AEPD (Spain) - EXP202410264

From GDPRhub
AEPD - EXP202410264
Authority: AEPD (Spain)
Jurisdiction: Spain
Relevant Law: Article 6(1) GDPR
Article 83(1) GDPR
Article 83(2) GDPR
Type: Complaint
Outcome: Upheld
Started: 10.06.2024
Decided: 23.05.2025
Published: 21.07.2025
Fine: 10,000 EUR
Parties: ADNAYA GREEN SOLUTIONS
National Case Number/Name: EXP202410264
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Spanish
Original Source: AEPD (in ES)
Initial Contributor: claratab

The DPA fined an electrical services company €10,000 for transferring the data subject's personal data to a grants management company without a valid legal basis. The former made a list of its customers available to a third party as part of an outsourcing arrangement.

English Summary

Facts

ADNAYA GREEN SOLUTIONS, S.L. (the controller) is a company that provides electrical work and services, including installing solar panels. The controller had a contract with a data subject, in which the controller processed their personal data to manage the data subject’s grants to install solar panels.

The data subject received several emails in April 2024 from a grants management company, informing them that the controller had gone bankrupt and proposing to continue managing grant applications. The data subject asked the grants management company how it obtained their data.

The grants management company replied that it worked with the controller and it had a shared list of all of the controller’s customers, from which it was assigned those it had to manage. From there, the grants management company also obtained the data for the rest of the customers it didn’t manage.

The consumer filed a complaint to the Spanish DPA on 10 June 2024.

Holding

The DPA stated out that, in accordance with Article 6(1) GDPR, the processing of personal data requires the existence of a legal basis. The DPA considered that the controller had transferred the data subject’s personal data without a legal basis. This would include the data subject’s name and email address, and realistically, their ID information as well. The DPA noted that grants management company obtained the data before the controller had communicated the bankruptcy situation to the data subject.

Therefore, the DPA imposed a fine of €10,000 to the controller. The DPA considered it a severe violation, as it involved processing without a legal basis. In addition, the fact that the controller assigned customers to the grants management company meant that the controller likely regularly transferred data subjects’ personal data without a legal basis. The DPA concluded that this suggested the number of people affected by the unlawful processing is high.

Comment

This decision should raise awareness among companies involved in subcontracting and outsourcing operations: the sharing of personal data, even in the form of a list and in any context, still constitutes processing and must comply with the principles of the GDPR.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.

1/11

 File No.: EXP202410264

SANCTIONING PROCEDURE RESOLUTION

From the procedure initiated by the Spanish Data Protection Agency and based on the following

BACKGROUND

FIRST: On June 10, 2024, a complaint was filed with the Spanish Data Protection Agency for a possible violation attributable to ADNAYA GREEN SOLUTIONS, S.L. with Tax Identification Number (NIF) B86998812 (hereinafter, the respondent).

The grounds for the complaint are as follows:

The complainant states that they provided their personal data to the respondent

for the management of subsidies for the installation of solar panels; they state that
on April 8, 2024, they received a letter from Gestoría de Subvenciones S.L. Alerting him of the financial situation ADYANA GREEN was facing and offering to manage the grant; he states that he subsequently received another message, to which he replied that he wanted to know how they had accessed his email, receiving a response indicating that ADYANA had provided it; he states that he did not consent to or authorize the transfer of his data.

Along with his complaint, he provides documents with the following content:

- Email dated 04/08/2024 from GESTORIA DE

SUBVENCIONES SL (info@subvenziona.es) and addressed to ***EMAIL.1 with the following content:

Good morning,
Following the bankruptcy of Green Solutions (who carried out the photovoltaic installation and the subsequent grant), the grant applications are close to the awarding phase, but are unattended and at risk of being lost, so the Administration has contacted us to manage these grants. You can check the status of your grant with your ID at
https://gestion.ayudasrenovablesmadrid.com/ (...)

The phases are as follows (...)

Please check the status of your application and contact Green Solutions to verify that your application is not being processed so that they can take action on the situation. If the deadlines are missed, you will lose the grant you have been waiting for.

We can handle your grant management. We are the participating company with the most applications and grants in the Community of Madrid, with more than 11,000 grants awarded. The cost of our management is (...) and we guarantee a high-quality service that will bring your application to the aid collection status as quickly as possible. We would simply transfer the file and from there we would take care of everything.

In any case, don't take this email as a sales pitch, but rather as a
reminder to check the status of your file so you don't lose the subsidy, which is the most important thing. By the way, given that Phase 2 of the justification is complex (and even more so considering that the installation company has disappeared and we will have to take care of part of the documentation they would have to resolve, we will have to take care of the rest), we offer our services because we believe we have the resources and experience to ensure you receive your subsidy effortlessly and at a reasonable price.

- Email dated 04/09/2024 from info@greensolutions.es with the subject Green Solutions Notice and the following content:

Good afternoon.
We are attaching a notice that may be of interest to you.
Please, if you have any questions, you can contact us at

tramites@greensolutions.es

Attached is a document with the following content:

(…) For several months now, and due to various circumstances, many of them

just chance, but not for the better, coupled with the contraction of the residential self-consumption sector, falling energy prices, the end of subsidies, and a much higher financial cost for consumer loans, our financial capacity has been greatly reduced. This fact has led us
to having to file for compulsory pre-bankruptcy proceedings due to the accumulated losses in the

2023 financial year, (…). Unfortunately, once self-consumption sales have been halted, our cash flow capacity has been reduced day by day, to the point that it has been almost impossible for us to provide after-sales service, incidents, and the complex documentation that you are requesting from us to continue managing your files. This has made it impossible for us to execute the contracts signed with you within the agreed timeframe. With the aim of providing a comprehensive solution to our clients, we have spoken with companies in our sector that can provide continuity to the services you need to complete your self-consumption installation:
- Continuity of administrative procedures (licenses, legalizations, and subsidies)
- Incident support

The companies (…), (…), and (…) have proposed providing a solution to the aforementioned only, contracting their maintenance service. (…).
We provide the links and contacts generated by each of the companies. In the case of forms, you must complete the information and they will contact you to explain everything included in your offer.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 3/11

In the case of contact by email, you can contact them directly. (…)

- Email thread containing the following:

o Email sent from the address info@subvenziona.es
dated 04/12/2024, in which a reminder of the email is sent
described in the previous point.
o Response dated 04/13/2023 from the address ***EMAIL.1, in which

the following is indicated: (…) I would like you to tell me how
you accessed my email, as I understand that at no time have I informed you of it. (…)
or Response email dated 04/15/2024 stating the following: (…) As I mentioned, we were working with
Green Solutions and we provided some grants for their clients

(about 300-400) when they were more strapped for work. We had
a shared list of all the clients, and from there they assigned us the ones
we had to manage. That's where we have the
data for the rest of the clients we don't manage.
o Email dated April 18, 2024, sent from the address

***EMAIL.1 and in response to the one indicated in the previous point, which states the following: This shows me that they have received information about me in a manner that does not comply with the personal data protection regulations.

o In response to said communication, from info@subvenziona.es dated April 19, 2024, an email was sent with the following content:

Our engineering company has already been absorbed by the current parent company, with which we operate with full permission and authorization from the government. We have thousands of grants already awarded and collected by our clients in Madrid. If you need help with your grant, we are here. If not, no problem.

We simply wanted to inform you of the situation so that you have a chance of receiving the grant.

SECOND: In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), on July 16, 2024, the respondent was notified of this complaint so that it could analyze it and inform this Agency within one month of the actions taken to comply with the requirements set forth in the data protection regulations.

The notification, which was carried out in accordance with the regulations established in Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP) via electronic notification, was not received by the data controller within the deadline for making it available, and was deemed rejected in accordance with the provisions of Article 65.4 of Organic Law 3/2018, of December 1, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD). 43.2 of the LPACAP (Spanish Accordance of the Spanish Civil Procedure Act) on July 27, 2024, as recorded in the certificate in the file.

Although the notification was validly served electronically, the procedure being deemed to have been carried out in accordance with the provisions of Article 41.5 of the LPACAP (Spanish Accordance of the Spanish Civil Procedure Act), a copy was sent by postal mail to: C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 4/11

and duly served on July 29, 2024.In this notification, the complainant was reminded of his obligation to communicate electronically with the Administration and informed of the means of accessing said notifications, reiterating that, from now on, he would be notified exclusively by electronic means.

THIRD: On September 10, 2024, in accordance with Article 65 of the LOPDGDD (Spanish Data Protection Act), the complaint filed by the complainant was admitted for processing.

FOURTH: On March 19, 2025, the Presidency of the Spanish Data Protection Agency agreed to initiate sanctioning proceedings against the respondent for the alleged violation of Article 6.1 of the GDPR, as defined in Article 83.5.a) of the GDPR.

FIFTH: After notification of the aforementioned initiation agreement in accordance with the rules established in the LPACAP (Spanish Civil Procedure Act) and the deadline for submitting allegations has elapsed, it has been determined that no allegations have been received from the respondent.

Article 64.2.f) of the LPACAP—a provision of which the respondent was informed in the agreement opening the procedure—establishes that if allegations are not made within the established period regarding the content of the initiation agreement, when it contains a precise statement regarding the imputed liability, it may be considered a proposed resolution. In the present case, the agreement initiating the sanctioning procedure determined the facts that specified the imputation, the violation of the GDPR attributed to the respondent, and the sanction that could be imposed. Therefore, taking into account that the respondent has not submitted any objections to the agreement initiating the case and in accordance with the provisions of Article 64.2.f) of the LPACAP (Spanish Civil Code), the aforementioned agreement is considered a proposed resolution in this case.

SIXTH: According to the report collected from the AXESOR tool, the respondent is a small company established in 2014, with a sales volume of (...) euros in 2022.

In light of all the actions taken by the Spanish Data Protection Agency in this case, the following facts are considered proven:

PROVEN FACTS

FIRST: The complainant provided the respondent with his personal data to manage subsidies for the installation of solar panels.

SECOND: On April 8, 2024, the claimant received an email from GESTORIA DE SUBVENCIONES SL (info@subvenziona.es) informing them of the defendant's bankruptcy and offering to manage their subsidy.
Subsequently, by email dated April 9, 2024, the defendant informed the claimant about the filing for compulsory pre-bankruptcy proceedings.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 5/11

THIRD: On April 13, 2024, the claimant requested information from GESTORIA DE SUBVENCIONES SL about how they obtained their email address. In response, they were informed that this information had been provided by the defendant. There was no record of the claimant's authorization.

LEGAL BASIS

I
Jurisdiction

In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and as established in Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), the President of the Spanish Data Protection Agency is competent to resolve this procedure.

Likewise, Article 63.2 of the LOPDGDD establishes that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development, and, insofar as they do not contradict them, in a subsidiary capacity, by the general rules on administrative procedures."

II

Obligation breached: violation of Article 6.1 GDPR

Article 6, Lawfulness of processing, of the GDPR, paragraph 1, establishes that:

“1. Processing shall only be lawful if at least one of the following conditions is met:

a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;

b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

c) processing is necessary for compliance with a legal obligation to which the controller is subject;

d) processing is necessary to protect the vital interests of the data subject or of another natural person;

e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that that

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 6/11

the interests or fundamental rights and freedoms of the data subject that require protection of personal data do not prevail over said interests,
particularly when the data subject is a child.

The provisions of letter f) of the first paragraph shall not apply to the processing carried out by public authorities in the exercise of their functions."

Consequently, and in accordance with the transcribed provision, the processing of personal data

requires the existence of a legal basis that legitimizes it.

Taking the foregoing into account, according to the facts described in the background, the respondent allegedly transmitted personal data corresponding to the claimant—at least his name, surname, and email address—to a third party,

GESTORIA DE SUBVENCIONES SL, without having a legal basis to do so.

Thus, as recorded in the file and reflected in the background information, the complainant received several emails in which GESTORIA DE SUBVENCIONES SL contacted them to continue the subsidy management service initiated by the respondent. It should be noted that, although the first email sent by GESTORIA DE SUBVENCIONES SL on April 8, 2024, already echoed the respondent's bankruptcy situation, the formal communication by the respondent of its pre-insolvency status occurred the following day, on April 9, 2024. Therefore, GESTORIA DE SUBVENCIONES SL had the complainant's data, as it had been provided by the respondent, even before the respondent communicated with its clients, including the complainant. As evidenced in subsequent communications between the complainant and GESTORIA DE SUBVENCIONES SL, in response to the complainant's question about the source of his data, the complainant stated the following: As I mentioned, we worked with Green Solutions and provided some grants for their clients (around 300-400) when they were more strapped for work. We had a shared list of all the clients, and from there they assigned us the ones we were to manage. This is where we get the data for the rest of the clients we do not manage.

Therefore, it is clear that the respondent provided the complainant's data—at least his first name, last name, and email address, and possibly other data related to the management of the contracted grant, such as his ID—to a third party, in this case, GESTORIA DE SUBVENCIONES SL.

At this point, it should be noted that the data being processed would be those necessary for processing the specific grant application, and among them would presumably also include the DNI (National Identity Document). It is important to note that the email sent to the claimant on April 8, 2024 by GESTORIA DE SUBVENCIONES SL states that they can check the status of their grant using their DNI (National Identity Document) at https://gestion.ayudasrenovablesmadrid.com/ (...). Therefore, the DNI (National Identity Document), which could be used to identify the grant application to the grantor, would also be one of the data required to initiate the grant processing. According to this evidence, the processing of this data, consisting of the transfer to a third party, was carried out without any legal basis for doing so.

Therefore, the known facts are considered to constitute an infringement, attributable to the respondent, for violation of Article 6.1 of the GDPR.

III
Classification of the violation of Article 6.1 of the GDPR and classification for the purposes of limitation

The violation attributed to the respondent is classified in Article

83.5 a) of the GDPR, which considers that the violation of "the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9" is punishable, in accordance with paragraph 5 of the aforementioned Article 83 of the aforementioned Regulation, "with administrative fines of up to €20,000,000 or, in the case of a company, an amount equivalent to up to 4% of the total global annual turnover of the preceding financial year, whichever is higher."

Article 71 of the LOPDGDD (Organic Law on the Protection of Personal Data), on Infractions, states that: "Infractions constitute the acts and conduct referred to in sections 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law."

And in its Article 72, it considers the following for the purposes of statute of limitations: “Infractions considered very serious:

1. In accordance with the provisions of Article 83.5 of Regulation (EU) 2016/679, the following are considered very serious and will be subject to a three-year statute of limitations:

infractions that constitute a substantial violation of the articles mentioned therein, and in particular, the following:

(…)
b) The processing of personal data without any of the conditions for the lawfulness of processing established in Article 6 of
Regulation (EU) 2016/679. (…)
IV
Sanction

In order to establish the administrative fine to be imposed, the provisions contained in Articles 83.1 and 83.2 of the GDPR must be observed, which state:

“1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article for infringements of this Regulation referred to in paragraphs 4, 5 and 6 are, in each individual case, effective, proportionate, and dissuasive.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 8/11

2. Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or as a substitute for the measures referred to in Article 58(2)(a) to (h) and (j). When deciding on the imposition of an administrative fine and its amount in each individual case, due account shall be taken of:

(a) the nature, gravity, and duration of the infringement, taking into account the
nature, scope, or purpose of the processing operation concerned, as well as the number of data subjects affected and the level of damage and/or harm suffered by them;
b) the intentionality or negligence of the breach;
c) any measures taken by the controller or processor to mitigate the damage suffered by the data subjects;
d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures they have implemented pursuant to Articles 25 and 32;
e) any previous breaches committed by the controller or processor;
f) the degree of cooperation with the supervisory authority to remedy the breach and mitigate any adverse effects of the breach;

g) the categories of personal data affected by the breach;
h) how the supervisory authority became aware of the breach, in particular whether the controller or processor notified the breach and, if so, to what extent;
(i) where the measures referred to in Article 58(2) have been previously ordered against the controller or processor concerned in relation to the same matter, compliance with those measures; (j) adherence to codes of conduct pursuant to Article 40 or certification mechanisms approved pursuant to Article 42; and (k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement. In relation to letter k) of Article 83.2 of the GDPR, the LOPDGDD, in its Article 76, "Sanctions and Corrective Measures," establishes that:

"2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account:

a) The continuous nature of the infringement.
b) The connection between the offender's activity and the processing of personal data.

c) The benefits obtained as a result of the infringement.
d) The possibility that the affected party's conduct could have led to the infringement.
e) The existence of a merger by absorption process subsequent to the infringement, which cannot be attributed to the acquiring entity.
f) The impact on the rights of minors.
g) The availability of a data protection officer, when not mandatory.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 9/11

h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms in those cases where there are disputes between them and any interested party."

In accordance with the provisions transcribed, for the purposes of determining the amount of the sanction to be imposed in this case for the violation of Article 6.1 of the GDPR, classified in Article 83.5.a) of the GDPR, for which the respondent is held responsible, the following circumstances are deemed to be present:

- The nature, severity, and duration of the violation, taking into account the

nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damages and losses they have suffered. In this regard, it should be noted that the facts revealed affect a basic principle regarding the processing of personal data, namely the lawfulness of processing, which the law imposes the most severe penalties. Furthermore, and according to the case file, the defendant likely routinely transferred the data of the individuals for whom it managed grants without any evidence of legal grounds for doing so. In this regard, what GESTORIA DE SUBVENCIONES SL stated is significant: "We worked with Green Solutions and granted some grants to their clients (around 300-400) when they were most strapped for work. We had a shared list of all the clients, and from there they assigned us the ones we were to manage. This is where we obtained the data of the remaining clients that we did not manage. These statements suggest that the number of people affected by these unlawful processing operations is high." - The intentionality or negligence in the infringement. According to the
file, the transfer of data to third parties without a legitimate basis was a practice that could be described as "common," and GESTORIA DE
SUBVENCIONES SL even claims the existence of a shared list of all clients. This statement suggests what would be a common practice in the

business of the respondent.

- The activity of the allegedly infringing entity is linked to the processing of personal data of both clients and third parties.

In the activity of the respondent entity, and specifically, within the scope of the processing operations that are the subject of this sanctioning procedure, the processing of personal data is essential since they relate to grant management procedures.

- The categories of personal data affected by the infringement.

The facts that initiated this sanctioning procedure relate

to a grant management procedure, and therefore, the personal data provided to a third party by the respondent without, allegedly,
legal grounds are all necessary for the aforementioned grant processing. It should be noted that the email sent to the complainant on
04/08/2024 by GESTORIA DE SUBVENCIONES SL states that

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 10/11

You can check the status of your grant with your ID at
https://gestion.ayudasrenovablesmadrid.com/ (...). Therefore, the DNI, which could be used to identify the requested subsidy to the granting Administration, would be one of the necessary data to initiate the subsidy process and, therefore, one of the data that was transmitted without any legal basis by the respondent.

In light of the facts presented, it is considered appropriate to impose a penalty on the respondent for the violation of Article 6.1 of the GDPR, as defined in Article 83.5.a) of the GDPR, in the amount of €10,000.00.

Therefore, in accordance with applicable legislation and having assessed the criteria for the grading of sanctions whose existence has been proven, the Presidency of the Spanish Data Protection Agency RESOLVES:

FIRST: TO IMPOSE a fine of €10,000.00 on ADNAYA GREEN SOLUTIONS, S.L., with Tax Identification Number (NIF) B86998812,
for a violation of Article 6.1 of the GDPR, as defined in Article 83.5.a) of the GDPR.

SECOND: NOTIFY this resolution to ADNAYA GREEN SOLUTIONS, S.L.

THIRD: This resolution will become enforceable once the deadline for filing an optional appeal for reconsideration expires (one month from the day following notification of this resolution) without the interested party having exercised this right.
The sanctioned party is hereby notified that they must pay the imposed sanction once this resolution becomes enforceable, in accordance with the provisions of Article 98.1.b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), within the voluntary payment period established in Article 68 of the General Collection Regulations, approved by Royal Decree 939/2005, of July 29, in relation to Article 68 of the General Regulation on Tax Collection. 62 of Law 58/2003, of December 17, by depositing the fine, indicating the sanctioned party's NIF (Tax Identification Number) and the procedure number shown in the heading of this document, into the restricted account IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX), opened in the name of the Spanish Data Protection Agency at CAIXABANK, S.A. Otherwise, collection will be carried out during the enforcement period.

Once the notification has been received and enforced, if the enforcement date is between the 1st and 15th of each month, inclusive, the deadline to make the voluntary payment will be the 20th of the following month or the next business day after, and if it is between the 16th and last day of each month, inclusive, the payment deadline will be the 5th of the second following month or the next business day after.

In accordance with the provisions of Article 50 of the LOPDGDD (Spanish Organic Law on the Protection of Personal Data), this Resolution will be made public once it has been notified to the interested parties.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 11/11

Against this resolution, which terminates the administrative process pursuant to Art. 48.6 of the LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, interested parties may optionally file an appeal for reconsideration before the President of the Spanish Data Protection Agency within one month from the day following notification of this resolution, or directly file an administrative appeal before the Administrative Litigation Division of the National Court, in accordance with the provisions of Article 25 and Section 5 of the Fourth Additional Provision of Law 29/1998, of July 13, regulating the Administrative Litigation Jurisdiction, within two months from the day following notification of this decision, as provided for in Article 46.1 of the aforementioned Law.

Finally, it is noted that pursuant to the provisions of Art. 90.3 a) of the LPACAP (Spanish Data Protection Act), a final administrative decision may be provisionally suspended if the interested party expresses their intention to file an administrative appeal.

If this is the case, the interested party must formally notify this fact in writing to the Spanish Data Protection Agency, submitting it through the Agency's Electronic Registry [https://sedeaepd.gob.es/sede-electronica-web/], or through one of the other registries provided for in Article 16.4 of the aforementioned Law 39/2015, of October 1. They must also forward to the Agency the documentation proving the effective filing of the administrative appeal. If the Agency does not become aware of the filing of the administrative appeal within two months from the day following notification of this resolution, it will terminate the provisional suspension.

938-100325
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es