AEPD (Spain) - EXP202409823

From GDPRhub
AEPD - EXP202409823
Authority: AEPD (Spain)
Jurisdiction: Spain
Relevant Law: Article 5(1)(c) GDPR
Type: Complaint
Outcome: Upheld
Started: 03.06.2024
Decided: 19.03.2025
Published: 21.04.2025
Fine: 600 EUR
Parties: n/a
National Case Number/Name: EXP202409823
European Case Law Identifier: n/a
Appeal: Not appealed
Original Language(s): Spanish
Original Source: AEPD (in ES)
Initial Contributor: cwa

The operator of a mobile application was fined €600 for requiring users to upload a copy of the ID card to attain “verified” status on the platform, in violation of Article 5(1)(c) GDPR.

English Summary

Facts

A data subject sought to become a “verified user” on a mobile application (the apps operator being the controller). Verification allowed for subscription to paid services within the app. In order to do this, the app required him to submit a copy of the front and back of his ID card which would then be stored on the app’s data base.

After the data subjected object to the processing of his ID in this way, the app's operator commissioned an external expert to review the process, who concluded that the requirement was intrusive and unnecessary.

On June 3rd 2024, the data subject filed a complaint with the AEPD (Spanish DPA).

Holding

The DPA found that the controller had infringed the principle of data minimisation in Article 5(1)(c) GDPR. The DPA reasoned that there were other, equally accessible alternatives that the controller could have used such as identity verification systems which would have been far less intrusive, not requiring the retention of data subject’s ID.

The DPA considered the infringement to be serious in nature, and initially levied a fine of €1,000. However, pursuant to Law 39/2015, a Spanish law concerning administrative proceedings, the DPA informed the controller that it may acknowledge its responsibility for the alleged violations and/or make a voluntary payment of the proposed fine. Each of these actions reduces the imposed fine by 20%. The controller opted to reduce the fine by 40%, both acknowledging its responsibility for the violations and paying the reduced sanction amount of €600.

Comment

This decisions is vague about what resources the outsourced third party uses to verify age and identity. If the third party is using databases of national identity documents, what is the gain to privacy?

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.

1/17

 File No.: EXP202409823

RESOLUTION TERMINATING THE PROCEDURE FOR RECOGNITION OF LIABILITY AND VOLUNTARY PAYMENT

From the procedure initiated by the Spanish Data Protection Agency and based on the following

BACKGROUND

FIRST: On March 19, 2025, the Presidency of the Spanish Data Protection Agency agreed to initiate sanctioning proceedings against A.A.A. (hereinafter, A.A.A.), through the agreement transcribed below:

<<
File No.: EXP202409823

AGREEMENT TO INITIATE SANCTIONING PROCEDURE

Regarding the actions taken by the Spanish Data Protection Agency and based on the following

FACTS

FIRST: On June 3, 2024, a complaint was filed with the Spanish Data Protection Agency for a possible infringement attributable to A.A.A., (hereinafter, A.A.A.), with NIF: ***NIF.1, as the controller of the App ***APP.1.

The facts brought to the attention of this authority are:

The complainant states that in order to be a "verified user" of the App (...), a copy of both sides of the DNI (National Identity Document) is improperly and unjustifiably requested (...), which entails collecting and storing scanned copies of DNI (National Identity Documents) or equivalent identification documents from users who wish to verify their identity. The complainant states that he registered for the app in November 2019 and that ***APP.1 unilaterally decided to delete his account for non-compliance with the rules, just after he had paid the fee for one year, that is, until November 2025. He also states that, when requesting to be removed from the app, there is no record of the destruction and use of that document, as well as of all the personal information collected in the process, and that minors are not respected. However, he does not provide anything to justify these two statements in his complaint.

Along with the claim, please provide:

- Image of the WhatsApp app dated 3/06/2024 with the following text:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 2/17

“We only accept the official identity card issued in your country or your

Passport.”

Don't scan or photograph a copy or a photocopy of the document, use
only the real document.

Try to make your document.”

“We only accept the official identity card issued in your country

or your passport.

Do not scan or photograph a copy or photocopy of the document, use
only the original document.

Try to make your document.”

(Unofficial translation)

SECOND: In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), this complaint was forwarded to the A.A.A. (National Data Protection Agency) so that it could analyze it and inform this Agency within one month of the actions taken to comply with the requirements set forth in the data protection regulations.

The notification of the transfer of the complaint, which was carried out in accordance with the rules

established in Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), was made on July 8, 2024, as recorded in the acknowledgment of receipt included in the file.

On August 7, 2024, this Agency received a response letter from the A.A.A., to which the following documentation is attached:

- A. Our policy on fraud, scams, and impersonators.
- B. Anatomy of the model scammer.
- C. Communication of files according to LOPD 1998

o 1. Communication of registration dated June 25, 2005
o 2. Registration of file modification dated March 9, 2008
o 3. Registration of file modification.
o 4. Registration of file modification dated July 14, 2012

o 5. Registration of file modification dated August 28, 2012
- D. Extract from the RAT corresponding to the activity Provision of the service of
***APP.1.
- E. Privacy and Data Protection Policy (as published on August 7, 2024 at ***URL.1

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 3/17

- F. Opinion issued by the data protection expert: Opinion letter on partial review of compliance with the LOPDGDD and GDPR of (...), dated July 25, 2024, which is reproduced below due to its relevance:

“(…):

- (…).
- (…):

- (…).
- (…).
- (…).
- (…).
- (…).
- (…).
- (…).
- (…).

(…).

(…)”

- G. Emails sent to the complainant as part of the interaction following violations of the terms of use.

A.A.A. states in his response that:

“(…).”

“The complainant is B.B.B., a user of ***APP.1 since 2018, and whose activity on the social network has generated activities at different times that contradicted its usage regulations and ultimately led to his deregistration on March 6, 2024. The

chronology of the main aspects of his activity as a user is included in
section 10 Summary of the complainant's activity on the social network ***APP.1.”

“Registration and most of the tools are free, although there is a
paid subscription that users can purchase additionally to gain access to additional tools specifically aimed at users who wish to

make more effective use of ***APP.1.”

In another order of matters, the defendant reports:
“The scope of (…) in which (…) intervene is a source of multiple situations that
can cause injury or impairment of the rights and freedoms of the

people who practice professions in the sector with the greatest impact on (…).
As a result of the aforementioned risks, ***APP.1 considers it essential
to conduct exhaustive monitoring of the information and activity occurring on its social network.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 4/17

“The processing of personal data affected by the claim filed is that corresponding to the Provision of the ***APP.1 service. This processing is an evolution of the processing activities declared since 2006 in accordance with the Data Protection Act (LOPD) of 1998 through the communications attached in Annex C. Currently, the security officer, a position held by the signatory of this response to the AEPD request, has documented this activity in the Register of Processing Activities (RAT) in accordance with the documentation attached in Annex D. This processing includes various purposes, which, as indicated in the RAT, are as follows:

• Allowing the user to create a public profile in which to showcase their work and advertise their services, (…), collaborations, and other activities related to their interest in (…).
• Allowing the user to find other users with whom to collaborate and contact them. • Allowing the user to organize (…) or collaborations so that other interested users can sign up and collaborate together.
... • Allow the user to receive notifications via email or the mobile app about
new users, (...), collaborations, or other events posted by other users.
Allow the user to write comments, like, add to favorites, and other ways to socially interact with content posted by other users.
• Allow the user to purchase an optional paid subscription that provides

additional access to special tools and features.
• Allow the user to obtain the "Verified Identity" badge on their profile.
• Allow the user to invite other users to register.
• Communicate with users, including by electronic means, for the purpose of managing and fulfilling the paid subscription, the

features offered, such as the publication of (...), communications about internal offers, news related to ***APP.1, and other purely transactional communications such as notifications about a received private message or confirmation for a password change.

Regarding the acquisition of verified account status, A.A.A. states:

“Data collection for the acquisition of verified account status.
Additionally, users who wish to access verified account status must:

- Upload a scanned copy of their ID or other identification document to the platform.

This information is uploaded to the platform and stored in the database until the administrator verifies that the identity matches the one declared by the user. At that time, it is deleted from the database.”
Regarding image storage, A.A.A. states:
- “A dedicated server where the source code and all user data are located.

Images uploaded by users are briefly stored on this server at the time of upload while they are processed. A few seconds later, they are automatically moved to the (…)

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 5/17

This server and all the data it contains are located in
***LOCATION.1, France, in the data center of (…).”

- “Similarly, all images uploaded by users are stored in
the (…) service, from where they are distributed through the (…) network for viewing by users.”

- “(…) uses the services of (…) to store a backup copy of the
database. These backup copies are stored on the servers that
(…) has in ***LOCATION.2, in the (…).”

Upon receiving the complaint, A.A.A. took the following actions:
- On July 13, 2024, 5 days after receiving the notification from the AEPD,

all identity verification processes were suspended as a preventive measure while legal advice was obtained. This is the message that users have encountered since then when attempting to request identity verification:

"The option to verify identity has been temporarily
disabled. Please try again later."

- On July 15, 2024, the services of a data protection expert were contracted to conduct a compliance review and issue an opinion on the main actions to be taken (...)".

THIRD: On September 3, 2024, in accordance with Article 65 of the LOPDGDD (Spanish Data Protection Act), the complaint was admitted for processing.

LEGAL BASIS

I
Jurisdiction

In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679

(General Data Protection Regulation, hereinafter GDPR), and as established in Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), the President of the Spanish Data Protection Agency is competent to initiate and resolve this procedure.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 6/17

II
Procedure

Likewise, Article 63.2 of the LOPDGDD establishes that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development, and, insofar as they do not contradict them, in a subsidiary capacity, by the general rules on administrative procedures."

In accordance with Article 64 of the LOPDGDD, and taking into account the characteristics of the alleged infringement, a sanctioning procedure shall be initiated.

The procedure will last a maximum of twelve months from the date of the initiation agreement. After this period, the proceedings will expire and, consequently, the proceedings will be archived, in accordance with the provisions of Article 64 of the LOPDGDD.

If no objections are made to this initial resolution within the stipulated period, it may be considered a proposed resolution, as established in Article 64.2.f) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP).

III

Preliminary Questions

In the present case, in accordance with the provisions of Articles 4.1 and 4.2 of the GDPR, personal data processing is established, since A.A.A.
carries out, among other processing, the collection and storage of personal data of natural persons such as name, surname, photographs, date of birth, email address, and, for verified users, a copy of their ID or identification document.

It is important to note that the application ***APP.1, as stated in its letter, A.A.A., has the following types of users, as of 2/08/2024:

- The number of active users is 27,974.

- The number of active users is 27,974. - The number of registered users is 139,979 (these are the active users from the previous point, plus those who: filled out the registration form but do not have an active profile on ***APP.1, did not fill out all the data required to create a profile, filled out their profile with incorrect or false data, canceled their account voluntarily, had their account canceled for some reason, spent too much time without accessing their account, and their profile was automatically put in "invisible" mode, and fake users created by bots or similar automated processes).
- The number of users with verified identity is 4,536.

A.A.A. carries out this activity in its capacity as data controller, given that it determines the purposes and means of such activity pursuant to Article 4.7 of the GDPR.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 7/17

The data contained in The image of the DNI is considered personal data, the processing of which is subject to the regime provided for in the GDPR, as well as its implementing provisions, in accordance with the provisions of Article 4.1 and 4.2 of the GDPR, which

provides the following:

Article 4 Definitions

For the purposes of this Regulation, the following definitions apply:

1) "personal data" means any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person shall be any person whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

2) "processing": any operation or set of operations performed on

personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or modification, extraction, consultation, use, communication by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction; (…)

IV
Breached Obligation. Data Minimization

Article 5.1(c) of the GDPR establishes:

"1. Personal data shall be:
(…)
(c) adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed ("data minimization");"

In the present case, the complainant states that to be a verified user of
***APP.1, it is necessary to upload a copy of the DNI or identity document to said application, with said copy being stored in the application's database.

Regarding "verified users," these are users who the administrator approved for one of the following reasons: they requested that their identity be verified, the administrator deemed it necessary to verify the user's age due to concerns that they might be a minor, and the administrator deemed it necessary to verify the user's identity due to concerns that the user might be impersonated.
Being a verified user means being able to subscribe to paid services, which users can contract additionally, to gain access to additional tools, especially aimed at users who wish to take advantage of ***APP.1 more effectively.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 8/17

In its response, A.A.A. confirms the requirement to attach a copy of the DNI or identity document to the application and states that this information is uploaded to the

platform and stored in the database until the administrator verifies that the identity corresponds to the one declared by the
user. All of this constitutes express recognition that A.A.A. is processing personal data excessively and unnecessarily:
"As described in the data collection process described in section 4
above, the verification process includes the temporary collection of a scanned copy of the data subject's DNI. Although the technical measures adopted and the short storage period of the copy minimize the associated risk, they do not allow it to be completely eliminated." (page 25 of 81).

Furthermore, A.A.A. Once the complaint was filed with this Agency, it commissioned a report from an external expert (...), which expressly states:

"The collection of scanned copies of DNI (National Identity Document) as a method of identity verification is intrusive and does not comply with current legal provisions."

Furthermore, on July 13, 2024, and as an immediate preventive measure, the A.A.A.
deactivated the account verification mechanism.

And all this because the verification of data accuracy can be carried out
without requesting a copy of the DNI or identity document, as there are other

equally valid alternatives that allow this verification to be carried out reliably, through identity verification systems, in accordance with legal requirements, without including a copy of the DNI. The respondent himself states in his letter that:

"To ensure compliance with the GDPR, we plan to change the identity verification method and outsource this task to an external company through an API service. This will further minimize the impact that obtaining images of users' ID documents for verification has on privacy and to achieve stricter compliance with the GDPR.

To this end, the following services have been consulted: (…), (…), and (…).

The technical requirements are currently being analyzed as a prerequisite for contracting. Once integrated into the current solution, the account verification process will be reactivated." (Page 26 of 81)

Recital 39 of the GDPR states that:

“…personal data must be adequate, relevant, and limited to what is necessary for the purposes for which they are processed. This requires, in particular, ensuring that their retention period is limited to a strict minimum. Personal data should only be processed if the purpose of the processing cannot reasonably be achieved by other means. To ensure that personal data are not retained longer than necessary, the data controller must establish deadlines for their deletion or periodic review…”

Thus, in conclusion, it is excessive to be able to require a copy of the DNI (National Identity Document) to be a verified user in the ***APP.1 application, since the purpose of this processing can be achieved by other means.

Therefore, based on the evidence currently available, the agreement to initiate sanctioning proceedings is considered to be the facts

known to us could constitute an infraction, attributable to the A.A.A., for violating the article transcribed above.

V

Classification of the violation of Article 5.1.c) of the GDPR and classification for the purposes of limitation

Article 83.5 of the GDPR classifies the violation of the following article as an administrative offense, which shall be punishable, in accordance with paragraph 2, by administrative fines of up to EUR 20,000,000 or, in the case of a company, by an amount equivalent to a maximum of 4% of the total annual global turnover of the preceding financial year, whichever is higher:

"a) the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9;"

For its part, the LOPDGDD (Organic Law on the Protection of Personal Data) in its Article 71, Infractions, states that:

“The acts and conduct referred to in sections 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law, constitute infringements.”

For the sole purpose of the statute of limitations, Article 72.1 of the LOPDGDD establishes the following:

"In accordance with the provisions of Article 83.5 of Regulation (EU) 2016/679, infringements that constitute a substantial violation of the articles mentioned therein, and in particular the following, are considered very serious and will be subject to a three-year statute of limitations:
a) The processing of personal data in violation of the principles and guarantees

established in Article 5 of Regulation (EU) 2016/679."

VI
Proposed Sanction

In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR must be observed, which state:

“1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article for violations of this Regulation indicated in sections 4, 9, and 6 are effective, proportionate, and dissuasive in each individual case.

2. Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or as a substitute for the measures provided for in Article 58, paragraph 2, letters a) to h) and j). When deciding on the imposition of an administrative fine and its amount in each case, The following shall be duly taken into account:
a) the nature, gravity, and duration of the breach, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage suffered by them;
b) the intentionality or negligence of the breach;
c) any measures taken by the controller or processor to mitigate the damage suffered by the data subjects;

d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures they have implemented pursuant to Articles 25 and 32;
e) any previous breaches committed by the controller or processor;
f) the degree of cooperation with the supervisory authority to remedy the breach and mitigate any adverse effects of the breach;

g) the categories of personal data affected by the breach; (h) the manner in which the supervisory authority became aware of the infringement, in particular whether the controller or processor notified the infringement and, if so, to what extent;
(i) where the measures referred to in Article 58(2) have been previously ordered against the controller or processor concerned in relation to the same matter, compliance with those measures;
(j) adherence to codes of conduct pursuant to Article 40 or certification mechanisms approved pursuant to Article 42; and
(k) any other aggravating or mitigating factors applicable to the circumstances of the case,

such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement.

For its part, Article 76 "Sanctions and corrective measures" of the LOPDGDD (Organic Law on Data Protection)
provides:

"1. The sanctions provided for in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the grading criteria established in paragraph 2 of the aforementioned article.

2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account:
a) The continuous nature of the infringement.
b) The connection between the offender's activity and the processing of personal data.
c) The benefits obtained as a result of the commission of the infringement.

d) The possibility that the affected party's conduct could have led to the commission of the infringement.
e) The existence of a merger by absorption process subsequent to the commission of the infringement, which cannot be attributed to the acquiring entity.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 11/17

f) The impact on the rights of minors.
g) Having, when not mandatory, a data protection officer.
h) Voluntary submission by the controller or processor to alternative dispute resolution mechanisms in cases where there are disputes between them and any interested party.

In the present case, considering the seriousness of the potential violation, especially considering the consequences its commission has on those affected, a fine would be imposed, in addition to the adoption of measures, if appropriate.

The fine imposed must be, in each individual case, effective, proportionate, and dissuasive, in accordance with the provisions of Article 83.1 of the GDPR.

The balance of the circumstances contemplated in Article 83.2 of the GDPR with respect to the alleged violation of the provisions of Article 5.1.c) of the GDPR, allows for the initial imposition of an administrative fine of €1,000.00 (ONE THOUSAND EUROS).

VII

Corrective Measures

If the violation is confirmed, the resolution that The order may establish the corrective measures that the offending entity must adopt to put an end to the breach of personal data protection legislation, in this case Article 5.1.c) of the GDPR, in accordance with the provisions of the aforementioned Article 58.2.d) of the GDPR, according to which each supervisory authority may "order the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specified manner and within a specified period."

Thus, the responsible entity may be required to bring its actions into compliance with personal data protection regulations, within the scope expressed in the previous Legal Basis.

This document establishes the alleged violation committed and the facts that could give rise to this potential breach of data protection regulations. From this, it is clear what measures to be adopted, without prejudice to the specific procedures, mechanisms, or instruments to implement them being the responsibility of the sanctioned party, since the data controller is fully familiar with their organization and must decide, based on proactive responsibility and a risk-based approach, how to comply with the GDPR and the LOPDGDD.

However, in this case, regardless of the foregoing, in accordance with the evidence currently available regarding the agreement to initiate sanctioning proceedings, the resolution adopted may require the A.A.A. Within 3 months from the date of the final decision of this procedure, the Court shall adopt the following measures:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 12/17

- Prove that the necessary measures have been adopted to ensure compliance with the provisions of Article 5.1.c) of the GDPR, without the need to

request a copy of the DNI or identity document for the registration of users identified in the App ***APP.1.

The imposition of this measure is compatible with the sanction consisting of an administrative fine, as provided in Article 83.2 of the GDPR.

Please note that failure to comply with the possible order to adopt measures imposed by this body in the resolution of this sanctioning procedure may be considered an administrative infraction pursuant to the provisions of the GDPR, classified as an infraction in Articles 83.5 and 83.6. Such conduct may lead to the opening of a subsequent administrative sanctioning procedure.

Please also remember that neither the recognition of the infraction committed nor, where applicable, the voluntary payment of the proposed amounts exempts you from the obligation to adopt the relevant measures to cease the conduct or correct the effects of the infraction committed, nor from the obligation to prove compliance with this obligation to this AEPD.

Therefore, in light of the above, the President of the Spanish Data Protection Agency,
HAS RESOLVED:

FIRST: TO INITIATE SANCTIONING PROCEEDINGS against A.A.A., with NIF ***NIF.1,
for the alleged violation of Article 5.1.c) of the GDPR, as defined in Article 83.5 of the GDPR.

SECOND: TO APPOINT C.C.C. as investigating judge and D.D.D. as secretary,
indicating that they may be challenged, if appropriate, in accordance with the provisions of Articles 23 and 24 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector (LRJSP).

THIRD: INCORPORATE into the file, for evidentiary purposes, the claim filed by the complaining party and its documentation, as well as the documents obtained and generated by the Subdirectorate General of Data Inspection in the proceedings prior to the initiation of this sanctioning procedure.

FOURTH: For the purposes provided for in Article 64.2 b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, the applicable sanction would be an administrative fine of €1,000.00 (ONE THOUSAND EUROS), without prejudice to the outcome of the investigation.

FIFTH: NOTIFY this agreement to A.A.A., with Tax Identification Number ***NIF.1, granting it a hearing period of ten business days to formulate any allegations and present any evidence it deems appropriate. In your written statement of allegations, you must provide your NIF (Tax Identification Number) and the procedure number shown in the heading of this document.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 13/17

In accordance with the provisions of Article 85 of the LPACAP (Spanish Civil Code), you may acknowledge your liability within the period granted for submitting allegations to this initiation agreement; this will result in a 20% reduction in the sanction to be imposed in this procedure. With the application of this reduction, the sanction would be set at €800.00 (EIGHT HUNDRED EUROS), and the procedure would be resolved with the imposition of this sanction.

Likewise, you may, at any time prior to the resolution of this procedure, voluntarily pay the proposed sanction, which will result in a 20% reduction in its amount. With the application of this reduction, the penalty would be set at €800.00, and its payment would terminate the proceedings, without prejudice to the imposition of the corresponding measures.

The reduction for voluntary payment of the penalty is cumulative with the applicable penalty for acknowledgment of liability, provided that this acknowledgment of liability is made clear within the period granted for submitting allegations at the opening of the proceedings. Voluntary payment of the amount referred to in the preceding paragraph may be made at any time prior to the resolution. In this case, if both reductions were applicable, the penalty would be set at €600.00 (SIX HUNDRED EUROS).

In any case, the effectiveness of either of the aforementioned reductions will be subject to the express withdrawal or waiver of any action or appeal against the penalty in administrative proceedings.

For these purposes, if you choose either of them, you must send the
General Subdirectorate of Data Inspection an express notification of your withdrawal

or waiver of any administrative action or appeal against the penalty, indicating which of the two reductions you are choosing, or whether you are choosing both.

If you choose to voluntarily pay any of the amounts indicated above (€800.00 or €600.00), you must do so by depositing it into account IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX) opened in the name of the Spanish Data Protection Agency at the bank CAIXABANK, S.A., indicating in the entry the reference number of the procedure shown in the heading of this document and the reason for the reduction in the amount you are claiming.

You must also send proof of payment to the Subdirectorate General of Inspection along with express notification of your withdrawal or waiver of any administrative action or appeal against the penalty in order to continue with the procedure in accordance with the amount paid.

Finally, it is noted that, pursuant to Article 112.1 of the LPACAP, no administrative appeal may be filed against this act.

1479-111224
Lorenzo Cotino Hueso
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 14/17

President of the Spanish Data Protection Agency
>>

SECOND: On March 26, 2025, A.A.A. proceeded to pay the fine in the amount of €600.00, making use of the two reductions provided for in the aforementioned initiation agreement, which implies acknowledgment of liability in relation to the events referred to in the initiation agreement and its legal classification.

THIRD: The initiation agreement transcribed above indicated that, if the infringement was confirmed, it could be agreed that the controller would be required to adopt appropriate measures to bring its actions into compliance with the regulations mentioned in this act, in accordance with the provisions of the aforementioned Article 58.2 d) of the GDPR, according to which each supervisory authority may "order the controller or processor to ensure that processing operations comply with the provisions of this Regulation, where appropriate, in a specific manner and within a specified period...".

Having acknowledged responsibility for the infringement, the measures included in the initiation agreement may be imposed.

LEGAL BASIS

I

Jurisdiction

In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (the General Data Protection Regulation, hereinafter GDPR), and as established in Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), the President of the Spanish Data Protection Agency is competent to resolve this procedure.

Likewise, Article 63.2 of the LOPDGDD establishes that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development and, insofar as they do not contradict them, in a subsidiary manner, by the general rules on administrative procedures."

II
Termination of the Procedure

Article 85 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), under the heading "Termination of Sanctioning Procedures" provides the following:

"1. Once a sanctioning procedure has been initiated, if the offender acknowledges responsibility, the procedure may be terminated with the imposition of the appropriate sanction.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 15/17

2. When the sanction is solely monetary in nature, or when a monetary sanction and a non-monetary sanction may be imposed, but the inadmissibility of the latter has been justified, voluntary payment by the alleged offender, at any time prior to the resolution, will result in the termination of the procedure, except with regard to restoring the altered situation or determining compensation for damages caused by the commission of the violation.

3. In both cases, when the sanction is solely monetary in nature, the body competent to resolve the procedure will apply reductions of at least 20% on the amount of the proposed sanction, which may be combined. The aforementioned reductions must be specified in the notification of initiation of the procedure, and their effectiveness will be conditional on the withdrawal or waiver of any administrative action or appeal against the penalty.

The percentage reduction provided for in this section may be increased by regulation.

III
Voluntary Payment and Acknowledgment of Responsibility

In accordance with the provisions of the aforementioned Article 85 of the LPACAP, the notified initiation agreement provided information on the possibility of acknowledging responsibility and voluntarily paying the proposed penalty, which would entail two cumulative reductions of 20% each. With the application of these two reductions, the penalty would be set at €600.00, and its payment would imply the termination of the procedure, without prejudice to the imposition of the corresponding measures.

Following notification of the aforementioned initiation agreement, the A.A.A. has proceeded to acknowledge responsibility and voluntarily pay the penalty, availing itself of the two proposed reductions. In accordance with section 3 of Article 85 of the LPACAP, the effectiveness of the aforementioned reductions will be conditional on the withdrawal or waiver of any administrative action or appeal against the penalty.

It should be noted that Please note that, in accordance with the provisions of the LPACAP, as well as the Supreme Court's jurisprudence on this matter, the exercise of voluntary payment by the alleged liable party does not exempt the administration from the obligation to resolve and notify all proceedings, regardless of their initiation. Similarly, Article 88 of the aforementioned law establishes that the resolution that concludes the proceedings will decide all issues raised by the interested parties and any other issues arising from them. Therefore, in accordance with applicable legislation and having assessed the criteria for graduating sanctions, the Presidency of the Spanish Data Protection Agency RESOLVES:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 16/17

FIRST: TO DECLARE the commission of the violations and CONFIRM the sanctions
determined in the operative section of the initiation agreement transcribed in this

resolution.

The sum of the aforementioned amounts results in a total of 1,000.00 euros.

After the A.A.A. has made prompt payment and acknowledged liability,

pursuant to Article 85 of the LPACAP, the aforementioned total is reduced by 40%, resulting in the final amount of 600.00 euros.

The effectiveness of the aforementioned reductions is conditioned, in all cases, on the withdrawal or waiver of any administrative action or appeal.

SECOND: DECLARE the termination of procedure EXP202409823, in accordance with the provisions of Article 85 of the LPACAP.

THIRD: ORDER the A.A.A. to notify the Agency within 3 months of this resolution becoming final and enforceable of the adoption of the measures described in the legal grounds of the initiation agreement transcribed in this resolution.

FOURTH: NOTIFY this resolution to the A.A.A.

FIFTH: In accordance with the provisions of Article 85 of the LPACAP (Spanish Civil Code), which conditions the reduction for voluntary payment and acknowledgment of liability on the withdrawal or waiver of any action or appeal in administrative proceedings, this resolution will become final in administrative proceedings and fully enforceable upon notification.

In accordance with the provisions of Article 50 of the LOPDGDD (Spanish Civil Code), this resolution will be made public once it has been notified to the interested parties.

Against this resolution, which terminates the administrative process as provided for in
Art. 114.1.c) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, interested parties may file an administrative appeal before the Contentious-Administrative Division of the National Court, in accordance with the provisions of Article 25 and section 5 of the fourth additional provision of Law 29/1998, of July 13, regulating the Contentious-Administrative Jurisdiction, within two months from the day following notification of this act, as provided for in Article 46.1 of the aforementioned Law.

However, in accordance with the provisions of Article 90.3.a) of the LPACAP, the final administrative decision may be provisionally suspended if the interested party expresses their intention to file an administrative appeal. If this is the case, the interested party must formally notify this fact in writing to the Spanish Data Protection Agency, submitting it through the Agency's Electronic Registry [https://sedeaepd.gob.es/sede-electronica-web/], or through any of the other registries provided for in Article 16.4 of the aforementioned Law 39/2015, of October 1. They must also forward to the Agency the documentation proving the effective filing of the administrative appeal. If the Agency does not become aware of the filing of the administrative appeal within two months from the day following notification of this resolution, it will terminate the precautionary suspension.

1259-260325
Lorenzo Cotino Hueso

President of the Spanish Data Protection Agency

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es