "P"). If the source is CDE, you must provide justification for the
transmission made by CDE and the content of the information transmitted.

Response:
"The origin of the data in the sample of the 500 records indicated corresponds, in
part (everything except the NIFs), to the files received from CDE on 06/27/2023
(northern zone census) and 03/21/2023 (rest of the country census), and the remainder (the NIFs), to the
production of Camerdata as described below (last paragraph of This

answer and the answer to question 5.6 above), based on the hashes
provided by CDE. The NIF is not received by Camerdata from CDE."

The following is provided as proof of the transmission made by CDE on March 21, 2023, in the attached files:

Document 6: "email_envío_CDE_21-03-2023.msg": Email sent by CDE, which also contains the document detailing the information transmitted. This document is also provided: Document 6 BIS: "SENT TO CAMERDATA 2022v7.docx"
The following is provided as proof of the transmission made by CDE on June 27, 2023, in the attached files:

Document 7: "email_envío_CDE_27-06-2023.msg": Email sent by CDE, which also contains the document detailing the information transmitted. This document is also provided. Document 8: “SENT TO CAMERDATA 2023_v1.docx”:
Regarding the content of the information transmitted, it consists of two files

received from CDE:
1) As stated, a file with the following format: NUMBER: sequential number that CDE assigns to each individual entrepreneur MD5 CODE: MD5 code resulting from applying the MD5 algorithm to the NIF 2) And another file with the following format,
as detailed in the document “SENT TO CAMERDATA 2023_v1.docx”:

Identification:
Number (sequential number that CDE assigns to each individual entrepreneur)
Name (last name and first name)
Regarding the main address:
sg (street acronym)

calle (street name)
numero (street number)
es_pis_pta (staircase, floor, door)
codmun (city code) municipality)

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 64/164

municipality (municipality name)
postal code
Regarding the business address:

sg (street acronym)
calle (street name)
numero (street number)
es_pis_pta (staircase, floor, door)
codmun (municipality code)
municipality (municipality name)

postal code
Activity:
seccion (activity section)
epigrafe (activity code)
origen (origin code)

To this end, the following screenshot, with the first 25 records of the
first
file, shows the following data (MD5 NUMBER/CODE):
Likewise, the following screenshot, with the first 25 records The
second
file contains the following data:

As

As explained in the previous section 5.6., the
following process is applied to these two files: (...) and the MD5 algorithm is applied to each combination. The resulting MD5 code is cross-referenced with the aforementioned first file received from CDE to obtain the correspondence with the sequential number associated with the rest of the data.

8.- You are requested to explain, providing documentary evidence of the statements that support your answer, the reason why CDE applies the hash algorithm to the NIF of the entrepreneurs and the usefulness of the hashes of the NIFs of the self-employed entrepreneurs that CDE provides you. In short, you are required to provide detailed information on the purpose of processing this data (the hash of the NIF of each of the self-employed entrepreneurs that you acknowledge receiving from CDE).

Response:

"This company understands that such explanation and accreditation is the sole responsibility of CDE, as this is a decision that falls within the jurisdiction of the company and its IT departments."

9. In its response to the information request from the Data Inspectorate, CAMERDATA provided a list of all the data contained in its company database regarding self-employed entrepreneurs and mentioned among them the so-called "Camerdata ID" (page 2 of its letter). Furthermore, in the Excel document that CAMERDATA provided to the Data Inspectorate attached to its response to the information request—a list of 500 self-employed individuals corresponding to the records obtained by sorting them alphabetically by first surname,

beginning with the letter "P"—the "Camerdata ID" field appears filled in with an alphanumeric data.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 65/164

Please provide information on the precise meaning of the "Camerdata ID" field; the origin of the alphanumeric data entered for each self-employed business owner record in the "Camerdata ID" field; the procedure used to generate it; if applicable, the type of personal data used to generate it and whether the cryptographic key is available to decrypt it; the purpose of its processing and whether or not it is subject to transfer; and, if applicable, the identity of its recipients.

Response:

"The "Camerdata ID" field is an identifier used as a key to identify each record in the database.

The "Camerdata ID" is obtained as (...)".

Likewise, the recipients of said data are not provided with any cryptographic key to decrypt it.

The "Camerdata ID" data is provided to those who request the business information services offered by CAMERDATA, including, on the one hand, entities in the sector

known as infomediary companies or information reusers, and, on the other hand, end-user customers who request it for their exclusive internal use.

10. In its response to the Inspectorate's request for information, after invoking
the legitimate interest of CAMERDATA and its clients as the legal basis for its

processing of the data of self-employed entrepreneurs, it refers to
the rights and freedoms of the data subjects and states that they "will not be violated by the processing described in this document, since […] 3. The exercise of the rights of data subjects regulated in Articles 15 to 22 of the GDPR is guaranteed."

It is requested that you provide evidence of how data subjects are informed of their rights and how the exercise of these rights by data subjects is guaranteed, in particular the right to object.

Answer:

"Regarding how CAMERDATA informs interested parties of their rights, the following files are attached:
- Document 9: "CONTROL Cámaras Info Autónomos.xlsx", which records semiannual requests to different chambers regarding the need to send newsletters or newsletters to interested parties.

As evidence of these requests, the following files are attached:
- Document 10:
"REMINDER_SENDING_INFO_AUTÓNOMOS_CHAMBER_GIRONA.pdf",
Document 11:

"REMINDER_SENDING_INFO_AUTÓNOMOS_CHAMBER_SABADELL.pdf
Document 12:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 66/164

“REMINDER_SENDING_INFO_FOR_SELF-EMPLOYED_CHAMBERS_VLC.pdf” containing
emails addressed to Chambers, reminding them of the need to publish
bi-annual newsletters or bulletins.

As evidence, a sample of some of the notifications issued

by different Chambers is attached, as an example:
- Document 13: "Bulletin of the Alicante Chamber of Commerce, May 9, 2024.pdf"
- Document 14: "Bulletin_Camara_VLC-March_22_2022.pdf"
- Document 15: "Electronic Bulletin. Wednesday, June 12, 2024.eml"
- Document 16: "DIGITAL BULLETIN OF THE ALICANTE CHAMBER_Include
Information related to self-employed workers.eml"
- Document 17: "BUTLLETÍ SABADELL INFO AUTÒNOMS OK.eml"
- Document 18: "NEWSLETTER OF THE MADRID CHAMBER_Include
noticia_autónomos.eml"

Regarding the location of the content related to the exercise of rights of the interested party, the following file is attached:
- Document 19:
“URL_FOOTERs_CAMERDATA_AND_CHAMBERS_OF_COMMERCE.xlsxx”, with a sample of the footer URLs, both for CAMERDATA and for different Chambers of Commerce, in which interested parties are informed about the Information

for self-employed persons regarding the protection of personal data and the exercise of the rights of interested parties.

Regarding how CAMERDATA guarantees interested parties the exercise of their rights, the following files are attached:
- Document 20: “PROCEDIMIENTO_DERECHOS_INTERESADOS_REV.pdf”, which

describes the system that allows the exercise of the interested party's rights to information, access, deletion, limitation, objection, and rectification in order to guarantee the exercise of these rights.

Document 21: “Protocol_Robinsons_Camerdata.pdf,” which describes the operations of the 24h environment, where actions related to the addition, modification, or deletion of applicants are performed.

- Document 22: “REPLY EMAIL FOR INTERESTED PARTIES.pdf,” which shows the standard email generated by the 24h environment once actions related to the addition, modification, or deletion of applicants have been performed.
- Document 23: “CAMERDATA WEB SCREEN CAPTURE LOG24H.pdf,” which shows a screenshot of the 24h environment access, accessible only by authorized personnel to perform actions related to the addition, modification, or deletion of applicants.

- Document 24: "CRM APPLICATION RECORD CAPTURE INTERESTED PARTIES.pdf", which shows a screenshot with evidence of the registration of requests, the interested parties and their status, as well as the request processing date and the action requested by the interested party.

- Document 25: "SAMPLE EMAILS FROM INTERESTED PARTIES.pdf", with some examples of messages from interested parties requesting to unsubscribe. - Document 26: "SAMPLE EMAILS FROM INTERESTED PARTIES.pdf", with some examples of emails, including the CAMERDATA response, which is generated once your data has been deleted or deleted.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 67/164

11. In its response to the Data Inspectorate's request for information, it stated that the total number of self-employed workers then listed in its database was 1,665,049 and also warned that "not all records have all the data listed above." At the same time, among the listed data that, according to CAMERDATA, is subject to processing, it mentioned the "generic email" (whose origin, it said, is KOMPASS) and the "telephone" data (whose origin, it said, is INFORMA and DATACENTRIC).

a. Please indicate the total number of self-employed registrations that include email and phone numbers in your database, after obtaining the information from KOMPASS, INFORMA, and DATACENTRIC. You are requested to indicate, of the total number of self-employed registrations, what percentage of registrations do not have the "generic email" information completed and what percentage do not have the phone number information completed.

b. Likewise, it is requested that, from the sample of self-employed entrepreneurs provided in the
Research Actions—a list of 500 self-employed individuals corresponding to the records resulting from having been sorted alphabetically by first surname,
beginning with the letter "P"—certify the origin of the telephone numbers listed therein.

Answer:
a. "Total number of self-employed registrations with email address: 0
Total number of self-employed registrations with telephone number: 242,308
Percentage of self-employed registrations that do not have email address information completed:

100%
Percentage of self-employed registrations that do not have telephone number information completed:
82.9%"

b. "The origin of the telephone numbers in the sample is as follows:

Informa Origin: 75
Datacentric Origin (formerly Schober): 7
32 telephone numbers originating from suppliers whose business relationship was terminated before of the application of the GDPR."

12. In its response to the Data Inspectorate's question regarding how it informs data subjects in compliance with Article 14 of the GDPR, it stated that, in compliance with the last paragraph of Article 14.5.b), it had adopted certain compensatory measures to protect the rights, freedoms, and legitimate interests of data subjects affected by the processing of their data:

a. It is requested that you provide documentary evidence of the date on which CAMERDATA posted the information notice on the website of the seven Chambers of Commerce, the text of which it provided to this Agency in its response to the Inspectorate's request.

b. It also stated in its response that it planned to incorporate the text of the aforementioned announcement in the "bulletins and newsletters" that the Chambers of Commerce periodically publish. It is requested that you provide documentary evidence of your response, where applicable, whether this measure is currently in place. and, if so, from what date, in which bulletin, and from which Chamber of Commerce.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 68/164

Answer:

a. "In reference to this point, the following files are attached:

-Document 27: "REQUEST FOR NEW CAMERDATA WEBSITE INFORMATION FOR THE SELF-EMPLOYED.pdf", which contains the email regarding CAMERDATA's request to the provider of the development process for the new CAMERDATA website and the implementation of information for the self-employed, as well as data protection. This inclusion means that all the Chambers' web portals, managed by CAMERDATA, have the same content.

- Document 28:
“PRESSUPOST_TASCA_FOOTER_INFORMACION_AUTONOMOS.pdf”, which

reflects the interactions prior to the implementation of the FOOTER and the agreement on the work to be performed by the web development provider KINCLIENT.

- Document 29: “BUDGET FOR THE IMPLEMENTATION OF THE FOOTER INFORMATION FOR THE SELF-EMPLOYED NEW WEBSITE CAMERDATA.pdf”, which contains the budget from the provider KINGCLIENT, describing the work related to the development of the FOOTER for the new CAMERDATA website.

Regarding said work, the following file is attached:
- Document 30: “KINGCLIENT FRA. 1056401475.pdf", as evidence of the
completion of the work referenced in the previous budget. (Document 29).

-Document 9: "CONTROL_Chambers_Info Autónomos.pdf", which shows the
dates and interaction with the different Chambers in the request, control, updating, and
launching of the websites, as well as the bulletins and/or Newsletters.

Regarding the insertion of the informative text by the Chambers on their own websites,

the files are attached:
-Document 31: "CONFIRMATION_CHAMBER_ALICANTE.pdf"
-Document 32: "CONFIRMATION_CHAMBER_BCN.pdf"
-Document 33: "CONFIRMATION_CHAMBER_CASTELLÓN.pdf"
-Document 34: “CONFIRMATION_CHAMBER_MD.pdf”
, with a list of email addresses and corresponding proof of the date

of insertion of their informational text.

There is no written proof of the insertion of the advertisements for
the Chambers of Valencia, Girona, and Sabadell, as the procedures for their request were made
by telephone. A certificate or conformity will be requested, if necessary,

from these Chambers regarding the insertion, as indicated in the attached document “CONTROL_Chambers_Info Autónomos.pdf” (Document 9), which
controls these operations.”

b. "This measure is currently in place. The dates of submissions by the Chambers, as well as the start date of these submissions, are recorded in each case in the following file:
- Document 9: "CONTROL_Chambers_Info Autónomos.xlsxx".


C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 69/164

In response to this point, the following files are attached:
-Document 13: “Alicante Chamber Bulletin, May 9, 2024.pdf”
-Document 14: “Bulletin_Camara_VLC-March 22, 2022.pdf”
-Document 15: “Electronic Bulletin. Wednesday, June 12, 2024.eml”
-Document 16: “ALICANTE CHAMBER DIGITAL BULLETIN_ Add Information

Regarding Self-Employed Workers.eml”
-Document 17: “SABADELL BUTLLET INFO AUTÒNOMS OK.eml”
-Document 18: “MADRID CHAMBER NEWSLETTER_ Add "noticia_autónomos.eml" containing emails with examples of bulletins and newsletters from different chambers and including the text transcribed in our written statement of allegations dated May 16 of this year.

The following files are attached:
- Document 10:
“REMINDER_SENDING_INFO_FOR_SELF-EMPLOYED_CHAMBERS_GIRONA.pdf”,
Document 11:

“REMINDER_SENDING_INFO_FOR_SELF-EMPLOYED_CHAMBERS_SABADELL.pdf
Document 12: “REMINDER_SENDING_INFO_FOR_SELF-EMPLOYED_CHAMBERS_VLC.pdf”
which compile a sample of the requests submitted semiannually to
different Chambers. This action is carried out by CAMERDATA proactively and is included in the draft ASEDIE code of conduct, as one of the proposed compensatory measures referenced, pending resolution by

the AEPD.

13.- You are requested to provide documentation proving that the "SmartAddress Services" contract, signed on February 3, 2020, between CAMERDATA and DMOVO ANALYTICS, a copy of which was provided as Annex 25 with the response to the Data Inspection, was in effect on the date the request was made, October 19, 2023, and was received by CAMERDATA on October 20, 2023, since the eighth clause of the contract states "This contract will have a term of three years," meaning that its term would have ended on February 3, 2023. If there is another contract that replaced it, you are requested to provide a copy.

Answer:

“Clause Eight of the “SmartAddress Services” contract, entered into on
February 3, 2020 between CAMERDATA and DMOVO ANALYTICS, provides literally that:

“EIGHTH. - TERM OF THE CONTRACT.
This agreement shall have a term of three years.
Notwithstanding the foregoing, the Parties agree that this Agreement shall be deemed

to be automatically extended for successive annual periods, starting from the
end of the initial term provided for in the preceding paragraph, unless, at least TWO MONTHS in advance of the expiration date of its initial term or
any of its extensions, either Party sends the other reliable communication
to the contrary.”

Since no communication was made between the parties contrary to the agreed automatic annual extension, there is no doubt that the contract was in force on 10/19/2023, the date on which the information request was sent by the AEPD.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 70/164

As documentary evidence of this fact, the annual invoice FV230576 issued by DMOVO ANALYTICS to CAMERDATA SA on 02/27/2023 is provided as Document
35: “invoice FV230576 from DMOVO to CAMERDATA SA.pdf”,

corresponding to the services for the period between 02/03/2023 and 02/02/2024, since Clause The ninth clause of the Contract establishes a cost of €24,000 per year for all services.”

14. You are requested to provide document Annex I to the “SmartAddress Services” contract signed on February 3, 2020 between CAMERDATA and DMOVO ANALYTICS.

The first clause of the aforementioned contract refers to Annex I in its third paragraph and states: “The specifications and technical requirements of the services to be provided are detailed in ANNEX I (SmartAddress Offer) to this Contract, which will consist of the specific services to be provided by Dmovo and accepted in all their terms by THE CLIENT, and which will be incorporated into this document as an integral part thereof for all purposes.”

Response:

"Attached is the file:

Document 36: "Oferta-SmartAddress.pdf", the SmartAddress Offer, which, as
specified in the document itself, is a commercial offer for services,
worked on between the parties prior to the signing of the contract, detailing the
specifications and technical requirements of the services to be provided."

15.- Please inform us whether, during the term of the "SmartAddress Services" contract, DMOVO ever requested CAMERDATA's authorization to
transfer the information obtained to third parties or use it for its own benefit, and whether CAMERDATA ever authorized this processing. In this regard, the
sixth stipulation of the aforementioned "SmartAddress Services" contract allows

DMOVO to provide confidential information received from CAMERDATA to third parties or use it for its own benefit if it has previously obtained your consent for such processing.

Answer:
"During the term of the contract, CAMERDATA has not authorized DMOVO on

any occasion to transfer the information covered by the contract to third parties, nor has it authorized DMOVO on
any occasion to use said information for its own benefit."

16. The "Confidentiality and Data Processing Agreement" signed with

DMOVO on December 18, 2019 refers to the existence of a business relationship between
both entities - "RN" - within the framework of which data processing takes place, to which the aforementioned Agreement is
applicable. You are requested to provide a copy of the contract or contracts or agreements that governed the aforementioned "RN."

Answer:
"The business relationship –"RN" – referred to in the "Confidentiality Agreement"
entered into with DMOVO on 12/18/2019 is the one that is finally established through the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 71/164

signing of the "SmartAddress Services" contract, signed shortly after on 02/03/2020
between CAMERDATA and DMOVO ANALYTICS.

Despite what is stated in Statement I of the Confidentiality Agreement, there has not been
any other business relationship formalized between CAMERDATA and DMOVO ANALYTICS prior to said Confidentiality Agreement. The origin of this factual error is unknown, as CAMERDATA's address subsequently changed. It could be assumed that it was probably due to the circumstance of that
the Agreement and the "SmartAddress Services" Contract were being negotiated at the

same time, and that the Agreement was ultimately signed before the terms of the Contract were fully
specified, so it may well have been that Manifesto I was mistakenly
carried over from an initial draft of the Agreement.

Furthermore, the date of February 15, 2016, cited in Manifesto II of the

"Confidentiality Agreement" signed with DMOVO on December 18, 2019, refers to the
date of the Business Database Transfer agreement between the Spanish Chamber of Commerce and Camerdata. We understand that the wording of Manifesto II of the
"Confidentiality Agreement" signed with DMOVO on December 18, 2019, could lead to
some confusion in this regard, but the truth is that there is no prior contract or
agreement with DMOVO.

17.- You are requested to provide proof of the connection between the "SmartAddress Services" contract, signed on February 3, 2020, and the "Confidentiality and Data Processing Agreement" signed with DMOVO on December 18, 2019. This document has been provided to this Agency with its objections to the initial agreement (Annex 6). This document has been provided to this Agency, given that it has stated

in its objections that the provisions of Article 28.3 of the GDPR that are missing
from the "SmartAddress Services" contract are included in the Confidentiality Agreement that it now provides.

Answer:

"As stated, the business relationship – "RN" – referred to in the "Confidentiality Agreement" entered into with DMOVO on 12/18/2019 is none other than the one finalized by the signing of the "SmartAddress Services" contract, signed on February 3, 2020 between CAMERDATA and DMOVO ANALYTICS.

In this sense, in pre-contractual relationships, it is advisable and customary to sign a confidentiality agreement between potential future contractors prior to signing the corresponding service contract, in order to advance their negotiations and properly specify the terms of the future contractual relationship.

In any case, the link between the aforementioned Confidentiality Agreement and the "SmartAddress Services" Contract is evident to the contractual parties, since in their business relationships they are subject to both contractual documents, fully complying with the provisions thereof."

18.- In its submissions to the initiation agreement, it has stated that it complies with the
provisions of Article 28.3 of the GDPR and that the contract for the provision of certain services it signed with DMOVO on February 3, 2020 - the "SmartAddress Services" contract - "establishes both the "object, duration, nature, and purpose of the processing" and "the type of personal data, categories of data subjects, and the obligations and rights of the controller," as required by the aforementioned

article." Please specify or transcribe the stipulation of the "SmartAddress Services" contract, which, in your opinion, indicates the "type of personal data" that CAMERDATA transfers to DMOVO in connection with the development and execution of the service provision contract and, consequently, is processed by DMOVO.

Answer:

“On the one hand, Clause Five of the “SmartAddress Services” contract specifies the data normalization processes to be performed. These processes are:
- Population normalization (INE),
- Street normalization (INE),

- Postal code assignment,
- Census section assignment (INE),
- Coordinate assignment,
- Grid assignment (GRID 100x100),
- Name normalization, and
- Delivery of the file in the format defined by the CLIENT.

Therefore, to enable the execution and purpose of the contract, the data submitted for processing is strictly necessary for DMOVO to carry out the processes covered by the contract.
For its part, Clause Eight of the contract specifies the duration of the processing.
On the other hand, the contractual obligations arising from the “SmartAddress Services” Contract are completed and integrated with the contractual regulations contained in the Confidentiality Agreement, which substantially contains the remaining provisions of Article 28.3 of the GDPR. In particular:

-Manifesto II refers to the purpose of the processing and the type of personal data and categories of data subjects, as the business data provided by the CDE and those contained in the CAMERDATA Spanish Business File are processed, as well as the nature and purpose of the processing consisting of the homogenization and transfer of said data to the aforementioned File.
-Second Agreement, section 2.1, establishes a general obligation to observe and comply with the provisions, specifically regarding the processing of personal data, in the LOPDGDD and the GDPR.
-Second Agreement, sections 2.2 and 2.3, establishes the stipulations contained in letters a) to h) of Article 28.3 of the GDPR. GDPR"

19.- According to the SmartAddress Services Agreement signed on February 3, 2020 between

CAMERDATA and DMOVO, the latter, in order to provide the contracted services,
receives "confidential information" from CAMERDATA.

a. You are requested to inform and provide documentary evidence of what data DMOVO has access to in order to provide CAMERDATA with the services covered by the agreement. (Note: You are not

requiring the data that is subject to standardization by DMOVO,
names and addresses).

b.- Please inform us whether, in order to streamline and facilitate the provision of the standardization service and ensure data integrity, CAMERDATA provides

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 73/164

DMOVO, in addition to the information (all or part) contained in each record in its database, the "hash" obtained as a result of applying this function to the information provided.

Answer:

a. "The data used for the standardization service is as follows:
Name, Street Name, Street Name, Street Number, Staircase-Floor-Door, Municipal Code, Municipal Name, and Postal Code.

Furthermore, it should be noted that the term "Confidential Information" in
Clause Six of the "SmartAddress Services" contract should be understood, as
is usually the case in contracts that use this term, that the
data provided to DMOVO to provide the contracted service may only be

used for the provision of said service, and may not be used for
any other purpose or transferred to third parties without prior written authorization from
CAMERDATA.
This follows from Clause Six of the contract, according to which:

"SIXTH. - CONFIDENTIALITY.

Dmovo undertakes to accept confidential information within a framework of trust for the proper execution of the agreed services and not to provide it to any third party or use it for its own benefit without obtaining the prior written consent of the other party.
The same is established in "First Agreement - Confidentiality", section 1.1 of the

"Confidentiality Agreement."

b. At no time is the "hash" provided to DMOVO.

20. CAMERDATA stated in its submissions to the initiation agreement that the

Italian Supervisory Authority "approved in 2021 the Code of Conduct for the processing of personal data for commercial information purposes, according to which the processing of such data for such purposes does not require the consent of the data subject, but is necessary for the pursuit of the legitimate interests of the providers who provide commercial information services and of the clients who request them for legitimate checks, as well as the common interest in the fairness of commercial transactions and the proper functioning of the market."

You are requested to provide a full copy of the aforementioned document and a link to the website of the Italian Data Protection Authority that allows access to the aforementioned document.

Answer:

“The “Guarante per la protezione dei dati personali,” the Italian supervisory authority, approved
in 2021 the Code of Conduct on Commercial Information, promoted

by the National Association of Commercial Information and Credit Management Companies (ANCIC). The Code was published in the Official Gazette of the Italian Republic,
“GU General Series no. 124”, dated May 26, 2021, and can be consulted at the
following link:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 74/164

https://www.gazzettaufficiale.it/atto/serie_generale/caricaDettaglioAtto/originario?
atto.dataPubblicazioneGazzetta=2021-05-
26&atto.codiceRedazionale=21A03063&elenco30giorni=false

For easier access to the aforementioned Code of Conduct, we attach the following file:
-Document 37: “Download the Italian Code of Conduct as it appears on the referenced website.pdf” as it appears on the referenced website.

21. CAMERDATA has stated in its allegations to the initiation agreement that it "receives from CDE the NIF of individual entrepreneurs and self-employed persons encrypted with the MD5 (Message Digest Algorithm 5) algorithm, commonly used to securely store data. The algorithm used is a HASH or unique fingerprint, and its main characteristic is that it is not possible to obtain the input value (NIF)

corresponding to an output value (HASH or MD5 fingerprint), so it is Camerdata that obtains the NIF by its own means." It is requested to provide information:

a. Whether, in addition to the encrypted NIF of individual entrepreneurs, CDE also
provides CAMERDATA with that data, the NIF, in plain text.

b. Whether CDE provides CAMERDATA with the algorithm used to encrypt the NIF data.

c. Yes, with respect to the remaining data of self-employed entrepreneurs other than the NIF (Tax Identification Number)
that CDE provides to CAMERDATA—whether for all or some of them—it also provides, in addition to the plain text of the data, the hash resulting from applying the algorithm

to that input information.

Answer:
a. "As stated, CDE does not provide the NIF data in plain text, but rather encrypted
with the MD5 code."

b. "No, CDE does not provide CAMERDATA with the algorithm used to encrypt the NIF data."

c. "No, CDE does not provide CAMERDATA with the hash resulting from applying the algorithm
to the remaining data other than the NIF of self-employed entrepreneurs."

22.- With its response to the Inspection request, CAMERDATA has provided, document 24, the contract signed with KOMPASS ESPAÑA, S.L.U. on 03/20/2023,
by virtue of which "CAMERDATA will transfer to KOMPASS the NIFs of the records contained
in the FEE database for which KOMPASS has the URL field informed and that

CAMERDATA does not have the generic email field (145,101 records)" and
"KOMPASS will transfer to CAMERDATA the records resulting from the webcrawling work for which the generic email field has been obtained, the
following fields:
- NIF - URL used for webcrawling (especially the universe of the

145,101 records) - The generic email obtained (as many as have been obtained per record)"

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 75/164

In order to determine the number of records covered by the contract, the The parties
previously cross-reference their databases. Thus, Clause 4 of the contract, "Economic Conditions," states: "Having carried out preliminary cross-referencing of both databases to verify the number of records covered by the contract, the following results were obtained: [..]."
Please provide information on the database cross-referencing process between CAMERDATA and KOMPASS.

Response:

"As stated, the contract with KOMPASS is intended for web crawling work solely related to legal entities.

The database cross-referencing process was as follows: KOMPASS provided CAMERDATA with the list of tax identification numbers of legal entities contained in its database,

with the URL field provided. From this list, CAMERDATA identified 145,101 legal entity records on which processing was performed."

23.- In the contracts that CAMERDATA signed with CERVED GROUP S.p.A. on
August 23, 2021, and with Axesor Conocer Para Decidir, S.A. (initially INFOTEL) on May 24, 2018—which includes the Addendum of July 25, 2012 to the 2009 contract and its

Annex I—it is stated that CAMERDATA provides these contracting parties with a hash, in addition to providing them with certain data on the self-employed entrepreneurs in plain text.

The contract with CERVED—document 19 submitted with its response to the Inspection request—indicates in its second clause, "Data Supply Conditions," that it provides the "CAMERDATA MD5 internal code" in addition to the "company name," the trade name, the Spanish identification code, the full address, and the IAE activity code, among other items.

For its part, the contract with AXESOR, specifically the 2012 Addendum, details in its second clause the data that CAMERDATA provides and refers to Annex I. A distinction is made between "File 1," relating to legal entities, and "File 2," relating to "main physical entities and branches, except for companies with IAE 8612." File 2, in addition to indicating that it is providing the "CIF", which it describes as
"Legal/Physical Sequential CIF", the company name, the trade name, the

street name and number, and the "other addresses", adds the "MD5" that it describes
as "Camerdata Internal Code".

The following are requested:
a. To provide documentary evidence of your response: the input information, the information to which the hash function is applied, and the resulting "Camerdata Internal Code".
b. If the "MD5" described in the AXESOR contract as "Camerdata Internal Code" and
the "CAMERDATA MD5 Internal Code" of the contract with CERVED are exactly the same
as the "Camerdata ID".

Answer:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 76/164

a. The "Camerdata Internal Code" field is obtained by applying the MD5 algorithm to a string resulting from concatenating the sequence number, street name, street name, street number, other address, postal code,

and city.
As an example, and to verify the answer, use the input string:
"CDT5DM000014322 ALBAIDA 0022 02 A 28037 MADRID"
The following "Camerdata Internal Code" would be obtained:
86dfad075717546b578a4891d80c1efa"

b. "The "MD5" described in the AXESOR contract as the "Camerdata Internal Code" and
the "CAMERDATA MD5 internal code" of the contract with CERVED are exactly the same as the "Camerdata ID."

24.- In relation to the contract signed with INFORMA D&B, S.A.U., on September 29, 2022,

(provided as document 10 with its response to the Inspection request), you are requested to provide Annex I, mentioned in clause six, "Confidentiality," which the aforementioned clause states "forms an integral part of this Agreement."

Although CAMERDATA has provided its response to the Inspection's request,

also included in document 10, the so-called "Annex I Confidentiality Agreement regarding the FIBAEMP_prenorm.TXT file," which is undated, the
content of this document—which relates to a processing order and has a
much narrower scope than the September 2022 contract—demonstrates that this cannot be the Annex referred to in the sixth stipulation.

Answer:
“The Unified Collaboration Agreement signed between INFORMA D&B, S.A.U and CAMERDATA on 09/29/2022 (document 10 provided at the time) constitutes, as
results from its Exhibits III, IV, and V and its First Clause, a unification into a single

contractual text of the initial collaboration agreement between both parties dated 01/01/2004
and its subsequent partial modifications made through annexes dated 12/01/2013, 04/15/2016, 04/13/2018, and 05/24/2018, among others.

Therefore, the aforementioned First Clause of the contract of 09/29/2022 provides that:

“By this Unified Collaboration Agreement, the rights and obligations and all the The clauses contained in the contracts and annexes reproduced below are hereby replaced by the terms of this Unified Collaboration Agreement.

In this process of unifying the regulation of the contractual relationship between INFORMA and CAMERDATA, the “Annex I Confidentiality Agreement in relation to the FIBAEMP prenorm.TXT file” was included as an annex to the Unified Collaboration Agreement of September 29, 2022. This was the Confidentiality Agreement signed on April 15, 2016, along with the Annex to the initial agreement of the same date. This agreement was not fully adapted to the new Unified Agreement. For this reason, there are discrepancies between the Unified Agreement and its Annex I.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 77/164

For this purpose, the Confidentiality Agreement is attached as Document 38: “2016_Conveni Informa
2016_Confidencialidad PreNormalización FIBAEMP”, Confidentiality
of April 15, 2016, which is the same "Annex I Confidentiality Agreement in relation to the FIBAEMP prenorm.TXT file," albeit with some minor modifications.

However, this does not mean in any way that Annex I does not govern the contractual relations between INFORMA and CAMERDATA, nor does it in any way restrict the current rights and obligations regarding the protection of personal data, as both parties are fully subject to the GDPR and LOPDGDD regulations, as expressly established in Clause Seven of the Unified Agreement of September 29, 2022. Therefore, there is no doubt, and both contractual parties understand this, that Annex I must be understood in the terms and to the fullest extent of the Unified Agreement and the new regulations on personal data protection.

ELEVENTH: On March 11, 2025, the investigating officer of the procedure proposed a resolution requesting that the President of the AEPD sanction CAMERDATA for violating Article 6.1 of the GDPR with a fine of €200,000 and for violating Article 14 of the GDPR, with a fine of €60,000.

The following violations attributed to it in the initiation agreement were also proposed to be closed:

Violation of Article 6.1. of the GDPR consists of "Having provided the company
KOMPASS with its File for the dual purpose of providing a feedback service for the information collected therein and for use by this entity
for its own activities."

Violation of Article 28 of the GDPR

Finally, it was proposed that the following measures be ordered:

(i) Within a maximum period of one month from the date the sanctioning resolution was issued, the deletion of all personal data relating to

self-employed entrepreneurs contained in the CAMERDATA files originating
from the transfer of databases made by the Spanish Chamber of Commerce.
(ii) Within a maximum period of one month from the date the sanctioning resolution is issued, cease processing personal data relating to self-employed entrepreneurs from the Spanish Chamber of Commerce until it has a legitimate basis.

(ii) Within a maximum period of three months from the date the sanctioning resolution is issued, inform the Court, in accordance with Article 14 of the GDPR, of the processing of the personal data of self-employed entrepreneurs by means of a personalized announcement or one that is relevant due to its format and nature. The inclusion of a general announcement on the Chambers of Commerce's website is not sufficient.

TWELFTH: On March 27, 2025, this Agency received a written statement of allegations
from CAMERDATA, which briefly focused on stating that there had been a
violation of the principle of criminality, absence of violation of Article 14, absence of

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 78/164

culpability and the existence of causes excluding culpability, as well as a violation
of the criteria applied to classify the sanction and a violation of the principle of proportionality, with respect to both violations, and the inappropriateness and

disproportionality of the proposed corrective measures.

Based on the actions taken in this proceeding and the documentation in the file, the following have been established:

PROVEN FACTS

FIRST: On February 15, 2016, the CDE (as assignor) and CAMERDATA (as assignee) signed a "Business Database Transfer Agreement," effective as of the date it was submitted to the Data Inspection, December 20, 2023.

The file subject to the transfer is named "Basic Business Census" and "Transferred Database" in the agreement.

SECOND: The contract determines in the clauses (agreements) and explanatory notes that are reproduced below what information the file subject to the transfer must contain, the purpose for which the transferee is expected to process the data, the conditions under which the transferee may transmit it to third parties, and the obligations assumed by both contracting parties regarding the downloading of information and updates:

- Regarding the "object" of the contract, the companies to which the information included in the file (records) refers, and the "information fields" related to each record that must be included in the transferred database, it stipulates:

"Object" (first agreement):

"1.1. By this Contract, the Transferor assigns and transfers to the Transferee, who, in turn, receives and acquires for itself a copy of all the business data contained in the Basic Business Census referred to above. Exhibit V (hereinafter the Transferred Database) updated as of January 2016, which
contains the information fields indicated in Annex I of 3,160,984
Company Registries.”
“[…]the Company Registry is understood to mean all the information fields in Annex
1 relating to each of the companies contained in the Transferred Database,

taking the company's NIF as the identifier for said registry.”

“1.2. The Company Registries that make up the Transferred Database refer
solely and exclusively to those indicated in the second paragraph of Exhibit V above.”

Company records that make up the database subject to transfer. They are detailed
in Exhibit V of the contract, which states:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 79/164

“Based on the indicated data [those in Exhibit IV] received from the collaborating public authorities (currently the State Agency for Tax Administration, the Agency of the Provincial Council of Navarre, and the Chambers of Commerce of the Basque Country), the Spanish Chamber of Commerce prepares the public census of companies under the name “Basic Business Census,” guaranteeing confidentiality in the processing and the exclusive use of the information received.

This census includes only and exclusively companies whose activity falls within any of the headings of Divisions 1 to 9, inclusive, of the

First Section of Annex I of Royal Legislative Decree 1174/1990, of September 28, approving the rates and instructions for the tax on economic activities, leaving companies whose activities fall within the remaining Sections and Divisions of said Annex excluded from the Basic Business Census.

Information fields relating to each of the companies contained in the Transferred Database. Agreement 1.1. of the contract refers to “Annex I” of the contract, which establishes:

“In accordance with the provisions of the First Agreement of the Contract, the Database

and its updates will contain the following information fields for each company listed therein (hereinafter Company Registry).
Data for each Company Registry
1. NIF
2. Name or corporate name of the company

3. Main address
4. Business address
5. IAE activity section
6. IAE activity”

-Regarding the “Purpose” of the transfer of data by CÁMARA to CAMERDATA, it is
stipulated (Second Agreement):
“The transferee will include the business data from the Transferred Database and its periodic updates in the Spanish Company File owned by it, and will process, complete, and enhance them in accordance with the terms of this Contract for the purpose of commercially offering it to companies and interested third parties

as a database of information on companies operating in Spanish territory."

-Regarding the transfer by CAMERDATA to third parties of the information it receives from the CDE, the contract authorizes CAMERDATA to transfer it once it has been incorporated
into its proprietary file (Spanish Companies File). Thus, it stipulates (seventh agreement):

"7.1.-The Transferee may not transfer, in whole or in part, to a third party the rights and
obligations that correspond to it under this contract, nor the Transferred Database, nor any of its updates, without the prior

express written authorization of the Transferor.
This prohibition excludes the transfer of data from the Transferred Database
incorporated in the Spanish Companies File owned by the Transferee, in accordance with the provisions of the Second and Third Agreements of the Contract."

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 80/164

-Regarding the conditions under which the transfer of the Transferred Database and its updates must be carried out, the third agreement (Effectiveness of the transfer)

refers to Annex 2 of the contract, which expressly states that it forms part of it for all purposes. Annex 2 – “Conditions of the Transfer of the Transferred Database” –
specifies, among others, the following obligations of each contracting party:

“For the transfer of the Transferred Database and its updates, the Parties undertake the following:

A) Obligations of the Transferor:
a.1) The Transferor guarantees to the Transferee:
(i) […]
(ii) That the data included in the Transferred Database and its updates are obtained from the public business census regulated by Law 4/2014, prepared by the

Transferor under the name of the Basic Business Census.
a.2) The transfer of the Transferred Database and its updates:
(i) Will cover all the information fields indicated in Annex 1 of the Business Database Transfer Agreement of February 15, 2016 (hereinafter the agreement) that the Assignor has at its disposal at the time of its preparation.

B) Obligations of the Assignee:
b.1) The Assignee undertakes to incorporate the information from the Assigned Database into the Spanish Company File and to process and market it under the terms agreed in the Contract and its Annexes.

b.2) The Assignee undertakes to always keep the business data in the Spanish Company File up to date and, to this end, undertakes to:
(i) Obtain from the Assignor all updates to the Assigned Database that the latter periodically makes within the following fifteen (15) business days [..].
(ii) Not to assign or market the Assigned Database or its updates, and not to

make copies other than backup copies.
(iii) Incorporate the information from the Company Registries of the updated Assigned Database into the Spanish Company File within the following thirty (30) business days. as of the date it is received from the Assignor […]”
(iv) Carry out said update by overwriting the Spanish Company File
with the information from the Assigned Database updated for each Administration Code submitted.

Consequently, the Assignee shall be obliged to delete
from the Spanish Company File the information from the Assigned Database previously submitted regarding said Administration Codes, which shall be
completely replaced and void, and the Assignee shall not be able to use said information for the purpose of the Contract or for any other purpose; may only

keep it blocked and available to public authorities, judges, and courts […]”

b.3) The Assignee may only inform interested third parties that the
source of the information in the Spanish Business File relating to the fields

in Annex 1 of the Contract corresponds to that of the Basic Business Census
when said file has incorporated the information from the Assignor's latest updated Assigned Database. Otherwise, it may not disclose said
source.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 81/164

b.4) Upon receipt of the Assigned Database or its update, the Assignee
will:

(i) Standardize names and addresses […]
(ii) Incorporate the information from the Assigned Database or its updates
processed in this way into the Assigned Database Spanish Companies owned by the Assignee.

b.5) The Spanish Company File that the Assignee develops and markets will have the following characteristics:

(i) The company registry and the fields of the Assigned Database indicated in Annex 1 of the Contract. The remaining fields of said File will not modify, alter, or contradict the fields of the Assigned Database and its updates.
(ii) Fields developed by the Assignee based on algorithms created by it.

(iii) Fields provided by the Assignee: such as Legal form, main activity, registered office, branches, business activity.
(iv) Fields provided by other legitimate and up-to-date sources: Business name, telephone number, fax number, CNAE (National Tax Code), website, date of incorporation, number of employees, turnover, imports/exports, positions (up to 5 positions with first and last names), type of company (for distinguish when it comes to autonomous non-sections 2 or 3), geodetic coordinates (in 3 universal systems), or others.”

b.6) The Assignee undertakes to provide the Assignor in a medium […] with the necessary data and information from the Spanish Business File […] for the

sole purpose of enabling the Assignor to verify compliance with the terms agreed in
the Contract and its Annexes. […]”

THIRD: CAMERDATA states (response of 11/13/2023 to the Inspection request) that “all the data contained in the CAMERDATA business database regarding self-employed workers” are:

“NIF, Company name, Business name, Generic email, Address, Postal Code, Municipality, Province, County, Census section, Telephone, Telephone 2, Company type, Main activity IAE, All IAE activities, Address type, Number of branches, Website, Year of incorporation, Employees, Imports/exports,

Company type, CNAE activity, Latitude wgs84, Longitude wgs84, Type coor
wgs84, ID Camerdata.”
It adds that not all records of self-employed entrepreneurs included in its file (which, it says, totals 1,665,049) have all the data indicated.

FOURTH: CAMERDATA states (response of 11/13/2023 to the Inspectorate's request) that the source of the NIF data for individual entrepreneurs included in its business database “is the public business census published by the Spanish Chamber of Commerce.”

It states (response to the Inspectorate's request):

“The NIF data is the Tax Identification Number.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 82/164

The data is sourced from the public business census published by the Spanish Chamber of Commerce in accordance with Law 4/2014 (hereinafter, the
Public Business Census). It is obtained each time a new business census is uploaded.
The NIF data is provided to clients who request the business information services offered by Camerdata, including, on the one hand, entities in the sector known as infomediary companies or information reusers (Axesor, Cerved, Datacentric, Equifax, Informa, Iberinform, and Moody's) and, on the other hand, end-user clients who request it for their exclusive internal use.

FIFTH: CAMERDATA acknowledges (allegations to the agreement initiating this procedure) that the NIF data does not appear in the public business register: "It is true that this data does not appear in the public business register."

It states that CDE does not provide it with the NIF data of self-employed entrepreneurs and that it obtains it through its own means. It receives it encrypted using an MD5 algorithm:

"With regard to the NIF data, it is true that this data does not appear in the public business register, and CDE does not provide it to Camerdata in accordance with agreement 12.2 of the contract signed between CDE and Camerdata on February 15, 2016."

"Camerdata receives from CDE the NIF data of individual entrepreneurs and self-employed entrepreneurs encrypted using the MD5 algorithm (Message Digest Algorithm 5), commonly used to store data securely. The algorithm used is a HASH or unique fingerprint, and its main characteristic is that it is not possible to obtain the input value (NIF) corresponding to an output value (HASH or MD5 fingerprint), so Camerdata obtains the NIF by its own means.

SIXTH: Regarding the means by which the NIF data of the self-employed workers is obtained, the following statement (response to the tests) states:

“The NIF is obtained by applying the following process:

- Input: file received from CDE (*) with the following format:
NUMBER: sequential number that CDE assigns to each individual entrepreneur
MD5 CODE: MD5 code resulting from applying the MD5 algorithm to the NIF (*)”

Specifically, for the sample of 500 self-employed workers, these would be the files received from CDE
on June 27, 2023 (northern zone) and March 21, 2023 (national zone).

- Process: all combinations of NIF numbers are generated in the individual entrepreneur format, and the MD5 algorithm is applied to each combination. The resulting MD5 code is cross-referenced with the file received from CDE to obtain the corresponding sequence number associated with the rest of the files. data.

SEVENTH: CAMERDATA provides, as proof of the transmission made by CDE:

On 03/21/2023: Document 6: “email_envío_CDE_21-03-2023.msg”. This is the email sent by CDE, which, in turn, contains the document detailing the transmitted information. Document 6 BIS: “SENT TO CAMERDATA 2022v7.docx”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 83/164

On 06/27/2023: Document 7: “email_envío_CDE_27-06-2023.msg”. This is the email sent by CDE, which contains the document detailing the transmitted information (Document 8: “SENT” A CAMERDATA 2023_v1.docx”)

The information transmitted consists of two files received from CDE:
1) A file with the following format:
NUMBER: Sequential number that CDE assigns to each individual entrepreneur
MD5 CODE: MD5 code resulting from applying the MD5 algorithm to the NIF

2) Another file with the following format, as detailed in the document “SENT
TO CAMERDATA 2023_v1.docx:
Identification:
Number (sequential number that CDE assigns to each individual entrepreneur)
Name (first and last name)

Regarding the main address:
sg (street acronym)
calle (street name)
numero (street number)
es_pis_pta (staircase, floor, door)
codmun (municipality code)

municipio (municipality name)
codpos (postal code)
Regarding the address of Activity:
sg (street acronym)
calle (street name)

numero (street number)
es_pis_pta (staircase, floor, door)
codmun (municipality code)
municipio (municipality name)
codpos (postal code)

Activity:
seccion (activity section)
epigrafe (activity code)
origen (origin code)

Provide a screenshot stating that it corresponds to the first 25 records

of the first file, containing the following data (MD5 NUMBER/CODE). And a screenshot with the first 25 records of the second file.

EIGHTH: The Spanish Chamber of Commerce has stated:

1. In the response to the Inspection request (dated 12/20/2023):
That the "public business census" contains, among other things, the "NIF field." And that
it provides CAMERDATA with all the fields related to the data of the self-employed entrepreneurs it processes. This is stated in the response to the Inspection request:

When asked about what data on self-employed entrepreneurs it processes:
"All the data contained in the Chamber of Spain's public business census regarding self-employed or individual entrepreneurs are detailed:" and
it mentions: The "NIF field", "Name field"; "Address field"; "Postal Code field"; "Province Code field"; "Province field"; "Municipality Code field";
"Municipality field"; "Heading field"; "Description field" and "ID field".

When asked about the transfer of data from the public business census to third-party entities, including CAMERDATA:
“The fields listed above are provided solely to CAMERDATA, S.A., as a commercial entity established by multiple Spanish Chambers of Commerce and the Chamber of Spain, for inclusion in its Spanish Business File, for the purpose of legitimately processing, completing, and enriching them, and to have a quality database of companies operating in Spanish territory so that it can be offered to interested companies and third parties. […].”

2. In the allegations to the agreement initiating procedure EXP202301678, CDE states that it does not transfer the NIF data of self-employed entrepreneurs to CAMERDATA,

but rather provides a “hash,” the result of an encryption process, “so the truth is that Camerdata does not receive these NIFs from CDE.”

NINTH: Regarding the public business census:

1. It is proven that the public business census is published openly through

the CDE website, www.camara.es, and that the information it provides regarding
individual business owners relates exclusively to the following data: first name,
last name, address, postal code, municipality, and activity. The NIF (Tax Identification Number) is not published.

This is confirmed by the screenshots obtained from the CDE website on
September 16, 2024, incorporated into the file by means of a Diligence dated September 17, 2024, which
allow us to verify the following:
a. That on the website www.camara.es (www.camara.es/funcion-consultiva/consulta-
del-censo-publico-de-empresas) under the heading "Public Business Census" there is

a list of options, and the first of these—"Description"—offers the following
information regarding the "Public Business Census":
"We provide you with the data included in the Public Census, which contains all the
legal and physical entities of the Official Chambers of Commerce, Industry,
Services, and, where applicable, Navigation of Spain."

That the file "contains one record per activity (it does not accumulate several activities
at the same address) and compiles the following data per record: Name,
Address, Postal Code, Municipality, Activity." The NIF (Tax Identification Number) is not mentioned.

b. That, when a query is made about an individual entrepreneur in the public business census

– from the "Public Business Census," the "Database" option (which says
"access our database from here"), which redirects to the "Consult the National Business Census" screen – the query result offers only the following information: first and last name, postal address (street name and number),
postal code, province and municipality name, IAE code, and description of the

activity. The NIF (Tax Identification Number) is not included.

2. It is confirmed in the file that when a query about an individual entrepreneur is made to the "public business census" through the corporate website of

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 85/164

CDE - from the "Public Business Census", "Database" option (which says "access our database from here"), which redirects to the "Consult the National Business Census" screen - the information provided includes a link to the CAMERDATA website preceded by this legend: "If you wish to obtain more information, consult the Camerdata Online Business File"

TENTH: In relation to the alphanumeric data "Camerdata ID" that appears for each self-employed entrepreneur record in the "Camerdata ID" field, CAMERDATA has declared (response to the procedure of (proof):

 That the "Camerdata ID" field is an identifier used as a key
to identify each record in the database.
 That it is obtained by applying the MD5 algorithm to a string of

characters resulting from concatenating the sequential number, street acronym,
street name, street number, other address, postal code, and city. And
adds "Therefore, no personal data is used to generate the "Camerdata ID" data."
 That the Camerdata ID is provided to those who request information services

from companies that offer CAMERDATA: entities in the sector known as
infomediary companies or information reusers and end-user clients who
request it for their exclusive internal use. The cryptographic key is not provided
for decryption.

ELEVENTH: CAMERDATA invokes legitimate interest (Article 6.1.f) of the GDPR) as the legitimate basis for processing, which consists of collecting data from the CDE, incorporating it into its systems, purifying, enriching, and transferring it to third-party clients. The data is collected from the CDE, incorporating it into its systems, purifying, enriching, and transferring it to third-party clients (response to the Inspection request of 11/13/2023). It adds that the data is obtained from public sources and that it is presumed, unless proven otherwise, that the legal basis of Article 6.1.f) of the GDPR is met by virtue of the provisions of Article 19 of the LOPDGDD.

In this regard, it has stated:
-“the legitimate interest of both Camerdata, [...], and the client accessing the data
is to promote their services and products to third parties interested in them,

as well as to provide information about individual entrepreneurs or professionals to third parties interested in contacting them to contract their services
or purchase their products.”
-“[…] the data of individual entrepreneurs, insofar as they act in such a capacity,
enjoy completely different protection from the personal data of natural persons with regard to their personal or private sphere of activity, since
Article 19.2 of the LOPDGDD establishes a legal presumption "iuris tantum" that
the processing of the data of self-employed persons or individual entrepreneurs is lawful under
Article 6.1.f) of the GDPR when certain requirements are met, specifically,
when they refer to them solely in such capacity and are not processed to establish
a relationship with them as natural persons.

[…] this presumption […] exempts the data subject from having to weigh whether
the data controller's interest does not prevail over the interests or fundamental rights and freedoms
of the data subject that require protection of personal data, […].

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 86/164

Thus, [...], in any case, it must be rebutted by means of evidentiary activity to the contrary."

It does not provide a balance of the rights and interests involved in the processing analyzed and, instead, refers to the "balance of judgment" that "has been carried out in the draft Code of Conduct of ASEDIE, an association of which CAMERDATA is a member."

TWELFTH: CAMERDATA transfers its data file, among others, to entities that

subsequently transfer it to their own clients and to clients who acquire it for their exclusive use, whose annual number ranges between 500 and 900 and whose contractual relationship is governed by a "general clause" defined by that company.

The file contains contracts with the following entities, which show that

CAMERDATA transfers its file containing data relating to individual entrepreneurs:

1. INFORMA D&B S.A.U. (hereinafter INFORMA), two contracts:
(i) Dated 01/07/2022, under which CAMERDATA authorizes INFORMA to market its self-employed database through BUREAU VAN
DIJK EDITIONS ELETRONIQUES SRL (hereinafter BVD), a MOODY'S ANALYTICS company.

(ii) Dated 09/29/2022, which states, among other stipulations, that the data included includes the CIF/NIF (Tax Identification Number), name or company name (for individual entrepreneurs), IAE (Tax Identification Number), full address (street, municipality, province), and telephone numbers. It contains

a Data Protection clause that establishes that both parties expressly submit
to the GDPR, the LOPDGDD, Law 34/2021, and all other applicable regulations. This paragraph is included: "For these purposes, CAMERDATA
declares that the data it communicates under this Agreement (Camerdata file) contains personal data of individual entrepreneurs (data subjects)

related to their commercial activity, and never to their private sphere,
and that this processing is lawful under the terms of Article 6.1.f) of the GDPR.

To the extent that CAMERDATA guarantees that the data originates from what has been known as publicly available sources, CAMERDATA guarantees that the data may be used to establish a relationship with said data subjects in their capacity as individual entrepreneurs."

2. Contracts signed between CAMERDATA and AXESOR CONOCER PARA DECIDIR S.A. (hereinafter AXESOR) or, under its previous name, INFOTEL Información y Telecomunicaciones, S.A. (hereinafter INFOTEL) dated September 15, 2009; July 25, 2012 (extension of the previous contract); July 25, 2014 (extension of the previous contract); and May 24, 2018.

The contracts state (first clause) that CAMERDATA will provide: "1.
Information contained in the file owned by it, called Individual Entrepreneurs, in accordance with the service details contained in the ANNEX to this contract, and which is incorporated herein for all purposes. […]

The ANNEX to the contract includes the following information: identifiers, name (company name and trade name, if available), full address (initials, street, number, other address, postal code, municipality, province, county), IAE (Economic Activities Tax), telephone number corresponding to the headquarters address, among other information.

3. Contract signed between CAMEDATA and IBERINFORM INTERNACIONAL S.A., on July 29, 2008, which states that, within the framework of this contract, both parties agree to comply with current legislation regarding the protection of personal data. The contract states that "all information contained in the FEE relates solely to commercial companies and individual entrepreneurs in their commercial aspect, and is outside the scope of data protection legislation, in accordance with Article 2 of the Implementing Regulations of Law 15/1999, of December 13." It is noted that the CLIENT will also use the information provided to enrich its own files.

4. Contract signed between CAMERDATA S.A. and DATACENTRIC, PDM, S.A., dated

April 25, 2017, and the Addendum dated July 19, 2019

5. Contract between CAMERDATA and CERVED GROUP S.p.A., signed on August 23, 2021, by virtue of which the former assigns the database of companies and self-employed workers to CERVED for its business activity, for its internal use and that of its subsidiaries.
That CERVED will also use the information for distribution and marketing to

third-party companies, except for the aforementioned infomediary companies.

THIRTEENTH: The file contains two contracts signed between CAMERDATA and KOMPASS, S.A.

a. Contract dated June 29, 2020, governing the terms of the collaboration between CAMERDATA and KOMPASS regarding the provision of the following services:
- "The transfer of 107,897 tax identification numbers (NIFs) of records contained in the Spanish Company File database [...]
- The transfer of the URL of the 107,897 tax identification numbers (NIFs) in the event that KOMPASS [...]".

b. Contract dated March 20, 2023, governing the terms of the collaboration between CAMERDATA and KOMPASS. The second clause, "Data Supply Conditions", establishes:
"Camerdata will transfer to KOMPASS the NIFs of the records contained in the FEE database for which KOMPASS has the URL field provided and for which Camerdata does not have the generic email field (145,101 records).
Kompass will transfer the records to Camerdata. resulting from the Webcrawling work
for which the email field was obtained, the following fields:
 NIF (Tax ID)

 URL used for Webcrawling (on the universe of 145,101 records)
 Generic email obtained […]”

FOURTEENTH: Regarding the purpose for which CAMERDATA processes the data of the self-employed workers obtained from CDE.

1. CAMERADATA's “Legal Notice on the Use of the Portal and Services” (incorporated by the inspector's diligence of 10/18/2023) states the following:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 88/164

“6. Information on the processing of data (FEE and marketed products) not obtained from the interested party, related to marketing and advertising
6.1. Basic Information

The records processed by Cameradata from the Spanish Company Files database containing personal data have been obtained by CAMERDATA after being legitimately collected, as the data has been obtained from an Official Census prepared by a public body, […]
The processing of these data is for the purpose of sending commercial and marketing communications, offering various goods or services that may be of interest to you.
[…]
6.2.3. Legitimacy of the processing:
[…] is carried out on data obtained from an Official Census prepared by a public body, […] without the need to obtain your prior consent,

based on the legitimate interest in knowing this information required by CAMERDATA's
Clients, as enabled in Article 6.1.f of the GDPR, and in Recital 47 of the GDPR, given that the intended purpose of our
clients is to conduct commercial and marketing communications campaigns, offering various goods or services that may be of interest to you.

In other cases, the legitimacy of the processing of this data by CAMERDATA's
Clients may correspond to the assumptions provided for in
letters b) or c) of Article 6.1 of the GDPR."
[…]
6.2.5. Purpose of the processing

The purpose of the processing is to conduct commercial and marketing communications
campaigns, to offer products or services
of our own or those of third-party companies that may be of interest to you, for marketing purposes, within the business sphere and never within the private sphere.
6.2.6. Recipients of Personal Data

Only our clients who have requested the creation of the custom database to be delivered, or third-party companies that, in turn, provide services to end users for the same marketing purposes, and those companies with which they have signed data processor agreements or contracts, will be able to access the personal data for which CAMERDATA is the data controller.

2. The announcement published on the corporate websites of some Chambers of Commerce
states the purpose for which CAMERDATA processes the data obtained from CDE:

“The data processed by CAMERDATA and related companies have been

legally collected by CAMERDATA and obtained from an official Census
prepared by a public body, […].”
The purpose of processing this data is to send commercial and marketing communications, offering various goods or services that may be of interest to you, as well as commercial information about the business activity carried out by the Self-Employed Person.

FIFTEENTH: Duty to provide information

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 89/164

CAMERDATA does not inform individual entrepreneurs about the processing of their personal data.

The following documents are included in the file, provided for the purpose of proving that it is exempt from the obligation to inform data subjects by virtue of the exception set forth in Article 14.5.b) of the GDPR due to the unaffordable cost of issuing an individual information communication:
-Budget for the company Meydis, S.L., (materials, handling, and distribution of communications) for an amount of €9,409,000.

-Budget for the State-owned Company Correos y Telégrafos, S.A., (handling, distribution, and postage of communications) for an amount of €4,266,900.
- Audit reports on the annual accounts for the fiscal years 2019, 2020, 2021, and 2022, which show that the annual income obtained from its total activity is, respectively, €941,238.83, €836,093.46,

€885,999.51, and €895,950.29.

SIXTEENTH: Duty of Information

CAMERDATA states that it has published the following informational text aimed at
self-employed workers regarding the protection of their personal data on the websites of

seven Chambers of Commerce:

“By means of this communication, all persons who are self-employed are informed of the processing of their personal data by
Camerdata.

The data processed by CAMERDATA has been legitimately collected by CAMERDATA and obtained from an official Census prepared by a public body.
The data corresponds to the person subject to the data (the self-employed worker) in the exercise of an activity listed in Royal Decree 2007 (RD 475/2007).

The purpose of processing this data is to send commercial and marketing communications, offering various goods or services that may be of interest to you, as well as commercial information about the business activity carried out by the self-employed worker.
If you wish to exercise your rights of access, rectification, deletion, restriction of processing, or objection to the processing of your contact information, you can send your request to the addresses indicated below.

We remind you that you can exercise your right to object to receiving commercial communications centrally, using the Robinson List services of ASEDIE member companies that are subject to its Code of Conduct:

CAMERDATA, S.A. […]
AXESOR CONOCER PARA DECIDIR S.A.
[…]
DATACENTRIC S.A.
[…]
IBERINFORM S.A.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 90/164

[…]
INFORMA S.A.
[…]

Equifax, S.A.

SEVENTEENTH: Dmovo Analytics, S.L., (DMOVO)

1. The following documents related to CAMERDATA and DOMOVO are included in the file:

a. SmartAddress Services Contract, dated 02/03/2020 (provided to the Data Inspectorate as an annex to the response to the request, document 25).
b. Confidentiality Agreement dated 12/18/2019 (provided as an annex to the allegations to the initiation agreement, document 6).
c. “Geographic Data Processing System,” Dmovo Analytics, S.L.: containing the

commercial offer to the data controller. Undated. (Provided during the trial phase, pages 2400 to 2416)

2. The stipulations governing the processing order and which must be included in the contract or other legal document pursuant to the law. Article 28.3 of the GDPR,
are included in the text of documents a, b, and c.

LEGAL BASIS

I

Jurisdiction

In accordance with the powers granted to each supervisory authority by Article 58.2 of the GDPR and as established in Articles 47, 48.1, 64.2, and 68.1 of the LOPDGDD,
the Presidency of the Spanish Data Protection Agency is competent to resolve this procedure.

Furthermore, Article 63.2 of the LOPDGDD establishes: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of
Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development, and, insofar as they do not contradict them,

subsidiarily, by the general rules on administrative procedures."

II

Personal data whose processing is the subject of this sanctioning procedure.

Article 19 of the LOPDGDD (Spanish Data Protection Act)

1. The sanctioning procedure at hand concerns exclusively the processing of personal data of individual entrepreneurs; of entrepreneurs who are natural persons.

Article 4.1 of the GDPR defines personal data as "any information relating to an identified or identifiable natural person ("the data subject"); an identifiable natural person shall be deemed to be any person whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person."

Article 1 of the GDPR, "Purpose", provides:

"1. This Regulation lays down rules relating to the protection of natural persons with regard to the processing of personal data and the rules on the free movement of such data.
2. This Regulation protects the fundamental rights and freedoms of natural persons, and in particular their right to the protection of personal data."

Article 2 of the GDPR, "Material Scope", devotes point 2 to the data processing that is excluded from its application, without any of the four cases it details expressly referring to natural persons.

In turn, Recital 14 of the GDPR states that "The protection granted by this Regulation should apply to natural persons, irrespective of their nationality or place of residence, in relation to the processing of their personal data. This Regulation does not regulate the processing of personal data relating to legal entities, and in particular to companies incorporated as legal entities, including the name and form of the legal entity and its contact details.

From the foregoing, it can be inferred that the protection provided by the GDPR extends to the processing of data of natural persons and that the only exceptions to this rule are those contemplated in the four cases described in Article 2.2 of the GDPR, none of which mentions sole proprietors. Therefore, the data of individual entrepreneurs are not excluded per se from the objective scope of application of Regulation (EU) 2016/679.

The current situation contrasts with the previous regulations, in which the Regulation implementing Organic Law 15/1999 on the Protection of Personal Data (RLOPD), approved by Royal Decree 1720/2007, of December 21, established in its Article 2, "Objective Scope of Application", Section 3:
"3. Likewise, data relating to individual entrepreneurs, when referring to them in their capacity as merchants, industrialists, or shipowners, shall also be deemed to be excluded from the applicable personal data protection regime.”
(Emphasis added)

2. In addition to what has been stated regarding the scope of application of the GDPR, it should be noted that the LOPDGDD (Article 19.2) incorporates, in relation to the processing of personal data of individual entrepreneurs, a rebuttable presumption of lawfulness based on the circumstance legitimizing the processing in Article 6.1.f) of the GDPR.

Article 19 of the LOPDGDD, “Processing of contact data, of individual entrepreneurs, and of liberal professionals,” provides:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 92/164

“1. Unless proven otherwise, the processing of contact data and, where applicable, data relating to the function or position held by natural persons who provide services to a legal entity shall be presumed to be covered by the provisions of Article 6.1.f) of Regulation (EU) 2016/679, provided that the following requirements are met: a) The processing relates solely to the data necessary for professional location.
b) That the purpose of the processing is solely to maintain relations of any kind with the legal entity for which the data subject provides services.

2. The same presumption shall apply to the processing of data relating to sole proprietors and independent professionals when the data relates to them solely in that capacity and is not processed to establish a relationship with them as natural persons.

3. The data controllers or processors referred to in Article 77.1 of this Organic Law may also process the data mentioned in the two preceding sections when doing so arises from a legal obligation or is necessary for the exercise of their powers. (Emphasis added)

The rebuttable presumption of lawfulness established in Article 19.2 of the GDPR is limited to the processing of contact data of individual entrepreneurs (not, as erroneously stated in the initiation agreement, to their location data) and also requires, for the processing of contact data of individual entrepreneurs to be covered by this presumption—the prevalence of the legitimate interest of the controller or third parties—that these requirements be met: (i) that they "refer to them [the individual entrepreneurs] solely in that capacity" as entrepreneurs; and (ii) that the processing of contact data is not intended to establish a relationship with them as individuals.

Opinion 757/2017, of October 26, of the Council of State, on the draft Organic Law on Data Protection (current LOPDGDD) dispels these doubts. that
might arise regarding the meaning and scope of the presumption of lawfulness contained in
Article 19.2 of the LOPDGDD. Commenting on what was Article 20 in the draft (current Article 19), it states:

"Article 20 of the Draft Regulation regulates the processing of contact data of natural persons who provide services to a legal entity (section 1) and of individual entrepreneurs (section 2), in both cases invoking the provisions of Article 6.1.f) of the Regulation as regulatory protection. In the first case, in order to understand that lawfulness exists under this article, the provision requires that the

processing relates only to the data necessary to locate the data subject professionally and that the purpose of the processing is solely to maintain relations of any kind with the legal entity for which the data subject provides their services; In the second, the processing relates solely to the data of entrepreneurs in that capacity and is not processed to establish a relationship with them as natural persons." (Emphasis added)

It follows from the foregoing that the processing of personal data of an entrepreneur, a natural person, other than contact data, even if they refer to it in their status as entrepreneur and their processing is not intended to establish a relationship with them as natural persons, cannot be covered by the rebuttable presumption of lawfulness in relation to Article 6.1.f) of the GDPR.

The resulting consequence is that, in all other cases, the data controller is obliged, by virtue of the principle of proactive accountability (Article 5.2 of the GDPR), to prove that there is an adequate legal basis under the GDPR on which the lawfulness of the processing is based.

III
About the data controller

Based on the investigations carried out, the existence of processing of personal data of individual entrepreneurs has been established, in accordance with the provisions of Articles 4.1 and 4.2 of the GDPR, for which CAMERDATA is the controller, as this entity determines the purposes and means of the processing it carries out.

CAMERDATA obtains personal data of individual entrepreneurs from the
CHAMBER OF SPANISH (CDE or CHAMBER), which transfers them to the company pursuant to a

"Business Database Transfer" contract signed in 2016. However, the CDE cannot process them for this purpose, or for any other purpose other than those specified in Article 8 of Basic Law 4/2014 on Chambers of Commerce. Industry,
Services and Navigation, the data obtained from the tax authorities.
Therefore, there is no legal basis for the transfer of data by the CDE

to CAMERDATA. This entity records, structures, and organizes the data collected from the CDE; in addition, it communicates it for commercial purposes to third parties and allows access to it by the entities with which it contracts data standardization services for its file.

IV
Context in which the processing is carried out

1.- Law 4/2014, of April 1, Basic Law of the Official Chambers of Commerce,
Industry, Services and Navigation (hereinafter, Law 4/2014 or Basic Law of Chambers)

Law 4/2014, issued—with the exception of its article 5.2—under article 149.1, sections 6, 13 and Article 18 of the Spanish Constitution (EC) establishes the
basic regulations of the Official Chambers of Commerce, Industry, Services, and, where applicable, Navigation (hereinafter, the Chambers) and the specific regime of the
Official Chamber of Commerce, Industry, Services, and Navigation of Spain (hereinafter, the
Chamber of Spain or CDE).

In accordance with the aforementioned Law, both the Chambers and the CDE are public-law corporations and enjoy legal personality and full capacity to act in the fulfillment of their purposes.

Law 4/2014 introduced into our legal system a chamber system of
"universal affiliation" without any financial obligation on its members, such that their affiliation to the respective Chamber occurs "ex officio"

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 94/164

(Article 7). Therefore, Law 4/2014 departs from the criteria followed by the previous law, Law 3/1993, which had established a model of mandatory membership and compulsory payment of fees, and from the one subsequently introduced through the reform

made to Law 3/1993 by Royal Decree-Law 13/2010, which changed it to a chamber-wide model of "voluntary membership."

Article 7 of Law 4/2014 states regarding membership in the Chambers:

"Natural or legal persons, national or foreign, who carry out commercial, industrial, service, or shipping activities in national territory shall be members of the Official Chambers of Commerce, Industry, Services, and Navigation within whose jurisdiction they have establishments, branches, or agencies, without any financial obligation or administrative burden arising from this.
The membership shall be carried out ex officio." (Emphasis added)

Article 5 of the Basic Law regulates the functions of the Chambers, distinguishing, by virtue of their nature, between functions of a "public-administrative nature" (contemplated in section 1), "public-administrative functions [...], in the manner and to the extent determined, where appropriate, by the Autonomous Communities" (section 2), and "other activities, which shall be private in nature and shall be provided under a free competition regime, which contribute to the defense, support, or promotion of commerce, industry, services, and navigation, or which are useful for the development of the aforementioned purposes and, in particular, for establishing business information and advisory services." (Section 3). (Emphasis added)

Article 5.1 of the Law provides that “The Official Chambers of Commerce, Industry, Services, and Navigation shall have the following public-administrative functions:
[…]
g) Manage, in accordance with Article 8 of this Law, a public census of all companies, as well as their establishments, branches, and agencies located in their district.” (Emphasis added)

In turn, within Chapter V of Law 4/2014, dedicated to the Official Chamber of Commerce, Industry, Services, and Navigation of Spain, Article 21, “Functions,” provides:

“1. The Official Chamber of Commerce, Industry, Services, and Navigation of Spain shall perform the following functions:
a) Promote the general interests of commerce, industry, services, and navigation at the national level.
b) Represent all the Chambers before various state and international bodies.

c) Coordinate and promote actions affecting all the Spanish Chambers.
d) Exercise, at the state level and in coordination with the Chambers of Commerce,
Industry, Services, and Shipping, the functions referred to in section 1 of

Article 5 of this Law.
[…]” .” (Emphasis added)

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 95/164

Regarding the functions entrusted to them, section 6 of Article 5 of the Basic Law on Chambers establishes that both the CDE and the Chambers "For the proper performance of their functions, [...] they may enter into agreements as provided for

in letters c) and d) of Article 4.1 of the Consolidated Text of the Law on Public Sector Contracts, [...] and enter into contracts in which the Public Administrations will comply with the provisions of the aforementioned Consolidated Text and use the other instruments permitted by current legislation. [...]."

2.- Examination of Article 8 of Law 4/2014.


Under the heading "Public Census," the provision establishes:

"The Official Chambers of Commerce, Industry, Services, and Navigation
shall prepare a public census of companies, which shall include individuals or legal entities,

national or foreign, that carry out commercial, industrial, service, and shipping activities in national territory. For this purpose, they shall have the collaboration of the competent tax administration
as well as other administrations that provide the necessary information, guaranteeing, in all cases, confidentiality in the processing and the
exclusive use of said information.

For the preparation of the public census of companies, the tax administrations
shall provide the Official Chamber of Commerce, Industry, Services, and Navigation of Spain and the Official Chambers of Commerce, Industry,
Services, and Navigation with the necessary data on the Tax on Economic Activities and

the census of companies. Only the employees of each Chamber shall have access
to the information provided by the tax administration. determined by the plenary session.

This information will be used to compile the public census of companies, to fulfill the public-administrative functions that this Law attributes to the Chambers, as well as to compile the electoral census referred to in Article 17 of the same.

Said personnel shall have, with regard to the aforementioned data, the same duty of confidentiality as tax administration officials. Failure to comply with this duty shall, in any case, constitute a very serious infraction in accordance with its disciplinary regime. (Emphasis added)

The transcribed regulation imposes on the CDE and the Chambers the obligation to prepare a public business census, and to fulfill this obligation, it

provides for the collaboration of the tax authorities.

The provision obliges the tax authorities to communicate—"shall provide," the regulation states—to both the CDE and the Chambers "the data" on the tax on economic activities (hereinafter, IAE) and the company censuses that are

"necessary" for the fulfillment of the purposes it establishes.

Furthermore, the CDE and the Chambers are authorized to process the information thus obtained not only for the purpose of preparing a public business census, but also for: i)

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 96/164

fulfill "the public-administrative functions that this Law attributes to the Chambers" and ii) the preparation of the electoral register referred to in Article 17 of Law 4/2014.

The authorization that the Law grants to the tax authorities to transfer or communicate to the CDE and the other Chambers the IAE data and company census data necessary for the purposes determined in its Article 8 is accompanied by the establishment of safeguards that aim to guarantee the protection of the right of individuals to the protection of their data.

In this sense, Law 4/2014 not only determines the specific purposes for which the CDE and the Chambers may process the data provided to them by the tax authorities. It also determines what data may be transferred—"those necessary" to fulfill said purposes—and imposes on the assignees of the data. data

(the CDE and the Chambers) the obligation to guarantee their "confidentiality" during the processing they carry out and "the exclusive use" of the information thus obtained.

Furthermore, in order to achieve effective compliance with the obligation of data confidentiality, it restricts the persons within the organization who may access the information provided by the tax authorities to those designated by the full Chamber. It adds that this person or persons will be subject to the "duty of confidentiality" required of tax administration officials.
The public business census, regulated in Article 8 of this Law, is an institutional registry whose main purpose is to identify and keep up-to-date all the natural or legal persons, national or foreign, who carry out economic activities—commercial, industrial, service, or shipping—in the national territory. Its preparation and management are the responsibility of the Chambers of Commerce and It is
based on data provided by tax authorities, as well as by other
public administrations that can provide necessary information. It should be noted

that, as can be deduced from the law, the purpose of this census is not commercial, but
strictly public-administrative. On the one hand, it serves as a basis for fulfilling
the functions that the law attributes to the Chambers of Commerce in their capacity as
public-law corporations, as bodies of representation, promotion, and
advice to the business community. It also has the specific additional purpose of compiling the electoral roll that determines who can participate

in the election processes for the representative bodies of the Chambers themselves.
The same limitation on specific personnel regarding access to the tax data
used to compile the census reflects that the census has an
institutional nature, linked to the functioning of the chamber system and the public management of the business community, and cannot be understood as a general source of economic publicity nor be confused with private databases used for
profit purposes. informational or commercial purposes.
The regulation of the Public Business Registry is what it is. Despite the functional and economic relevance that a business information ecosystem may represent, the truth is that the legislator, although he could have chosen to expressly establish a legal regime for the publicity or general access to this data—accompanied by appropriate guarantees—has not done so. The current regulations in Spain—possibly unlike other European Union countries—have not articulated a regulatory framework that provides openly, and with legal support, the availability of these databases with information on individual entrepreneurs, even when such access could serve legitimate public or private interests and is mediated by obligations of transparency, oversight, and accountability.
Thus, the only option is to resort to the possibilities offered by the legal system, in In this case, the use of individualized or granular access management is not currently the case. The legitimacy, appropriateness, or usefulness of other purposes or interests, other than those determined by the legislator for the business census, is not discussed here. The business census has not been designed by the legislator to cover an instrument for purposes that can be pursued through the processing of data on individual entrepreneurs by infomediary entities, such as the interest of such entities in structuring and offering information on business or professional activities carried out by individuals, in response to continued demand from multiple sectors. This purpose, where appropriate, could support a legitimate interest that would allow the creation of information products that support decision-making in commercial, contractual, or professional settings. Consequently, several purposes that could be considered legitimate in other contexts do not fit within the legal framework of this census. Thus, the census is not contemplated as serving as a business verification tool. available to third parties, nor does it provide companies, public administrations, or professionals with access to data to assess the existence, continuity, or economic capacity of an entrepreneur before entering into contracts or establishing legal relationships.

Although this purpose may be useful for mitigating risks or strengthening security in commercial transactions, it is not provided for in the law as a specific function of the chamber's census.
Nor is it included among its objectives to allow verification of the professional or business status of an individual in compliance with specific regulations, such as those related to public procurement, anti-money laundering, or financing, even though such needs exist in other areas.

Furthermore, the law does not attribute to the census the purpose of promoting the individual entrepreneur, nor does it grant it a publicity character in the sense of increasing the subject's visibility or competitive positioning in the market. Access to census data is also subject to strict confidentiality conditions, which reinforces its restricted nature and its internal use by Chambers.
Finally, although Article 19 of the LOPDGDD, and under its conditions, allows the

processing of professional location data of individual entrepreneurs to
facilitate economic and legal relations, it is not linked to the public census. Therefore,
it should be understood that the chamber census does not cover or enable uses aimed at
processing data for informational, commercial, or analytical purposes by third parties, which must be based on other sources and different legal mechanisms.
If these purposes are pursued through data processing tools and processes,

there must be a legitimacy that does not facilitate the regulation of the business census.
And, in any case, data processing that is appropriate and relevant to the business census according to its legal design must comply with the provisions of the GDPR. Therefore, the provisions of Law 4/2014 regarding the public census that

concern or are related to the processing of personal data of individual entrepreneurs can only be interpreted in light of the GDPR and the LOPDGDD.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 98/164

3.- Communication of data by the AEAT to the CDE and the Chambers

3.1.- As we have indicated, Article 8 of the Basic Law on Chambers imposes on the

Tax Administrations a duty to collaborate with the CDE and the Chambers
and must provide them with the IAE (Tax Income Tax) and company census data that are necessary, among other purposes, for the preparation of a public business census.

The legal basis for the AEAT's transfer to the CDE and the Chambers of Commerce of the data on individual entrepreneurs obtained through the IAE (Tax Income Tax) and the census of entrepreneurs, professionals, and withholding agents for the purposes and under the terms set forth in Article 8 of Law 4/2014 is that established in letter c) of Article 6.1. of the GDPR:
“The processing is necessary for compliance with a legal obligation imposed on the data controller. All this, without prejudice to the fact that the transferring tax authority must always be able to prove that the processing carried out has complied with the other principles that, pursuant to Article 5 of the GDPR, govern data processing.

Regarding the duty to inform about the transfer or communication of data, it should be noted that - although Article 13 of the GDPR obliges the data controller, when personal data have been obtained directly from the data subject, to inform them about “the recipients or categories of recipients of the data” (paragraph 1, letter e) and that, “When […] the data controller plans to further process personal data for a purpose other than that for which they were collected,” they must provide the data subject, prior to such further processing, information about that other purpose and any additional information. Relevant pursuant to section 2 (section 3) - in the case at hand, the AEAT is not obliged to inform the CDE or the Chambers of the transfer of their data, nor of the purpose of such communication.

This follows from section 4 of Article 13 of the GDPR, which states: "The provisions of paragraphs 1, 2, and 3 shall not apply when and to the extent that the data subject already has the information," interpreted in light of Recital 62 of the GDPR:

"[…] it is not necessary to impose an obligation to provide information when the data subject already has the information, when the registration or communication of personal data is expressly provided for by law, […]." Therefore, in relation to the transfer of the tax data of self-employed entrepreneurs by the AEAT to the CDE, insofar as it represents an obligation for the AEAT imposed by a law (formerly Article 8 of the Law). 4/2014) is not required to provide information pursuant to

Article 13.4 of the GDPR.

Furthermore, the AEAT includes in its Register of Processing Activities (RAT) the processing activity that consists of communicating to the CHAMBER OF SPAIN and the Chambers the
data provided to the "census of entrepreneurs, professionals, and withholding agents (forms 036

and 037)".

3.2.- Agreement between the CHAMBER OF SPAIN and the AEAT

The CDE and the AEAT signed an agreement on November 25, 2019 "for the transfer of tax information to the Official Chambers for the exercise of their public-administrative functions," published in the Official State Gazette (BOE) on December 20, 2019.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 99/164

The agreement was extended in 2023. On December 19, 2023, the AEAT (Spanish Tax Agency) and the CDE (Spanish Delegation of Deputies) signed an
"Addendum to modify and extend the agreement between the State Agency for Tax Administration and the Official Chamber of Commerce, Industry, Services and Navigation of Spain for the transfer of tax information to the Official Chambers for the exercise of their public-administrative functions," published in the Official State Gazette (BOE) on February 16, 2024. In this document, they agreed to extend the agreement for four years, effective from December 20, 2023, with the amendments that affect clauses eight ("Control and security of the data provided") and nine ("Data protection").

The currently valid agreement therefore includes the amendments incorporated by the Addendum. The aforementioned. Its Statement of Reasons reproduces the following paragraph from the original Agreement:

“The Official Chamber of Commerce, Industry, Services, and Navigation of Spain
is a Public Law Corporation, with its own legal personality and full
capacity to act in the fulfillment of the purposes entrusted to it by Law
4/2014, of April 1, […]. In addition, it performs public functions, especially
those listed directly and indirectly in letters d) to i) of Article
21.1 of Law 4/2014.

The Official Chambers of Commerce, […], when acting in the exercise of the
administrative or public-administrative functions entrusted to them
by law, are considered public administrations.”
(Emphasis added)

The Agreement, with the modifications incorporated following the Addendum signed in December 2023, establishes the conditions and procedure governing the transfer of information from the AEAT to the Chambers and the CDE, stating that it "preserves in all cases the rights of the persons to whom it refers" and, in summary, has the following content:

i. It states that its nature is administrative and is governed by the provisions of the LRJSP (twenty-first clause)

ii. It establishes that the data provided by the Tax Agency are those declared by taxpayers and other parties obliged to provide information (sixth clause),

and therefore constitute tax data.

iii. It establishes that, in the event that the information includes personal data of the interested parties, both the transferor, the Tax Agency, and the transferee, the Chamber of Commerce of Spain and the Chambers of Commerce will process the data in accordance with the GDPR

(clause nine)

iv. Regarding the purpose of communicating the data to the CDE and the Chambers, clause "Second. Purpose of the transfer of information" states:

"The transfer of information from the Tax Agency will have the exclusive purpose of collaborating with the Spanish Chamber of Commerce and the Chambers in the development of the public functions assigned to them when, for the exercise of these functions, the regulatory regulations require

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 100/164

the provision of a certification issued by the Tax Agency or the
submission, in original, copy, or certification, of the tax returns of the interested parties or any other communication issued by the Tax Agency, particularly in the case of those not obliged to declare. In these
cases, the information that must be included in such documents will be requested
directly from the Tax Agency, provided that it is necessary for the
exercise of such functions and relates to a large number of interested parties or
affected parties.

Annex III of this Agreement sets out the public functions to be
performed by the Chambers.

The transfer of data from the Tax on Economic Activities and the
company censuses will be for the exclusive purpose of preparing the

public company census, fulfilling the public-administrative functions that Basic Law 4/2014 on the Official Chambers of Commerce,
Industry, Services and Navigation attributes to the Chambers, as well as the
preparation of the electoral register referred to in Article 17 of the same
Law.

For its part, Annex III of the agreement separately addresses the public-administrative functions of the CDE and those of the Chambers.

“The public functions to be performed by the Official Chamber of Commerce, Industry, Services, and Navigation are listed directly and indirectly in

letters d) to i) of article 21.1 of Law 4/2014, […]:

Article 21.1 of Law 4/2014, of April 1, Basic Law of the Official Chambers of Commerce, Industry, Services, and Navigation:

“1. The Official Chamber of Commerce, Industry, Services, and Navigation of Spain shall perform the following functions:

d) Exercise at the state level and, in coordination with the Chambers of Commerce, Industry, Services, and Navigation, the functions referred to in section 1
of article 5 of this Law.

e) Report, with the nature and scope provided for in current legislation, on the
drafts of state laws or provisions of any rank that directly affect commerce, industry, services, and navigation.
f) Advise the General Administration of State, under the terms it establishes, on matters related to commerce, industry, services, and navigation.
g) Perform the public-administrative functions assigned to it,
when they affect the State as a whole.
h) Manage, under the terms established in the agreements with the Ministry of
Economy and Competitiveness, the actions provided for in the Chamber's Internationalization

Plan and the Chamber's Competitiveness Plan.
i) Perform national and international commercial mediation and arbitration functions, in accordance with current legislation.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 101/164

The Official Chambers of Commerce, Industry, Services, and Navigation are
Public Law Corporations with legal personality and full capacity
to act in the fulfillment of their purposes and, when acting in the exercise
of the administrative or public-administrative functions entrusted by law, are considered public

administrations. The public-administrative functions are listed in
Article 5 of Law 4/2014, of April 1, Basic Law of the Official Chambers of Commerce,
Industry, Services, and Navigation:

Article 5 of Law 4/2014, Basic Law of the Official Chambers of Commerce,
Industry, Services, and Navigation:

"1. The Official Chambers of Commerce, Industry, Services, and Navigation
shall have the following public-administrative functions:
a) […].
g) Manage, in accordance with Article 8 of this Law, a public census of

all companies, as well as their establishments, branches, and agencies
located within their district.
h) […]

2. The Official Chambers of Commerce, Industry,
Services, and Navigation shall also be responsible for carrying out the public-administrative functions

listed below, in the manner and to the extent determined, where appropriate, by the Autonomous Communities.
a) […]”

v. Provision of information (clause seven). The provision of information is
set out in Annex I to the Agreement, according to which when the information comes from

company census data and is intended for the preparation of the "public company census" (Article 8 of Law 4/2014) and for the preparation of the electoral census
(Article 17), it shall be provided annually. And the information regarding IAE data for the preparation of the public business census (Article 8 of Law 4/2014) and the electoral register (Article 17) will be updated annually, with semiannual updates.

vi. Prior authorization from the interested parties is not required when the transfer of IAE data and business census data is required by Article 8 of Law 4/2014.

vii. The fourth stipulation states that the information transferred by the AEAT may only be

recipients of the CDE (Department of Economic Development) and the Chambers "that have been assigned the public functions that justify the transfer." It adds:

"Under no circumstances may the recipients be bodies, organizations, or entities that perform functions other than those described in the second clause of this Agreement."

"All of this is without prejudice to the strict use of the information sent by the Tax Agency for the purposes that justify it and for which it is requested. In any case, the recipient may not transfer the information sent by the Tax Agency to third parties."

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 102/164

viii. Clause eight refers to the control and security of the data processed and states:

“1. The control and security of the data provided shall be governed by the provisions of the regulations in force at any given time regarding data protection and information security and, in particular, by Regulation (EU) 2016/679 […], Organic Law

3/2018, […] the regulatory provisions of the internal legal system regarding the protection of personal data, Royal Decree 3/2010, of January 8, which regulates the National Security Framework in the field of Electronic Administration […], and the Information Security Policy of the Tax Agency and the Chambers that adhere to this Agreement.”

Section 2 provides for the existence of "controls over the custody and use of the information provided under this Convention," differentiating between the internal controls carried out by the "entity transferring the information" (section a) and,
(section b), "control by the entity holding the transferred information."

ix. Obligation of confidentiality. Clause ten establishes that "All authorities,
officials, and other personnel who have knowledge of the data or information
provided under this Convention shall be bound to the strictest and complete confidentiality regarding them. Violation of this obligation will entail incurring the
criminal, administrative, and civil liabilities that may arise, as well as subjection to the exercise of the powers corresponding to the Data Protection Agency."

4.-Preparation by the CDE of the public business census: Data it contains.

The CDE prepares a public business census in compliance with the provisions of Article 8 of Law 4/2014. The public business census, pursuant to the principle of universal membership in the Chambers of Commerce set forth in Article 7 of Law 4/2014, includes all entrepreneurs, whether legal entities or individuals. To the extent that the public business census processes data of individual entrepreneurs, personal data, it is subject to the provisions of the GDPR.

The information on individual entrepreneurs provided by the CDE's public business census, which can be accessed from its corporate website, contains only the following data:
- Name and surname
- Address (street type, name, number, and sometimes the floor)
- Town/City
- Province

- Postal code
- Number of the section of the IAE
- description of the activity.
However, the NIF information is not included.

Thus, the content of the public business census prepared by the CDE, and referred to in Article 8 of Law 4/2014, is, as its name indicates, that which is publicly accessible.
Currently, it is available through the CDE website. For its preparation, the CDE does not use all the data transmitted to it by the tax authorities, but only those that are "necessary."

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 103/164

On the contrary, the so-called "Basic Business Census," which is the file transferred between the CDE and CAMERDATA by virtue of the private contract signed between the two in 2016, contains more personal data than that provided by the public business census, since that The "Basic Business Census" does include
the NIF (Tax Identification Number) of individual business owners. The public business census, which, as stated, is accessible from the CDE's corporate website for general and free access, does not provide NIF (Tax Identification Number).

Therefore, the "Basic Business Census" is not the Public Business Census referred to in Article 8 of Law 4/2014 and contains other additional data subject to the duty of confidentiality.

The processing carried out in the preparation by CDE of a public business census complies with the principle of data minimization (Article 5.1.c, GDPR) since the data published is only that which is adequate, relevant, and necessary for the purpose of the public census.

For the public business census referred to in the law, this information was not required. What would have been different is the inclusion and If applicable, publicity of the

NIF (Tax Identification Number) if it is a publicity tool other than the business register regulated by law.
The NIF (Tax Identification Number) of the individual entrepreneur is not necessary for the intended purpose
with the processing provided for in Article 8 of Law 4/2014: the preparation of a
public business register. Furthermore, it is excessive, since it unequivocally identifies the natural person. To this end, it should be added that the
legal system has not established a general obligation to formally publicize
this information (the NIF) for individual entrepreneurs—as opposed to what does exist for
commercial companies—with some exceptions: such as that for the shipping company and
some others provided for in special laws, such as Law 10/2010 on the Prevention of
Money Laundering and the Financing of Terrorism or Law 34/2002, of July 11, on Information Society Services. and e-commerce. In this regard, it is worth remembering that Article 19 of the Spanish Commercial Code provides: “1.
Registration in the Commercial Registry shall be optional for individual entrepreneurs,
with the exception of shipping companies.”

The personal data of individual entrepreneurs that are required are those that are included in the public business register pursuant to Article 8 of Law 4/2014, which is freely accessible to the general public through the CDE website. The obligation imposed by Article 8 of Law 4/2014 entails, for individual entrepreneurs—for all of them, by virtue of the principle of universal membership in the Chambers of Commerce—a restriction on the fundamental right to the protection of their personal data, as recognized by Article 18.4 of the Spanish Constitution. There is no reason for the scope of such a restriction on their fundamental right to be unnecessarily accentuated by including in the so-called public register data, such as the NIF, which is not essential.

The controversy that may arise regarding whether the NIF data of individual entrepreneurs should be processed by including them in the public business census, the compilation of which is entrusted to the CDE and the Chambers of Commerce, was

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 104/164

resolved negatively after a proportionality assessment, applying the constitutional doctrine contained, among others, in STC 39/2016, of March 31. The Supreme Court echoed this in the Supreme Court ruling of 11/02/2016 (appeal 2538/2015), which stated:

"Having raised the debate on proportionality between the rights invoked in conflict, it should be remembered that the Constitutional Court has been outlining this proportionality judgment, declaring that it requires the concurrence of three requirements or conditions. On the one hand, a judgment of suitability, referring to determining whether the measure adopted is capable of achieving the proposed objective. Secondly, a judgment of necessity, understood in the sense that the purpose pursued by the measure is essential for its legitimate purpose and cannot be achieved by other means that avoid the infringement of other rights or are less severe.
And thirdly, a judgment of proportionality in the strict sense, insofar as the measure adopted is weighted and balanced, as it results in more benefits for the purpose pursued than harm. in the infringement of rights also protected."

To this end, we note that the purpose of the public business register is that which results from Article 8 of the Law that establishes it. This provision, in addition to being the basis for the legality of the data processing entailed in the public business register, should specify—as required by Article 6.3 of the GDPR—the purposes of the processing, the types of data, and the possibility of communication to third parties, among other issues.

Article 8 of Law 4/2014 refers to "necessary" data, and in the absence of further specification in the sense indicated by Article 6.3 of the GDPR, it is mandatory to adhere to the limits of the legal mandate, applying data protection regulations in all cases. Accordingly, the purpose of this provision (Article 8 of Law 4/2014) is none other than to compile a list of business owners. Regarding individuals, this status results from registration in the census and inclusion in a section of the IAE (Tax Income Tax), data that appears in the public census, accompanied by a description of the activity. If the name of the business and the first and last names of the individual entrepreneur are also provided, as well as an address—information that in many cases could be excessive—it is clear that, for the purposes of preparing a public business census, that is, a list of companies that carry out their activity in Spanish territory, when it comes to individual entrepreneurs, the aforementioned data is more than sufficient, and it is in no way "necessary"—that is, it is not "essential"—that such a list or census include information such as the NIF (Tax Identification Number), which undoubtedly identifies the individual whose dignity and moral integrity must prevail over other interests, however legitimate they may be.

Nor is it admissible to justify the "need" for the NIF (Tax Identification Number) of the individual entrepreneur in this list of companies, which is the census, in the supposed requirements of legal certainty in commercial transactions. It is one thing—as in fact It happens that the individual entrepreneur provides the NIF (Tax Identification Number) within the framework of the specific commercial relationships they maintain, whether pre-contractual or contractual, and a very different one is the one raised here: the need or not for the individual entrepreneur's NIF (Tax Identification Number) to be included in a public list of Spanish companies when the company as such is already identified in said list or list. The proportionality judgment in the strict sense cannot prosper: No harm arises for the purposes of the purpose intended by Article 8 of Law 4/2014 - the preparation of a list of companies based in Spanish territory - from the individual entrepreneur's NIF not being included in the public list of companies when the company as such is already identified therein by other data that we have mentioned. This does not arise from the fact of not including the data. The inclusion of the NIF of the business individual in the list constitutes the slightest impairment of legal security in commercial transactions, since in the context of the relationships that these business individuals maintain with third parties in the performance of their activity, the data in question is provided to them when there is an obligation to do so (for example, when provided for by specific regulations on the issuance of invoices). On the contrary, the negative impact on the individual of the public dissemination, in a general manner and outside the context of the specific business relationships they maintain, of data such as the NIF that undoubtedly identifies them is more than evident. The extremely serious consequences that may arise from the processing of the NIF of the individual in the manner indicated are also evident and well-known, as they are commonplace. In conclusion, it is not proportional to the purposes pursued by the public business census contemplated in Article 8 of Law 4/2014 - provision 101- which is mandatory to comply with, to the extent that it constitutes the legal basis for this processing - that it includes the NIF data of individual entrepreneurs. This is fully understood by the CDE, which has failed to include it in the public census.

We therefore reiterate that, while the content of the public business census prepared by the CDE, and referred to in Article 8 of Law 4/2014, is, as its name indicates, that which is currently publicly accessible through the corporate website of the CHAMBER, the database that the CDE provides to CAMERDATA under the name "Basic Business Census" has a broader content than the public census strictly speaking, since it includes the NIF data of individual entrepreneurs obtained by the CDE through information received from public authorities and, pursuant to the Agreement signed with the The AEAT is

prohibited from transferring data to third parties.

VI
Regarding Article 19 of the LOPDGDD.

To the extent that Article 19 of the LOPDGDD is sought to be used to support the

legitimacy of data processing, it is important to remember some grounds to be taken into account.
Thus, the GDPR in particular and the LOPDGDD are the general regulation that, for constitutional purposes, permits data processing without consent. One avenue for
legitimacy without consent is the legitimate interest protected by the GDPR (Article 6.1 f). It should be noted that our legislator in the LOPDGDD has created some cases of
presumption of legitimate interest, in which there is greater certainty if these

conditions are met. In any case, the avenue for legitimacy of processing without consent
based on legitimate interest does not require a "normative presumption." Legitimate interest
constitutes an autonomous legal basis, which does not depend on the existence of a national
norm that presumes it. This is expressly recognized by the EDPB in its Recent
guidelines. The absence of a normative presumption by a law (as in our case, Article 19.2 of the LOPDGDD) in no way excludes the possibility of legitimacy based on legitimate interest.

Thus, "legitimate interest" can validly operate even in contexts not expressly regulated by national legislation, such as in cases of presumption of legitimacy. However, its evaluation requires a more intensive analysis, and in these cases, its application requires a more restrictive and guarantor-based approach.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 106/164

There is no presumption, so the data controller based on legitimate interest must justify, based on the principle of proactive accountability, the suitability, necessity, and proportionality of the processing, as well as the effective prevalence of its interest over the rights and freedoms of the data subject. The absence of a legal presumption This increases the burden of argument and documentation for the data controller.
Cases must be considered in which there is a regulation of legitimate interest that is similar or close to the one being argued (such as Article 19.2, the prerequisites of which are not given here). Likewise, specific regulations must be taken into account (such as the

Chambers of Justice Act). Legal regulations may contain express prohibitions that undoubtedly will not allow data processing, and there may also be rules that determine or guide the purpose of data use. In these cases, on a case-by-case basis, it will be necessary to analyze whether or not the deviation from the purpose of the data is compatible and, if applicable, whether this new purpose can be legitimized by a new basis for legitimation,

such as a specific regulation or, where appropriate, legitimate interest. In these cases,
the admissibility of legitimation will undoubtedly depend on compliance with
a whole series of prerequisites, requirements, and guarantees. These requirements will become more
intense. Due to the nature of the data, the impact on the affected groups and various rights, in addition to data protection and the purposes of the processing.

On these grounds, it is now appropriate to rule out the existence of the conditions of Article 19 of the LOPDGDD. This article establishes a rebuttable presumption of the lawfulness of processing, which affects, among other subjects, individual entrepreneurs. Article 19 of the LOPDGDD, "Processing of contact data, of sole proprietors and of liberal professionals", states:

"1. Unless proven otherwise, the processing of contact data and, where applicable, data relating to the function or position held by natural persons who provide services to a legal entity shall be presumed to be covered by the provisions of Article 6.1.f) of Regulation (EU) 2016/679, provided that the following requirements are met:

a) That the processing relates solely to the data necessary for their professional location.

b) That the purpose of the processing is solely to maintain relations of any kind with the legal entity for which the data subject provides their services.

2. The same presumption shall apply to the processing of data relating to sole proprietors and liberal professionals when the data relates to them only in that capacity and is not processed to establish a relationship. relationship
with them as natural persons.

3. The data controllers or processors referred to in
Article 77.1 of this Organic Law may also process the data mentioned
in the two previous sections when this arises from a legal obligation or
is necessary for the exercise of their powers."

This Agency cannot dispute, for the reasons explained below,
that Article 19.2 of the GDPR has no other scope than to establish a

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 107/164

presumption of legality that applies exclusively to the contact data of individual entrepreneurs.

According to its literal wording, Article 19.1 of the LOPDGDD establishes a
iuris tantum presumption of legality that is defined through two elements: its

foundation and its purpose. It is based on Article 6.1.f) and relates to contact information or, where appropriate, the function or position held. The presumption thus defined in Article 19.1 applies to natural persons who provide services to a legal entity. When Article 19.2 of the LOPDGDD refers to the application of "the same presumption," it must be taken as defined in Section 1: by the aforementioned elements of its basis and purpose. Therefore, Article 19.2 states nothing other than that the rebuttable presumption, based on Article 6.1.f), the purpose of which is contact information, will apply to the processing of data of self-employed entrepreneurs. Furthermore, such an interpretation of the text of the regulation is supported by Opinion 757/2017, of October 26, of the Council of State on the draft Organic Law on Data Protection (currently LOPDGDD). Commenting on what was Article 20 (currently Article 19) in the draft Organic Law, it states:

"Article 20 of the Draft Law regulates the processing of contact data of natural persons who provide services to a legal entity (section 1) and of individual entrepreneurs (section 2), in both cases invoking the provisions of Article 6.1.f) of the Regulation as regulatory protection. In the first case, in order to understand that there is legality under this article, the provision requires that the processing relate only to the data necessary to locate the data subject and that the purpose of the processing is solely to maintain relations of any kind. nature with the legal entity for which the data subject provides their services; secondly, that the processing relates solely to the data of the entrepreneurs in that capacity and is not processed to establish a relationship with them as natural persons."

The commentary included in Opinion 757/2017 of the Council of State on Article 20 of the Draft Organic Law (currently Article 19 of the LOPDGDD) confirms that the presumption established therein applies exclusively to the contact data of self-employed entrepreneurs. This is because it indicates that Article 20 of the Draft Law "regulates the processing of contact data" and then specifies who the data are; who the persons to whom such data pertain: natural persons who provide services for a legal entity (section 1) and individual entrepreneurs (section 2). If what the opinion intended was that Article 20 of the Draft Regulation regulates the processing of contact data only for natural persons who provide services to a legal entity and for sole proprietors, all their data, the copulative conjunction "and" would not exist. Furthermore, the commentary adds that "in both cases," that is, in the processing of contact data in Sections 1 and 2 of Article 20 of the Draft Regulation, the basis for lawfulness is found in Article 6.1.f) of the Regulation. From there, the commentary examines the requirements, respectively, of Sections 1 and 2, based on Article 6.1.f) of the GDPR, for the processing—clearly, of contact data—to be lawful.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 108/164

Furthermore, the CJEU, in its judgment of October 4, 2024, Case C 200/23,
considered that Article 6 of the GDPR establishes an exhaustive list of grounds that
may legitimize the processing of personal data, with those not based on the data subject's consent being subject to a
restrictive interpretation.

“94 In this regard, it should be recalled that Article 6(1), first subparagraph, of the GDPR provides for an exhaustive and binding list of cases in which processing of personal data may be considered lawful. Therefore, in order to be considered lawful, processing of personal data must fall within one of the cases contemplated in that provision [see,

to that effect, judgment of 22 June 2021, Latvian Republikas
Saeima (Points for traffic violations), C 439/19, EU:C:2021:504,
paragraphs 99 and the case-law cited].

95 In the absence of consent from the data subject to the processing of his or her personal data pursuant to point (a) of Article 6(1), first subparagraph, or
where consent has not been given freely, specifically, in an informed and unambiguous manner, within the meaning of point 11 of Article 4 of the GDPR, Such processing

may, however, be justified where it meets one of the requirements of necessity referred to in points (b) to (f) of the first subparagraph of Article 6(1) of Regulation (EU) No 1994/2023 (see, to that effect, judgment of
4 July 2023, Meta Platforms and Others (General terms and conditions of service of a social network), C 252/21, EU:C:2023:537, paragraph 92).

96 In this context, the justifications provided for in the latter provision,

insofar as they allow processing of personal data
carried out without the data subject's consent to be lawful, must be subject to a restrictive interpretation [judgment of 4 July 2023, Meta Platforms and
Others (General terms and conditions of service of a social network), C 252/21,
EU:C:2023:537, paragraph 93 and the case-law cited].”

Following this line of argument, it must be considered that the presumption of legitimate interest

contained in Article 19.2 of the LOPDGDD must be interpreted strictly, as it is a provision that not only allows the processing of personal data without the consent of the data subjects, but also legitimizes the processing of the personal data of individual entrepreneurs, based on the legality of Article 6.1.f) of the GDPR, without requiring the data controller to perform the mandatory weighing of the conflicting interests.

Regulations must be interpreted taking into account not only the proper meaning of the words, but also their context, the social reality of the time in which they are to be applied, and the spirit and purposes pursued by the regulations of which they are part (Article 3.1 of the Civil Code). In the case under consideration, it cannot be said that the law has authorized the processing of any business data to carry out any processing operations for any purpose, whether lawful or not, and regardless of the lawful origin of the personal data. It would not be possible to say, for example, that the regulation authorizes contracting with an individual entrepreneur regardless of their will.

Article 19 of the LOPD cannot be separated from the GDPR. It is not permissible to interpret it outside of or without regard to the GDPR, but only and exclusively in the context of the Regulation from which it originates. And in this regard, it is emphasized that the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 109/164

objective guiding the development of the GDPR is to guarantee effective and
uniform protection of the right to personal data protection in the Member States of the Union.

Regarding this aspect of the GDPR, the Court of Justice of the European Union (CJEU) of 27/02/2025, Case C-203/22, states:

"51 Finally, with regard to the purposes of the GDPR, it is necessary
to recall that the objective of this Regulation is, in particular, to
ensure a high level of protection of the fundamental rights and freedoms
of natural persons, in particular their right to the
protection of personal data, enshrined in Article 16 TFEU and

guaranteed as a fundamental right in Article 8 of the Charter, which
complements the right to privacy guaranteed in Article 7 of that
[see, to this effect, judgment of 4 October 2024, Schrems
(Disclosure of data to the general public), C 446/21, EU:C:2024:834,
paragraph 45 and the case-law cited].

52 Thus, as its recital 11 also specifies, the GDPR Its

purpose is to strengthen and specify the rights of data subjects (judgment of 4 May 2023, Austrian Data Protection Act and CRIF, C 487/21,
EU:C:2023:369, paragraph 33 and the case-law cited)"

Recital (11) states that "The effective protection of personal data in the
Union requires that the rights of data subjects and the
obligations of those who process and determine the processing of personal data be strengthened and specified, and that equivalent powers be granted in Member States to
monitor and ensure compliance with the rules relating to the protection of personal data, with infringements being punishable by equivalent sanctions."

For this purpose, the GDPR has articulated mechanisms that the Directive did not foresee, which reinforce the effectiveness of the fundamental right and which cannot be ignored when interpreting a regulation in light of the GDPR. Worth mentioning, among others, is the principle of proactive accountability (Article 5.2), which is applied to all the principles of Article 5.1 of the GDPR and shifts the burden of proof of compliance to the data controller. The approach focuses on the risk that the fundamental rights and freedoms of individuals may pose to them, so that the impact that a violation of the right to data protection may have on fundamental rights and freedoms gives this fundamental right an instrumental role in protecting all of the individual's fundamental rights and freedoms. Or protection by design, which requires the

controller to implement appropriate technical and organizational measures to ensure
and demonstrate that the processing complies with this Regulation.

The name, surname, tax identification number, and even the address of the business establishment, in
cases where it is also the home address of the self-employed entrepreneur, are personal data of the individual and do not lose their nature due to the fact that they carry out a business activity. A broad interpretation of Article 19.2 of

the LOPDGDD that would advocate that all personal data of a self-employed entrepreneur, when the processing is in any way related to business activity, are excluded from the protection that the GDPR guarantees to "all natural persons" would be radically contrary to the spirit of the GDPR and would not be supported by a single one of its provisions.

The interpretation of Article 19.2 of the LOPDGDD (Spanish Data Protection Act), which maintains that the processing of all data of a self-employed entrepreneur when "it relates to them solely in that capacity" enjoys a presumption of lawfulness, effectively nullifies for this group of individuals the principle of proactive accountability (Article 5.2) regarding the lawfulness of the processing of their personal data and, consequently, the guarantees established by the GDPR for the protection of the rights of individuals.
This, we insist, is true when the personal data processed has never lost that character due to the fact that its processing relates to the individual entrepreneur in that capacity, a term that is very difficult to implement in practice and that inevitably leads to a permanent situation of legal uncertainty regarding the protection of the personal data of more than one and a half million individuals.

The argument in favor of understanding that Article 19.2 of the LOPDGDD includes all data of individuals who are self-employed entrepreneurs is not only contrary to the spirit of the GDPR and its provisions, but would also constitute a restriction of a fundamental right that is disproportionate to the purposes it pursues, as it would limit the level of protection of the fundamental rights and freedoms of individuals it pursues for a certain group.

This interpretation is reinforced by the recent ECJ judgment of 3 April 2025, Case C-710/23, which, in relation to the data of natural persons representing legal persons, states:

“22 Thus, information relating to the identity of identified or identifiable natural persons who, as a legally provided body or as members of such a body, have the power to bind a company with respect to third parties constitutes ‘personal data’ within the meaning of Article 4(1) of the GDPR. The fact that such information is part of the context of a professional activity cannot deprive it of its classification as personal data (see, by analogy, judgment of 9 March 2017, Manni,

C-398/15, EU:C:2017:197, paragraphs 32 and 34 and the case-law cited).

23 As the Commission notes, this interpretation cannot be invalidated
by recital 14 of the GDPR, because the second sentence of that
recital refers to the "name" and "contact details" of the
legal person, and not to natural persons acting in the name or on
behalf of a legal person.

24 Specifically, it should be noted that the first and last names of an
identified or identifiable natural person constitute personal data within the
meaning of Article 4(1) of the GDPR. The same applies to the signature of
such a natural person (see, to that effect, judgment of 4 October
2024, Agentsia po vpisvaniyata, C-200/23, EU:C:2024:827, paragraph 136).

28 In any event, it does not in any way follow from the wording of Article 4(2) of the GDPR that the EU legislature intended to reserve the
qualification of "processing" to such operations depending on the purpose of
these.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 111/164

29 This interpretation is consistent with the objective pursued by the GDPR,
as set out in Article 1 and recitals 1 and 10 of this Regulation,
which consists, in particular, in ensuring a high level of protection of the
fundamental rights and freedoms of natural persons, in particular the
right to respect for private life, in relation to the processing of personal
data, enshrined in Article 8(1) of the Charter and in
Article 16(1) TFEU (see, to this effect, judgment of 9
January 2025, Association Mousse, C-394/23, EU:C:2025:2, paragraph 21 and
the case-law cited).

30 Specifically, the communication of data such as first name, surname, The signature and contact details of a natural person representing a legal person falls within the concept of "processing" within the meaning of Article 4(2) of the GDPR. As is clear from paragraphs 27 to 29 of this judgment, the fact that the communication of such data is for the sole purpose of making it possible to identify a natural person authorized to act on behalf of a legal person is irrelevant for the purposes of classifying it as "processing" within the meaning of that provision. 31 In the light of the foregoing considerations, the answer to the first question is that Article 4(1) and (2) of the GDPR must be interpreted as meaning that the communication of the name, surname, signature and contact details of a natural person representing a legal person constitutes processing of personal data. The fact that such communication is made for the sole purpose of making it possible to identify A natural person authorized to act on behalf of that legal entity is irrelevant in this regard.”

Consequently, this Agency understands that the processing of personal data of a natural person entrepreneur other than contact data does not enjoy the presumption of lawfulness based on Article 6.1.f) of the GDPR. This is true even if the processing relates to data belonging to the natural person in their capacity as entrepreneur and even if the processing is not intended to establish a personal relationship. The consequence is, in accordance with the principle of proactive accountability (Article 5.2 GDPR), that the controller of personal data of individual entrepreneurs other than contact data does not enjoy the presumption provided for in Article 19 of the LOPDGDD and has the burden of proving that the processing carried out is protected by a basis of lawfulness in accordance with Article 6 of the GDPR.

In this Agency's opinion, Article 19.2 of the LOPDGDD (General Data Protection Act) would only exclude contact information from the presumption of lawfulness, so the data controller will be required to demonstrate that the processing of other data of individual entrepreneurs was lawful due to a legal basis under the GDPR.

However, having established the above, it is worth referring to the specific factual situation that concerns us here: the processing of data on individual entrepreneurs by the tax authorities, pursuant to Law 4/2014, for the purposes expressly established in the law, such as the preparation of the public census, the performance of public-administrative functions, and the preparation of the electoral census. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 112/164, and may not be used for any purpose other than that established by law. The communication of data by the tax authorities is protected by the legal basis contained in Article 6.1.c) of the GDPR, as it is imposed by Law 4/2014. It is particularly complex to admit processing based on legitimate interest based on a purpose imposed by law.

This, in the best-case scenario, would require determining a legitimate interest of sufficient intensity while structurally guaranteeing the rights of those affected.

Even considering that the interests pursued could be of sufficient intensity and scope, in a case of legitimate interest without a particular basis or legal presumption, they would have to be accompanied by a strict weighing and

assessment to ensure that the processing is strictly proportional. This would always be accompanied by evidence from those who do not enjoy a legal presumption of legitimate interest. Thus, where appropriate, for legitimate interest to be accepted as a valid basis for legitimation in the processing of personal data, especially the more impactful and widespread the processing is, as would be the case here, a series of compensatory guarantees must be effectively applied to ensure the protection of the rights and freedoms of the data subjects. Processing must be strictly proportional, which requires that the data processed and the purposes pursued not be exceeded. Furthermore, transparency must be guaranteed for the data subject, with clear and accessible information about the legal basis invoked and the interests pursued. It is essential that the exercise of the right to object is genuinely guaranteed in practice, including simple, effective, and accessible channels for its exercise. Likewise, technical and organizational measures must be adopted to reduce the impact of processing on the rights of data subjects, which may include the anonymization or pseudonymization of data where possible. The entity
responsible for the processing must have conducted a prior data protection impact assessment

in cases required by regulations or when the processing is particularly sensitive, and assess, where appropriate, the need for prior consultation
with the supervisory authority. It must also be able to demonstrate that it has considered the data subject's
reasonable expectations based on the context in which the data was collected.
Furthermore, it is advisable to have internal controls and periodic audits

to verify compliance with these guarantees, as well as to establish additional protection mechanisms, such as codes of conduct or certification schemes.
All of this can be complemented by a periodic review of the processing and its
effects on the rights of those affected, in order to assess whether the conditions of legitimate interest and compensatory measures remain adequate and
proportionate over time.

This means that no more information should be processed than necessary, nor should it be retained for longer than necessary. Data minimization and purpose limitation thus become essential conditions for validating the judgment of necessity.
In the present case, moreover, the data subjects would have no expectation that their data could be subject to processing.

VII
Response to the allegations regarding the initiation agreement
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 113/164

1. CAMERDATA requests that the procedure be declared null and void and invokes the
existence of a radical nullity defect as a result of the violation of the

right to defense guaranteed by Article 24 of the Constitution.

In this regard, it is worth remembering that, according to the doctrine repeatedly set forth by the
Constitutional Court (CC), for the existence of a lack of defense to be established,
it is not sufficient that a formal violation has occurred, but rather that a lack of defense of a material nature has occurred. STC 290/1993, Legal Basis 4, states: "For a lack of defense to be considered constitutionally relevant, which places the interested party outside any possibility of alleging and defending their rights in the proceedings, a merely formal violation is not sufficient; it is necessary that this formal violation result in a material effect of defenselessness, an effective and real impairment of the right to defense (STC 149/1998, Legal Basis 3), with the consequent real and effective harm to the affected interested parties (SSTC 155/1988, Legal Basis 4, and 112/1989, Legal Basis 2)." (Emphasis added)

-The first of the facts that CAMERDATA invokes as the cause of the lack of defense is "having sent a request for information, prior to the initiation of the

case, without informing the data subject of the reason for such a request." Regarding this
specific matter, the following considerations are made:

Among the powers that Article 58.1 of the GDPR grants to data protection authorities are:

"a) order the controller and the processor, and, where appropriate, the
representative of the controller or processor, to provide any information
required for the performance of their duties;
[…]
e) obtain from the controller and the processor access to all personal

data and all information necessary for the performance of their duties."

We must also point out that failure to comply with these orders is classified as an
administrative offense in the GDPR, whose Article 83.5 establishes that the following will be sanctioned:
"e) […] failure to provide access in violation of Article 58, paragraph 1."

In turn, the LOPDGDD provides in Article 47 that "The Spanish Data Protection Agency is responsible for supervising the application of this Organic Law and of Regulation (EU) 2016/679 and, in particular, for exercising the functions established in Article 57 and the powers provided for in Article 58 of the same regulation, in this Organic Law, and in its implementing provisions."

Article 51 of the LOPDGDD specifically refers to inspection functions, stating in sections 2 and 4: "2. Investigative activities shall be carried out by officials of the Spanish Data Protection Agency or by officials outside the agency expressly authorized by its Presidency." "4. Officials who carry out investigative activities shall be considered law enforcement officers in the exercise of their functions and shall be obliged to maintain confidentiality regarding any information they learn in the course of such exercise, even after they have ceased to do so."

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 114/164

The scope of the investigation activity is specified in Article 53 of the LOPDGDD in these terms:

“1. Those carrying out investigation activities may collect the information necessary to fulfill their duties, conduct inspections, request the display or delivery of necessary documents and data, examine them at the location where they are stored or where processing is carried out, obtain copies of them, inspect the physical and logical equipment, and request the execution of processing and management programs or procedures for supporting the processing subject to investigation.”

And correlatively to these functions, the LOPDGDD establishes a duty to collaborate in the development of investigations carried out by the Agency: Article 52, "Duty to collaborate," states:

"1. Public Administrations, including tax and social security authorities, and individuals shall be obliged to provide the Spanish Data Protection Agency with the data, reports, background information, and supporting documents necessary to carry out its investigation activities.
When the information contains personal data, the communication of said data shall be covered by the provisions of Article 6.1 c) of Regulation (EU) 2016/679."

In conclusion, there is a European Regulation that obliges the data controller to provide the supervisory authority with access to the information necessary for the exercise of its functions and, in addition, classifies the failure to comply with this obligation as an administrative offense. And an Organic Law that determines who will carry out the inspection work, details the activities in which the inspection may be carried out, and establishes a duty of cooperation.

The investigative actions, during which CAMERDATA was requested to provide this Agency with the information and the

documents requested, were initiated by agreement of the Agency's Director and carried out by an inspector from this Spanish Data Protection Agency, therefore, within the scope of the LOPDGDD and the GDPR.

It should be added that these types of inspection actions prior to the initiation of an administrative sanctioning procedure, when, as is the case here, they are

included in a law that also provides for sanctions for non-compliance, are
in accordance with the right not to incriminate oneself and do not represent—as suggested to the contrary—a violation of the right to defense.

The Constitutional Court (CC) has ruled on the mandatory compatibility of the

right not to incriminate oneself with certain legal obligations imposed on the citizen to cooperate with the Administration. The Constitutional Court has considered the right not to testify against oneself to be applicable to the scope of sanctioning proceedings (Judgment of the Constitutional Court
197/1995, of December 21), but specifies that this right must be qualified.

In this regard, in the Constitutional Court's opinion, the basic qualification of this right is that
in the administrative sanctioning procedure, it must be reconciled, by legal imperative and
in order to guarantee essential legal rights, with the defendant's compliance, under threat of sanction, with certain obligations to cooperate with the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 115/164

Administration in the investigation or inspection of the facts. STC 161/1997, of October 2, states that the legal obligation of a motor vehicle driver to submit to a breathalyzer test is consistent with the right not to testify against themselves, because "in the complex balance of guarantees and interests that come together in the sanctioning procedure: the guarantees against self-incrimination [...] do not [...] encompass [...] the right to evade preventive, investigative, or evidentiary measures that [...] the authorities may order. [...] The generic configuration of a right not to undergo any evidentiary procedure would leave public authorities defenseless in the performance of their functions." STC 76/1990, of April 26, and 197/1995, of December 21, rule in the same vein. There are also rulings along the same lines in ordinary case law,
by which we refer to the Supreme Court ruling of 21/05/2008 (rec. 3378/2007).

Therefore, the alleged lack of defense of the CAMERDATA entity must be rejected

due to the fact that, within the framework of inspection proceedings, the
Data Inspectorate of the Agency sent it a request for information prior to the
initiation of the sanctioning procedure. Nor can a lack of defense arise from the
failure to inform it of the reason for such a request, since those proceedings
were initiated by agreement of the Director of the Agency in accordance with the provisions of the
LOPDGDD (Legal Data Protection Act).

- Regarding the other alleged defenselessness—having been forwarded a voluminous administrative file (1,807 pages) “without granting it additional time,” which is why, it says, “has made it materially impossible for this company to review said file, and therefore its right to defense has been seriously impaired,”—two clarifications are required, according to which the alleged nullity cannot prosper.

The first clarification is that the maximum time by which an administrative deadline may be extended under the LPACAP is half of the time initially set for the procedure in question.

Article 32 of the LPACAP states that “The Administration, unless otherwise provided, may grant, ex officio or at the request of the interested parties, an extension of the established deadlines, not to exceed half of them, […].”

It is confirmed in the documentation in the file that in a document
signed by the investigating body on May 10, 2024, at CAMERDATA's request, it was agreed

to extend the period initially set for submitting arguments (10 business days) by the
maximum legally permitted (5 business days). Thus, contrary to what CAMERDATA
erroneously asserts, it was indeed granted an extension to submit arguments, and, furthermore, for the maximum time allowed.

The second clarification has to do with the reality of what happened—facts that
are proven by the documentation in the file—which demonstrate the extent to which the lack of time to submit arguments and present evidence is related to the management of that entity.

CAMERDATA accepted the notification of the initiation agreement on April 25, 2024, and the ten-business-day period for objections began the following day, April 26, 2024. The entity requested an extension of the period for objections and the delivery of a copy of the file in a letter submitted on May 7, 2024, after 6 of the 10 business days granted for objections had already elapsed. In a letter dated May 10, 2024, electronically notified on the same day and whose acceptance was recorded as having taken place on May 14, 2024, the entity was informed of the extension of the period it had requested and informed

that the documentation had been sent. Regarding the requested documentation, which, due to its volume and the format of some of its documents, had to be sent by postal courier, CAMERDATA states that it received it on May 13, 2024.

Without prejudice to the foregoing, and for the sake of completeness, it is emphasized that several months have passed since CAMERDATA had possession of the documentation

of the file that was sent to it—documentation that, incidentally, it was already aware of beforehand, if not in its entirety, at least the vast majority—and yet it has not availed itself of the opportunity offered by Article 76 of the LPACAP to submit, until the hearing, allegations, documents, or other evidence that are relevant to its rights.

For the reasons stated above, the request for a declaration of nullity of the proceedings due to an alleged violation of the right to defense cannot be admitted.

2. In defense of its claim to have the proceedings dismissed, CAMERDATA alleges the nonexistence of the violations alleged in the

initiation agreement. In summary, it presents these arguments:

2.1. Violations of Article 6.1 of the GDPR:

The agreement initiating this procedure charged CAMERDATA with three alleged

violations of Article 6.1 of the GDPR, each of which is specified in the following
processing:
"a) Having collected and processed in its own information system the data transmitted by the CDE without a lawful basis.
b) Having transferred to third parties, without a lawful basis, its Spanish Company File, whose most relevant data, such as the NIF, were obtained from the CDE.
c) Having transferred its File to the company KOMPASS for the dual purpose of providing a feedback service on the information collected therein and for use by this entity for its own activities."

2.1.1. Violations of sections a) and b).

It invokes the existence of a legal basis for lawfulness, Article 6.1.f) of the GDPR,
based on the iuris tantum presumption of lawfulness in Article 19.2 of the LOPDGDD. The
consequence, in its understanding, is that it is up to this Agency to overrule the
presumption of lawfulness it enjoys, which it considers extendable to all data of entrepreneurs

as such (which includes the NIF).

It invokes the absence of the subjective element of culpability that would determine the
nonexistence of the infringement. It bases the absence of culpability "on the legitimate trust generated by the AEPD's own actions" in relation to its

processing of the data of self-employed entrepreneurs.

Alternatively, it invokes the non-application of the circumstances considered to be
aggravating factors.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 117/164

2.1.2. Violation of section c)

Regarding the violation of Article 6.1 of the GDPR described in the initiation agreement in letter
“c) Having transferred its File to the company KOMPASS for the dual purpose of providing a feedback service for the information collected therein and for use by this entity for its own activities” -

CAMERDATA alleges that the data transferred is exclusively data from companies

incorporated as legal entities, and therefore denies any violation of the GDPR. Alternatively, it invokes the non-application of the circumstances considered as aggravating factors.

The examination of this violation and the allegations made by CAMERDATA is carried out

in Grounds VI of this proposed resolution.

2.2. Violation of Article 14 of the GDPR

CAMERDATA believes that the legal considerations and reasoning of the initial agreement do not conform to the facts or the legal system for the following

reasons:
a. The conduct described does not constitute a violation of Article 14 of the GDPR because (i) the duty to inform data subjects under Article 14.5.b) of the GDPR has been fulfilled, due to the disproportionate effort required, and (ii) it was not committed through fault or negligence.

b. Alternatively, it considers that none of the factors used to determine the amount of the fine that could be imposed cannot be established: severity, fault or intentionality, category of sensitive data, and connection to the offender's activity.

This violation and the allegations made by CAMERDATA are examined in Grounds VIII of this proposed resolution.

2.3. Violation of Article 28 of the GDPR.

The Court denies having violated this provision, which the agreement initiating the sanctioning procedure attributed to it, considering that the contract signed with DMOVO ANALITYCS, S.L., dated February 3, 2020, for the provision of certain services, "although it contains a confidentiality clause, does not incorporate the other provisions established in Article 28.3 of the GDPR, and therefore this obligation must be deemed to have been breached."

This violation and the allegations made by CAMERDATA are examined in Grounds X of this proposed resolution.

VIII

Response to the allegations regarding the proposed resolution

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 118/164

1. According to CAMERDATA, the principle of typicality has been breached.

CAMERTATA focuses on reiterating that a literal or grammatical, teleological interpretation that takes into account the legislative history, the social reality of the time in which it is to be applied, or based on the current social and economic context in which Article 19.2 of the LOPDPGDD applies, excludes the processing of data of individual entrepreneurs to whom the presumption of lawfulness extends

from being limited to mere "contact data."
However, on this issue, it should be noted that the GDPR, which has been directly applicable

in Spain since 2018, does not contemplate any general exclusion for data of individual entrepreneurs. On the contrary, it considers that any data relating to an
identified or identifiable natural person is personal data and must be subject to the
guarantees established in the regulations. In this sense, Article 19.2 of the LOPDGDD only establishes a legitimate interest for the processing of contact data of individual entrepreneurs within the framework of professional relationships, and under certain

conditions or guarantees.

Article 2.3 of the RLOPD referred to "merchants, industrialists, or shipowners,"
but without establishing a general principle of exclusion from the data protection regime, but rather delimiting in which specific cases it may not apply. The LOPDGDD
expressly repeals any provisions of equal or lower rank that contradict,
oppose, or are incompatible with the provisions of the GDPR and the LOPDGDD
(Sole Repealing Provision, paragraph 3). The GDPR does not exclude individual entrepreneurs from its protective mantle; therefore, Article 2.3 of the LOPD must be expressly repealed.

Article 8 of Law 4/2014, of April 1, Basic Law on Official Chambers of Commerce, Industry, Services, and Navigation, establishes that the information provided by the State Tax Administration Agency (AEAT) to the Chambers of Commerce must be used exclusively for the preparation of the public business census, the electoral register, and for the public functions that the law itself assigns to these entities.
This legal limitation prevents further use of the data by third parties for purposes other than those expressly provided for in the law, such as marketing it through business databases. CAMERDATA seeks to rely on the
presumption of Article 19.2 of the LOPDGDD (Spanish Data Protection Act) without taking into account the limits of this presumption, which also allows for proof to the contrary as it is a rebuttable presumption and does not allow for processing contrary to the law.

The European Data Protection Board (EDPB) has reiterated in its Guidelines
1/2024 on the processing of personal data based on legitimate interest that the

existence of a legitimate interest requires a lawful interest, which is not the case here.
Finally, regarding the fact that the NIF is essential for the proper fulfillment of

the legal obligation to provide truthful and accurate data and that it is business-related data, it should be noted that Article 8 of Law 4/2014 itself imposes
the limitation of the fundamental right to data protection, conferring on the CDE and the Chambers of Commerce the obligation to compile a public census of companies. It is this law that
establishes the scope of the limitation by establishing its purpose, as required by

Article 6.3 of the GDPR, without the data processing being able to go beyond the
legally established purpose. Article 8 says nothing about the conditions
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 119/164

under which further processing of personal data may be considered compatible with
the purposes of its initial collection. The NIF (Tax Identification Number) is not published in the public business register, and
the enabling law establishes an obligation of confidentiality regarding the data provided

by the tax authorities. Therefore, the existence of a
supposed legitimate interest cannot be invoked to justify data processing that is
prohibited.

2. Regarding the absence of a violation of Art. 14 of the GDPR, since, in CAMERDATA's opinion, the exception set forth in Article 14(5)(b) would apply, the following should be noted:

The claim submitted by CAMERDATA seeks to justify the failure to comply with the information obligation set forth in Article 14 of the GDPR by invoking the exception

contemplated in its paragraph 5(b), alluding to an alleged disproportionate effort due to the large number of data subjects.

However, this argument cannot be accepted for several reasons.

Recital 62 of the GDPR, as well as the EDPB Transparency Guidelines, make it clear that the exemption must be interpreted restrictively and can only be
applied when exceptional circumstances arise, with the controller being required to provide specific and documented proof that all requirements are met.

In this case, CAMERDATA has not proven the technical impossibility nor has it justified
with objective and verifiable criteria that the economic or administrative effort is

effectively disproportionate under the terms required by the GDPR.
And, above all, in the event of admitting the disproportionate effort of informing
all interested parties, it would have been essential to prove that it had adopted the
appropriate measures to protect the rights, freedoms, and legitimate interests of the
self-employed workers, in particular that it had made available to them the information it is

obliged to provide in accordance with Article 14, paragraphs 1 and 2 of the GDPR.
The publication of a privacy policy on a website cannot
be considered an adequate measure in itself when the processing involves the
collection and transfer of personal data without the prior knowledge of the interested parties.

In this regard, the Transparency Guidelines under Regulation 2016/679 (wp260rev.01) of the former WG29, adopted by the EDPB, state the following:

“64. Where a controller seeks to invoke the exception provided for in Article 14(5)(b) on the grounds that providing the information would entail a disproportionate effort, the controller must weigh the effort involved in providing the information to the data subject against the effects and impact of not receiving the information for the data subject. The controller must document this assessment in accordance with its proactive accountability obligations. In such a case, Article 14(5)(b) specifies that the controller must take appropriate measures to safeguard the rights, freedoms and legitimate interests of the data subject. This also applies where a controller determines that it is impossible to provide the information or that doing so would render impossible or seriously impede the achievement of the objectives of the data subject. processing. An appropriate measure, as specified in Article 14(5)(b), that controllers must always take is to make the information public. Controllers can do this in several ways, for example, by publishing the information on their website, or by proactively announcing the information in a newspaper or on posters at their premises. In addition to making the information public, the other appropriate measures will depend on the circumstances of the processing, but these may include: carrying out a data protection impact assessment; applying pseudonymization techniques to the data; minimizing the data collected and the storage period; and implementing technical and organizational measures to ensure a high level of security. On the other hand, there may be situations in which the controller is processing personal data without it being necessary to identify the data subjects (for example, with pseudonymized data). In such cases, Article 11(1) may also be relevant, as it provides that a data controller shall not be obliged to maintain, obtain, or process additional information to identify the data subject for the sole purpose of complying with the GDPR.

However, in this case, CAMERDATA has not adopted any adequate measures to protect the rights of data subjects. Furthermore, as the EDPB has pointed out, such measures do not replace the individual duty of information, especially in processing operations with a high potential impact on the rights and freedoms of data subjects.

Furthermore, there is no evidence that CAMERDATA has individually evaluated
other possible less burdensome measures, such as the sending of progressive or layered communications, the use of automated electronic means, or any

formula that, without implying a disproportionate effort, would guarantee a minimum level
of individualized information in accordance with the principle of transparency.

In short, the claim presented does not sufficiently demonstrate that the
legal requirements for applying the exception of Article 14.5.b) of the GDPR are met, nor that the
measures adopted are sufficient to replace the duty of direct information. CAMERDATA's actions, therefore, constitute a clear violation of Article 14, as
the personal data of thousands of individuals have been processed without them being

effectively and fully informed about the processing of their personal data, nor of their
source, nor of their rights.

3 Regarding the absence of culpability due to the existence of causes that exclude culpability in both violations, CAMERDATA argues that it has made a reasonably justified interpretation of the applicable regulations.

Regarding this argument, it is important to highlight that Law 40/2015 requires that violations be committed intentionally or negligently, but this does not mean that a company can avoid liability by claiming ignorance or its own interpretations of the regulations. CAMERDATA had an obligation to verify the legality of the data it marketed, especially when processing personal information of individual entrepreneurs. Opinion 3/2010 of the Article 29 Working Party (WP29) - WP 173 - issued
during the validity of the repealed Directive 95/46/EEC, whose provisions are
currently applicable, states that the "essence" of proactive accountability is
the obligation of the data controller to implement measures that, under

normal circumstances, ensure that data protection rules are complied with in the context of processing operations and to have
documents available that demonstrate to data subjects and the Authorities
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 121/164

control what measures have been adopted to achieve compliance with data protection rules.

For these purposes, the provisions of Recital 74 of the GDPR are taken into account:

"The controller's responsibility should be established for
any processing of personal data carried out by the controller or on its own behalf. In
particular, the controller should be obliged to implement timely and effective measures and

should be able to demonstrate the compliance of the processing activities with
this Regulation, including the effectiveness of the measures. Such measures should take
into account the nature, scope, context, and purposes of the processing, as well as the
risk to the rights and freedoms of natural persons."

Completing the above and in development of Article 5.2 of the GDPR, Articles 24 and 25 of the same legal text must be cited. The latter indicates, with respect to “Data Protection by Design and by Default,” that the fundamental right to the protection of personal data is much more than mere technology, as its focus is on the risks to the rights and freedoms of data subjects arising from the processing of personal data,

“1. Taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing, as well as the risks of varying likelihood and severity that processing entails for the rights and freedoms of natural persons, the data controller shall apply, both when determining the means of processing and at the time of processing, appropriate technical and organizational measures, such as pseudonymization, designed to effectively implement data protection principles, such as data minimization, and integrate the necessary safeguards into the processing, in order to comply with the requirements of this

Regulation and protect the rights of data subjects.

2. The data controller shall implement appropriate technical and organizational measures to ensure that, by default, only personal data necessary for each of the specific purposes of the processing are processed…”

The lack of measures to guarantee the principle of lawfulness and the right of data subjects to information demonstrates negligent conduct.

4. Violation of the criteria applied to grade the sanction

In this regard, it should be noted that the reasons that determined the grading of the sanctions to be imposed are set out in paragraph XIV of this resolution, to which we refer. However, it is worth highlighting the following:

Article 83.2 of the GDPR establishes that the duration of a violation and the number

of data subjects are key criteria for graduating sanctions, as they reflect both the scope of the non-compliance and the controller's persistence in maintaining a situation contrary to the regulations. In this case, the continued illegal processing and the lack of information for several years for a large number of data subjects constitute the seriousness of the violations, which aggravates CAMERDATA's liability.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 122/164

Regarding the special nature of the NIF (Tax Identification Number), although the NIF is not part of the
special categories of data set out in Article 9 of the GDPR, its improper processing is particularly sensitive, as it constitutes key data for identifying

and linking a natural person to multiple administrative, financial, and tax procedures, which aggravates the impact of unlawful processing. The use of the NIF without an adequate legal basis and without adequate information for interested parties increases the risks of identity theft and misuse, which implies the need to apply a sanction proportional to the severity of the infringing conduct.

Regarding the connection between the offender's activity, Article 76.2 of the LOPDGDD (Spanish Data Protection Act) states that "In accordance with the provisions of Article 83.2.k) of Regulation (EU)

2016/679, the following may also be taken into account: (…)
b) The connection between the offender's activity and the processing of personal data."

The legislator has provided for the possibility of taking into consideration whether the offender,
through their activity, is linked to the processing of personal data.
Therefore, the possibility of "reproach" for the violation could be greater. In this case, it is; this is a company linked to the processing of personal data. Therefore, this circumstance has been taken into account by this Agency when graduating the fine for the violations subject to this sanctioning procedure.

In this regard, the National Court has considered that it is correct to consider the aggravating circumstance provided for in art. 76.2.b) of the LOPDGDD, provided that the aforementioned link exists, and this has been considered in numerous rulings, including those dated July 4, 2024 (rec. 382/2022), which states in relation to the aforementioned circumstance that:

"It is also possible to appreciate the aggravating circumstance of the continuous nature of the infringement,
set forth in Article 76.2.a) of Organic Law 3/2018, of December 5, on the Protection

of Personal Data and the Guarantee of Digital Rights, referring to this when we analyze the application of the GDPR to the infringement at hand.
Likewise, the assessment of the link between the infringer's activity and the processing of personal data (Article 72.2.b) of Organic Law 3/2018, of December 5), due to the fact that the appellant's activity is linked to the processing of personal data. of both customer and third-party data; the aforementioned

connection is well known, since the entity, due to its activity, is in constant contact with customers and third parties, processing a large volume of data, which imposes a greater
duty of diligence.”

5. Regarding the violation of the principle of proportionality.

It should be noted that Article 83.1 of the GDPR provides that “Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article for the infringements of this Regulation indicated in paragraphs 4, 5, and 6 are, in each individual case, effective, proportionate, and dissuasive.”

Thus, as can be deduced from the provision invoked, the fines must be effective, proportionate, and dissuasive to achieve the purpose intended by the GDPR.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 123/164

It is true that for this system to function with all its guarantees, several elements must be implemented fully and completely. The application of rules outside the GDPR regarding the determination of fines in each of the Member States applying their national law, whether due to aggravating or mitigating circumstances not provided for in the GDPR—or in the LOPDGDD in the Spanish case, as permitted by the GDPR itself—would render the system ineffective, rendering it meaningless, teleological, and unconventional. The result would be that the fines imposed for various violations would no longer be effective, proportionate, and dissuasive. And this would also deprive data subjects of the effective guarantee

of their rights and freedoms, weakening the uniform application of the GDPR. It would diminish the mechanisms for protecting citizens' rights and freedoms,
and would be contrary to the spirit of the GDPR.

The GDPR is endowed with its own principle of proportionality, which must be applied strictly.

Regarding the principle of proportionality of sanctions, the National Court has stated in numerous rulings that the principle of proportionality cannot be exempt from judicial review, since the margin of appreciation granted to the

Administration in imposing sanctions within the legally established limits must be developed by weighing, in all cases, the concurrent circumstances in order to achieve the necessary and proper proportion between the alleged acts and the liability required, given that any sanction must be determined in accordance with the magnitude of the violation committed and according to a criterion of proportionality in relation to the circumstances of the act. Therefore, proportionality constitutes a normative principle imposed on the Administration and that limits the scope of its sanctioning powers.

Thus, in accordance with the circumstances of this case, which have been meticulously and appropriately evaluated, this resolution does not violate the principle of proportionality in determining the sanction imposed. It is considered balanced and proportionate to the seriousness of the violation committed, the importance of the facts, and the circumstances taken into account in determining the sanction. No reasons are found to further justify the reduction, especially considering the amount that such sanctions may amount to in accordance with Art. 83.5 of the GDPR, which provides for violations of
Articles 6 and 14 of the GDPR, "administrative fines of a maximum of €20,000,000 or,

in the case of a company, an amount equivalent to a maximum of 4% of the total global annual turnover of the previous financial year, whichever is higher."

In the present case, CAMERDATA has a turnover of 100,000 euros, resulting in the fines imposed for violations of Articles 6 and 14 of the GDPR, which would be at the lower end of the possible administrative fine that could be imposed on the data controller and far from the maximum of 4% of the total global annual turnover of the previous financial year, taking into account turnover.

6- Regarding the inappropriate and disproportionate nature of the proposed corrective measures, it is indicated that

In the present case, corrective measures are ordered to prevent incidents such as the one that occurred and led to the opening of the sanctioning procedure.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 124/164

The GDPR grants the AEPD corrective powers as the supervisory authority in its
Article 58.2, sections a) to j). Specifically, letter d) of the provision establishes that the supervisory authority may "order the controller or processor to comply with the provisions of this Regulation, where appropriate, in a specific manner and within a period of time..."

The corrective measures ordered in this resolution are intended to address the infringement committed and to correct the effects of the infringement. This is done so with the aim of preventing further violations of the fundamental right to the protection of personal data of data subjects. Therefore, there is no room for disproportionate action when the measure is intended solely to prevent further violations of the GDPR.

IX

Infringement of Article 6.1 of the GDPR

Article 5 of the GDPR, relating to the principles governing the processing of personal data, includes, among them, Article 5.1.a), the principle of lawfulness. Any processing of personal data must be based on one of the legal grounds specifically listed in Article 6.1 of the GDPR, which provides:

“1. Processing shall only be lawful if at least one of the following conditions is met:

a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
b) processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract;
c) processing is necessary for compliance with a legal obligation applicable to the data controller;

d) processing is necessary to protect the vital interests of the data subject or of another natural person;
e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a Third, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
The provisions of point (f) of the first paragraph shall not apply to processing carried out by public authorities in the exercise of their duties.

The principle of lawfulness ensures that all data processing operations are carried out on a valid legal basis; that throughout the processing cycle, the data are processed with a justifiable reason. For each processing operation, the controller must establish a valid legal basis appropriate to the specific purpose of that processing. Under this principle, data controllers are required to identify a valid legal basis before carrying out any processing operation.

Recital 40 of the GDPR states:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 125/164

“For processing to be lawful, personal data must be processed with the consent of the data subject or on another legitimate ground established by law, whether by this Regulation or by other Union or Member State law to which this Regulation refers, including the need for compliance with a legal obligation applicable to the controller or the need to perform a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.”

2. CAMERDATA is found to have violated Article 6.1 of the GDPR for having processed the personal data of individual entrepreneurs without an adequate legal basis under the GDPR. It collects the data provided by the CDE, processes it in its own information system, and transfers it to third parties for use or feedback to its own file (called the Spanish Business File or FEE) or to individuals for processing for their own purposes.

The agreement initiating this procedure charged CAMERDATA with three alleged violations of Article 6.1 of the GDPR, each of which is specified in the following processing actions:

“a) Having collected and processed in its own information system the data transmitted by the CDE without a lawful basis.
b) Having transferred to third parties, without a lawful basis, its Spanish Company File, the most relevant data of which, such as the NIF, were obtained from the CDE.
c) Having transferred its File to the company KOMPASS for the dual purpose of providing it with a feedback service for the information collected therein and for use by this entity for its own activities.”

The investigations confirm that, in compliance with Article 8 of Law 4/2014, the tax authorities transfer to the CDE information obtained from the IAE and census data concerning individual entrepreneurs. The conditions applicable to the transfer of tax information on self-employed entrepreneurs by the AEAT (Tax Agency) to the CDE are regulated in the agreement signed on December 20, 2019 (Agreement for the transfer of tax information to Official Chambers for the fulfillment of their public-administrative functions). The agreement prohibits (clause four) the transfer of the information received to third parties.

In 2016, the CDE and CAMERDATA signed a "Transfer of Business Databases" contract, the purpose of which is the transfer by the former to the latter of "a copy of all the business data contained in the Basic Business Census referred to in Exhibit V above (hereinafter the Transferred Database) [...] which contains the information fields indicated in Annex I [...]."

The contract stipulates that "The Transferred Database will be updated periodically under the terms agreed upon by the Parties in the contract and its annexes." Among the personal

data of the individual entrepreneurs included in the "Transferred Database" is the NIF (Tax Identification Number).

In this regard, Annex I of the contract details that the database and its

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 126/164

updates will contain the following information fields for each company listed therein: Number 1 indicates the "Company NIF." The remaining information fields in the transferred and updated Database are (2) the

name or corporate name of the company; (3) main address; (4) business address; (5) IAE (Emergency Tax Identification Number) activity section; and (6) IAE (Emergency Tax Identification Number) activity.

In its response to the Inspectorate's request, CAMERDATA reported "all" the personal data relating to self-employed entrepreneurs included in its database and detailed its origin and whether it was transferred to third parties. The first piece of data, it stated at the time, was the NIF (Tax Identification Number), the source of which it stated:
"The source of the data is the public business census published by the Spanish Chamber of Commerce in accordance with the provisions of Law 4/2014 (hereinafter, the Public Business Census), and is obtained each time a new business census is uploaded."

And regarding its transfer, it states that "The NIF data is transferred to clients who request the business information services offered by Camerdata, including, on the one hand, entities in the sector known as infomediary or information reusing companies (Axesor, Cerved, Datacentric, Equifax, Informa, Iberinform, and Moody's) and, on the other hand,

final clients who request it for their exclusive internal use."

However, as evidenced in the file, the public business census, that is, the one published on the CDE website under the authorization granted by Article 8 of Law 4/2014, does not include the NIF data of

individual entrepreneurs. The data included in the public census are,
exclusively, name, surname, address, postal code, municipality, and activity (IAE heading and description of the activity).

The agreement to initiate the procedure indicated that CDE, in addition to having provided

the data contained in the public business register to CAMERDATA without a legal basis, had provided it with additional data, such as the NIF (Tax Identification Number). In short, it had provided CAMERDATA with information in addition to that published
in the public register, since the NIF (Tax Identification Number) is not included therein.

CAMERDATA responded to its allegations regarding the initiation agreement by offering a

new version of the facts (which it justifies as a material error). It now acknowledges that
the NIF (Tax Identification Number) is not included in the public business register and states that CDE does not
provide the NIF (Tax Identification Number) of self-employed entrepreneurs, but rather obtains it by its own means, as what it receives is the NIF (Tax Identification Number) encrypted using an MD5 algorithm.

At this point, it is necessary to make a specific reference to the source of the data on the NIF of the individual entrepreneurs that CAMERDATA processes in its systems. Although the initial information was that the CDE provided it in plain text and that it came from the public business census, once it was proven that it was not included in the public census, the CDE maintains that what the CDE provides is not the NIF but the hash of the NIFs, data that it obtains through its own means.

This claim, however, cannot be accepted. What the CDE provides to CAMERDATA is the NIF data of the self-employed, albeit pseudonymized. The result of applying the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 127/164

hash function on the self-employed person's NIF data does not, in this case, result in anonymized information that is therefore excluded from the scope of the GDPR. Rather, it results in pseudonymized personal data that CAMERDATA reverts, as can be seen from its statements and from what will be explained below.

Article 4.5 of the GDPR defines pseudonymization as "the processing of personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures designed to ensure that the personal data are not attributed to an identified or identifiable natural person."

Recital 26 of the GDPR indicates that anonymized data is outside the scope of the GDPR:

“Therefore, the principles of data protection should not apply to anonymized

information.” And that pseudonymised data and information linked to that dataset are indeed included in the protection provided by the GDPR:

“The principles of data protection should apply to all information relating to an identified or identifiable natural person. Pseudonymised personal data, which could be attributed to a natural person by the use of additional information, should be considered information about an identifiable natural person. In determining whether a natural person is identifiable, all means, such as identification, which could reasonably be used by the controller or any other person to directly or indirectly identify the natural person should be taken into account. In determining whether there is a reasonable likelihood that means will be used to identify a natural person, all objective factors, such as the costs and time required for identification, should be taken into account, taking into account both the technology available at the time of the processing and technological developments.”

The nature of pseudonymised personal data, which, in this case, is the The result obtained from applying the hash function to specific input information is

evidenced in light of Opinion 05/2014 on anonymization techniques, WP216,
adopted by the Article 29 Working Party (WP29) on April 10, 2014. Its explanation is even clearer when the information to which the technique is applied is, as is the case here, the NIF (Tax Identification Number), and this circumstance is known to CAMERDATA.

Opinion 05/2014 of the WP29 devotes a specific section to pseudonymization

on which it states:
"Pseudonymization consists of replacing one attribute (usually a
single attribute) with another in a record. Consequently, there remains a
high probability of indirectly identifying the natural person; in other
words, the exclusive use of pseudonymization does not guarantee an anonymous

data set. However, this opinion examines this method due
to the numerous misconceptions and errors that exist about it.
Pseudonymization reduces the linkability of a data set to the
identity of the data subject; it is, therefore, a useful security measure,
but it is not an anonymization method.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 128/164

The result of pseudonymization may be independent of the initial value (such as a random number generated by the data controller or a surname chosen by the data subject) or derived from the original values of an attribute or set of attributes, such as in the case of hash functions or encryption systems.

It refers to the most commonly used pseudonymization techniques and mentions the hash function:

"Hash function: This is a function that returns a fixed-size result from an input value of any size (this input can be made up of a single attribute or a set of attributes). This function is not reversible, meaning there is no risk of reversing the result, as in the case of encryption. However, if the range of the input values of the hash function is known, these values can be passed through the function to obtain the actual value of a given record. For example, if the hash function is applied to the national identification number to pseudonymize a data set, this attribute can be obtained simply by running the function with all possible input values and comparing the results with the values in the data set. Hash functions are typically designed to run relatively quickly, making them subject to brute-force attacks. 16 Tables can also be created. precalculated to achieve
a massive reversal of a large number of hash values.
The use of a "salted" hash function (in which a random value,
known as "salt," is added to the attribute to which the hash function is applied) can reduce

the probability of obtaining the input value. However, using reasonable
means, it is still possible to calculate the original value of the attribute
hidden behind the result of a salted hash function17."

We bring up CAMERDATA's response to the question posed during the

testing phase about the means by which it obtains the NIF data of self-employed workers. Answer:

“The NIF is obtained by applying the following process:
- Input: file received from CDE (*) with the following format:
NUMBER: sequential number that CDE assigns to each individual entrepreneur

MD5 CODE: MD5 code resulting from applying the MD5 algorithm to the NIF (*)”
[…]
- Process: all NIF number combinations are generated in the individual entrepreneur format, and the MD5 algorithm is applied to each combination. The resulting MD5 code is cross-referenced with the file received from CDE to obtain the

correspondence with the sequential number associated with the rest of the data.”

Two elements are worth mentioning: On the one hand, the process used by CAMERDATA is the same as that described in Opinion 05/2014 of the WP29 as a prototypical case in which the information provided can be reversed through a hash. On the other hand, the input information includes a sequential number that CDE assigns to each individual entrepreneur. This sequential number also appears in the file with the rest of the data on the self-employed entrepreneurs that it provides. In this regard, we refer to the seventh Proven Fact, which includes the documentation that CAMERDATA provided during the testing phase regarding the transmission carried out by the CDE. It is stated that the CDE sent it two files:

1) A file with the following format:
NUMBER: Sequential number that CDE assigns to each individual entrepreneur

MD5 CODE: MD5 code resulting from applying the MD5 algorithm to the NIF.

2) Another file with the following format, as detailed in the document
“SENT TO CAMERDATA 2023_v1.docx:
Identification:
Number (sequential number that CDE assigns to each individual entrepreneur)

Name (first and last name)
Regarding the main address:
sg (street acronym)
street (street name)
number (street number)

[…]”

Consequently, the fact that CDE has not provided CAMERDATA with the self-employed workers' NIF data in plain text—as stipulated in the contract signed between the two—but, as stated by CAMERDATA, has provided the NIF hash,
does not mean that it will not provide the NIF data. In this case—with the information provided, the sequential number assigned by the EDPB to each individual entrepreneur—the personal data of the individual entrepreneur's NIF is transferred, although pseudonymized. As the WP29 Opinion makes clear, the hashing technique can be a security measure, but it may not imply data anonymization.

Recently, on January 16, 2025, the EDPB approved Guidelines 01/2025 on pseudonymization. Section 88 states the following:

“88. Within the scope of pseudonymization, it should not be possible to attribute pseudonymized data relating to a data subject whose identifiers are known. This could be done by applying the pseudonymization transformation to such identifiers, obtaining the pseudonym, and locating the pseudonymized data attached to that pseudonym. (For example, if you know that the transformation is simply a SHA256 hash of a name, you could apply this to all the names you have elsewhere and then see which hashes match in the dataset.) Therefore, the transformation must include information that the pseudonymized controller keeps secret and that an unauthorized person cannot use. Only possession of the secret information should allow the calculation of the pseudonym given the identifier. In order to limit the probability of a successful guess or brute-force search, the secrets must have sufficient entropy. Entropy refers here to the randomness of the secret parameter. For example: If the
controller selects the date on which the pseudonymization transformation was applied
as a parameter, the entropy of this parameter will be very low. However, if the

controller selects a randomly generated string of 20 alphanumeric characters
as the secret parameter, the entropy is high.) For the first class, cryptographic algorithms, this information takes the form of secret parameters or keys. For the
second class, lookup tables, the controllers keep the tables secret. (Our translation)

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 130/164

3. The legal basis that CAMERDATA invokes in its allegations to the initiation agreement
as the basis for the data processing carried out is the prevalence of its legitimate interest (Article 6.1.f). It considers that, according to Article 19.2 of the LOPDGDD enjoys
a rebuttable presumption of lawfulness based on this legal basis, and is therefore exempt from proving the prevalence of its legitimate interests over the interests, rights, and freedoms of the data subjects. Accordingly, it would be up to this Agency to overrule the presumption of lawfulness that it understands to protect it.

However, the conclusion reached by CAMERDATA when interpreting the scope of Article 19 of the LOPDGDD cannot be accepted.

Article 19 of the LOPDGDD, "Processing of contact data, data of individual entrepreneurs, and independent professionals," provides:

"1. Unless proven otherwise, the processing of contact data and, where applicable, data relating to the function or position held by natural persons who provide services to a legal entity shall be presumed to be covered by the provisions of Article 6.1.f) of Regulation (EU) 2016/679, provided that the following requirements are met:

a) The processing relates solely to the data necessary for their professional location.
b) The purpose of the processing is solely to maintain relations of any kind with the legal entity for which the data subject provides their services.

2. The same presumption shall apply to the processing of data relating to sole proprietors and independent professionals when the data relates to them solely in that capacity and is not processed to establish a relationship with them as natural persons.

3. The data controllers or processors referred to in Article 77.1 of this Organic Law may also process the data mentioned in the two previous sections when this arises from a legal obligation or is necessary for the exercise of their powers. (Emphasis added)

Section 2 of Article 19 of the LOPDGDD incorporates a rebuttable presumption of lawfulness, based on the circumstance described in letter f) of Article 6.1 of the GDPR, with respect to the processing of data of individual entrepreneurs, which is limited exclusively to contact data. It also requires that these requirements be met: (i) that they "refer to them solely in that capacity" as entrepreneurs; and (ii) that the processing of contact data is not intended to establish a relationship with them as natural persons.

The rebuttable presumption of lawfulness contemplated in Article 19.2 of the LOPDGDD applies only to the processing of "contact data" of individual entrepreneurs. An exception to this general rule is made if the processing of such contact data is intended to establish a relationship with the entrepreneurs as individuals. Physical.

Opinion 757/2017, of October 26, of the Council of State, on the preliminary draft

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 131/164

of the Organic Law on Data Protection (current LOPDGDD) dispels any doubts that may arise regarding the meaning and scope of the iuris tantum presumption of lawfulness contained in Article 19.2 of the LOPDGDD. Commenting on what was, in the preliminary draft, Article 20 (current Article 19), it states:

“Article 20 of the Preliminary Draft regulates the processing of contact data of natural persons who provide services to a legal entity (section 1) and of individual entrepreneurs (section 2), in both cases invoking the provisions of Article 6.1.f) as regulatory protection. of the Regulation. In the first case, in order to

understand that there is legality under this article, the provision requires that the
processing relates only to the data necessary to locate the interested party's professional activity and that the purpose of the processing is solely to maintain
relations of any kind with the legal entity for which the affected party provides their services; In the second, the processing relates solely to the data of the entrepreneurs in that capacity and is not processed to establish a relationship with them as natural persons." (Emphasis added)

It follows from the foregoing that the processing of personal data of an entrepreneur or natural person that is not contact data, even if it also relates to them in their capacity as entrepreneurs and whose processing is not intended to establish a relationship with them as natural persons, will not be covered by the rebuttable presumption of lawfulness in relation to Article 6.1.f) GDPR.

The consequence is that the data controller is obliged, by virtue of the principle of proactive accountability (Article 5.2 GDPR), to demonstrate that there is an adequate legal basis under the GDPR on which the lawfulness of the processing is based.

Translating these considerations to the facts under consideration, it is clear that The information concerning each self-employed entrepreneur that CAMERDATA processes, provided by the CDE, includes numerous non-contact data: starting with the NIF (Tax Identification Number), which undoubtedly identifies the individual, up to the IAE (Tax Identification Number). Therefore, the file containing the information relating to each entrepreneur, as long as it is not limited to processing contact data, does not enjoy the presumption of lawfulness based on the prevailing legitimate interest (Article 6.1.f GDPR).

The consequence of the above is that no presumption of lawfulness covers the processing of data of self-employed entrepreneurs carried out by CAMERDATA.

For its part, CAMERDATA, in its extensive arguments, expresses its disagreement with the idea that the purpose of the public business register is exclusively that derived from Article 8 of the LPACAP (Spanish Tax Code). It also maintains that the NIF (Tax Identification Number) of self-employed entrepreneurs It is business data. It states in this regard: "Ultimately, the NIF, as business data, is not part of the privacy and intimacy of individual entrepreneurs, but is essential data for operating in the market and for the security of commercial legal transactions."

It considers that the data of self-employed entrepreneurs are subject to a specific legal regime and sees Article 19.2 of the GDPR as confirmation of this opinion:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 132/164

"Therefore, there is no doubt that the data of individual entrepreneurs, insofar as they act in such a capacity, enjoy completely different protection from the personal data of natural persons with regard to their private or private sphere of activity."

He defends a particular interpretation of Article 19 that is consistent with the specific legal regime to which, he says, the data of self-employed entrepreneurs are subject, according to which "all" data of self-employed entrepreneurs, when referring to them in that capacity, are included in the rebuttable presumption established in Article 19 of the LOPDGG.

Thus, it states: "Thus, Article 19 of the LOPDGDD establishes a legal presumption "iuris tantum" that the processing of data of self-employed or individual entrepreneurs is lawful under Article 6.1.f) of the GDPR when certain requirements are met."

This statement is erroneous insofar as it is incomplete: the requirements must indeed be met and are set out in Article 19.2 of the LOPDGDD, but not all data of individual entrepreneurs are subject to the presumption of lawfulness to which we are referring, but only, as stated in the initial agreement (page 45,

paragraph transcribed above), "contact information."

CAMERDATA thus concludes that Article 19.2 of the LOPDGDD exempts it from having to assess whether the data subject's interests or fundamental rights and freedoms that require personal data protection do not prevail over its legitimate interest or that of third parties.

4. Regarding the alleged violations of Article 6.1 of the GDPR, sections a) and b), which were attributed to CAMERDATA in the initiation agreement.

4.1. The initiation agreement attributed this entity with violations of Article 6.1 of the GDPR for the conduct described in sections a) and b):
a) Having collected and processed in its own information system the data transmitted by the CDE without a lawful basis.

b) Having transferred its Spanish Company File to third parties, without any legal basis, the most relevant data, such as the NIF, obtained from the CDE.”

CAMERDATA maintains:

(i) That, based on the reasoning set forth, in relation to the conduct

described in sections a and b, no violation of the principle of lawfulness has been proven, given that it enjoys a presumption of prevalence of legitimate interest under Article 19.2 of the GDPR.

(ii) That, also limited to those two cases of infringement of Article 6.1 of the GDPR

that were imputed in the initiation agreement, these conducts do not contain the
indispensable subjective element of the infringement.

4.2. CAMERDATA alleges that the lack of culpability it invokes is well-founded.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 133/164

“in the legitimate trust generated by the AEPD's own actions” in relation to the processing of personal data of self-employed workers or individual entrepreneurs. It then emphasizes that, in its opinion, it is striking that the initiation agreement did not mention “circumstances of relevance to the purposes of this procedure, known to the supervisory and control body, which directly affect the determination of whether or not Camerdata acted intentionally or negligently.”

The following are relevant circumstances:

-a. The AEPD Resolution of 27/02/2001, issued in the case initiated as a result of the complaint filed against a Chamber of Commerce for the transmission to third parties of data contained in the public business register regulated by Law 3/1993.

-b. The consultation by the AEPD Legal Department, which, it says, restores the interpretation

made by the aforementioned resolution (link to the resolution:
https://www.aepd.es/documento/2001-9901.pdf)

-c. The Legal Department's response to a consultation from ASEDIE, dated
30/09/2014, reference number 383358/2014 (a consultation raised after the approval of Law 4/2014), in which the Legal Department The Agency's Legal Department stated:
"Thus, as long as the data refers solely to legal entities, without
containing any personal data other than that mentioned in Article 2.2 of the implementing regulations of the Organic Law, or to individual entrepreneurs, in the terms just described and related solely and exclusively to the commercial activity of such entrepreneurs, data protection regulations will not apply.

Therefore, without prejudice to the provisions of other regulations, their communication will not be subject
to the provisions of Organic Law 15/1999."

-d. The Resolution denying approval of the ASEDIE Code of Conduct (File No. CC/0003/2018), in which neither the Subdirectorate General of the Central Data Protection Registry nor the AEPD Legal Department, in their respective reports, found any objections to the processing of personal data of individual entrepreneurs and independent professionals. Thus, the resolution of the aforementioned file expressly states the following:
"Regarding the remaining content, the report of the Subdirectorate General of the General Data Protection Registry issues a positive overall assessment, considering that it responds to the specific needs of the promoter, facilitates and specifies the application of the GDPR, and provides sufficient guarantees."

-e. The report of the Legal Department of the AEPD No. 0089/2020, which specifies the processing operations in which the legitimate interest of the data controller is not found to prevail, specifically, data processing (i) for credit information systems related to the fulfillment of monetary, financial, or credit obligations and (ii) for solvency information systems with data obtained from public sources or that the data subject has made manifestly public, contained in sections 2 and 3 of Annex II, which should be deleted.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 134/164

"However, this Report does not raise any objection to Annex I of the Code of Conduct, which includes the economically relevant information services on companies. commercial and other legal entities, individual entrepreneurs, and

professionals.”

-f. That the General Secretariat of the AEPD has agreed to initiate procurement file EX20240028 for "Economic-Financial and Commercial Information Analysis Services," the purpose of which is to contract a service for the AEPD providing economic-financial and commercial information for any entity, regardless of its legal form, including self-employed individuals, associations, and foundations. Specifically, the purpose of the contract will consist of the following activities:

It is not possible to share the arguments that CAMERDATA alleges to support the "legitimate trust" that the Agency has supposedly generated with its actions and from which it seeks to derive the absence of negligence on its part in the processing of personal data of self-employed entrepreneurs carried out without a lawful basis in accordance with the GDPR.

Regarding the references made in sections a., b., and c. above, it is indicated that

it seems evident that, when there has been a Legislative change affecting the scope of data protection regulations, a resolution issued during the validity of the LOPD and its implementing regulations (currently in force, but insofar as it does not conflict with the GDPR and the LOPDGDD) cannot coincide with the one issued applying the current regulations. This Agency has not created any undue legitimate trust, which would have occurred if, under the currently applicable regulations, it had acted in the same way as with the provisions of the LOPD and the RLOPD that are no longer applicable.

With regard to the resolution denying the ASEDIE Code of Conduct (section d), it cannot be used to justify the alleged legitimate trust that the Agency may have unduly generated regarding the processing of the personal data of self-employed entrepreneurs. The principles underlying the Agency's decision to deny approval of the Code of Conduct are the same as those applicable to some of the issues raised in this procedure. the
entity against which this procedure is directed. Both the AEPD resolution

refusing to approve the aforementioned Code of Conduct and other very recent AEPD sanctioning resolutions are an example of the application
of current regulations and the criteria upheld by the GDPR, so, according to them,
it is not possible to claim ignorance or legitimate trust in positions that the
Agency has long since abandoned because compliance with the principle of legality requires it.

Regarding the reference made to the contracting process initiated by the
Secretary General regarding the contracting of information services from an
infomediary company, two more elements are added.

On the one hand, 1) this sanctioning procedure relates to the processing of personal data without a lawful basis, which does not exclude the possibility that the data of self-employed workers may be subject to processing provided that it is based on one of the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 135/164

circumstances covered by Article 6.1 of the GDPR, so the data controller must act proactively to ensure that an adequate basis is in place.

And 2) That the so-called publicly available sources do not operate as legal bases for processing under the GDPR (there are only those mentioned in Article 6.1), so the data controller has the burden (ex Article 5.2 GDPR) of adopting measures to ensure that the processing it carries out has a lawful basis and must be able to prove compliance.

4.3. In light of the foregoing considerations, this proposed resolution concludes that the iuris tantum presumption of legality established in Article 19.2 of the LOPDGDD does not have the meaning, and consequently the scope, attributed to it by CAMERDATA.

Consequently, it considers proven the existence of a violation of Article 6.1 of the GDPR, which materializes in the collection of data from the CDE, processing it in its systems, transferring it to third parties, both for marketing purposes and for providing feedback to the file owned by it or to individuals for its own purposes, without a legal basis, since the iuris tantum presumption of legality of Article 19.2 of the LOPDGDD does not apply to such processing.

5. Regarding the alleged violation of Article 6.1 of the GDPR, specified in the initiation agreement in the case "c) Having transferred its File to KOMPASS for the dual purpose of providing a feedback service for the information collected therein and for use by KOMPASS for its own activities.

5.1. In its allegations regarding the initiation agreement, CAMERDATA asserts that the data transferred does not violate the GDPR, as it is exclusively data from companies established as legal entities. For this reason, it rejects the violation of Article 6.1 of the GDPR,

ascertained in the initiation agreement, specified in CAMERDATA's communication to KOMPASS, without a lawful basis, of the personal data of self-employed entrepreneurs for the purpose of providing feedback to the file and subsequent use in their business activities without a legal basis.

In defense of the argument that the data processed is exclusively from Legal entities claim:

- That the universe of transferred records is completely different from the number of self-employed individuals or individual entrepreneurs in the Spanish Business File:
CAMERDATA processes data on a total of 1,665,049 self-employed individuals or individual entrepreneurs, while the number of records transferred to KOMPASS is 107,807 (in the 2020 contract) and 145,101 (in the 2023 contract).

- That the 2020 contract expressly refers to Tax Identification Codes (CIFs), which clearly—although erroneously since 2008—indicates that these are data from companies incorporated as legal entities. This naming error is corrected in the 2023 contract since, strictly speaking, since 2008, the CIF has also been called the NIF, which was previously only applicable. to natural persons.

-That the file contains, submitted as document annex 5 to the allegations to the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 136/164

initiation agreement, a document signed by the CEO of KOMPASS declaring that the
registries used to carry out its "webcrawling" work have been
exclusively those of legal entities, their NIFs, their URL addresses, and their

generic email addresses, and in no case those of natural persons or sole proprietors.

It invokes Article 53.3 of the LPACAP (Spanish Civil Code), according to which, in administrative procedures of a sanctioning nature, the presumption of non-existence of administrative liability is established until proven otherwise.

It concludes that, since the data transferred under the contract signed with KOMPASS are not personal data, they are not data. of self-employed entrepreneurs, but only of companies and legal entities - such action does not violate Article 6.1 or any other provision of the GDPR, as it is not applicable to them according to its recital 14.

The proceedings regarding this violation must be closed.

5.2. The contracts signed with KOMPASS were provided by CAMERDATA at the request of the Inspectorate in response to the request to provide a copy of all contracts with third-party entities that resulted in the processing or transfer of data of self-employed entrepreneurs.

The two contracts provided, from 2020 and 2023, do not contain any express mention of the nature of the data processed. Furthermore, the contract signed in 2020 refers to CIFs (Tax Identification Numbers), which were the identifiers used exclusively for legal entities until 2008, but which, with great care, Frequently, they continued to be used as an equivalent to the NIF (Tax Identification Number) for years afterward.
The 2023 contract refers to the NIF (Tax Identification Number), with no indication of the nature of the data processed, so it is likely an extension of the previous contract, which everything indicates concerned data belonging to entities rather than individuals.

A reasonable doubt arises regarding the existence of processing contrary to Article 6.1 of the GDPR with regard to the processing operation connected with the contracts entered into with KOMPASS, which must be resolved by resorting to the in dubio pro reo principle. This principle, in the event of doubt regarding a specific and determining fact, requires in all cases to resolve said doubt in the manner most favorable to the data subject.

For all the above reasons, the violation of Article 6.1 of the GDPR described in section c) should be closed. Having transferred its File to KOMPASS for the dual purpose of providing it with an information feedback service. collected therein and for use by this entity for its own activities, as mentioned in the initiation agreement.

6. In light of the foregoing considerations, this draft resolution

concludes that the iuris tantum presumption of legality established in Article 19.2 of the LOPDGDD does not have the meaning, nor consequently the scope, attributed to it by CAMERDATA.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 137/164

Consequently, it considers proven the existence of a violation of Article 6.1 of the GDPR, which materializes in having collected from the CDE, processed in its systems, transferred to third-party entities, both for marketing purposes and to feed back the file owned by it or to persons for its own purposes, without a legal basis, since the iuris tantum presumption of legality does not apply to said processing. Legality of Article 19.2 of the LOPDGDD.

X
Classification and limitation period for the violation of Article 6.1 of the GDPR

The violation of Article 6.1 of the GDPR for which this draft resolution holds CAMERDATA responsible is classified in Article 83.5 b) of the GDPR, which provides:
"Violations of the following provisions shall be punishable, in accordance with

paragraph 2, with administrative fines of up to EUR 20,000,000 or, in the case of a company, an amount equivalent to a maximum of 4% of the total global annual turnover of the preceding financial year, whichever is higher: a) the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9;

For the sole purpose of determining the statute of limitations for violations of Article 6.1 of the GDPR, the LOPDGDD provides in Article 72, "Infractions considered very serious": 1. Pursuant to the provisions of Article 83.5 of Regulation (EU) 2016/679, violations that constitute a substantial violation of the articles mentioned therein, and in particular, the following, are considered very serious and will be subject to a three-year statute of limitations:
a) […].
b) The processing of personal data without any of the conditions for the lawfulness of processing established in Article 6 of Regulation (EU) 2016/679 being met.

XI
Violation of Article 14 of the GDPR

Article 5 of the GDPR details the principles governing the processing of personal data, including Article 5.1.a), the principle of transparency.

Article 12.1 of the GDPR, under the heading "Transparency of information, communication, and methods for exercising the data subject's rights," provides that:

"The controller shall take appropriate measures to provide the data subject with all information referred to in Articles 13 and 14, as well as any communication pursuant to Articles 15 to 22 and 34 relating to the processing, in a concise, transparent, intelligible, and easily accessible manner, in clear and plain language, in particular any information specifically addressed to a child. The information shall be provided in writing or by other means, including, where appropriate, by electronic means." Upon request by the data subject, the information may be provided verbally, provided that the data subject's identity can be proven by other means.”

Article 14 of the GDPR addresses the information that the data controller is obliged to

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 138/164

provide when the personal data have not been obtained from the data subject:

“1. Where the personal data have not been obtained from the data subject, the data controller shall

provide the following information:
a) the identity and contact details of the controller and, where applicable, of his or her representative;
b) the contact details of the data protection officer, where applicable;
c) the purposes for which the personal data are processed, as well as the legal basis for the processing;

d) the categories of personal data concerned;

(e) the recipients or categories of recipients of the personal data, where applicable;
(f) where applicable, the controller's intention to transfer personal data to a recipient in a third country or international organization and the existence or absence of an adequacy decision by the Commission, or, in the case of transfers referred to in Articles 46 or 47 or the second subparagraph of Article 49(1), reference to the appropriate safeguards and the means of obtaining a copy of them or the place where they have been made available.

2. In addition to the information referred to in paragraph 1, the controller shall provide the data subject with the following information necessary to ensure fair and transparent processing of data concerning the data subject: a) the period for which the personal data will be stored, or, where that is not possible, the criteria used to determine that period; b) where processing is based on Article 6(1)(f), the legitimate interests of the controller or of a third party; c) the existence of the right to request from the controller access to, rectification or erasure of, or restriction of processing of, personal data concerning the data subject, and to object to processing, as well as the right to data portability; (d) where processing is based on Article 6(1)(a) or Article 9(2)(a), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
(e) the right to lodge a complaint with a supervisory authority;
(f) the source of the personal data and, where applicable, whether they are from publicly available sources;
(g) the existence of automated decision-making, including profiling, as referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject.

3. The controller shall provide the information referred to in paragraphs 1 and 2: a) within a reasonable period after obtaining the personal data, and no later than within one month, taking into account the specific circumstances in which such data are processed;

b) if the personal data are to be used for communication with the data subject, at the latest at the time of the first communication to that data subject; or
c) if communication to another recipient is planned, at the latest at the time when the personal data are communicated for the first time.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 139/164

4. Where the controller plans to further process personal data for a purpose other than that for which they were obtained, it shall, prior to such further processing, provide the data subject with information about that other purpose and any other relevant information referred to in paragraph 2.

5. The provisions of paragraphs 1 to 4 shall not apply where and to the extent that:
a) the data subject already has the information;

b) communication of that information proves impossible or would entail a disproportionate effort, in particular for processing for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, subject to the conditions and safeguards referred to in Article 89(1), or to the extent that the obligation referred to in paragraph 1 of this Article is likely to

make impossible or seriously impede the achievement of the objectives of such processing. In
such cases, the controller shall take appropriate measures to safeguard the rights,
freedoms and legitimate interests of the data subject, including by making the information public;
c) collection or disclosure is expressly provided for by Union or Member State law to which the controller is subject and which

lays down appropriate measures to safeguard the legitimate interests of the data subject; or
d) where the personal data must remain confidential on the basis of an obligation of professional secrecy regulated by Union or Member State law, including a statutory obligation of secrecy."

With regard to the principle of transparency, the provisions of Recitals 39, 58, 60, and 61 of the GDPR are also taken into account.

(39) “All processing of personal data must be lawful and fair. It must be absolutely clear to natural persons that personal data concerning them are being collected, used, consulted, or otherwise processed, as well as the extent to which such data are or will be processed. The principle of transparency requires that all information and communication relating to the processing of such data be easily accessible and easy to understand, and that simple and clear language be used. This principle refers in particular to information to data subjects about the identity of the controller and the purposes of the processing, and to additional information to ensure fair and transparent processing with regard to the natural persons concerned and their right to obtain confirmation and communication of the personal data concerning them that are being processed. Natural persons must be aware of the risks, rules, safeguards, and rights relating to the processing of personal data, as well as how to assert their rights in relation to the processing. In particular, the specific purposes for processing personal data must be explicit and legitimate, and must be determined at the time of collection. Personal data must be adequate, relevant, and limited to what is necessary for the purposes for which they are processed. This requires, in particular, ensuring that their retention period is limited to a strict minimum. Personal data should only be processed if the purpose of the processing cannot reasonably be achieved by other means. To ensure that personal data are not retained longer than necessary, the data controller must establish deadlines for their deletion or periodic review. All reasonable measures must be taken to ensure that inaccurate personal data are rectified or deleted. Personal data must be processed in a manner that ensures security and (58) “The principle of transparency requires that all information addressed to the public or the data subject be concise, easily accessible, and easy to understand, and that it be used in clear and plain language and, where appropriate, visually visible. This information could be provided electronically, for example, when it is addressed to the public, through a website. This is particularly relevant in situations where the proliferation of actors and the technological complexity of the practice make it difficult for the data subject to know and understand whether, by whom, and for what purpose personal data concerning them are being collected, as is the case with online advertising. Since children deserve specific protection, any information and communications concerning them should be provided in clear and plain language that is easy to understand.”

(60) “The principles of fair and transparent processing require that the data subject be informed of the existence of the processing operation and its purposes. The controller should provide the data subject with all necessary additional information to ensure fair and transparent processing, taking into account the specific circumstances and context in which the personal data are processed. The data subject should also be informed of the existence of profiling and of the consequences of such processing. If personal data are obtained from data subjects, they should also be informed of whether they are obliged to provide them and of the consequences if they fail to do so. Such information may be transmitted in combination with standardized icons that provide, in an easily visible, intelligible, and clearly legible manner, an adequate overview of the envisaged processing. Icons presented in electronic format should be machine-readable.”

(61) “Data subjects should be provided with information about the processing of their personal data at the time they are collected from them or, if they are collected from another source, within a reasonable period, depending on the circumstances of the case. If the personal data can be legitimately disclosed to another recipient, the data subject should be informed at the time they are first disclosed to the recipient. A controller planning to process data for a purpose other than that for which they were collected must provide the data subject, prior to such further processing, with information about that other purpose and other necessary information. Where the source of the personal data cannot be provided to the data subject because several sources have been used, general information should be provided.”

2. The decision to initiate the disciplinary procedure in question attributed to CAMERDATA an alleged infringement of Article 14 of the GDPR for failing to inform data subjects of its processing of data concerning them. CAMERDATA did not obtain personal data directly from the data subjects.
Instead, this information, particularly the NIF (Tax Identification Number), first and last names, business address, IAE heading, and description of the activity, was obtained from CDE, which, in turn, receives it from the tax authorities.

The mandate contained in Article 14 requires the data controller to provide data subjects with certain information related to the processing of their data. The importance of the obligation imposed in this provision lies in that it provides data subjects with a clear and complete understanding of how their personal data is being used, which is essential for building a relationship based on trust with the entities that handle their data. It facilitates and guarantees that data subjects exercise their data protection rights, including the right to object to the processing, access, rectification, and erasure of their personal data, among others. It strengthens the legitimacy of personal data processing by ensuring that it is carried out within the established legal framework and in accordance with the principles of the GDPR. It helps protect individuals against the misuse of their personal data, ensuring that it is only used for specific, legitimate, and explicitly informed purposes. It helps data controllers with compliance with data protection regulations, avoiding penalties and damage to their reputation that could result from non-compliance.

In its response to the Inspectorate's request for information and in its allegations to the

start agreement, CAMERDATA claims in its defense that it has not violated the obligation to inform imposed by Article 14 of the GDPR, arguing that it is exempt under Article 14.5.b) of the GDPR, since individual communication of the information to each data subject would entail an unaffordable financial effort. In this regard, the file, submitted with its response to the Inspectorate's request, includes two estimates for the cost of personalized communication to more than one million people, as well as information on its turnover for the previous four fiscal years.

CAMERDATA claims that the exemption from the obligation to inform data subjects is based on Article 14.5. b) of the GDPR and Recital 62 of the GDPR and is in line with the criteria of Report WP260.rev01 17/ES (last revised on April 11, 2018).

As measures aimed at strengthening the safeguards for data subjects in a matter such as the one at hand, it states that it has initiated the process of publishing an information notice on the Chambers' websites, the text of which it has provided—and which is included in the Proven Facts. It has stated that it plans to begin publishing it in bulletins and newsletters and in widely circulated national newspapers on an annual basis.

Article 14, paragraph 5, establishes that the provisions of paragraphs 1 to 4 shall not apply where and to the extent that “(b) communication of such information proves impossible or involves a disproportionate effort, in particular for processing for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, subject to the conditions and safeguards set out in Article 89, paragraph 1, or to the extent that the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impede the achievement of the objectives of such processing. In such cases, the controller shall take appropriate measures to safeguard the rights, freedoms and legitimate interests of the data subject, including by making the information public.”

Regarding this matter—the impossibility of providing information or disproportionate effort—the WP29 Guidelines on Transparency under Regulation (EU) 2016/679, adopted on November 29, 2017, last revised and adopted on April 11, 2018, state:

“61. Pursuant to Article 14.5(b), as with the “impossibility test” situation, “disproportionate effort” may also apply, in particular, to processing “for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, subject to the conditions and safeguards set out in Article 89(1).” Recital 62 also refers to these purposes as cases where providing information to the data subject would entail a disproportionate effort and establishes that, in this regard, consideration should be given to the following: the number of data subjects, the age of the data, and the appropriate safeguards adopted. Given the emphasis in Recital 62 and Article 14.5(b) on archiving, research, and statistical purposes regarding the application of this exemption, WP29's position is that this exception should not be routinely used by controllers who do not process personal data for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes. WP29 emphasizes that, where these are the purposes pursued, the conditions set out in Article 89.1 must continue to be met, and the provision of the information must constitute a disproportionate effort.

“64. Where a controller seeks to apply the exception in Article 14.5(b) on the basis that providing the information would entail a disproportionate effort, it should carry out a balancing exercise to assess the effort that would be required for the controller to provide the information to the data subject in relation to the impact and effects on the data subject if the information were not provided. This assessment must be documented by the controller in accordance with its accountability obligations. In such a case, Article 14.5(b) specifies that the controller must take appropriate measures to safeguard the rights, freedoms, and legitimate interests of the data subject. This also applies where a controller determines that providing the information is impossible or would likely render impossible or seriously impair the achievement of the purposes of the processing. An appropriate measure, as specified in Article 14.5(b), that controllers must always take is to make the information available to the data subject. Publicly available. A controller can do this in several ways, for example, by publishing the information on its website or by proactively advertising the information in a newspaper or on posters at its premises. Other appropriate measures, in addition to making the information publicly available, will depend on the circumstances of the processing, but may include conducting a data protection impact assessment; applying pseudonymization techniques to the data; minimizing the data collected and the storage period; and implementing technical and organizational measures to ensure a high level of security. C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 143/164

Thus, on the one hand, Article 14.5.b) specifies that, in such cases, “the controller shall take appropriate measures to safeguard the rights, freedoms and legitimate interests of the data subject, including by making the information public.” On the other hand, Recital 64 mentions that: (i) the controller must conduct a documented assessment of the processing, in accordance with its accountability obligations, of the effort involved in providing the information to the data subject in relation to the impact and effects on the data subject if the information were not provided. (ii) Appropriate measures to safeguard the rights, freedoms and legitimate interests of the data subject. (iii) It indicates that an appropriate measure, “as specified in Article 14.5 (b), which controllers must always take, is to make the information publicly available. A controller may do this in several ways, for example, by publishing the information on its website or by proactively advertising the information in a newspaper or on posters at its premises. Other appropriate measures, in addition to making the information publicly available, will depend on the circumstances of the processing, but may include conducting a data protection impact assessment; applying pseudonymization techniques to the data; minimizing the data collected and the storage period; and implementing technical and organizational measures to ensure a high level of security.”

In light of the above, the following points are worth mentioning:

a) Regarding the content of the announcement that CAMERDATA published through its inclusion on the websites of seven Chambers of Commerce (according to the information provided), the information that should be made public is that indicated in Article 14 of the GDPR. The information, in accordance with Article 12 of the GDPR, must be complete, as the provision indicates that appropriate measures will be taken to provide the interested party with "all the information indicated in Articles 13 and 14." An analysis of the announcement published by CAMERDATA reveals that it omits the following information:

- It does not provide information on the categories of personal data it processes (requirement of Article 14.1.d of the GDPR).
- It does not provide information on the period during which the personal data will be retained or, when that is not possible, on the criteria used to determine this period (section a of Article 14.2).
-It does not state the source of the personal data and, if applicable, whether

it comes from publicly available sources. The announcement does not state that the data
comes from information provided by the CDE. No mention is made of it (requirement of Article 14.2.f) and it is limited to indicating that it was obtained from an "official census prepared by public bodies."
- It does not inform about the legitimate interests of the controller or a third party,

despite claiming that the processing is based on Article 6.1.f) (circumstance of Article 14.1.b)

b) Furthermore, in view of what is indicated in section 64 of the Transparency Guidelines, "Where a controller seeks to apply the exception

of Article 14.5 (b) on the basis that the provision of the information would involve a disproportionate effort, it should carry out a balancing exercise to assess the effort that providing the information to the data subject would entail in relation to the impact and effects on the data subject."

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 144/164

data subject if the information is not provided. This assessment must be documented by the data controller in accordance with its accountability obligations.

However, there is no evidence that CAMERDATA has assessed and documented the effort that would be required compared to the impact and effects on the data subject of not providing the information.

c) Recital 61 shows that the Article 29 Working Party emphasizes that the
exemption of Article 14.5.b) should not be routinely used by data controllers

who do not process personal data for archiving purposes of public interest, scientific or historical research, or statistical purposes.

d) The documentation provided by CAMERDATA on the publication of informational

announcements in some Chambers of Commerce shows that, at least on the
Valencia Chamber's website, the announcement appears in the Chamber's "Transparency" tab, so it is difficult to consider
that this is an announcement that meets minimum publicity and dissemination requirements.

Based on the foregoing, it is concluded that CAMERDATA has not demonstrated that it has complied with the appropriate measures to protect the rights, freedoms, and legitimate interests of data subjects that would allow for the exemption from the duty to inform under Article 14.5.b) of the GDPR. It is reiterated that the guarantees adopted by CAMERDATA are clearly insufficient, as some of them had not even been implemented at the time of the inspections. Only the inclusion of an informative text on the websites of the Chambers of Commerce of Madrid, Valencia, Barcelona, Sabadell, Girona, Alicante, and Castellón had been implemented. Therefore, in addition to this measure being insufficient on its own, it does not even extend to the websites of all the Chambers.

CAMERDATA has also argued in its defense that the alleged violation does not involve the subjective element of culpability, so no administrative liability can arise from the alleged failure to comply with the obligation imposed by Article 14 of the GDPR.

With regard to the presence of the culpability element of the violation, there is no doubt that this element exists and is reflected in a very serious lack of diligence by the data controller, CAMERDATA, which unquestionably exceeds the failure to exercise due diligence necessary to constitute the subjective element of the violation. This is so, as it allows for the inclusion, as an aggravating circumstance, of the circumstance of

culpability (understood as a lack of due diligence, as provided for in Article 83.2 of the GDPR).

CAMERDATA maintains that the lack of culpability it invokes is based
on "the legitimate trust generated by the AEPD's own actions" in relation

to the processing of personal data of self-employed workers or individual entrepreneurs. It then emphasizes that, in its opinion, it is striking that the initiation agreement does not mention "circumstances of relevance for the purposes
of this procedure, known to the supervisory and control body, which

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 145/164

directly impact the determination of whether or not Camerdata acted intentionally or negligently."

Well, the relevant circumstances that CAMERDATA mentions are the following:

-a. The AEPD Resolution of 27/02/2001, issued in the case initiated as a result of the complaint filed against a Chamber of Commerce for the transmission to third parties of data contained in the public business register regulated by Law 3/1993.

-b. The consultation by the AEPD Legal Office, which, it says, reflects the interpretation made in the aforementioned resolution (link to the resolution:
https://www.aepd.es/documento/2001-9901.pdf)

-c. The Legal Department's response to a query from ASEDIE, dated
09/30/2014, reference number 383358/2014 (a query raised after the approval of Law 4/2014), in which the Agency's Legal Department reported in the following terms:

"Thus, provided that the data refers solely to legal entities, without
containing any personal data other than that mentioned in Article 2.2 of the implementing regulations of the Organic Law, or to individual entrepreneurs, in the terms

just described and related solely and exclusively to the commercial activity of such entrepreneurs, data protection regulations will not apply.
Therefore, without prejudice to the provisions of other regulations, their communication will not be subject
to the provisions of Organic Law 15/1999."

-d. The Resolution denying approval of the ASEDIE Code of Conduct (File No. CC/0003/2018) states that neither the Subdirectorate General of the Central Data Protection Registry nor the Legal Department of the AEPD, in their respective reports, found any objections to the processing of personal data of individual entrepreneurs and independent professionals. Thus, the resolution of the aforementioned file expressly states the following:
"Regarding the remaining content, the report of the Subdirectorate General of the General Data Protection Registry issues a positive overall assessment, considering that

it meets the specific needs of the promoter, facilitates and specifies the
application of the GDPR, and provides sufficient guarantees."
-e. The report of the AEPD Legal Department, No. REF 0089/2020, which

specifies the processing operations in which the legitimate interest of the data controller is not found to prevail, specifically, data processing (i) for credit information systems related to the fulfillment of monetary, financial, or credit obligations and (ii) for solvency information systems with data obtained from public sources or that the data subject has manifestly made public, contained in sections 2 and 3 of Annex II, which

should be deleted.
"However, this Report does not raise any objection to Annex I of the Code of Conduct, which lists the economically relevant information services

on commercial companies and other legal entities, individual entrepreneurs, and liberal professionals."

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 146/164

-f. That the General Secretariat of the AEPD has agreed to initiate procurement file EX20240028 for "Economic-Financial and Commercial Information Analysis Services," the purpose of which is to contract a service for the AEPD providing economic-financial and commercial information for any entity, regardless of its legal form, including self-employed individuals, associations, and foundations.
It is not possible to share the arguments the entity alleges to support the "legitimate trust" it has been using in its processing of the personal data of self-employed entrepreneurs, which the Agency allegedly generated with its actions. Legitimate trust supposedly aroused by this Agency, from which CAMERDATA seeks to derive the absence of negligence in the breach of its obligation to inform data subjects imposed by Article 14 of the GDPR.

Regarding the relevant facts mentioned in sections a, b, and c above, it is sufficient to note that, given that a change has occurred that affects the scope of application of data protection regulations in relation to business individuals following the effective application of the GDPR, a resolution issued during the validity of the LOPD and its implementing regulations (currently in force, but insofar as it does not conflict with the GDPR and the LOPDGDD) cannot coincide with the resolution issued applying the current regulations. This Agency has not created
any undue legitimate trust, which, on the contrary, would have occurred if, under the current regulations, the provisions of the
LOPD and the RLOPD, which are no longer applicable, were applied.

With regard to the resolution denying the ASEDIE Code of Conduct (section d), under no circumstances can it be used to justify the alleged legitimate trust that the Agency may have unduly generated regarding the processing of the personal data of self-employed entrepreneurs. The principles underlying the
Agency's decision to deny approval of the Code of Conduct are the same as those applicable to some of the issues discussed in this procedure and rejected by CAMERDATA. Both the AEPD resolution denying approval of the aforementioned Code of Conduct and other AEPD sanctioning resolutions very recently are examples of the application of current regulations and the criteria upheld by the GDPR. Therefore, based on them, it is not possible to claim ignorance or legitimate trust in positions that the Agency long ago abandoned, as required by the principle of legality.

CAMERDATA maintains that the lack of culpability it invokes is based on "the legitimate trust generated by the AEPD's own actions" in relation to the processing of personal data of self-employed workers or individual entrepreneurs. He then emphasizes that, in his opinion, it is striking that the initiation agreement did not mention "circumstances of relevance to the purposes of this procedure, known to the supervisory and control body, that directly affect the determination of whether or not Camerdata acted intentionally or negligently."
As such relevant circumstances, he cites:

-a. The Resolution of February 27, 2001, of the AEPD (Spanish Agency for Data Protection) in the case initiated as a result of a complaint filed against a Chamber of Commerce for the transmission to third parties of data contained in the public business register, regulated by Law 3/1993.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 147/164

-b. The consultation of the AEPD Legal Department, which, it says, restores the interpretation
made in the aforementioned resolution (link to the resolution:
https://www.aepd.es/documento/2001-9901.pdf)

-c. The Legal Department's response to a query from ASEDIE, dated
09/30/2014, reference number 383358/2014 (a query raised after the approval of Law 4/2014), in which the Agency's Legal Department stated: "Thus, provided that the data refers
solely to legal entities, without containing any personal data other than that

mentioned in Article 2.2 of the implementing regulations of the Organic Law, or to
individual entrepreneurs, in the terms just described and related
solely and exclusively to the commercial activity of such entrepreneurs, data protection regulations will not apply. Therefore, without prejudice to the provisions of other regulations, their communication will not be subject to the provisions of Organic Law 15/1999."

-d. The Resolution denying approval of the ASEDIE Code of Conduct (File No. CC/0003/2018), in which neither the Subdirectorate General of the Central Data Protection Registry nor the AEPD Legal Department, in their respective reports, found any objections to the processing of personal data of individual entrepreneurs and independent professionals. Thus, the resolution of the aforementioned file expressly states the following:

"Regarding the remaining content, the report of the Subdirectorate General of the General Data Protection Registry issues a positive overall assessment, considering that it responds to the specific needs of the promoter, facilitates and specifies the application of the GDPR, and provides sufficient guarantees."

-e. The report of the AEPD Legal Department, No. REF 0089/2020, which specifies the processing operations in which the legitimate interest of the data controller is not found to prevail, specifically, data processing (i) for credit information systems related to the fulfillment of monetary, financial, or credit obligations and (ii) for solvency information systems with data obtained from public sources or that the data subject has manifestly made public, contained in sections 2 and 3 of Annex II, which should be deleted.

"However, this Report does not raise any objection to Annex I of the Code of Conduct, which includes economically relevant information services on commercial companies and other legal entities, individual entrepreneurs, and liberal professionals."

-f. That the General Secretariat of the AEPD has agreed to initiate contracting file EX20240028 for "Economic, financial, and commercial information analysis services," the purpose of which is to contract a service for the AEPD providing economic, financial, and commercial information to any entity, regardless of its legal form, including self-employed individuals, associations, and foundations. Specifically, the purpose of the contract will consist of the following activities:
It is not possible to share the arguments the entity alleges to support the "legitimate trust" that the Agency has supposedly generated with its actions, from which it seeks to deduce the absence of negligence in CAMERDATA's failure to comply with its obligation to inform data subjects imposed by Article 14 of the GDPR.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 148/164

In relation to the citations included in sections a., b., and c. above, it is sufficient to point out that it seems clear that, when there has been a legislative change that affects the scope of application of data protection regulations, a resolution issued

during the validity of the LOPD and its implementing regulations (currently in force, but insofar as it does not conflict with the GDPR and the LOPDGDD) cannot coincide with one issued applying the current regulations. This Agency has not created any undue legitimate trust, which would have occurred if, under the regulations currently in force, it had acted in the same way as with the provisions of the LOPD and the RLOPD, which are no longer applicable.

Regarding the resolution denying ASEDIE's Code of Conduct (section d), under no circumstances can it be used to justify the alleged legitimate trust that the Agency may have improperly generated regarding the processing of the personal data of self-employed entrepreneurs. The principles underlying the Agency's decision to deny approval of the Code of Conduct are the same as those applicable to some of the issues discussed in this procedure and rejected by CAMERDATA. Both the AEPD's resolution denying approval of the aforementioned Code of Conduct and other AEPD sanctioning resolutions very recently are representative of the application of current regulations and the criteria defended by the GDPR. Therefore, based on them, it is not possible to claim ignorance or legitimate trust in positions that the Agency has long since abandoned, as it requires respect for the principle of legality.

One more clarification should be added regarding CAMERDATA's reference to the
contracting process initiated by the General Secretariat of this Agency regarding the
information services of an infomediary company. On the one hand, this sanctioning procedure concerns the processing of personal data without a
lawful basis. Nothing prevents the data of self-employed entrepreneurs from being processed if the processing has an adequate legal basis under the GDPR. Therefore, if an infomediary company processes personal data of
a natural person, whether or not they are an entrepreneur, they must have an adequate legal basis under the GDPR. Nothing prevents an infomediary from processing data of
natural person entrepreneurs who comply with the principle of lawfulness. Based on these premises, the
Agency may contract with an infomediary who can provide information that may or may not be about natural person entrepreneurs, but which in all cases must be based on an adequate legal basis.

Considering the evidence and proof presented in the proceedings, this proposed resolution finds a violation of the obligation to inform data subjects imposed by Article 14 of the GDPR.

This violation is significant in itself, regardless of whether CAMERDATA's processing of personal data concerning entrepreneurs is unlawful. Even in situations where the processing of personal data may be considered unlawful due to the lack of an adequate legal basis pursuant to Article
6.1 of the GDPR, the data controller is still obliged to comply with the principle of transparency and, therefore, must inform data subjects about the processing of their data under the terms of Article 14 of the GDPR if such data was not obtained directly from the data subjects, as is the case here.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 149/164

XII

Classification and limitation period for the violation of Article 14 of the GDPR

The violation of Article 14 of the GDPR for which this proposed resolution considers CAMERDATA responsible is classified in Article 83.5 b) of the GDPR, which provides:

"Infringements of the following provisions shall be punished with administrative fines of up to €20,000,000 or,

in the case of a company, an amount equivalent to a maximum of 4% of the total global annual turnover of the preceding financial year, whichever is higher:
[…]
b) the rights of data subjects pursuant to Articles 12 to 22:"

For the sole purpose of determining the limitation period Statute of Limitations for Violations of Article 14 of the GDPR. The LOPDGDD provides in Article 72.1:

“In accordance with the provisions of Article 83.5 of Regulation (EU) 2016/679, violations that constitute a substantial violation of the articles mentioned therein, and in particular the following, are considered very serious and will be subject to a three-year statute of limitations:

[…]
h) Failure to inform the data subject about the processing of their personal data in accordance with the provisions of Articles 13 and 14 of Regulation (EU)

2016/679 and Article 12 of this Organic Law.”

XIII
Breach of Article 28 of the GDPR

The agreement to initiate the sanctioning procedure attributes to CAMERDATA an
alleged breach of Article 28 of the GDPR based on the fact that the data processing contract signed with DMOVO—a copy of which was provided at the request of the Data Inspectorate—although it contains a confidentiality clause, does not incorporate the other provisions established in Article 28.3 of the GDPR, and therefore this obligation must be deemed to have been breached.

Article 28 of the GDPR, "Data Processor," provides:

"1. Where processing is to be carried out on behalf of a controller, the controller shall only select a processor that offers sufficient guarantees

to implement appropriate technical and organizational measures to ensure that the processing complies with the requirements of this Regulation and ensures the protection of the rights of the data subject.

2. The processor shall not use another processor without the prior written authorization, whether specific or general, of the controller. In the latter case, the processor shall inform the controller of any planned changes to the addition or replacement of other processors, giving the controller the opportunity to object to such changes.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 150/164

3. Processing by the processor shall be governed by a contract or other legal instrument in accordance with Union or Member State law, which binds the processor

to the controller and sets out the subject matter, duration, nature and purpose of the processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller. Such contract or legal act shall stipulate, in particular, that the processor:
"a) shall process the personal data only on documented instructions from the controller, including with respect to transfers of personal data to a third country or an international organization, unless required to do so by Union or Member State law to which the processor is subject; in such a case, the processor shall inform the controller of this legal requirement prior to processing, unless such law prohibits this on important grounds of public interest;

b) shall ensure that persons authorized to process personal data have committed themselves to confidentiality or are subject to a statutory obligation of confidentiality;
c) shall take all necessary measures in accordance with Article 32;
d) shall respect the conditions referred to in paragraphs 2 and 4 for using another processor;

e) shall assist the controller, taking into account the nature of the processing, through technical and organizational measures appropriate measures, whenever possible, to enable the controller to comply with its obligation to respond to requests that exercise the data subject rights set out in Chapter III;
(f) shall assist the controller in ensuring compliance with the obligations

set out in Articles 32 to 36, taking into account the nature of the processing
and the information available to the processor;
(g) shall, at the controller's choice, delete or return all personal data once the provision of the processing services has ended, and shall delete existing copies unless retention of the personal data is required under

Union or Member State law;
(h) shall make available to the controller all information necessary to demonstrate
compliance with the obligations set out in this Article, as well as
to enable and assist audits, including inspections, by the controller or another auditor authorized by the controller.
With regard to point (h) of the first subparagraph, the processor shall immediately inform the controller. if, in its opinion, an instruction infringes this Regulation or other data protection provisions of the Union or the Member States."

CAMERDATA signed a contract with DMOVO ANALYTICS, S.L., (hereinafter DMOVO) on

February 3, 2020, establishing a collaborative framework for the provision of technological development, information processing, and consulting services by DMOVO. It is indicated that the services consist of a periodic process of processing and adjusting the name and address data from the company and self-employed registries for which CAMERDATA is the data controller.

In its allegations regarding the initial agreement, CAMERDATA denies the existence of this infringement and maintains that the signed contract does comply with the provisions of Article 28.3

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 151/164

of the GDPR. In this regard, it states that the contract establishes the "object, duration, nature, and purpose of the processing," "the type of personal data, categories of data subjects, and the obligations and rights of the data controller." It also indicates that it makes

express and repeated reference to observing and complying with the provisions of the GDPR and the LOPDGDD "regarding access, processing, and transfer of personal data."

With its allegations (document no. 6), it submits the "Confidentiality Agreement" that both parties signed on December 18, 2019. It explains that it was not provided at the time of

complying with the prior request for information made by the AEPD, "because
at that time no information was provided and, therefore, its scope was unknown."

Its argument consists of indicating which stipulations of the Confidentiality Agreement of
12/18/2019 and the Contract of 02/03/2020 correspond to each of the

provisions of Article 28.3 of the GDPR, with the aim of proving that all the
requirements of Article 28.3 of the GDPR are reflected in the Contract or the Confidentiality Agreement. In this regard, it states:

1. The provision of Article 28.3.a) of the GDPR, according to which “the data processor shall process the data solely following the documented instructions of the controller,” is

incorporated into Agreement 2.3.b) of the Confidentiality Agreement, which provides that “the information and data subject to processing shall be used solely and
exclusively for the development and execution of the contractual relationship, in accordance with the agreements established between the parties and following Camerdata's instructions.” The agreement continues by stating that “under no circumstances may the processor

process, use, or apply them for a different purpose or in violation of said regulations.”

2. The provision of Article 28.3.c) of the GDPR, relating to "all necessary measures in accordance with Article 32 GDPR" on the "Security of processing", is

incorporated through:

- Covenant 2.3.a) of the Convention, according to which the party receiving the information is obliged to have "the necessary technical and organizational means to ensure the security and confidentiality of any personal information provided."

- Covenant 2.3.e) of the Convention, according to which “personal data shall not be recorded in files that do not meet the legally required conditions regarding their integrity and security and that of the processing centers, premises, equipment, systems, and programs.”
- Covenants 2.3.g) and 2.3.k) of the Convention, according to which the confidentiality guarantees and criteria of the Convention shall extend to “any type of medium containing personal data (digital or non-digital) to which access is obtained” by reason of the development and execution of the contractual relationship.

3. Article 28.3.d) of the GDPR, according to which the first processor “shall respect the conditions indicated in paragraphs 2 and 4 for using another processor,” is transferred to Covenant 2.3.d) of the Convention, which prohibits subcontracting to third parties “the execution of any access or processing of personal data
communicated without the prior express written authorization of Camerdata.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 152/164

4. Article 28.3.e) of the GDPR, pursuant to which “the processor shall assist the controller, taking into account the nature of the processing, through appropriate technical and organizational measures, whenever possible, to enable the controller to fulfill its obligation to respond to requests that aim to exercise the rights of data subjects set out in Chapter III,” is incorporated into Covenants 2.5 and 2.6 of the Convention.

Under the first, DMOVO is obliged to immediately inform Camerdata of “the content and scope of any right of access, rectification, erasure, and objection exercised by any data subject of personal data that is being processed as a data subject.” of the data processor." And in accordance with
Pact 2.6, DMOVO "will not directly process any responses to data subjects, limiting its actions to keeping the data controller informed at all times," who assumes responsibility for handling any exercise of data subjects' rights regarding personal data protection.

5. Article 28.3.f) of the GDPR, according to which the data processor shall assist the data controller "in ensuring compliance with the obligations established in Articles 32 to 36, taking into account the nature of the processing and the information available to the data processor," is incorporated through Pact 2.3.f) of the Convention.

It establishes DMOVO's obligation both to comply with "the provisions of the LOPDGDD and the GDPR" and to monitor "the proper logical and physical protection of the personal data provided" by the data controller and the implementation of the "technical and organizational measures that are necessary, taking into account the state of the data. of the technology, the nature of the data stored, and the risks to which they are exposed, whether arising from human action or from the physical or natural environment.”

6. Article 28.3.g) GDPR, according to which, at the controller’s discretion, the

processor shall delete or return all personal data upon completion of the provision of processing services, and shall delete existing copies unless the retention of the personal data is required under Union or Member State law,” is incorporated through:

- Covenant 2.3.q) of the Convention. It stipulates that, upon termination or resolution of the

contractual relationship, DMOVO "will return all confidential information and all personal data provided by... (Camerdata) and will not retain any copies thereof, immediately destroying any media or documents containing any confidential information or personal data, without the need for an express request" from Camerdata.

-Covenant 1.4 of the Agreement provides that, upon termination of the contractual relationship, both parties
"shall return all data, documentation, computer or telematic media, or any other type of media provided in the execution of the same, except in the
case where there is a legal obligation to retain such media in accordance with and in the manner provided by the applicable regulations."

7. Article 28.3.h) of the GDPR, which refers to making available to the controller all the information necessary to demonstrate compliance with the obligations established in this article, as well as to allow and contribute to the performance of audits, including inspections, by the controller or another auditor authorized by the controller, as well as its second paragraph, according to which the processor shall immediately inform the controller if, in its opinion, an instruction infringes this Regulation or other data protection provisions of the Union or the Member States, is incorporated through:

-Furthermore, Covenant 2.3.ll) of the Convention establishes DMOVO's obligation to keep Camerdata informed of "any type of incident that may have

an impact on the integrity or confidentiality of the data."

It also provides that Camerdata may "inspect, either itself or through technicians
designated for this purpose, the premises, facilities, equipment, and measures implemented" by
DMOVO, such as DMOVO's obligation to keep Camerdata informed of

"any type of incident that may have an impact on the integrity or
confidentiality of the data."

CAMERDATA concludes that, through the 2020 Contract and the Confidentiality Agreement submitted in the allegations process, the provisions of Article 28.3 were incorporated into the
regulation of the contractual relationship, meaning that this

obligation has been fulfilled and no violation of the provision has occurred,
which is why it is appropriate to order the closing of the sanctioning procedure with respect to
this violation.

Two additional clarifications should be made. First, neither the contract nor the

Confidentiality Agreement mentions what data CAMERDATA provides to DMOVO to carry out the service. However, the
document provided during the testing phase, corresponding to Annex I to the contract,
called "Geographic Data Processing System," which contains the commercial offer, details the procedure to be followed and specifies which data must be

previously processed to carry out the standardization process. Furthermore, the
requirement of Article 28.3.b) of the GDPR, which CAMERDATA did not mention in its statement of allegations, is also included in the Confidentiality Agreement.

Therefore, considering that it is proven through the documentation in the file that in the contractual relationship between DMOVO, as data processor,

and CAMERDATA, as data controller, all the requirements referred to in
Article 28.3 of the GDPR were documented (albeit scattered across three different documents), there is no evidence of conduct contrary to that provision, and therefore it is necessary to propose closing the aforementioned infringement (Article 28.3 of the GDPR), which was attributed to CAMERDATA in the agreement initiating this

procedure.

XIV
Sanction

1. The corrective powers attributed to the AEPD as supervisory authority are listed in Article 58.2 of the GDPR, sections a) to j). The provision mentions, among them, section i), the power to sanction with an administrative fine in accordance with
Article 83 of the GDPR.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 154/164

Administrative fines should be imposed on CAMERDATA for the violations
of Articles 6.1 and 14 of the GDPR mentioned in the preceding Grounds,

without prejudice to the corrective measures ordered.

Article 83 of the GDPR, "General conditions for the imposition of administrative fines", states in its first paragraph that the supervisory authority shall ensure that the
imposition of fines for the violations of this Regulation indicated in paragraphs 4, 5, and 6 comply, in each individual case, with the principles of effectiveness,

proportionality, and deterrence.

The principle of proportionality requires a correlation between the violation and the sanction, with the prohibition of unnecessary or excessive measures, so that the sanction is appropriate to achieve the purposes that justify it. To ensure adequacy

between the sanction and the violation committed, Article 83.2 of the GDPR provides a list of criteria that help to determine its amount. The provision establishes:

"Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or as a substitute for the measures provided for in Article 58(2)(a) to (h) and (j). When deciding whether to impose an administrative fine and its amount in each individual case, due account shall be taken of:
a) the nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage suffered by them;

b) the intentionality or negligence involved in the infringement;
c) any measures taken by the controller or processor to mitigate the damage suffered by data subjects;
d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures they have implemented pursuant to Articles 25 and 32;
e) any previous infringement committed by the controller or processor;
f) the degree of cooperation with the supervisory authority to remedy the breach and mitigate the potential adverse effects of the breach;
g) the categories of personal data affected by the breach;
h) how the supervisory authority became aware of the breach, in particular whether the controller or processor notified the breach and, if so, to what extent;
i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned in relation to the same matter, compliance with those measures;

j) adherence to codes of conduct pursuant to Article 40 or to certification mechanisms approved pursuant to Article 42; and
k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the breach.

The LOPDGDD, Article 76, "Sanctions and Corrective Measures", provides in relation to
Article 83.2.k) that the following may be taken into account:
"a) The ongoing nature of the infringement.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 155/164

b) The connection between the offender's activity and the processing of personal data.
c) The benefits obtained as a result of committing the infringement.

d) The possibility that the affected party's conduct could have led to the commission of the infringement.
e) The existence of a merger by absorption process subsequent to the commission of the infringement, which cannot be attributed to the acquiring entity.
f) The impact on the rights of minors.
g) Having, when not mandatory, a data protection officer.

h) Submission by the controller or processor, on a voluntary basis, to alternative dispute resolution mechanisms, in cases where there are disputes between them and any interested party."

Furthermore, it should be noted that Articles 83.5 and 83.4 of the GDPR

respectively provide that the maximum amount of the penalty imposed will be the greater of the following two amounts: "€20,000,000 or, in the case of a company, an amount equivalent to a maximum of 4% of the total annual global turnover of the preceding financial year" in the case of Article 83.5, and
€10,000,000 or, in the case of a company, an amount equivalent to a maximum of 2% of the total annual global turnover of the preceding financial year" in the case of Article 83.4 of the GDPR.

We recall that the fourth background to this proposal states that CAMERDATA's turnover during the 2021 financial year was €886,000.

2. For each of the GDPR violations for which CAMERDATA is held responsible, the circumstances that apply are examined in order to determine the amount of the fine.

2.1. Violation of Article 6.1 of the GDPR:

The following factors from Article 83.2 of the GDPR are considered aggravating factors, reflecting a greater unlawfulness of the conduct and/or culpability of the data controller:

-Article 83.2.a): "the nature, severity, and duration of the violation, taking into account

the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damages they have suffered."

This circumstance is particularly relevant in scaling up the amount of the administrative fine

to be imposed for the violation of the principle of lawfulness. This is because the aspects on which the circumstance in section a) pivots the
greater or lesser severity of the conduct being assessed, once applied to the
facts at hand, demonstrate in the present case an indisputable additional
respect to the unlawfulness of the conduct and the culpability of CAMERDATA.

The processing operation carried out without an adequate legal basis under the GDPR consisted of the collection of personal data from self-employed entrepreneurs,
provided by the CDE under a private contract, and subsequently transferred by

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 156/164

CAMERDATA for commercial purposes—since that is the purpose of the commercial activity of the party responsible for this infringement—to third-party entities that will use them directly, essentially, for marketing purposes, or in turn transfer them to other entities for similar purposes.

The collection of personal data from individual entrepreneurs, its systematization, enrichment, and subsequent transmission carried out by CAMERDATA, has been able to take place—and consequently, the personal data of self-employed entrepreneurs may have reached third parties for use for the specific purposes of their business activity—thanks to the transfer made by the CDE.

The nature, purpose, and scope of this processing operation are affected by relevant aspects that cannot be ignored and that demonstrate the seriousness of the processing that is intended to be assessed for the purposes of imposing a sanction that is

proportionate, effective, and dissuasive:

First, the agreement signed between the AEAT and the CDE (an agreement published in the BOE) for the transfer of data expressly prohibits (clause four) the CDE from transferring the data obtained to third parties, since the sole purpose of this transfer by the tax authorities is to compile the public business census. And this is also the legislator's intention, which, in the Explanatory Statement of Law 4/2014, paragraph II, states verbatim: "that the Official Chambers of Commerce, Industry, Services, and Navigation will compile a public census of companies, for the preparation of which they will have the collaboration of the competent tax administration, guaranteeing, in all cases, the [...] exclusive use of the information for the legally established purposes."

Thus, the purpose entrusted to the CDE by Article 8 of the aforementioned Law is fulfilled and exhausted with the publication of the census on its corporate website, so that this limitation on the purpose of processing the data covered by this procedure cannot be ignored. Secondly, it cannot be ignored that, since the information published through the public census is strictly limited to that purpose, and there is an express prohibition on transferring information to third parties, and Article 8 of Law 4/2014 provides that it provides, the CDE transmits to CAMERDATA, and this entity receives without question, not only the information related to self-employed workers that can be accessed from its corporate website, but also additional data, such as the NIF (Tax Identification Number) of these individuals, which is not published in the public business census. Thirdly, CAMERDATA is a holding company of the Chambers of Commerce (as the CDE refers to it), which was established in the 1980s by various Chambers of Commerce.

The transmission of data by the CDE to CAMERDATA occurs with the full knowledge of the former of the subsequent transmissions that CAMERDATA plans to make to third parties, and with the full knowledge of the latter, CAMERDATA, of the origin of the data: the tax authorities. A simple reading of the contract signed between the two in 2016 is enough to verify these points.

Also relevant is the extremely high number of people who have been affected by the unlawful processing of their data, around one and a half million individuals

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 157/164

who are business owners. The seriousness of the conduct is amplified when considering the null expectations that those affected could have had that the processing that materializes the violation of Article 6.1 of the GDPR could be carried out.

- Article 83.2.b): "intentionality or negligence in the violation."

The subjective element or culpability in the broad sense is an integral requirement of an
administrative violation. In our legal system, the requirement of strict liability is prohibited. In this regard, we can mention the ruling

246/1991, of December 19, of the Constitutional Court, which states:
"Specifically, regarding culpability, this Court has declared that, indeed, the Spanish Constitution undoubtedly enshrines the principle of culpability as a basic structural principle of criminal law […]. This principle of culpability also governs administrative offenses, since, to the extent that the sanction of said offense is one of the manifestations of the State's ius puniendi, a regime of strict or no-fault liability is inadmissible in our legal system (STC 76/1990)."

Furthermore, the principle of culpability is enshrined in Law 40/2015 on the Legal Regime of the Public Sector, which establishes in Article 28, under the heading

"Liability":
"1. Only natural persons and legal entities, as well as, when a law recognizes their capacity to act, affected groups, unions and entities without legal personality, and independent or autonomous assets, who are held liable for them due to intent or negligence."

Following the definition set forth in the ruling of the Supreme Court, Administrative Litigation Division, dated July 6, 2010, "Guilt must be understood as the personal judgment of blame directed at the perpetrator (by action or omission) of a typical and unlawful act; this implies and requires that the perpetrator be the cause of the action or omission that constitutes the unlawful conduct—as perpetrator, accomplice, or accessory after the fact; that he or she be imputable, without circumstances that alter his or her capacity to act; and that he or she be culpable, that is, that he or she acted consciously and willfully, either intentionally or negligently."

The manifestations of culpability, broadly understood—as an element of the infringement—are intent or intentionality and negligence or negligence, which, in turn, can be of varying degrees.

In the present case, when assessing the presence, as an aggravating circumstance of the infringement of Article 6.1 of the GDPR, of the circumstance described in letter b) of Article 83.2 of the GDPR—"the intentionality or negligence of the infringement"—we are not referring to the culpability element essential to constitute the sanction, but rather to an additional "plus" of culpability: that is, the presence in the infringing conduct of a very serious, highly relevant, and significant lack of diligence on the part of the data controller that completely exceeds the subjective element that constitutes the infringement.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 158/164

CAMERDATA has processed data concerning more than one and a half million individuals without an adequate legal basis under the GDPR, despite having all the evidence and information necessary to verify that the data transferor was not authorized to transfer the data and, therefore, any processing it carried out on the data obtained—reception, transfer to third parties for commercial and/or marketing purposes, or for the purpose of data standardization—lacked a lawful basis pursuant to Article 6.1 of the GDPR. The assessment of the extremely serious lack of due diligence also highlights the fact that the processing was carried out within the scope of the company's business activity, in which professional conduct required it to exercise greater rigor and diligence in complying with the obligations imposed by the GDPR.

Article 83.2.g) GDPR: "The categories of personal data affected by the infringement."

Although the literal wording of Article 83.2.g) of the GDPR appears to link this classification criterion exclusively to Article 9 of the GDPR, the GDPR nevertheless contains references to other classifications of data that reflect the purpose pursued by Article 83.2 of the GDPR: to scale the amount of the fine in accordance with the principles of proportionality and effectiveness. Thus, Recitals 51 and 75 of the GDPR

distinguish a group of personal data that, by their nature, are particularly
"sensitive" due to the significant risk that their processing may entail for fundamental rights and freedoms, as it may cause physical, material, or immaterial damage.

This group or category includes, in addition to the specially protected data regulated by Article 9 of the GDPR, many others. Recital 75 mentions personal data whose processing may entail a risk of varying severity and
probability for the rights and freedoms of natural persons and refers to data whose processing "may give rise to discrimination,

identity theft or fraud, financial loss, damage to reputation,
loss of confidentiality of data subject to professional secrecy, unauthorized reversal of pseudonymization, or any other significant economic or social harm."

The DNI's numerical identifier, along with the verification character corresponding

to the tax identification number, unequivocally identifies a natural person.This quality makes it particularly sensitive data, since if its processing is not accompanied by the necessary technical and organizational measures to ensure that the person identified with it is truly its owner, a third party can easily impersonate a natural person, or, in other words, commit identity fraud, with the associated risks to the privacy, honor, and assets of the person impersonated.

Article 83.2.k) GDPR in conjunction with Article 76 b) of the LOPDGDD: "The connection between the offender's activity and the processing of personal data."

The performance of its activities routinely requires the processing of personal data, which impacts the due diligence required to comply

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 159/164

with the principles governing the processing of personal data and the quality and effectiveness of the technical and organizational measures that must be implemented to ensure respect for this right.

No factors are observed that mitigate the culpability or unlawfulness of the conduct that violates Article 6.1 of the GDPR.

In light of the concurrent circumstances, it is proposed to impose an administrative fine on CAMERDATA
for the violation of Article 6.1 of the GDPR in the amount of
€200,000 (two hundred thousand euros).

2.2. Violation of Article 14 of the GDPR:

The following circumstances of Article 83.2 of the GDPR constitute aggravating circumstances, reflecting a greater unlawfulness of the conduct and/or culpability of the offender:

- Article 83.2.a): "the nature, severity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage and harm they have suffered."

An examination of the nature, scope, and purpose of the processing operation carried out by CAMERDATA in light of the breach of the transparency obligation reveals the extraordinary seriousness of the infringement committed.

The violation of Article 14 of the GDPR, on which the circumstance in paragraph a) is projected, affects the duty of transparency that the GDPR imposes on the controller; the
duty to provide the data subject with clear and complete information about the processing of their personal data, especially in cases such as the one at hand, where the

data controller does not collect the data directly from the data subject. The duty to inform therefore becomes an essential instrument to truly and
effectively guarantee that data subjects can exercise the rights recognized by data protection regulations, since it is difficult for them to
exercise them if they are not even aware that the processing is taking place.

When the processing operation has the characteristics presented here, in which
the offending party has collected the data from an entity that also did not receive it
from its data subject and who was not informed of its processing (the transfer to CAMERDATA) despite being obliged to do so by Article 14 of the GDPR, and in which, in turn, this transferor obtained the data from the entity that did collect it directly from the data subject,
but who was not informed of this chain of subsequent processing,
given that the transfer by the recipient of the data to its transferee (later the transferor of CAMERDATA) occurred in compliance with a legal obligation,
that the data are linked to the processing for the specific purpose provided for in the Law, and that the recipient has additionally guaranteed, through an agreement with the transferor, the
express prohibition of transferring the data to third parties, the seriousness arising from the lack of
information in which the data subject is involved is extraordinary. The seriousness of the GDPR breach for which CAMERDATA is held responsible is also underscored by the lack of expectations that the data subject may have who has

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 160/164

provided their data to a tax authority in compliance with a legal obligation, that it may be processed for the purpose for which CAMERDATA intends it.

-Article 83.2.b): "intentionality or negligence in the violation."

The subjective element or culpability in the broad sense is an integral requirement of the administrative violation. In our legal system, the requirement of strict liability is prohibited. In this regard, we can mention the ruling

246/1991, of December 19, of the Constitutional Court, which states:
"Specifically, regarding culpability, this Court has declared that, indeed, the Spanish Constitution undoubtedly enshrines the principle of culpability as a basic structural principle of criminal law […]. This principle of culpability also governs administrative offenses, since, to the extent that the sanction of said offense is one of the manifestations of the State's ius puniendi, a regime of strict or no-fault liability is inadmissible in our legal system (STC 76/1990)."

Furthermore, the principle of culpability is enshrined in Law 40/2015 on the Legal Regime of the Public Sector, which establishes in Article 28, under the heading

"Liability":
"1. Only natural persons and legal entities, as well as, when a law recognizes their capacity to act, affected groups, unions and entities without legal personality, and independent or autonomous assets, who are held liable for them due to intent or negligence."

Following the definition set forth in the ruling of the Supreme Court, Administrative Litigation Division, dated July 6, 2010, "Guilt must be understood as the personal judgment of blame directed at the perpetrator (by action or omission) of a typical and unlawful act; this implies and requires that the perpetrator be the cause of the action or omission that constitutes the unlawful conduct—as perpetrator, accomplice, or accessory after the fact; that he or she be imputable, without circumstances that alter his or her capacity to act; and that he or she be culpable, that is, that he or she acted consciously and willfully, either intentionally or negligently."

The manifestations of culpability, broadly understood—as an element of the infringement—are intent or intentionality and negligence or negligence, which, in turn, can be of varying degrees.

In the present case, when assessing the presence, as an aggravating circumstance of the infringement of Article 14 of the GDPR, of the circumstance described in letter b) of Article 83.2 of the GDPR—"the intentionality or negligence of the infringement"—we are not referring to the culpability element essential to the sanction, but rather to an additional "plus" of culpability: that is, the presence in the infringing conduct of a very serious, highly relevant, and significant lack of diligence on the part of the data controller that completely exceeds the subjective element that constitutes the infringement.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 161/164

CAMERDATA has breached its obligation to inform the data subjects whose data it processes about the processing, in accordance with Article 14 of the GDPR. In addition to the vulnerability this poses for the data subjects—given that CAMERDATA does not collect their personal data, nor did the transferring entity collect it from them, and that the transferor did not inform them—there is also the lack of expectations among the data subjects regarding the existence of this processing.

This does not prevent us from finding a very serious lack of diligence on the part of CAMERDATA in its breach of the obligation to inform, given that certain actions on its part—examined in the relevant grounds of this proposal—have not had the potential to constitute a compensatory measure for the lack of information.

-Article 83.2.g) GDPR: "The categories of personal data affected by the infringement."

Although the literal wording of Article 83.2.g) of the GDPR appears to link this grading criterion exclusively to Article 9 of the GDPR, the GDPR nevertheless contains references to other data classifications that reflect the purpose pursued by Article 83.2 of the GDPR: to grade the fine in accordance with the principles of proportionality and effectiveness. Thus, recitals 51 and 75 of the GDPR

distinguish a group of personal data that, by their nature, are particularly "sensitive" due to the significant risk that their processing may entail for fundamental rights and freedoms, as it may cause physical, material, or immaterial damage.

This group or category includes, in addition to the specially protected data regulated by Article 9 of the GDPR, many others. Recital 75 mentions personal data whose processing may entail a risk of varying severity and likelihood for the rights and freedoms of natural persons and refers to data whose processing "may give rise to discrimination,

identity theft or fraud, financial loss, damage to reputation,
loss of confidentiality of data subject to professional secrecy, unauthorized reversal of pseudonymization, or any other significant economic or social harm."

The numerical identifier of the DNI, together with the verification character corresponding

to the tax identification number, unequivocally identifies a natural person.This quality makes it particularly sensitive data, since if its processing is not accompanied by the necessary technical and organizational measures to ensure that the person identified with it is truly its owner, a third party can easily impersonate a natural person, or, in other words, commit identity fraud, with the associated risks to the privacy, honor, and assets of the person impersonated.

Article 83.2.k) GDPR in conjunction with Article 76 b) of the LOPDGDD: "The connection between the offender's activity and the processing of personal data."

The performance of its activities routinely requires the processing of personal data, which impacts the due diligence required to comply

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 162/164

with the principles governing the processing of personal data and the quality and effectiveness of the technical and organizational measures that must be implemented to guarantee respect for this right.

No mitigating factors are apparent.

Given the circumstances, CAMERDATA must be fined €60,000 (sixty thousand euros) for violating Article 14 of the GDPR.

XV

The resolution establishes the violations committed and the facts that led to the breach of data protection regulations. From this, it is clear what measures to be adopted. However, the specific type of procedures, mechanisms, or instruments to implement them are the responsibility of the sanctioned party. The data controller is fully familiar with its organization and must decide, based on proactive responsibility and a risk-based approach, how to comply with the GDPR and the LOPDGDD.

Without prejudice to the foregoing, CAMERDATA is ordered to take the following measures:

(i) Within a maximum period of one month from the date the sanctioning resolution is issued, it shall delete all personal data
relating to self-employed entrepreneurs contained in CAMERDATA's files that originate from the transfer of databases made by the Spanish Chamber of Commerce.

(ii) Within a maximum period of one month from the date the sanctioning resolution is issued, the Chamber of Commerce of Spain shall cease processing personal data relating to self-employed entrepreneurs until a legitimate basis exists.

(ii) Within a maximum period of three months from the date the sanctioning resolution is issued, the Chamber shall inform the Chamber of Commerce, pursuant to Article 14 of the GDPR, of the processing of the personal data of self-employed entrepreneurs by means of a personalized announcement or one that is relevant due to its format and characteristics. The inclusion of a general announcement on the Chamber of Commerce's website shall not be sufficient.

Please note that failure to comply with the order to adopt measures imposed by this body in the sanctioning resolution may be considered an administrative violation pursuant to the provisions of the GDPR, classified as a violation in Articles 83.5 and 83.6. Such conduct may lead to the initiation of a subsequent administrative sanctioning procedure.

Therefore, in accordance with applicable legislation and having assessed the criteria for graduating the sanctions whose existence has been proven,

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 163/164

The Presidency of the Spanish Data Protection Agency RESOLVES:

FIRST: TO IMPOSE CAMERDATA, S.A., with NIF A78035896, for an infringement

of Article 6.1 of the GDPR, classified in Article 83.5.a) of the GDPR, with an administrative fine (Article 58.2.i GDPR) in the amount of €200,000 (two hundred thousand euros).

SECOND: TO IMPOSE CAMERDATA, S.A., with NIF A78035896, for an infringement,
for an infringement of Article 14 of the GDPR, classified in Article 83.5.b) of the GDPR,
with an administrative fine (Article 58.2.i GDPR) in the amount of €60,000 (one hundred thousand euros).

THIRD: DISMISS the violation of Article 6.1 of the GDPR, classified in Article 83.5.a) of the GDPR, consisting of "c) Having transferred its File to the company KOMPASS for the dual purpose of providing a feedback service for the information collected therein and for use by this entity for its own activities," which was attributed to it in the agreement initiating this procedure.

FOURTH: DISMISS the violation of Article 28 of the GDPR, classified in Article 83.4.a) of the GDPR, which was attributed to it in the agreement initiating this procedure.

FIFTH: ORDER CAMERDATA, S.A., with Tax Identification Number (NIF) A78035896, pursuant to
Article 58.2.d) of the GDPR, to demonstrate that it has complied with the following
measures:

(i) Within a maximum period of one month from the date the sanctioning resolution is issued, it must demonstrate that it has deleted all personal data relating to self-employed entrepreneurs contained in CAMERDATA's files originating from the transfer of databases made by the
Spanish Chamber of Commerce.

(ii) Within a maximum period of one month from the date the sanctioning resolution is issued, the Court shall certify that it has ceased processing personal data relating to self-employed entrepreneurs from the Spanish Chamber of Commerce until it has a legitimate basis.

(iii) Within a maximum period of three months from the date the sanctioning resolution is issued, the Court shall certify that it has informed, in accordance with Article 14 of the GDPR, of the processing of the personal data of self-employed entrepreneurs by means of a personalized announcement or one that is relevant due to its format and characteristics, without the inclusion of a general announcement on the website of the Chambers of Commerce being sufficient.

SIXTH: NOTIFY CAMERDATA, S.A. of this resolution.

SEVENTH: This resolution will become enforceable once the deadline for filing an optional appeal for reconsideration expires (one month from the day following notification of this resolution) without the interested party having exercised this right.
The sanctioned party is hereby notified that they must pay the imposed sanction once this resolution becomes enforceable, in accordance with the provisions of Article 98.1.b) of Law 39/2015, of October 1, on the Common Administrative Procedure of the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 164/164

Public Administrations (hereinafter LPACAP), within the voluntary payment period
established in Article 68 of the General Collection Regulations, approved by Royal
Decree 939/2005, of July 29, in relation to Article 10. 62 of Law 58/2003, of December 17, by depositing the fine, indicating the sanctioned party's NIF (Tax Identification Number) and the procedure number shown in the heading of this document, into the restricted account IBAN: ES93-0000-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX), opened in the name of the Spanish Data Protection Agency at CAIXABANK, S.A. Otherwise, the fine will be collected during the enforcement period.

Once the notification has been received and enforced, if the enforcement date is between the 1st and 15th of each month, inclusive, the deadline for making the voluntary payment will be the 20th of the following month or the next business day after, and if it is between the 16th and last day of each month, inclusive, the payment deadline will be the 5th of the second following month or the next business day after.

In accordance with the provisions of Article 50 of the LOPDGDD (Organic Law on the Protection of Personal Data), this Resolution will be made public once it has been notified to the interested parties.

Any appeal against this resolution, which terminates the administrative process pursuant to Article 48.6 of the

LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, interested parties may optionally file an appeal for reconsideration before the
Presidency of the Spanish Data Protection Agency within one month from the day following notification of this resolution, or directly file an administrative appeal before the Contentious-Administrative Division of the

National Court, in accordance with the provisions of Article 25 and Section 5 of the Fourth Additional Provision of Law 29/1998, of July 13, regulating the Contentious-Administrative Jurisdiction, within two months from the day following notification of this decision, as provided for in Article 46.1 of the aforementioned Law.

Finally, it is noted that pursuant to the provisions of Art. 90.3 a) of the LPACAP (Spanish Data Protection Act), a final administrative decision may be provisionally suspended if the interested party expresses their intention to file an administrative appeal.
If this is the case, the interested party must formally notify this fact in writing to the Spanish Data Protection Agency, submitting it through the Agency's Electronic Registry [https://sedeaepd.gob.es/sede-electronica-
web/], or through one of the other registries provided for in Article 16.4 of the aforementioned Law 39/2015, of October 1. They must also forward to the Agency the documentation proving the effective filing of the administrative appeal. If the Agency does not become aware of the filing of the administrative appeal within two months from the day following notification of this resolution, it will terminate the provisional suspension.

938-100325

Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es
  1. Article 8, Law 4/2014, of April 1, Basic Law of the Official Chambers of Commerce, Industry, Services and Navigation https://www.boe.es/buscar/act.php?id=BOE-A-2014-3520#a8
  2. This quote can be found on page 110 of the decision