AEPD (Spain) - PS-00020-2025: Difference between revisions
No edit summary |
m Fixed link |
||
| Line 11: | Line 11: | ||
|Original_Source_Name_1=AEPD | |Original_Source_Name_1=AEPD | ||
|Original_Source_Link_1=https://www.aepd.es/documento/ps- | |Original_Source_Link_1=https://www.aepd.es/documento/ps-00020-2025.pdf | ||
|Original_Source_Language_1=Spanish | |Original_Source_Language_1=Spanish | ||
|Original_Source_Language__Code_1=ES | |Original_Source_Language__Code_1=ES | ||
Latest revision as of 09:54, 16 July 2026
| AEPD - PS-00020-2025 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 5(1)(f) GDPR Article 35 GDPR Article 58(2) GDPR |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | |
| Decided: | |
| Published: | 01.07.2026 |
| Fine: | 200,000 EUR |
| Parties: | Alkora S.A.U. |
| National Case Number/Name: | PS-00020-2025 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Spanish |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | bms |
The DPA fined an insurance broker €200,000 after a ransomware attack exposed data of around 40,000 people. The DPA found that the broker implemented insufficient security measures and failed to carry out a DPIA.
English Summary
Facts
Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices.
The controller first estimated that 25,000 persons were affected. It later stated that the incident had affected around 40,000 persons, including 75 minors. The incident affected confidentiality, availability and integrity. The attacker encrypted systems and exfiltrated between 3.5 and 4 TB of information from the document management server.
The affected data included identification and contact data, ID numbers, dates of birth, financial and insurance data, bank account numbers, health data, employee data and access credentials. The controller also processed data relating to minors in accident claims. A data subject complained to the DPA after being informed that their personal data had been exposed. The data subject was concerned about identity theft and requested additional information from the controller.
During the investigation, the DPA found that the controller had known that its IT systems faced an extreme cybercrime risk before the breach. The forensic report could not determine the initial entry point because the servers had been encrypted, but it showed that attackers could move laterally through the infrastructure, obtain privileged access, install tools, exfiltrate data and encrypt systems.
The controller had carried out a risk analysis in 2019, but this document concluded that no DPIA was necessary. After the breach, a later analysis found that a DPIA was necessary for treatments involving health data and minors. The controller did not prove that it had carried out the required DPIA.
Holding
The DPA held that the controller violated Article 5(1)(f) GDPR. It considered that the controller had failed to ensure the integrity and confidentiality of the personal data under its responsibility. The DPA emphasised that the principle in Article 5(1)(f) GDPR is not limited to the existence of isolated security measures. Rather, the controller must implement adequate technical and organisational measures capable of ensuring that personal data is protected against unauthorised or unlawful processing, loss, destruction or damage.
The DPA rejected the controller’s argument that the attack was an external criminal act that could not be attributed to it. The DPA found that the controller was aware of an extreme cyber risk and that its internal vulnerabilities and security posture allowed the attackers to move through the systems, access personal data and encrypt files. The DPA therefore considered that the controller’s measures were clearly insufficient.
The DPA also held that the controller violated Article 35 GDPR. The controller processed high-risk categories of data, including health data and data concerning minors. In these circumstances, it should have carried out a DPIA before the processing. The DPA found that the controller’s 2019 risk analysis wrongly concluded that no high risk existed, while its later documentation acknowledged that a DPIA was necessary.
The DPA proposed a fine of €150,000 for the infringement of Article 5(1)(f) GDPR and €100,000 for the infringement of Article 35 GDPR, totalling €250,000. The controller paid voluntarily without acknowledging liability, obtaining a 20% reduction under Spanish Administrative Law (39/2015). The final payable amount was therefore €200,000.
The DPA also ordered the controller, under Article 58(2)(d) GDPR, to prove within three months from the enforceability of the decision that it had carried out the mandatory DPIA required under Article 35 GDPR.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.
Case No.: EXP202400624 DECISION TO TERMINATE THE PROCEEDINGS DUE TO VOLUNTARY PAYMENT Regarding the proceedings conducted by the Spanish Data Protection Agency and based on the following BACKGROUND FIRST: On April 15, 2025, the Presidency of the Spanish Data Protection Agency decided to initiate disciplinary proceedings against ALKORA EBS CORREDURIA DE SEGUROS Y REASEGUROS SAU (hereinafter, ALKORA). Following notification of the decision to initiate proceedings and after analyzing the arguments submitted, a proposed resolution was issued on February 16, 2026, the text of which is transcribed below: << Case No.: EXP202400624 PROPOSED RESOLUTION ON DISCIPLINARY PROCEEDINGS Regarding the proceedings conducted by the Spanish Data Protection Agency and based on the following: Contents BACKGROUND..................................................................................................................3 FIRST: On April 22, 2023, this Agency was notified of a data breach involving ALKORA EBS CORREDURIA DE SEGUROS Y REASEGUROS SAU, with Tax ID No. A01051747 (hereinafter, ALKORA) .............................................................................................3 SECOND: On December 27, 2023, a complaint was filed with the Spanish Data Protection Agency regarding the previously reported data breach of personal data...........5 THIRD: Pursuant to Article 65.4 of Organic Law 3/2018, of December 5, on Data Protection and the Guarantee of Digital Rights (hereinafter LOPDGDD), said complaint was forwarded to ALKORA so that it could analyze it and inform this Agency, within one month, of the actions taken to comply with the requirements set forth in data protection regulations .......................................................................................................................................7 FOURTH: On March 27, 2024, in accordance with Article 65 of the LOPDGDD, the complaint was accepted for processing ....................................................................................20 6 Jorge Juan Street, 28001 – Madrid2/76 www.aepd.es sedeaepd.gob.es FIFTH: The Subdirectorate General for Data Inspection conducted preliminary investigative proceedings to clarify the facts in question, pursuant to the functions assigned to supervisory authorities under Article 57.1 and the powers granted under Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VIII of the LOPDGDD ........................................................................................................................................................20 Origin and Development of the Data Breach.......................................................................21 Number of individuals affected: .............................................................................................22 Types of data:...........................................................................................................................23 Risk Analysis and Impact Assessment (RA and IIA)..........................................................28 Technical security measures prior to a breach ...................................................................29 Reactive technical measures: ................................................................................................33 Training activities related to personal data protection: ......................................................34 Organizational measures following the breach ...................................................................35 SIXTH: On April 15, 2025, the Presidency of the Spanish Data Protection Agency agreed to initiate sanctioning proceedings against the respondent, in accordance with the provisions of Articles 63 and 64 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), for the alleged violation of Article 5.1.f) of the GDPR and Article 35 of the GDPR, as defined in Article 83.5 of the GDPR and Article 83.4 of the GDPR, respectively.................................35 SEVENTH: After being notified of the aforementioned decision to initiate proceedings in accordance with the provisions of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), on May 6, 2025, ALKORA filed a written statement of defense in which, in summary, it stated that ........................................................................................................................................................36 EIGHTH: On October 17, 2025, an expert report submitted by ALKORA was received, in accordance with what was announced in its written statement of defense regarding the decision to initiate disciplinary proceedings.............................................................................36 NINTH: According to the report retrieved from the AXESOR tool on February 8, 2026, ALKORA is an enterprise incorporated in 1989, with a turnover of 24,007,236 euros in 2024................................................................................................................................................36 TENTH: A list of the documents on file in the proceedings is attached as an annex .......36 PROVEN FACTS ..............................................................................................................................36 LEGAL GROUNDS ..........................................................................................................................46 I Jurisdiction...................................................................................................................................46 II Preliminary Issues ....................................................................................................................47 III Objections to the Decision to Initiate Proceedings .............................................................48 6 Jorge Juan Street, 28001 – Madrid3/76 www.aepd.es sedeaepd.gob.es IV Breach of Obligation. Integrity and Confidentiality.............................................................63 V Classification of the violation of Article 5.1.f) of the GDPR and determination for the purposes of the statute of limitations ........................................................................................74 VI Proposed sanction for the violation of Article 5(1)(f) of the GDPR..................................74 VII .....Failure to Comply. Data Protection Impact Assessment .........................................................................................................................................................78 VIII Classification of the violation of Article 35 of the GDPR and determination of the statute of limitations .....................................................................................................................85 IX Proposed sanction for the violation of Article 35 of the GDPR ........................................86 X Adoption of measures..............................................................................................................89 PROPOSED RESOLUTION............................................................................................................89 ANNEX ...............................................................................................................................................91 BACKGROUND FIRST: On April 22, 2023, this Agency was notified of a personal data breach involving ALKORA EBS CORREDURIA DE SEGUROS Y REASEGUROS SAU, with Tax ID No. A01051747 (hereinafter, ALKORA). The facts brought to the attention of this authority were as follows: “On Friday, April 21, at the start of the workday, unauthorized access was detected; the perpetrators hacked and encrypted the servers, databases, and email systems, and infected all of the enterprise’s computers. They left a document/note in all users’ folders stating that the systems had been hacked and urging users to contact them via a link. The incident was reported to the police.” “The source of the incident was: External: Others, unrelated to the controller and processor What might have happened? You may select multiple options: Cyberincident: Encrypted device / data hijacking As a result of the incident, the following have been affected: Confidentiality, Availability Specifically regarding the data affected by the breach of confidentiality. Is the data securely encrypted, anonymized, or protected in such a way that it is unintelligible to anyone who may have gained access, or that individuals cannot be identified? No Refers specifically to the data affected by the availability breach. Has the availability of the personal data been restored so that it can be processed normally? Not yet, but it will be restored shortly” “Select the types of data that have been affected…: Basic data (e.g., first name, last name, date of birth), National ID number, Foreign Resident ID number, passport, and/or any other identification document; payment method data (bank card, etc.); 6 Jorge Juan Street, 28001 – Madrid4/76 www.aepd.es sedeaepd.gob.es location data, contact information, health data (exclusively for employees, limited to what is essential for the employment relationship), access or identification credentials (User name and/or password).” “Are there any minors among the affected individuals?: No Are there members of vulnerable groups among the affected individuals, such as survivors of gender-based violence or those at risk of social exclusion?: No The affected individuals fall into the following categories: Customers/Citizens, Subscribers/Prospective Customers, Employees In total, how many people have had their data affected by the personal data breach? (If you do not know the exact number, provide an estimate) 25,000” “Indicate the date the data breach was detected, defined as the date on which the controller became certain that personal data had been compromised: 04/21/2023 Do you know the date the breach began? The exact date: Indicate the start date of the breach: 04/21/2023 The breach was detected through: A report from a member of the controller’s or processor’s organization” “Has the breach been communicated to the affected individuals under the conditions described above? To be decided” “Has the controller designated a DPO? No” On May 17, 2023, this Agency received a second letter from ALKORA with the intention of “amending a previous notification to provide relevant information,” in which the information initially provided remained the same as in the letter dated April 22, 2023, with the exception of: “What might have happened? You may select multiple options: Documentation lost, stolen, or left in an insecure location; Cyber incident: Encrypted device / data hijacking; Cyber incident: Identity theft (phishing) / compromise of User or Administrator account; Cyber incident: Unauthorized access to data in an information system (corporate or online service). As a result of the incident, the following have been affected: Confidentiality, Availability, Integrity” “Specifically regarding the data affected by the integrity breach. Select the most appropriate option: Data altered, but with no evidence of illegal or improper use. What might have happened? You may select multiple options: Identity theft, Falling victim to phishing or spamming campaigns, Loss of control over personal data To what extent could the identified consequences affect individuals? Individuals will not be affected or may experience some very limited and reversible inconveniences that they will overcome without any problem (time spent re-entering information, annoyances, irritations, etc.)” “How do you assess the probability that the aforementioned harm will materialize for the affected individuals with the indicated severity? Low 6 Jorge Juan Street, 28001 – Madrid5/76 www.aepd.es sedeaepd.gob.es * Enter a brief description of what happened... On the night of Thursday, April 20, through Friday, April 21, 2023, ALKORA experienced service interruptions in its local production environment. On Friday, April 21, technical staff encountered an encrypted information system. Both employee workstations and servers were affected. Consequently, all IT services dependent on those servers were unavailable. On April 21, a report was filed with the national police, and the report was expanded the following day to include ALKORA’s subsidiaries among those affected by the cybersecurity incident. The services of ***ENTERPRISE.1 were contracted on April 21 to analyze the scope of the attack and confirm whether a data exfiltration had occurred. The results of the commissioned expert report reveal that the attacker is (...). The encryption of the servers directly impacts the integrity and availability of the enterprise’s systems and applications. Furthermore, the data exfiltration impacts the confidentiality of the enterprise’s sensitive documents, as well as customers’ personal data. The expert report concludes that a TOTAL OF 3.5/4 TB of information has been EXFILTRATED. Those affected have been notified. ALKORA is currently operating at 100% capacity thanks to the restoration of the backup it had outsourced to the cloud.” “Are there minors among the affected individuals? Yes” “Do you know the date the breach began? Approximately / Estimated. Indicate the start date of the breach: 04/16/2023” “Indicate the date the breach was resolved: 05/17/2023” “Has the breach been communicated to the affected individuals under the conditions described above? Yes Date of notification: 04/26/2023 Number of people notified: 25,000 Method of notification: Personal communication sent to each affected individual (postcard, email, text message, or similar)” “Has the controller designated a DPO? Yes” SECOND: On December 27, 2023, a complaint was filed with the Spanish Data Protection Agency regarding the previously reported data breach involving personal data. The facts brought to the attention of this authority were as follows: “… On May 11, 2023, my insurance company, ALKORA, notified me that it had suffered a cyberattack on April 21, 2023, and that it had filed a report and notified the Spanish Data Protection Agency… I was informed that my personal data had been exposed. Concerned that my personal data might be used illegally, I went to the National Police station nearest my home, where I was told that I could not file a report until the crime had actually been committed. I need guidance on how to refute the presumption that I was the one who committed the act, when in reality it was the person who illegally possesses my data (for 6 Jorge Juan Street, 28001 – Madrid6/76 www.aepd.es sedeaepd.gob.es example, to apply for a loan in my name) and that I have been a victim of identity theft resulting from cybersecurity breaches.” Attached to the complaint are the following: - A copy of an email sent on May 24, 2023, by the complainant to ALKORA, with the subject line “Request to File a Security Breach Report” and the following content: “Good morning, Regarding the email received on May 11, 2023 (which I have attached), stating that you had suffered a security breach, and as someone affected by it, I would like to request a copy of the report you filed, to which you refer in the aforementioned letter. I look forward to hearing from you. Sincerely” Below is an email with the following content: “On April 21, ALKORA’s computer systems were the victim of a security breach resulting from an external cyberattack. Upon detecting the breach, we activated all established security mechanisms and protocols, immediately notifying the Spanish Data Protection Authority and filing the corresponding report with the authorities to investigate the incident. Additionally, we notified all customers we were able to reach of this situation; however, in some cases, this was hindered by the encryption of a portion of our database resulting from the cyberattack. Therefore, as soon as we were able to access your data, we contacted you to inform you of this incident. As of today, as part of the ongoing investigations, we can confirm that, in addition to the encryption of your personal data, there has been a data breach involving the Professional Liability insurance policy application forms; consequently, these forms have been compromised or are accessible to unauthorized third parties. In light of this, we strongly recommend that you exercise extreme caution in your day-to-day digital transactions and activities: in particular, be on the lookout for phishing attempts—be wary of suspicious emails, phone calls, and messages that may be attempts to trick you into revealing personal or banking information. We also ask that you report any communication purporting to be from us—whether by phone or email—that does not follow our usual format. As for ALKORA’s operations, we are returning to 100% operational capacity following a few days of mandatory system shutdown to ensure our customers’ security and enable specialized teams to investigate the security breach. You may therefore contact your usual account manager as usual for any transactions. We want to assure you that we are making every effort to resolve this incident as quickly as possible, with full guarantees, and by prioritizing the security of our clients at all times, sparing no expense or resources. We are confident of a prompt resolution of the matter and will strive to maintain open communication with you to keep you informed of any developments in this regard. You may also request, if you wish, 6 Jorge Juan Street, 28001 – Madrid7/76 www.aepd.es sedeaepd.gob.es about this incident via the following email address: seguridad.rcp@alkora.es Sincerely, ALKORA SECURITY” - Copy of an email received on May 25, 2023, by the complainant from ALKORA, in response to the previous message, with the following content: “Good morning, Following the work being carried out by the teams of professionals handling this matter, we can confirm that the document server from which the data exfiltration occurred did not contain any of your documents. On the other servers—for which we cannot confirm that a data breach occurred— the only personal data on record would be your first and last names and your ID number. Regarding your request for a copy of the police report filed, please note that we regret that we cannot comply with your request, as it is a document of confidentiality for the enterprise. However, we are providing you with the address of the police station where the report was filed: ***ADDRESS.1. Sincerely, ALKORA SECURITY” THIRD: In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on Data Protection and the Guarantee of Digital Rights (hereinafter LOPDGDD), said complaint was forwarded to ALKORA so that it could analyze it and inform this Agency, within one month, of the actions taken to comply with the requirements set forth in data protection regulations. The notification of the referral of the complaint, which was carried out in accordance with the provisions of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), was issued on January 15, 2024, as evidenced by the acknowledgment of receipt on file. On February 14, 2024, this Agency received a written response stating: - “(…)” d) Approximately 25,000 individuals were affected, solely at the national level (Spain)” - “They may have been affected; however, as we indicated, the encryption of all servers by (...) has limited our ability to analyze the data: 1. Basic information on individual customers, corporate customers (policyholders, insured parties, beneficiaries), potential customers, and staff: First name, last name, date of birth, National ID number (DNI), Foreign Resident ID number (NIE), passport, and/or any other identification document; economic or financial data (excluding payment methods); contact information; health data (exclusively for employees, limited to what is essential for the employment relationship); and access or identification credentials (User name and/or password). 2. Health data of individual customers with life insurance and/or accident insurance.” 6 Jorge Juan Street, 28001 – Madrid8/76 www.aepd.es sedeaepd.gob.es - “Among the possible consequences for those affected by the data breach, we can highlight potential identity theft and blackmail or extortion.” - “(…).” - The security measures implemented prior to the incident are as follows: (…) AVAILABILITY OF INFORMATION Attached as Annex V is the Risk Analysis conducted on September 19, 2019, from which the security measures referred to in this section are derived.” In this regard, Annex V attached to ALKORA’s letter dated February 14, 2024, stated: (…) - Regarding the copy of the Record of Processing Activities where the incident occurred, ALKORA states: o Regarding “LABOR AND HR”: “Categories of data subjects: Employees” “Identifying data: National ID number or Tax ID number, First and last names, Postal or email address, Phone number, Handwritten signature, Social Security number or mutual insurance number” Special categories of data: Digitized fingerprint (biometric data) Other type of data Characteristics Personal, Academic and professional, Details of employment, Transactions of goods and services.” o Regarding “INSURANCE BROKERAGE FOR INDIVIDUALS”: “Identifying information: ID number or Tax ID number, first and last names, mailing or email address, phone number, handwritten signature Special categories of data: N/A Other types of data: Personal data, academic and professional information, transactions involving goods and services, social circumstances, commercial information, economic, financial, and insurance information” o Regarding “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS”: 6 Jorge Juan Street, 28001 – Madrid9/76 www.aepd.es sedeaepd.gob.es “Identifying data: National ID number (DNI) or Tax ID number (NIF), first and last names, mailing or email address, phone number, handwritten signature Special categories of data: Health Other types of data: Personal data, academic and professional information, transactions involving goods and services, social circumstances, economic, financial, and insurance information” o Regarding “INSURANCE CLAIMS”: “Identifying information: National ID number (DNI) or Tax ID number (NIF), first and last names, mailing or email address, phone number, handwritten signature, image Special categories of data: Health Other types of data: Personal data, academic and professional information, transactions involving goods and services, social circumstances, economic, financial, and insurance information” o Regarding “TAX AND ACCOUNTING”: “Identifying information: ID number or tax ID number, first and last names, mailing or email address, phone number Special categories of data: N/A Other types of data: N/A” - As a result of the incident, the following security measures had already been implemented: • (…) Additionally, at that time, Alkora was in the process of strengthening the security of its systems by implementing the following security measures: • (…) Attached to the written response to the referral is: - Appendix I: Police report dated April 22, 2023 - Appendix II: Notification of the data breach to the AEPD, dated April 22, 2023 - Appendix III: Supplementary notification of the data breach to the AEPD, dated May 17, 2023 - Appendix IV: Notification of the data breach to INCIBE, dated May 18, 2023 - Appendix V: Risk Analysis dated September 19, 2019, from which the security measures referred to in the section on information availability are derived The document attached as Annex V is unsigned; it indicates that it is “Version: 0.1,” dated September 19, 2019, and it contains the following: - Regarding “Filing System 1: EMPLOYMENT AND HR”: 6 Jorge Juan Street, 28001 – Madrid10/76 www.aepd.es sedeaepd.gob.es o It is considered that the identifying data and other specified data subject to processing have an initial risk rating of “Low.” o Regarding “Data Protection (Integrity and Confidentiality),” it states that “There are adequate measures in place to protect the data against unauthorized processing and loss or destruction in accordance with the provisions of this document,” an initial risk of “Medium” is assigned, and the measures detailed are “Ensuring that adequate technical and organizational measures have been implemented to protect the data through the corresponding periodic annual verification,” after which a final risk of “Very low” is assigned. o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data subject rights and freedoms,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “It has been verified that the risk analysis conducted does not identify any threats with a probability of high risk to the data subject rights and freedoms,” after which a final risk of “Low” is assigned. o Regarding “Access to special categories of data,” it is stated that “There are no special categories of data,” and therefore an initial and final risk rating of “Very Low” is assigned. - Regarding “Filing System 2: INSURANCE BROKERAGE FOR INDIVIDUALS”: o It is considered that the identifying data and other specified data subject to processing have an initial risk of “Low.” o Regarding “Data Protection (Integrity and Confidentiality),” it is indicated that “There are adequate measures in place to protect the data against unauthorized processing and loss or destruction, in accordance with the provisions of this document,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “Ensure that adequate technical and organizational measures have been implemented to protect the data through the corresponding periodic annual verification,” after which a final risk of “Very low” is assigned. o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data subject rights and freedoms,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “It has been verified that the risk analysis conducted does not identify any threats with a probability of high risk to the data subject rights and freedoms,” after which a final risk of “Low” is assigned. o Regarding “Access to special categories of data,” it is stated that “There are no special categories of data,” and therefore an initial and final risk rating of “Very Low” is assigned. - Regarding “Filing System 3: LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS”: 6 Jorge Juan Street, 28001 – Madrid11/76 www.aepd.es sedeaepd.gob.es o It is considered that the identifying data and other specified data subject to processing have an initial risk of “Low.” However, health data is assigned an initial risk of “High.” o Regarding “Data Protection (Integrity and Confidentiality),” it is stated that “There are adequate measures in place to protect the data against unauthorized processing and loss or destruction, in accordance with the provisions of this document,” it is assigned an initial risk of “Medium,” and the measures are detailed as follows: “Ensure that adequate technical and organizational measures have been implemented to protect the data through the corresponding periodic annual verification,” after which a final risk of “Low” is assigned o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data subject rights and freedoms,” an initial risk rating of “Medium” is assigned, and the measures detailed are: “It has been verified that the risk analysis conducted does not identify any threats with a probability of high risk to the data subject rights and freedoms,” after which a final risk rating of “Low” is assigned. o Regarding “Access to Special Categories of Data,” it is stated that “There are additional security measures in accordance with the provisions of section 4.4 of this document”; an initial risk rating of “Medium” is assigned, and the measures are detailed as follows: “An up-to-date record must be maintained of personnel with access to special categories of personal data. It is recommended to strengthen these measures with two-factor authentication, encryption…”, after which a final risk rating of “Very low” is assigned. - Regarding “Filing System 4: INSURANCE CLAIMS”: o It is considered that the identifying data and other specified data subject to processing have an initial risk of “Low.” However, health data is assigned an initial risk of “High.” o As for “Data Protection (Integrity and Confidentiality),” it is stated that “There are adequate measures in place to protect the data against unauthorized processing and loss or destruction, in accordance with the provisions of this document,” it is assigned an initial risk of “Medium,” and the measures are detailed as follows: “Ensure that adequate technical and organizational measures have been implemented to protect the data through the corresponding periodic annual verification,” after which a final risk of “Low” is assigned. o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data subject rights and freedoms,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “It has been verified that the risk analysis conducted does not identify any threats with a high probability of risk to the data subject rights and freedoms,” after which a final risk of “Low” is assigned. 6 Jorge Juan Street, 28001 – Madrid12/76 www.aepd.es sedeaepd.gob.es o Regarding “Access to special categories of data,” it is stated that “ADDITIONAL security measures are in place in accordance with the provisions of section 4.4 of this document”; an initial risk rating of “Medium” is assigned, and the measures are detailed as follows: “An up-to-date record must be maintained of personnel with access to special categories of data. It is recommended to strengthen these measures with two-factor authentication, encryption…”, after which a final risk rating of “Very low” is assigned. - Regarding “Filing System 5: TAX AND ACCOUNTING”: o The identifying data subject to processing is considered to have an initial risk of “Low.” o As for “Data Protection (Integrity and Confidentiality),” it is stated that “There are adequate measures in place to protect the data against unauthorized processing and loss or destruction, in accordance with the provisions of this document,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “Ensure that adequate technical and organizational measures have been implemented to protect the data through the corresponding periodic annual verification,” after which a final risk of “Low” is assigned o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data subject rights and freedoms,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “It has been verified that the risk analysis conducted does not identify any threats with a high probability of risk to the data subject rights and freedoms,” after which a final risk of “Low” is assigned. o Regarding “Access to special categories of data,” it is stated that “There are no special categories of data,” and therefore an initial and final risk rating of “Very Low” is assigned. - In section “4.4. SECURITY BY DESIGN AND BY DEFAULT” of the document, the following measures are detailed to ensure data availability: o (…) - “Processing of data on children under 14 years of age” is mentioned as a specific processing activity, indicating that “DATA PROCESSING on children under 14 years of age is carried out only in cases of school accidents”; it is assigned a medium initial risk, and the measures indicated are “Ensure that the measures referred to in section 4.4 are adopted through the corresponding periodic annual verification,” after which a final risk of “Low” is indicated. - In the section on “ORGANIZATION,” it is stated that a data protection officer is not required, “because the enterprise’s main activity] CONSISTS of processing personal data but NOT on a LARGE SCALE, nor is it regulated under Art. 34 of the LOPDGDD.” It is also stated that a data protection officer is not required. 6 Jorge Juan Street, 28001 – Madrid13/76 www.aepd.es sedeaepd.gob.es (DPIA) because “the processing does not pose a high risk to the rights and freedoms of natural persons.” FOURTH: On March 27, 2024, in accordance with Article 65 of the LOPDGDD, the complaint was accepted for processing. FIFTH: The Subdirectorate General for Data Inspection proceeded to conduct preliminary investigative actions to clarify the facts in question, by virtue of the functions assigned to supervisory authorities under Article 57.1 and the powers granted under Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VIII of the LOPDGDD. As a result of the actions taken, the following facts have come to light: Origin and development of the data breach: ALKORA includes in Annex I of its letter dated July 9, 2024, in response to this Agency’s request, the forensic report prepared by the enterprise ***ENTERPRISE.1, Version V 1.0 dated May 3, 2023, unsigned, which states that due to the encryption of the information on the servers, “The method of intrusion, as well as the point of entry, remain undetermined.” That forensic report states that “The encryption of all servers has limited the ability to analyze the data, thereby preventing the collection of evidence regarding the initial intrusion,” and that certain system deficiencies have limited the scope of the forensic analysis: “Several factors have contributed to limiting the investigative capacity of the ***ENTERPRISE.1 team: • (…) However, the forensic report identifies some of the actions carried out by the attacking group following the initial intrusion, consisting of: - access to the messaging management server: “(…)” - reconnaissance from that server to gather information about domain administrators, elevate their User privileges, and move throughout the rest of the system: “(…)” It also indicates that the encryption of the Active Directory domain controllers does not allow for a detailed account of the attacker’s privilege escalation process, but it determines that the following events took place over the next three days: - privilege escalation - access to the local administrator account (…) ***SERVER.1, which grants the highest privileges on the system 6 Jorge Juan Street, 28001 – Madrid14/76 www.aepd.es sedeaepd.gob.es - installation and execution of the program ***PROGRAM.1, despite being blocked twice by ***PROGRAM.2; the attacker manages to conceal their activity and avoid further blocks by the antivirus - installation of the program ***PROGRAM.3 - data exfiltration - encryption of servers and workstations The forensic report also states: “The attackers were able to move freely throughout ALKORA’s infrastructure (…).” “The ransomware is deployed manually on ***SERVER.1 and automatically on the workstations (…).” This Agency wishes to note that, in its letter dated February 14, 2024, in response to the referral of the complaint outlined in the second background section, ALKORA stated that recovery efforts began on April 25, database recovery took place between April 26 and 30, and that its systems were brought back online between April 27 and May 26, 2023. Number of people affected: In Annex II of its letter dated July 9, 2024, in response to a request from this Agency, ALKORA provides the emails exchanged with INCIBE, to which it reported on May 18, 2023, the exfiltration of between 3.5 and 4 TB of data, although it does not specify what portion of that volume corresponds to personal data. Among other documents, a copy of an email dated May 18, 2023, from ALKORA toincidencias@incibe-cert.es is provided, with the following content: “Good afternoon, We hereby wish to inform INCIBE of the security breach detected at ALKORA EBS CORREDURIA DE SEGUROS Y REASEGUROS SAU (and its subsidiaries SANCHEZ CASTAÑON S.L. and VERSPIEREN AGENCIA DE SUSCRIPCION SAU) on April 21. (…) … the threat involves both the total loss of said data and its sale and disclosure. The encryption of the servers directly impacts the integrity and availability of the enterprise’s systems and applications. Furthermore, the data exfiltration compromises the confidentiality of the enterprise’s sensitive documents, as well as customers’ personal data. All of ALKORA’s servers and systems were affected by the attack. The expert report concludes that a TOTAL OF BETWEEN 3.5 AND 4 TB of information has been EXFILTRATED—that is, all the information that was on the document management server. (…) As of the date of this writing, ALKORA is operating at 100% capacity thanks to the restoration of the backup it had outsourced to the cloud.” In the data breaches submitted to this Agency on April 22 and May 17, 2023, ALKORA stated: - that it had suffered a breach of confidentiality, availability, and integrity due to a cyberattack; 6 Jorge Juan Street, 28001 – Madrid15/76 www.aepd.es sedeaepd.gob.es - that the affected activity involved the processing of data belonging to approximately 25,000 individuals, including minors; - that the data was not encrypted. Subsequently, in its letter dated July 9, 2024, ALKORA raised the approximate number of affected individuals to 40,000: “The total number of individuals affected by the breach of which we are aware is around 40,000. Initially, following the breach, the number of affected individuals was estimated at 25,000, as information from the databases was unavailable due to their unavailability. Once the databases were gradually restored, we were able to determine that a larger number of people were affected. We then proceeded to notify those affected of the breach either directly or, in the case of group policies, through the policyholders, using the channels mentioned in this letter. Data on minors is processed solely in connection with the handling of accident claims, which were stored in PDF files in network folders on the server but are not recorded in Alkora’s databases; Over the past four years, Alkora has processed only 75 accident claims, which include only the minor’s first name, last name, date of birth, and general information about the circumstances of the accident.” When asked about the number of minors affected, ALKORA reiterated in its letter dated December 23, 2024, in response to a request from this Agency: “[…] these files were stored as PDFs in network folders on the server but were not recorded in Alkora’s databases. Over the past four years, Alkora EBS Correduría de Seguros y Reaseguros, S.A.U. has processed only 75 accident claims, representing a total of 75 minors affected by the data breach […]” Types of data: In its letter dated February 14, 2024, in response to the referral of the complaint, ALKORA stated that the types of personal data affected were: “1. Basic data of individual customers, corporate customers (policyholders, insured parties, beneficiaries), potential customers, and staff: First name, last name, date of birth, National ID number, Foreign Resident ID number, passport, and/or any other identification document; economic or financial data (excluding payment methods); contact information; health data (exclusively for employees, limited to what is essential for the employment relationship); and access or identification credentials (User name and/or password). 2. Health data of individual customers with life insurance and/or accident insurance policies.” ALKORA provided, as a Risk Analysis (RA), in Annex V of its letter dated February 14, 2024, the document “RISK ANALYSIS OF ALKORA EBS CORREDURÍA DE SEGUROS, S.A.U. BASED ON REGULATION (EU) 2016/679,” 6 Jorge Juan Street, 28001 – Madrid16/76 www.aepd.es sedeaepd.gob.es dated September 19, 2019, which included the RAT (Record of Processing Activities), detailing five “filing systems”: Filing system No. Name Data Subjects Purposes 1 LABOR AND HR - Employees - Human Resources - Payroll Management - Work Hours Tracking and Monitoring 2 INSURANCE BROKERAGE FOR INDIVIDUALS - Policyholder - Insured - Beneficiary - Economic, financial, and insurance services - Advertising and Business Development 3 LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS - Policyholder - Insured - Beneficiary - Economic, financial, and insurance services - Advertising and Business Development 4 INSURANCE CLAIMS - Insured - Claims processing and tracking - Social assistance management 5 TAX AND ACCOUNTI NG - Clients and users - Suppliers - Client management, accounting, tax, and administrative matters When asked about the types of data included in the generic terms “Personal Characteristics” and “Social Circumstances” used in the RAT, ALKORA provided details in its letter dated July 9, 2024: “We have provided tables breaking down the types of data related to personal data and social circumstances for each of the filing systems in the submitted RAT: EMPLOYMENT AND HR Other Types of Data Personal characteristics: marital status, family, date of birth, place of birth, age, sex, nationality INSURANCE BROKERAGE FOR INDIVIDUALS Other types of data Personal : date of birth, age. Social circumstances: housing characteristics, residence, property, and possessions (only for home insurance) LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS 6 Jorge Juan Street, 28001 – Madrid17/76 www.aepd.es sedeaepd.gob.es Other types of data Personal : date of 6 Jorge Juan Street, 28001 – Madrid18/76 www.aepd.es sedeaepd.gob.es birth, place of birth, age, gender, nationality. INSURANCE CLAIMS Other types of data Personal characteristics: marital status, family, date of birth, place of birth, age, sex, nationality. Social circumstances: characteristics of housing, residence, property, and possessions (only in the case of home insurance) 3.2. Processing operations involving bank account numbers of customers, potential customers, and employees Bank account numbers are included only in the following processing activities: • Payment of payroll and personnel expenses: “Labor and HR” filing system • Customer collections: “Tax and Accounting” filing system. 3.3. Processing operations, if any, that include information on bank cards: Alkora only uses duly authorized corporate cards for the payment of living expenses, transportation, and/or corporate travel (the “Labor and HR” filing system+). There are no other processing operations.” Based on ALKORA’s statements in Annex V (Risk Analysis of September 19, 2019) of its letter dated February 14, 2024, and on the statements in its letter dated July 9, 2024, it appears that its data processing activities included at least the following types of data: - National ID Number or Tax ID Number (all filing systems) - First and last names (all filing systems) - Mailing or email address (all filing systems) - Phone number (all filing systems) - Image (filing system “INSURANCE CLAIMS”) - Handwritten signature (“LABOR AND HR”; “INSURANCE BROKERAGE FOR INDIVIDUALS”; “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS”; “INSURANCE CLAIMS” filing systems) - Social Security or mutual insurance number (filing system “LABOR AND HR”) - Health (filing systems “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS”; “INSURANCE CLAIMS”) - Marital status (filing systems “EMPLOYMENT AND HR”; “INSURANCE CLAIMS”) - Family (filing systems “EMPLOYMENT AND HR”; “INSURANCE CLAIMS”) - Date of Birth (filing systems “EMPLOYMENT AND HR”; “INSURANCE BROKERAGE FOR INDIVIDUALS”; “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS”; “INSURANCE CLAIMS”) 6 Jorge Juan Street, 28001 – Madrid19/76 www.aepd.es sedeaepd.gob.es - Place of birth (filing systems “EMPLOYMENT AND HR”; “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS”; “INSURANCE CLAIMS”) - Age (filing systems “LABOR AND HR”; “INSURANCE BROKERAGE FOR INDIVIDUALS”; “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS”; “INSURANCE CLAIMS”) - Gender (filing systems “LABOR AND HR”; “INSURANCE BROKERAGE FOR LIFE AND ACCIDENT INSURANCE FOR INDIVIDUALS”; “INSURANCE CLAIMS”) - Nationality (filing systems “LABOR AND HR”; “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS”; “INSURANCE CLAIMS”) - Characteristics of lodging, housing, properties, and possessions in home insurance (filing systems “INSURANCE BROKERAGE FOR INDIVIDUALS,” “INSURANCE CLAIMS”) - Academics and Professionals (filing systems “EMPLOYMENT AND HR”; “INSURANCE BROKERAGE FOR INDIVIDUALS”; “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS”) - Commercial information (filing systems “INSURANCE BROKERAGE FOR INDIVIDUALS”; “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS”) - Employment details (filing systems “LABOR AND HR”; “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS”; “INSURANCE CLAIMS”) - Economic, financial, and insurance filing systems (filing systems: “LABOR AND HR”; “INSURANCE BROKERAGE FOR INDIVIDUALS”; “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS”; “INSURANCE CLAIMS”) - Bank account number (filing systems “LABOR AND HR,” “TAX AND ACCOUNTING”) - Corporate bank card numbers (“LABOR AND HR” filing system) The aforementioned Risk Analysis indicated that the following “SPECIFIC PROCESSING” was carried out (p. 64): - Concept: “Processing of data on children under 14 years of age” – Application: “Data on children under 14 years of age is processed only in the event of school- related claims” Regarding the processing of minors’ data, ALKORA stated in its letter dated July 9, 2024: “Data on minors is processed solely in the handling of accident claims […] which include only the minor’s first name, last name, date of birth, and general information regarding the circumstances of the accident.” On page 415 of Annex VII of the letter dated July 9, 2024, a copy is attached of a presentation on a data protection and information security training session conducted in 2024 by ALKORA, which included the following: 6 Jorge Juan Street, 28001 – Madrid20/76 www.aepd.es sedeaepd.gob.es “What personal data does Grupo Alkora process as the ‘Controller’? • Individual customers: National ID number or Tax ID number, first and last names, contact information (address, phone number, email), signature, personal and professional characteristics, social circumstances, commercial, economic, financial, and insurance information, and health-related data (life and accident insurance).” Meanwhile, on page 22 of Annex I to ALKORA’s brief dated July 9, 2024, the forensic report dated May 3, 2023, stated: “Analysis of lateral movement during the attack period has shown that the attackers were able to move freely throughout the entire information system by compromising privileged accounts, such as domain administrators.” And on page 33 of that same report: “The encryption of the servers directly impacts the integrity and availability of the enterprise’s systems and applications. Furthermore, the exfiltration of data impacts the confidentiality of the enterprise’s sensitive documents, as well as customers’ personal data.” “The integrity and availability of all systems and services have been impacted.” In ALKORA’s 2024 training activities, on page 415 of Annex VII of its submission dated July 9, 2024, the processing of personal data was mentioned: “Individual customers: National ID number or Tax ID number, first and last names, contact information (address, phone number, email), signature, personal and professional characteristics, social circumstances, commercial, economic, financial, and insurance information, and health-related data (life and accident insurance).” As mentioned above: - The RAT provided as Annex V to the letter dated February 14, 2024, in response to the referral of the complaint, listed five “filing systems” processed by ALKORA. - The postal or email address and telephone number appeared in all “filing systems,” 1 through 5. - The signature appeared in the filing systems 1 through 4. - ALKORA stated in its letter dated July 9, 2024, that the checking account number was included in the filing system 5 for the purpose of collecting payments from customers. The claimant stated in the complaint that she was a client of ALKORA, which implies that she must have been an insured party, policyholder, or beneficiary—or all of the above— from which it follows that she must have been included in at least one of the “filing systems” 2 (insurance brokerage for individuals) or 3 (life and accident insurance brokerage for individuals), in addition to being included in File 5 (tax and accounting). From Annex I of ALKORA’s submission dated July 9, 2024, which includes the forensic report dated May 3, 2023 (pages 22 and 33 of the document, including all annexes), it follows that 6 Jorge Juan Street, 28001 – Madrid21/76 www.aepd.es sedeaepd.gob.es the data breach affected customers’ personal data and that the attackers gained access to all of it. Along with the complaint, the complainant provided the email she sent to ALKORA on May 24, 2023, in which she stated that she received notification of the breach on May 11 and requested a copy of the police report mentioned therein. ALKORA responded the following day, denying the request for a copy of the police report (although it provided the report number) and further stated: “Following the work being carried out by the teams of professionals handling this matter, we can confirm that there were no documents belonging to you on the document server from which the data exfiltration occurred. On the other servers—for which we cannot confirm that a data breach occurred—the only personal data on record would be your first and last names and your national ID number.” From the information extracted from Annex V of the response to the referral of the complaint and from its letter dated July 9, 2024, and its annexes, it can be inferred that the breach may have affected the other types of data included in both the “filing system” and the “file” 2 and 3, and at least, among other things, the complainant’s signature, phone number, mailing address and/or email address, and bank account number—and not just her first and last names and ID number, as ALKORA informed her on May 25, 2023. Risk Analysis and Data Protection Impact Assessment (R&DPIA): As mentioned above, filing systems numbers 3 and 4 involved the processing of health data, and filing systems numbers 1 and 5 involved the processing of bank account numbers. The Risk Analysis provided as Annex V to the letter dated February 14, 2024, in response to the referral of the complaint, lists, among others, the following sections under “REGULATORY COMPLIANCE” (file number in parentheses): Security Policy (1; 2; 3; 4; 5) - Processing Risks: “The processing has been analyzed, and there is no likelihood of a high risk to the data subject rights and freedoms.” Security Policy (3; 4) - Impact Assessment: “The processing has been analyzed in accordance with the Report on the Need to Conduct an Impact Assessment, and there is no likelihood of a high risk to the data subject rights and freedoms.” The “ORGANIZATION” section of the aforementioned Risk Analysis stated: “[A DPIA is not required because] the processing does not pose a high risk to the rights and freedoms of natural persons.” 6 Jorge Juan Street, 28001 – Madrid22/76 www.aepd.es sedeaepd.gob.es ALKORA also provides, as Annex III to its letter dated July 9, 2024 (pages 52–119 of the document including all annexes), an unsigned Risk Analysis (RA), version 2.0 dated November 1, 2023, which was prepared after the data breach, in which it reclassifies the initial and final risks for filing systems 3 and 4—which involve the processing of health data—as “High”; this RA maintains the initial and final risks associated with the processing of filing systems 1 and 5—which include banking data—as “Medium” and “Low,” respectively. This new AR also mentions the need to conduct a Data Protection Impact Assessment (DPIA) for files 3 and 4. ALKORA also provides, as Annex IV to its letter dated July 9, 2024 (pages 120–130 of the document containing all annexes), an unsigned report, version 2.0 dated November 1, 2023, on the need to conduct impact assessments, which concludes that such assessments are necessary for the “Health and Life Insurance Brokerage” and “Claims” filing systems due to the processing of special categories of data and data on vulnerable groups: “Conclusions: At least two of the criteria established in the AEPD’s list of processing activities are met in the “Health and Life Insurance Brokerage” and “Claims” filing systems, as they involve data on vulnerable groups, such as minors, as well as special categories of data—‘health data’—therefore making it necessary to conduct a Data Protection Impact Assessment on the aforementioned processing activities, as they could pose a high risk to the data subject rights and freedoms. Likewise, Alkora prepared a report on the need to appoint a data protection officer, in which it analyzed whether or not large-scale processing of personal data is taking place; the analysis was inconclusive due to the lack of clarity in the criteria established by WP 243. However, since at least two of the AEPD’s criteria are already met, we consider it necessary to conduct a Data Protection Impact Assessment (DPIA) regarding the processing of minors’ data and health data in the relevant filing systems.” There is no record in this case file that ALKORA provided this Agency with the aforementioned DPIA reports. Technical security measures prior to the breach: ALKORA submitted, as Annex V to its brief dated July 9, 2024 (pp. 131–221 of the document including all annexes), an unsigned internal audit report on its information systems, version v0.04 dated February 20, 2022 (prior to the breach). The IT services risk assessment table in that report, on page 194, indicated an “Extreme” risk (marked in red) for the information systems and web portals with respect to cybercrimes. It follows from that report that ALKORA: - Due to (…). - Relyed on the protection (…). - Did not consider it a source of risk (…). - Considered it sufficient (…). - Created virtual servers (…). - I considered the installed antivirus software (…). 6 Jorge Juan Street, 28001 – Madrid23/76 www.aepd.es sedeaepd.gob.es - I considered the solutions adopted (…) to be adequate: “(…)” - I considered that no significant improvements could be made in (…). - It had a (…) service which, according to the forensic report (Annex I of ALKORA’s brief dated July 9, 2024), was not effective. The internal audit report provided as Annex V to ALKORA’s brief dated July 9, 2024 (page 167 of the document including all annexes), stated: (…) Regarding the antivirus software, the forensic report submitted as Annex I to ALKORA’s brief dated July 9, 2024 (pp. 2–44 of the document containing all annexes), indicated that the ***PROGRAMA.2 antivirus software that was installed did not issue any alerts during the encryption of at least one of the workstations. The recommendations in the aforementioned forensic report revealed that ALKORA could have implemented additional measures, which are described on pages 35 through 37 of the document including all annexes, and which the report recommends be adopted as a “High” priority: - (…) In addition, the forensic report recommends the adoption of twenty-two other measures, which it classifies as “Medium” and “Low” priorities. ALKORA also provides, as Annex V b of its submission dated July 9, 2024 (pages 222–318 of the document including all annexes), an unsigned “pentesting” (penetration testing of its computer system) audit report, Version 1.0, dated July 9, 2024. The penetration test, conducted by ***SISTEMA.1, revealed that: “The security audit revealed a number of vulnerabilities and weaknesses which, when jointly exploited, would enable the entire domain to be compromised by gaining domain Administrator privileges, with access only to the internal network.” (unofficial translation: “The security audit revealed a series of vulnerabilities and weaknesses that, when exploited together, would have allowed the entire domain to be compromised by obtaining domain administrator privileges, with access only to the internal network”). Section 3.4 of Annex V b (password audit) stated that (…) The aforementioned audit highlighted eight “high” severity vulnerabilities: - (…) And 10 “medium” vulnerabilities: - (…) 6 Jorge Juan Street, 28001 – Madrid24/76 www.aepd.es sedeaepd.gob.es Reactive technical measures: The internal audit report provided as Annex V to ALKORA’s letter dated July 9, 2024, highlighted some of the reactive measures adopted by ALKORA following the breach: - (…) ALKORA also submitted, as Annex V(c) to its brief dated July 9, 2024 (pp. 319–324 of the document containing all annexes), an unsigned internal incident resolution report dated April 10, 2024, following the penetration test, in which it stated (…). When asked about the level of network segmentation ((…)), ALKORA states in its brief dated December 23, 2024, that: “(…)” Training activities related to personal data protection: ALKORA provides an internal audit report on its information systems as Annex V to its letter dated July 9, 2024 (pages 131–221 of the document, including all annexes), prior to the breach, which indicated that it did not provide cybersecurity training on a widespread basis, but only to employees who requested it, and that it did so because of its reliance on antivirus software. ALKORA refers (pp. 30–32 of its brief dated July 9, 2024) to the documentation provided in Annex VII of that brief, relating to training programs that included topics on personal data protection. Among these, four continuing education reports are provided (pp. 327–389 of the document, including all annexes), which ALKORA stated it had completed prior to the data breach (from 2020 to 2023). These reports pertain to its insurance training program, which, as indicated in the reports, the company is required to provide under: - Royal Decree 764/2010, of June 11, implementing Law 26/2006, of July 17, on private insurance and reinsurance mediation regarding statistical, accounting, and business information, and professional competence. - Resolution of February 18, 2011, of the General Directorate of Insurance and Pension Funds, establishing the requirements and basic principles of training programs for insurance intermediaries, reinsurance brokers, and other persons directly involved in private insurance and reinsurance mediation. The annual reports for the years 2020 through 2022 included a section (in 2020, a 20-hour program covering six topics, and in 2021 and 2022, a 26-hour program covering five topics) on regulatory compliance related to personal data protection. The reports mention attendance at these training activities but do not mention their evaluation. 6 Jorge Juan Street, 28001 – Madrid25/76 www.aepd.es sedeaepd.gob.es The 2020 and 2022 reports mention that “In addition to this program, some team members have also participated in other training activities,” for which they provide a list but do not specify the number of participants or their professional profiles. The 2023 report describes a training program attended by 20 people, 15 of whom successfully completed it, with a total course load of 25 hours for Level II staff (15 hours for Level III staff) that includes one module (number 3) titled “Data Protection Regulations” and another (number 7) titled “Network Security,” out of a total of seven modules. ALKORA also provides, as Annex VII e of its brief dated July 9, 2024 (pages 390–405 of the document containing all annexes), a January 2024 report regarding a 2-hour training session on personal data protection, which includes the results of an assessment test taken by 139 participants, and the content of which ALKORA provides as a PowerPoint presentation (Annex VII f, pp. 406–430 of the document containing all annexes). Additionally, ALKORA provides, from Annex VII g through Annex VII r of its submission dated July 9, 2024 (pages 431 through 465 of the document with all annexes), copies of several emails, which it states were distributed by the IT department to ALKORA staff, containing cybersecurity awareness content, including one warning of a phishing attempt detected at the company in the weeks leading up to the breach. Organizational measures taken after the breach: In the annexes to the letter dated July 9, 2024, ALKORA provides documentation regarding the adoption or modification of organizational measures following the breach: - Attached as Annex VII s (pages 466–473 of the document containing all annexes) is a document titled “Data Protection Policy,” version 1.0 dated November 7, 2023, unsigned. - Attached as Annex VII t (pages 474–589 of the document containing all annexes) is a document titled “Information Systems Security Policy,” version 1.0 dated November 7, 2023, unsigned. - Attached as Annex VII u (pages 590–595 of the document with all annexes) is a document titled “Annex to the Protocol on Best Practices for Personal Data Protection and Information Security,” version v.1 dated March 1, 2024, unsigned. - Attached as Annex VII v (pages 596–600 of the document containing all annexes) is a document titled “Procedure for Protecting Filing Systems Containing Personal Data with a Password,” version v2, dated May 2024, unsigned. 6 Jorge Juan Street, 28001 – Madrid26/76 www.aepd.es sedeaepd.gob.es SIXTH: On April 15, 2025, the Presidency of the Spanish Data Protection Agency decided to initiate disciplinary proceedings against the respondent, in accordance with the provisions of Articles 63 and 64 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), for the alleged violation of Article 5.1.f) of the GDPR and Article 35 of the GDPR, as defined in Article 83.5 of the GDPR and Article 83.4 of the GDPR, respectively. SEVENTH: After being notified of the aforementioned decision to initiate proceedings in accordance with the provisions of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), on May 6, 2025, ALKORA submitted a written statement of defense in which, in summary, it asserted that: - There had been no violation of Article 5.1.f) of the GDPR - An impact assessment was not required (Art. 35 GDPR) - Therehad any culpability and should be applied the principle of proportionality It was also noted that a request had been made for an expert technical report to verify the adequacy of the security measures implemented by the brokerage at the time of the security breach, which would be submitted as soon as it was issued by the external expert who had been commissioned. Accompanying the arguments was an external legal report analyzing the entity’s decision not to conduct a Data Protection Impact Assessment (DPIA). EIGHTH: On October 17, 2025, an expert report submitted by ALKORA was received, as announced in its written response to the decision to initiate disciplinary proceedings. NINTH: According to the report retrieved from the AXESOR tool on February 8, 2026, ALKORA is an enterprise incorporated in 1989, with a turnover of €24,007,236 in 2024. TENTH: A list of the documents on file in this proceeding is attached as an annex. Based on the proceedings conducted in this case and the documentation in the case file, the following facts have been established: PROVEN FACTS FIRST: ALKORA was the victim of a ransomware attack, the sequence of events of which, according to the company’s report, was as follows: (…) Regarding the details of the attack, as reported by ALKORA: 6 Jorge Juan Street, 28001 – Madrid27/76 www.aepd.es sedeaepd.gob.es • (…) According to ALKORA: - (…) SECOND: The forensic report provided by ALKORA, which analyzes the breach, identifies some of the actions carried out by the attacking group following the initial intrusion, consisting of: - access to the messaging management server: “(…)” - reconnaissance from that server to gather information about domain administrators, elevate their User privileges, and move throughout the rest of the system: “(…)” It also indicates that over the next three days the following occurred: - privilege escalation - access to the local administration account (…) ***SERVER.1, which grants the highest privileges on the system - Installation and execution of the program ***PROGRAM.1, despite being blocked twice by ***PROGRAM.2; the attacker manages to hide and avoid further blocking by the antivirus - Installation of the ***PROGRAM.3 program - data exfiltration - Encryption of servers and workstations The forensic report also states: “The attackers were able to move freely throughout ALKORA’s infrastructure (…).” “The ransomware is deployed manually on ***SERVER.1 and automatically on the workstations (…)” According to the forensic report: “Analysis of lateral movement during the attack period has shown that the attackers were able to move freely throughout the entire information system by compromising privileged accounts, such as domain administrators.” THIRD: Regarding the circumstances preceding the attack that may have contributed to its success, ALKORA notes the following: - “(…)” These are measures that, therefore, did not exist prior to the incident but were, on the contrary, adopted in response to it. 6 Jorge Juan Street, 28001 – Madrid28/76 www.aepd.es sedeaepd.gob.es FOURTH: According to the information provided by ALKORA and included in the case file, certain system deficiencies have affected the investigation of the attack itself: “Several factors have contributed to limiting the investigative capacity of the ***ENTERPRISE.1 team: • (…) FIFTH: In the data breach notifications submitted to this Agency on April 22 and May 17, 2023, ALKORA stated: - that it had suffered a breach of confidentiality, availability, and integrity due to a cyberattack; - that the affected activity involved the processing of data belonging to approximately 25,000 individuals, including minors; - that the data was not encrypted. Subsequently, in its letter dated July 9, 2024, ALKORA revised the approximate number of affected individuals to 40,000. According to the forensic report provided by ALKORA: “The encryption of the servers directly impacts the integrity and availability of the enterprise’s systems and applications. Furthermore, the data exfiltration impacts the confidentiality of the enterprise’s sensitive documents, as well as customers’ personal data.” “The integrity and availability of all systems and services have been impacted.” SIXTH: Regarding the types of data, in its letter dated February 14, 2024, in response to the referral of the complaint, ALKORA stated that the types of personal data affected were: “1. Basic data of individual customers, corporate customers (policyholders, insured parties, beneficiaries), potential customers, and staff: First name, last name, date of birth, National ID number, Foreign Resident ID number, passport, and/or any other identification document; economic or financial data (excluding payment methods); contact information; health data (exclusively for employees, limited to what is essential for the employment relationship); and access or identification credentials (User name and/or password). 2. Health data of individual customers with life insurance and/or accident insurance policies.” Meanwhile, on page 22 of Annex I to ALKORA’s brief dated July 9, 2024, the forensic report dated May 3, 2023, stated: “Analysis of lateral movement during the attack period has shown that the attackers were able to move freely throughout the 6 Jorge Juan Street, 28001 – Madrid29/76 www.aepd.es sedeaepd.gob.es entire information system by compromising privileged accounts such as domain administrators.” SEVENTH: ALKORA also provides, as Annex V(b) to its brief dated July 9, 2024 (pages 222–318 of the document including all annexes), an unsigned “pentesting” (penetration testing of its computer system) audit report, Version 1.0, dated July 9, 2024. The penetration test, conducted by ***SISTEMA.1, revealed that: “The security audit revealed a number of vulnerabilities and weaknesses which, when jointly exploited, would enable the entire domain to be compromised by gaining domain administrator privileges, with access only to the internal network.” (unofficial translation: “The security audit revealed a series of vulnerabilities and weaknesses that, when exploited together, would have allowed the entire domain to be compromised by obtaining domain administrator privileges, with access only to the internal network”). Section 3.4 of Annex V b (password audit) indicated that (…). The aforementioned audit highlighted eight “high” severity vulnerabilities: - (…) And 10 “medium” vulnerabilities: - (…) EIGHTH: When asked about the level of network segmentation ((...)), ALKORA states in its letter dated December 23, 2024, that: (…) NINTH: In the Risk Analysis conducted by ALKORA on September 19, 2019, version 0.1, submitted as Annex V to ALKORA’s letter dated February 14, 2024, in response to the referral of the complaint, five files are listed: “LABOR AND HR,” “INSURANCE BROKERAGE FOR INDIVIDUALS,” “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS,” “INSURANCE CLAIMS,” and “TAX AND ACCOUNTING.” Regarding the “LABOR AND HR” filing system, the following is stated: “Categories of data subjects: Employees” “Identifying data: National ID number (DNI) or Tax ID number (NIF), first and last names, mailing or email address, phone number, handwritten signature, Social Security number or mutual insurance number Special categories of data: Digitized fingerprint (biometric data) Other type of data Characteristics Personal, Academic and professional, Details of employment, Transactions of goods and services.” 6 Jorge Juan Street, 28001 – Madrid30/76 www.aepd.es sedeaepd.gob.es Regarding “INSURANCE BROKERAGE FOR INDIVIDUALS”: “Identifying information: ID number or Tax ID number, first and last names, mailing or email address, phone number, handwritten signature Special categories of data: N/A Other types of data: Personal data, academic and professional information, transactions involving goods and services, social circumstances, commercial information, economic, financial, and insurance information” Regarding “ “BROKERAGE INSURANCE INSURANCE LIFE LIFE AND ACCIDENT FOR INDIVIDUALS”: “Identifying information: ID number or tax ID number, first and last names, mailing or email address, phone number, handwritten signature Special categories of data: Health Other types of data: Personal data, academic and professional information, transactions involving goods and services, social, economic, financial, and insurance-related circumstances” Regarding “INSURANCE CLAIMS”: “Identifying information: National ID number (DNI) or Tax ID number (NIF), first and last names, mailing or email address, phone number, handwritten signature, image Special categories of data: Health Other types of data: Personal data, academic and professional information, transactions involving goods and services, social circumstances, economic, financial, and insurance information” Regarding “TAX AND ACCOUNTING”: “Identifying information: ID number or tax ID number, first and last names, mailing or email address, phone number Special categories of data: N/A Other types of data: N/A” Regarding the risks associated with each filing system, the aforementioned Risk Analysis states: - Regarding “Filing System 1: EMPLOYMENT AND HR”: o The identifying data and other specified data subject to processing are considered to have an initial “Low” risk. o Regarding “Data Protection (Integrity and Confidentiality),” it is stated that “There are adequate measures in place to protect data against unauthorized processing and loss or destruction, in accordance with the provisions of this section of the document,” an initial risk level of “Medium” is assigned, and the measures detailed are “Ensuring that adequate technical and organizational measures have been implemented to protect the data through the corresponding periodic annual verification,” after which a final risk level of “Very low” is assigned. 6 Jorge Juan Street, 28001 – Madrid31/76 www.aepd.es sedeaepd.gob.es o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data subject rights and freedoms,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “It has been verified that the risk analysis conducted does not identify any threats with a probability of high risk to the data subject rights and freedoms,” after which a final risk of “Low” is assigned. o Regarding “Access to special categories of data,” it is stated that “There are no special categories of data,” and therefore it is assigned an initial and final risk rating of “Very Low.” - Regarding “Filing System 2: INSURANCE BROKERAGE FOR INDIVIDUALS”: o It is considered that the identifying data and other specified data subject to processing have an initial risk of “Low.” o Regarding “Data Protection (Integrity and Confidentiality),” it is indicated that “There are adequate measures in place to protect the data against unauthorized processing and loss or destruction, in accordance with the provisions of this document,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “Ensure that adequate technical and organizational measures have been implemented to protect the data through the corresponding periodic annual verification,” after which a final risk of “Very low” is assigned. o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data subject rights and freedoms,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “It has been verified that the risk analysis conducted does not identify any threats with a high probability of risk to the data subject rights and freedoms,” after which a final risk of “Low” is assigned. o Regarding “Access to special categories of data,” it is stated that “There are no special categories of data,” and therefore an initial and final risk rating of “Very Low” is assigned. - Regarding “Filing System 3: LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS”: o It is considered that the identifying data and other specified data subject to processing have an initial risk of “Low.” However, health data is assigned an initial risk of “High.” o Regarding “Data Protection (Integrity and Confidentiality),” it is stated that “There are adequate measures in place to protect the data against unauthorized processing and loss or destruction, in accordance with the provisions of this document,” it is assigned an initial risk of “Medium,” and the measures are detailed as follows: “Ensure that adequate technical and organizational measures have been implemented to protect the data through the corresponding periodic annual verification,” after which a final risk of “Low” is assigned 6 Jorge Juan Street, 28001 – Madrid32/76 www.aepd.es sedeaepd.gob.es o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data subject rights and freedoms,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “It has been verified that the risk analysis conducted does not identify any threats with a high probability of risk to the data subject rights and freedoms,” after which a final risk of “Low” is assigned. o Regarding “Access to special categories of data,” it is stated that “ADDITIONAL security measures are in place in accordance with the provisions of section 4.4 of this document”; an initial risk rating of “Medium” is assigned, and the measures are detailed as follows: “An up-to-date record must be maintained of personnel with access to special categories of data. It is recommended to strengthen these measures with two-factor authentication, encryption…,” after which a final risk rating of “Very low” is assigned. - Regarding “Filing System 4: INSURANCE CLAIMS”: o It is considered that the identifying data and other specified data subject to processing have an initial risk of “Low.” However, health data is assigned an initial risk of “High.” o As for “Data Protection (Integrity and Confidentiality),” it is stated that “There are adequate measures in place to protect the data against unauthorized processing and loss or destruction, in accordance with the provisions of this document,” it is assigned an initial risk of “Medium,” and the measures are detailed as follows: “Ensure that adequate technical and organizational measures have been implemented to protect the data through the corresponding periodic annual verification,” after which a final risk of “Low” is assigned. o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data subject rights and freedoms,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “It has been verified that the risk analysis conducted does not identify any threats with a high probability of risk to the data subject rights and freedoms,” after which a final risk of “Low” is assigned. o Regarding “Access to special categories of data,” it is stated that “ADDITIONAL security measures are in place in accordance with the provisions of section 4.4 of this document”; an initial risk rating of “Medium” is assigned, and the measures are detailed as follows: “An up-to-date record must be maintained of personnel with access to special categories of data. It is recommended to strengthen these measures with two-factor authentication, encryption…”, after which a final risk rating of “Very low” is assigned. - Regarding “Filing System 5: TAX AND ACCOUNTING”: o The identifying data subject to processing is considered to have an initial risk of “Low.” 6 Jorge Juan Street, 28001 – Madrid33/76 www.aepd.es sedeaepd.gob.es o As for “Data Protection (Integrity and Confidentiality),” it is stated that “There are adequate measures in place to protect the data against unauthorized processing and loss or destruction, in accordance with the provisions of this document,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “Ensure that adequate technical and organizational measures have been implemented to protect the data through the corresponding periodic annual verification,” after which a final risk of “Low” is assigned o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data subject rights and freedoms,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “It has been verified that the risk analysis conducted does not identify any threats with a high probability of risk to the data subject rights and freedoms,” after which a final risk of “Low” is assigned. o Regarding “Access to special categories of data,” it is stated that “There are no special categories of data,” and therefore an initial and final risk rating of “Very Low” is assigned. - “Processing of data of children under 14 years of age” is mentioned as a specific processing activity, indicating that “Data processing of children under 14 years of age is carried out only in cases of school accidents”; an initial risk of “Medium” is assigned, and the measures indicated are “Ensure that the measures referred to in section 4.4 through the corresponding periodic annual verification,” after which a final risk of “Low” is indicated. This document also includes the following sections under “REGULATORY COMPLIANCE” (file number in parentheses): Security Policy (1; 2; 3; 4; 5) - Processing Risks: “The processing has been analyzed, and there is no likelihood of a high risk to the data subject rights and freedoms.” Security Policy (3; 4) - Impact Assessment: “The processing has been analyzed in accordance with the Report on the Need to Conduct an Impact Assessment, and there is no likelihood of a high risk to the data subject rights and freedoms.” The “ORGANIZATION” section of the aforementioned Risk Analysis stated: “[A DPIA is not required because] the processing does not pose a high risk to the rights and freedoms of natural persons.” TENTH: In the unsigned Risk Analysis provided by ALKORA, version 2.0 dated November 1, 2023, submitted as Annex III to its letter of July 9, 2024, the initial and final risks for filing systems 3 and 4 are reclassified as “High,” which 6 Jorge Juan Street, 28001 – Madrid34/76 www.aepd.es sedeaepd.gob.es These include the processing of health data; this risk assessment maintains the initial and final risks associated with the processing of filing systems 1 and 5—which contain banking data—at “Medium” and “Low,” respectively. This new risk analysis mentions the need to conduct a Data Protection Impact Assessment (DPIA) for filing systems 3 and 4. ELEVENTH: In ALKORA’s unsigned report, version 2.0 dated November 1, 2023, on the need to conduct impact assessments, which ALKORA provides as Annex IV to its letter dated July 9, 2024, it is concluded that DPIA are necessary for the “Health and Life Insurance Brokerage” and “Claims” filing systems due to the processing of special categories of data and data on vulnerable groups: “Conclusions: At least two of the criteria established in the AEPD’s list of processing activities are met in the “Health and Life Insurance Brokerage” and “Claims” filing systems, as they involve data on vulnerable groups, such as minors, as well as special categories of data—‘health data’—therefore making it necessary to conduct a Data Protection Impact Assessment on the aforementioned processing activities, as they could pose a high risk to the data subject rights and freedoms. Likewise, Alkora prepared a report on the need to appoint a data protection officer, in which it analyzed whether or not large-scale processing of personal data is taking place; the analysis was inconclusive due to the lack of clarity in the criteria established by WP 243. However, since at least two of the AEPD’s criteria are already met, we consider it necessary to conduct a Data Protection Impact Assessment (DPIA) regarding the processing of minors’ data and health data in the relevant filing systems.” TWELFTH: Based on the information contained in the case file and that provided by ALKORA, there is no record that a Data Protection Impact Assessment has been conducted. LEGAL GROUNDS I Jurisdiction In accordance with the powers granted to each supervisory authority under Article 58(2) of Regulation (EU) 2016/679 (GDPR), and as established in Articles 47, 48(1), 64(2), and 68(1) of Organic Law 3/2018 of December 5 on Data Protection and the Guarantee of Digital Rights (hereinafter, LOPDGDD), the Presidency of the Spanish Data Protection Agency has jurisdiction to rule on this proceeding. Likewise, Article 63.2 of the LOPDGDD provides that: “Proceedings handled by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, this Organic Law, the 6 Jorge Juan Street, 28001 – Madrid35/76 www.aepd.es sedeaepd.gob.es issued in implementation thereof and, to the extent they do not contradict them, on a subsidiary basis, by the general rules on administrative procedures.” II Preliminary Issues Article 4(1) of the GDPR defines “personal data” as: “any information relating to an identified or identifiable natural person (‘the data subject’); an identifiable natural person is one whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.” Article 4(2) of the GDPR defines “processing” as: “any operation or set of operations performed on personal data or sets of personal data, whether by automated means or not, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.” Article 4(7) of the GDPR defines the “controller” or “data controller” as: “the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing; if Union or Member State law determines the purposes and means of the processing, the controller or the specific criteria for its designation may be established by Union or Member State law.” In turn, article 4.8) of the GDPR defines the “processor” as the natural or legal person, public authority, agency, or other body that engages in personal data processing on behalf of the controller. In the present case, in accordance with the provisions of Articles 4(1) and 4(2) of the GDPR, the processing of personal data has taken place, since ALKORA carries out, among other processing activities, the collection and storage of personal data of natural persons: national ID number or tax ID number, first and last names, mailing or email address, telephone number, image, handwritten signature, social security or mutual insurance number, health data, marital status, family information, date and place of birth, age, sex, nationality, housing and property data, academic and professional data, commercial information, employment data, economic, financial, and insurance data, and bank account number. ALKORA carries out this activity in its capacity as the controller, as it is the entity that determines the purposes and means of such activity, pursuant to Article 4.7 of the GDPR. 6 Jorge Juan Street, 28001 – Madrid36/76 www.aepd.es sedeaepd.gob.es III Objections to the Notice of Initiation With regard to the arguments raised in the decision to initiate these disciplinary proceedings, we will address them in the order set forth by ALKORA. FIRST. Regarding the absence of a violation of Article 5(1)(f) of the GDPR ALKORA argues that the mere existence of vulnerabilities does not, in and of itself, constitute proof of a violation of Article 5(1)(f) in conjunction with Article 32 of the GDPR. Furthermore, article 32 of the GDPR requires the controller to adopt “appropriate technical and organizational measures to ensure a level of security appropriate to the risk,” without requiring absolute security or imposing an obligation to achieve a specific result. Moreover, there is no list of mandatory measures; rather, the choice of appropriate and reasonable measures is left to the discretion of the controller. ALKORA understands that the technical reports provided demonstrate, precisely, the existence of an active policy for reviewing, detecting, and rectifying vulnerabilities, which shows the entity’s diligence in managing the security of the personal data processed. The fact that the vulnerabilities were identified and subsequently corrected reinforces—rather than undermines—compliance with the principle of proactive responsibility set forth in Article 5(2) of the GDPR. It was a reactive report in response to a security breach. The aim is to identify potential improvements, but until then, the level of security was more than acceptable. Furthermore, a violation can only be concluded to exist when it is proven that the measures adopted were manifestly insufficient in light of the actual and foreseeable risk, which must be assessed ex post but by applying ex ante criteria—that is, those that were reasonable at the time of processing. ALKORA argues that, in the regulatory authority’s notice of initiation, the Agency merely transcribes several technical reports submitted that allegedly demonstrate that the measures adopted prior to the breach were insufficient; however, the Agency does not explain why they were insufficient or to what extent. It makes no evaluative judgment whatsoever, which constitutes a clear lack of reasoning. It does not even address whether the hypothetical vulnerabilities mentioned in the decision to initiate the sanction are linked to the breach in question or whether their proper implementation could have prevented it. The Agency does not state to what extent those hypothetical vulnerabilities affected the breach or whether, had they been implemented, the breach could have been prevented. ALKORA argues that, in the present case, the insurance brokerage designed and carried out—prior to the security incident occurring—a structured risk analysis tailored to the nature of the processing operations, the type of data processed—primarily identifying, contact, and contractual data—and the volume and profile of the data subjects. This risk analysis, developed in accordance with 6 Jorge Juan Street, 28001 – Madrid37/76 www.aepd.es sedeaepd.gob.es methodologies accepted in the field of cybersecurity and data protection—enabled the entity to identify potential threats, establish impact scenarios, and adopt security measures that were proportionate and tailored to the operational environment. It notes that, thanks to this preliminary analysis, the brokerage had in place access control mechanisms, network segmentation, robust password policies, access monitoring protocols, and a contingency plan that was activated immediately upon detection of the incident. All of this enabled the security breach to be detected and contained quickly. Consequently, it cannot be considered that there was a violation of Article 5.1.f) of the GDPR simply because a breach occurred or because technical reports issued by external experts at ALKORA’s instance highlight certain areas for improvement (this is the purpose of such reports, and all of them identify room for improvement—but this cannot be called negligence; rather, it is active responsibility and continuous risk assessment). In this case, the entity has rigorously applied the principle of active responsibility at all stages of processing. It has documented its processing activities in the record provided for in Article 30, conducted risk analyses in accordance with recognized methodologies, implemented security policies, trained its staff, and appointed a data protection officer in accordance with Article 37 of the GDPR. In this regard, prior to the occurrence of the breach, the organization states that it had implemented the following technical measures: - (…) Furthermore, upon the occurrence of a data breach, the organization activated its notification protocols, assessed the impact, notified the AEPD within the legal deadline, and took immediate corrective measures. Among these measures, it requested a technical report specifically intended to identify potential risks and determine possible improvements that could be implemented within the organization. This report is the sole basis on which the Agency has imposed a penalty on ALKORA, which the company finds surprising because that report was requested in defense of the principle of proactive responsibility, precisely for the purpose of detecting vulnerabilities and thereby enabling improvement. The company points out that all systems have vulnerabilities and are subject to improvement, but this does not imply that the measures were insufficient given the nature of the data processed. To argue that the mere occurrence of a breach demonstrates the inadequacy of the security measures implemented by the affected entity is tantamount to imposing strict liability on it in an area where, as is well known, such an obligation would be impossible to fulfill. In this regard, first, this Agency wishes to point out that the purpose of the present enforcement proceeding is to determine ALKORA’s liability for a possible violation of Article 5(1)(f) of the GDPR and Article 35 of the GDPR, exclusively. 6 Jorge Juan Street, 28001 – Madrid38/76 www.aepd.es sedeaepd.gob.es The principle set forth in Article 5(1)(f) imposes on the controller of any processing of personal data the obligation—the guarantee—to prevent unauthorized or unlawful processing of such data, as well as its loss or destruction. In other words, a controller must not process personal data if it is unable to guarantee the confidentiality and integrity of such data, prevent third parties from accessing data that does not concern them, and prevent the loss or destruction of such data. In this regard, controllers must ensure the integrity and confidentiality of the personal data being processed through technical and organizational measures of all kinds. Compliance with this requirement would therefore be demonstrated by: (i) the adoption and implementation of technical and organizational measures of all kinds aimed at ensuring the confidentiality and integrity of the personal data being processed; and (ii) the absence of any instances of loss of confidentiality or integrity of the personal data being processed. Failure to comply, on the other hand, would result from the absence of measures or failure to comply with those adopted, as well as a loss of confidentiality of the data being processed. When a breach of confidentiality occurs, unauthorized access to personal data by a third party means that such data may be used for unknown, even fraudulent, purposes, resulting in a total and absolute loss of control over it. This loss of control over one’s own personal data constitutes a violation of the fundamental right to data protection recognized in Article 18.4 of the Spanish Constitution, as the Constitutional Court has stated (Judgement 292/2000, dated November 30, 2000): “The fundamental right to data protection seeks to guarantee individuals the power to control their personal data, its use, and its destination, with the purpose of preventing its unlawful trafficking, which is harmful to the dignity and rights of the data subject (…). The guarantee established by the legal system will be achieved through the application of appropriate technical or organizational measures of all kinds. These are not strictly or solely security measures. There are diverse and numerous technical and organizational measures—other than security measures—that the controller may implement as a means of ensuring this principle. In this regard, the AEPD’s Guide on “Risk Management and Impact Assessment in Personal Data Processing” states that, “(…), it must be emphasized that addressing the risks that personal data processing may pose to individuals’ rights and freedoms cannot be limited to applying security measures exclusively. Therefore, security risk management is just one of the activities involved in managing risks to rights and freedoms and must be subordinate to the latter. Furthermore, from the perspective of the GDPR, mitigation measures must be aimed at reducing the impact and likelihood of data breaches affecting the data subject.” If only security measures were taken into account in relation to Article 5(1)(f) of the GDPR, this would amount to oversimplifying the essence of the GDPR, compliance with which is not limited to the implementation of technical and organizational security measures; in our case, it would mean reducing the guarantee required by the principles of integrity and confidentiality to one achieved solely through measures of 6 Jorge Juan Street, 28001 – Madrid39/76 www.aepd.es sedeaepd.gob.es security. Of course, the appropriate technical or organizational measures referred to in Article 5.1.f) of the GDPR may be security measures, but they are not the only ones. A violation of this provision—a breach of confidentiality or integrity—can occur even in the absence of any security measures or despite their inadequacy. This legal requirement constitutes an obligation of result, the breach of which constitutes a result-based infringement. The Supreme Administrative Court ruling of May 13, 2024, issued in Appeal No. 0002336/2021, states this (emphasis added). On this basis, the plaintiff entity, in its capacity as the data controller, is held liable for breaching the duty of confidentiality and integrity under Article 5.1.f) of the GDPR, given the outcome of those nine complaints, which indicate that it had not ensured adequate security in the processing of personal data, as evidenced by the identity theft that occurred. Ultimately, a third party was able to access the personal data of the line holders without the existing security measures being able to prevent it. Constituting, in short, further evidence that the security measures in place at the time the events occurred were inadequate, is the established fact that a change was made to those measures, as highlighted in the fifteenth established fact in the contested decision, according to which: “VDF has subsequently subsequently implemented measures and developed action plans to prevent fraud involving duplicate SIM cards, focusing on four lines of action (…)”. Therefore, Vodafone, as the entity responsible for ensuring the integrity and confidentiality of the personal data processed, and given that, in the nine reported cases, security measures were ultimately insufficient, must be held liable for the alleged violation of Article 5.1.f) of Regulation (EU) 2016/679. Article 5(1)(f) of the GDPR strictly requires that confidentiality and integrity be guaranteed, and its application necessitates a loss of confidentiality and/or integrity—that is, a specific outcome. In the present case, the absence of specific security measures designed specifically to ensure confidentiality—namely, encryption and pseudonymization (or anonymization)—is what led to the breach of the confidentiality of personal data. If the data had been encrypted, anonymized, or pseudonymized, the criminals would have only obtained unintelligible information. On the contrary, the measures adopted should have taken into account the “real and foreseeable” risk—in ALKORA’s words—to the rights and freedoms of the data subjects at the time of processing; in this case, the measures implemented by ALKORA were not adequate given the risk to the data subject rights and freedoms, which resulted in a breach of the confidentiality of such data. The GDPR takes a proactive approach, requiring controllers to analyze the risks involved in and to which the processing of personal data is exposed, in order to implement 6 Jorge Juan Street, 28001 – Madrid40/76 www.aepd.es sedeaepd.gob.es appropriate measures based on those risks. It also requires the ongoing assessment of such risks in order to monitor and update the measures in place. This implies that it is not merely a matter of assessing the measures to be implemented at a given moment—whether before or after such processing takes place—in relation to the actual and foreseeable risk to the data subject rights and freedoms. Rather, it also involves continuously reviewing those risks in order to adapt those measures at every stage of the processing. The GDPR does not provide a list of measures that apply based on the data being processed; rather, it stipulates that the controller and processor must implement technical and organizational measures appropriate to the risk posed by the processing, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of the processing, and the likelihood and severity of the risks to the rights and freedoms of data subjects. In this regard, Recital 83 of the GDPR states that: “(83) In order to maintain security and prevent the processing from infringing the provisions of this Regulation, the controller or processor must assess the risks inherent in the processing and implement measures to mitigate them, such as encryption. These measures must ensure an appropriate level of security, including confidentiality, taking into account the state of the art and the cost of implementation in relation to the risks and the nature of the personal data to be protected. When assessing the risk to data security, consideration must be given to the risks arising from the processing of personal data, such as the accidental or unlawful destruction, loss, or alteration of personal data transmitted, stored, or otherwise processed, or the unauthorized disclosure of or access to such data, which may, in particular, result in physical, material, or non-material damage.” In accordance with Recital 74 of the GDPR, the controller is responsible for demonstrating that the measures adopted are effective: “The controller must be held accountable for any processing of personal data carried out by the controller or on the controller’s behalf. In particular, the controller must be required to implement appropriate and effective measures and must be able to demonstrate the compliance of processing activities with this Regulation, including the effectiveness of the measures. Such measures must take into account the nature, scope, context, and purpose of the processing, as well as the risk to the rights and freedoms of natural persons.” These technical and organizational measures are included as part of the principle of proactive accountability, which requires the controller to conduct a prior assessment of the risk that the processing of personal data may pose, based on which the appropriate measures will be adopted. The GDPR seeks to anticipate infringements or violations of rights in order to prevent them. This proactive approach to the “ongoing implementation” of the measures 6 Jorge Juan Street, 28001 – Madrid41/76 www.aepd.es sedeaepd.gob.es implies that they are not static but dynamic; it is up to the controller to determine at all times which measures are necessary to ensure the confidentiality, integrity, and availability of personal data and to mitigate or erase risks to individuals’ rights. The first step is to conduct a “risk analysis” to assess the threats. It is the controller or processor who must demonstrate this diligence through a robust and effective internal control system. Therefore, a mere formal demonstration of compliance will not suffice; rather, this principle requires a preemptive, conscious, diligent, and proactive approach on the part of organizations regarding all personal data processing activities they carry out. The adoption of these measures—or the manner in which they are applied—will depend on factors that must be taken into account in each case, such as the type of processing and the risk that such processing poses to the data subject rights and freedoms. Consequently, due diligence must be tailored to the level of data protection risks and the characteristics of the organization. The concept of due diligence can be defined as “the degree of prudence, activity, or diligence that can reasonably be expected—and with which a prudent and reasonable organization normally acts—under specific circumstances; it is not measured by an absolute standard, but rather depends on the relative facts of the case in question.” Therefore, due diligence is an ongoing process of monitoring and preventing the negative effects of an organization’s activities on data protection. In the present case, at the time the agreement to initiate these disciplinary proceedings was signed, there was no evidence that ALKORA had acted in a proactive manner with regard to the potential risks and rights of data subjects in connection with the processing. On October 17, 2025, ALKORA submitted to this Agency an expert report dated October 15, 2025, in which, after analyzing the status of the systems prior to the incident and the post-incident audit report, it concludes that the measures adopted prior to the incident were appropriate. In this regard, it is noteworthy that ALKORA, through a self-prepared report submitted months after the incident occurred, seeks to refute the information it had previously provided—both in the breach notifications submitted to the AEPD and in the various technical reports submitted during the course of the preliminary investigative proceedings. It is also noteworthy that, in its written arguments submitted in response to the decision to initiate proceedings, ALKORA indicated that it had access control mechanisms, network segmentation, robust password policies, access monitoring protocols, and a contingency plan that was activated immediately upon detection of the incident. All of this enabled the security breach to be detected and contained quickly. 6 Jorge Juan Street, 28001 – Madrid42/76 www.aepd.es sedeaepd.gob.es Regarding this argument, let us recall the information provided by ALKORA, which is on record and appears in the “Proven Facts” section of this Proposed Resolution: - Regarding the onset of the breach and its detection: (…) • Subsequently, reconnaissance activities began to gather information about the domain administrators, in order to elevate their User privileges and move throughout the rest of the system: “(…)”. It also indicates that over the next three days the following occurred: - privilege escalation - access to the account for administration account (…) ***SERVER.1, which grants the highest privileges on the system - installation and execution of the program ***PROGRAM.1, despite the lock in two instances by on the ***PROGRAM.2; the attacker manages to hide and avoid further blocking by the antivirus - installation of the program ***PROGRAM.3 - data exfiltration - encryption of servers and workstations In short, the breach began on April 16 with access to the server, followed by three days of reconnaissance, privilege escalation, and access to the local administrator account—with the highest privileges—installation of the malicious program ***PROGRAM.1—bypassing antivirus blocks, installing the program ***PROGRAM.3, exfiltrating data, and encrypting it. All of this occurred without ALKORA detecting this malicious activity until April 21—five days later. - Regarding network segmentation, note that the forensic report also states: “The attackers were able to move freely throughout ALKORA’s infrastructure (…).” “The ransomware is deployed manually on ***SERVER.1 and automatically on the workstations (…)” According to that forensic report: “Analysis of lateral movement during the attack period has shown that the attackers were able to move freely throughout the entire information system by compromising privileged accounts, such as domain administrators.” 6 Jorge Juan Street, 28001 – Madrid43/76 www.aepd.es sedeaepd.gob.es Furthermore, when asked about the level of network segmentation ((...)), ALKORA stated in its letter dated December 23, 2024, that: (…) - Regarding the password policy, which ALKORA describes as robust, it should be noted that ALKORA also provides, as Annex V b of its submission dated July 9, 2024, a “pentesting” (penetration testing of its computer system) audit report, Version 1.0 dated July 9, 2024, according to which: “The security audit revealed a series of vulnerabilities and weaknesses that, when exploited in combination, would have allowed the entire domain to be compromised by obtaining domain administrator privileges, with access limited to the internal network.” Section 3.4 of that Annex V b (password audit) stated that (…). - Regarding access monitoring, it should be noted that, with respect to the circumstances preceding the attack that may have been related to its success, ALKORA states the following: • (…) In other words, basic measures such as multi-factor authentication, strengthening access controls, or updating antivirus software were implemented only after the attack. Finally, regarding the occurrence of the data breach in confidentiality, it is worth noting that in the personal data breach notifications submitted to this Agency on April 22 and May 17, 2023, ALKORA stated: - that it had suffered a breach of confidentiality, availability, and integrity due to a cyberattack; - that the affected activity involved the processing of data belonging to approximately 25,000 individuals, including minors; - that the data was not encrypted. Subsequently, in its letter dated July 9, 2024, ALKORA revised the approximate number of affected individuals to 40,000. It is also important to note that, according to the forensic report provided by ALKORA: “The encryption of the servers directly impacts the integrity and availability of the enterprise’s systems and applications. Furthermore, the data exfiltration impacts the confidentiality of the enterprise’s sensitive documents, as well as customers’ personal data.” 6 Jorge Juan Street, 28001 – Madrid44/76 www.aepd.es sedeaepd.gob.es “The integrity and availability of all systems and services have been compromised.” It should also be noted that the “pentesting” (penetration testing of its IT system) audit report dated July 9, 2024—that is, after the breach—highlights eight “high” severity vulnerabilities: - (…) And 10 “medium” vulnerabilities: - (…) Finally, ALKORA states that, to date, no actual harm has been caused to the rights and freedoms of the data subjects, and the best proof of this is that the sole complaint received neither proves nor even alleges that any harm was suffered as a result of the security breach. In this regard, this Agency wishes to point out that the fact that ALKORA is unaware of whether any actual harm to the data subject rights and freedoms occurred does not mean that no harm occurred at all. In any case, the fact that there was no evidence that any harm had occurred is one of the circumstances that this authority has taken into account when determining the proposed penalty, pursuant to the provisions of Article 83(2) of the GDPR. Likewise, it is worth recalling the Constitutional Court’s ruling in STC 292/2000, which states that “the fundamental right to data protection seeks to guarantee individuals the power to control their personal data, its use, and its destination, with the aim of preventing its unlawful trafficking, which is harmful to the dignity and rights of the data subject. (…) The right to data protection guarantees individuals the power to dispose of such data; furthermore, the content of the fundamental right to data protection consists of the power to dispose of and control personal data, which empowers the individual to decide which of those data to provide to a third party—whether the State or a private individual—or which data that third party may collect, and which also allows the individual to know who possesses such personal data and for what purpose, and to object to such possession or use. These powers of control and disposal over personal data—which constitute part of the content of the fundamental right to data protection—are legally embodied in the right to consent to the collection, acquisition, and access to personal data, as well as its subsequent storage and processing, and its possible use or uses, by a third party, whether the State or a private individual. And this right to consent to the disclosure and processing—whether computerized or not—of personal data requires, as indispensable complements, on the one hand, the right to know at all times who has access to that personal data and for what purpose it is being used, and, on the other hand, the right to object to such possession and use. (…) Thus, this power of control over one’s own data disappears when the confidentiality of the data being processed is breached, as has occurred in this case. 6 Jorge Juan Street, 28001 – Madrid45/76 www.aepd.es sedeaepd.gob.es Also noteworthy is the CJEU judgment of September 4, 2023, rendered in Case C-655/23, which states that “60 In particular, the Court of Justice has emphasized that from the illustrative list of ‘damages’ or ‘harm’ that data subjects may suffer, set forth in the first sentence of Recital 85 first sentence, of the GDPR, it follows that the EU legislature intended to include within these two concepts, in particular, the mere ‘loss of control’ over the personal data of those data subjects as a result of a breach of that Regulation, even where there has been no specific misuse of the data in question. Such a loss of control may be sufficient to cause “non-pecuniary damage” within the meaning of Article 82(1) of that Regulation, provided that the data subject demonstrates that he or she has actually suffered such damage, however minimal, without the concept of “non-pecuniary damage” requiring proof of the existence of additional tangible negative consequences (see, to that effect, the judgement of October 4, 2024, Agentsia po vpisvaniyata, C-200/23, EU:C:2024:827, paragraphs 145, 150, and 156, and the case law cited there). (emphasis added). Therefore, it follows from the foregoing that the harm to the data subjects’ right to data protection lies in the loss of control over that data itself; a loss of control that inevitably occurs when the confidentiality of their personal data is compromised through access to it by unauthorized third parties. For all of the foregoing reasons, the argument raised is dismissed. SECOND. Regarding the non-requirement of an impact assessment (Art. 35 GDPR) ALKORA has attached, as Document No. 1 to its written response to the order initiating these proceedings, the report issued by ***ENTERPRISE.2, dated December 11, 2023, whose conclusions stated that: - “Following a comprehensive assessment of the factors involved in Alkora’s processing activities, it is concluded that the circumstances requiring a Data Protection Impact Assessment do not apply in this case.” It states that this conclusion was reached because the mere processing of all such data does not automatically trigger the obligation to conduct a Data Protection Impact Assessment (DPIA) when, as was the case here, the processing was residual and linked to very specific purposes that, in and of themselves, did not pose a high risk to the interests and data subject rights. In this regard, this Agency wishes to express its disagreement with the above statement. In the present case, the issue is not that ALKORA should have conducted a Data Protection Impact Assessment (DPIA) due to residual processing linked to very specific purposes, but rather that this Agency considers that, due to its regular business activities, ALKORA was carrying out processing that, taken as a whole, poses a high risk to the data subject rights and freedoms. 6 Jorge Juan Street, 28001 – Madrid46/76 www.aepd.es sedeaepd.gob.es ALKORA states that the decision not to conduct a DPIA was based on the following considerations: - The processing of health data and data on minors in the context of ALKORA’s claims management is incidental, ancillary, and limited to very specific situations in which such information is necessary to process a complaint in the interest of the insured or beneficiary. This is not a massive or systematic processing operation, nor is it central to the entity’s core business activity; the entity does not engage in any large-scale processing of such data, nor does it carry out systematic monitoring of data subjects, nor does it engage in profiling or automated decision-making processes that affect the rights and freedoms of natural persons. The processing does not follow an intensive, mass, or persistent approach, but is strictly limited to cases in which the data subject has suffered personal injury or a minor has been affected, and such information is required to file a complaint for the corresponding compensation with the insurance company. In this regard, the brokerage’s activity falls within the scope of insurance mediation, and the processing of sensitive data does not form part of the core of its business activity, as required by the European Data Protection Board (EDPB) to consider that a high-risk scenario exists that would require a Data Protection Impact Assessment (DPIA). In this regard, this Agency wishes to point out that Article 35 of the GDPR does not require a DPIA to be conducted solely in cases involving large-scale processing, systematic monitoring, profiling, automated decision-making, or anything of that nature. Nor does this Agency consider that ALKORA engages in such processing. However, this Agency wishes to reiterate that Article 35 of the GDPR requires a DPIA to be conducted when the processing of personal data is likely to result in a high risk to the data subject rights and freedoms, as in the present case, where data on minors affected by an accident, employees’ biometric data, and customers’ health, economic, financial, and bank account information are processed, among others, including data that cannot be changed (such as ID or tax identification numbers, date of birth) or is very difficult to change (address)—all of which, when combined, may pose a high risk to data subjects if compromised. - ALKORA notes that, in accordance with the Art 29 Working Party (now the EDPB) Guidelines on Data Protection Impact Assessments (WP248 rev.01), the requirement for a DPIA arises when several risk factors are present cumulatively: it is not sufficient that special categories of data are processed if such processing is not carried out on a large scale or systematically. The residual and exceptional nature of the processing in this case precludes the existence of a “high risk” to the data subject rights and freedoms. In this regard, this Agency reiterates that Article 35 of the GDPR does not require a Data Protection Impact Assessment (DPIA) to be conducted solely in cases involving mass processing, systematic monitoring, profiling, automated decision-making, or anything of that nature. Nor does it consider that ALKORA engages in such processing. Nor is the issue that ALKORA should conduct a DPIA for residual processing linked to very specific purposes; rather, this Agency considers that, due to its 6 Jorge Juan Street, 28001 – Madrid47/76 www.aepd.es sedeaepd.gob.es regular activities, ALKORA was carrying out processing that, taken as a whole, poses a high risk to the data subject rights and freedoms. Article 35 of the GDPR requires a DPIA to be conducted when the processing of personal data may pose a high risk to the rights and freedoms of data subjects, as in the present case, in which data on minors affected by an accident, employees’ biometric data, and customers’ health, economic, financial, and bank account information are processed, among others, including data that cannot be changed (such as national ID or tax ID numbers, date of birth) or is very difficult to change (address)—all of which, when combined, may pose a high risk to data subjects if compromised. Specifically, ALKORA argues that the aforementioned WP248 lists nine criteria “in order to provide a more specific set of processing operations that require a DPIA due to their inherent high risk, taking into account the specific elements of Article 35(1) and Article 35, paragraph 3, subparagraphs (a) through (c), the list to be adopted at the national level pursuant to article 35, paragraph 4, and recitals 71, 75, and 91, as well as other references in the GDPR to processing operations that “are likely to result in a high risk,” none of which apply to the ALKORA case. In this regard, this Agency wishes to point out that the aforementioned list refers to activities that are likely to result in a high risk, but it is by no means an exhaustive list. Furthermore, among the listed circumstances are “4. Sensitive data or highly personal data: this includes the special categories of personal data defined in Article 9 (for example, information about individuals’ political opinions), as well as personal data relating to criminal convictions and offenses as defined in Article 10” and “6. The linking or combining of datasets, for example, from two or more data processing operations carried out for different purposes or by different controllers in a manner that exceeds the data subject’s reasonable expectations,” both of which apply in the present case, as explained above. In any case, Article 35 of the GDPR requires a Data Protection Impact Assessment (DPIA) to be conducted when the processing of personal data is likely to result in a high risk to the rights and freedoms of data subjects, as in the present case, where data on minors affected by an accident, employees’ biometric data, and customers’ health, economic, financial, and bank account number data are processed, among others, including data that cannot be changed (such as national ID or tax ID numbers, date of birth) or is very difficult to change (address)—all of which, when combined, may pose a high risk to the data subjects if compromised. - ALKORA states that it processes the data of policyholders and beneficiaries in accordance with the legal and contractual obligations required of it as an insurance intermediary. It does not use this data for any purpose other than strict compliance with the obligations legally assigned to it as an insurance distributor. And it is no coincidence that, unlike insurance companies, insurance brokerages are not required to appoint a DPO. 6 Jorge Juan Street, 28001 – Madrid48/76 www.aepd.es sedeaepd.gob.es This is due to the clear purpose limitation on the processing activities they carry out. In this regard, this Agency wishes to note that it does not consider that ALKORA processes personal data for any purpose other than the provision of services as an insurance company, but it does consider that the fact that such enterprises are not required to appoint a DPO has nothing to do with the possibility that the data processing carried out by ALKORA does not pose a high risk to the data subject rights and freedoms, which must be analyzed on a case-by-case basis pursuant to Article 35 of the GDPR. - ALKORA argues that appropriate technical and organizational measures, proportionate to the risk, have been adopted, including: o (…) And that these measures significantly reduce the level of potential risk that could arise from the processing, to a threshold at which conducting a DPIA in accordance with Article 35 of the GDPR is not required. This Agency views the adoption of such measures favorably but considers that, even with these measures in place, the risk to the data subject rights and freedoms remains high, given that ALKORA handles data on minors affected by an accident, employees’ biometric data, and customers’ health, economic, financial, and bank account information, among other data, including data that cannot be changed (such as national ID or tax ID numbers, date of birth) or is very difficult to change (address), all of which, when combined, could pose a high risk to the data subjects if compromised. - ALKORA cites the list published by the AEPD of processing activities that require a Data Protection Impact Assessment (DPIA). It notes that the processing described is not included in that list, nor in the EDPB’s positive or negative lists, which reinforces the conclusion that there is no legal obligation per se to conduct the assessment. In this regard, this Agency wishes to point out that such a list is neither exhaustive nor definitive. It is reiterated that Article 35 of the GDPR requires a DPIA to be conducted when the processing of personal data may pose a high risk to data subject rights and freedoms, as in the present case, where data on minors affected by an accident, employees’ biometric data, and customers’ health, economic, financial, and bank account information are processed, among others, including data that cannot be changed (such as ID or tax identification numbers, date of birth) or is very difficult to change (address)—all of which, when combined, may pose a high risk to the data subjects if compromised. Finally, ALKORA argues that, although it was ultimately decided—with proper justification— not to conduct a data protection impact assessment (DPIA) of the processing activities, an analysis was indeed carried out of the main risks that could arise from those processing activities. And that, while the advisability of conducting a DPIA was initially assessed, a thorough analysis of the context, nature, and scope of the processing led 6 Jorge Juan Street, 28001 – Madrid49/76 www.aepd.es sedeaepd.gob.es to the conclusion that the conditions required by Article 35 of the GDPR for it to be mandatory were not met. In this regard, this Agency wishes to point out that, although the enterprise conducted an analysis of the potential risks, it considers that said analysis was inadequate, since in this case the data being processed includes that of minors affected by an accident, employees’ biometric data, and customers’ health, economic, and financial data as well as bank account numbers, among other information—including data that cannot be changed (such as national ID or tax ID numbers, date of birth) or is very difficult to change (address)— all of which, when combined, could pose a high risk to the data subjects if compromised. For all of the foregoing reasons, this argument is dismissed. THIRD. Regarding the absence of fault and the application of the principle of proportionality. ALKORA argues that even in the hypothetical case that a formal deficiency were found in the security measures or in the risk assessment, this could not be considered a serious infringement, but rather, if anything, an action that should be rectified through corrective measures or a warning, in line with the principle of proportionality and based on Article 58(2)(b) of the GDPR. Furthermore, ALKORA has demonstrated active cooperation with this Agency at all times and a commitment to continuous improvement in the area of data protection. In this regard, this Agency wishes to point out that failing to have risk-appropriate measures in place to ensure the confidentiality of the data being processed, as well as failing to conduct an impact assessment when the processing carried out may pose a high risk to the data subject rights and freedoms, constitutes a serious infringement for the purposes of the GDPR; therefore, a fine may be imposed, if applicable. Consequently, this argument is rejected. IV Failure to Comply. Integrity and Confidentiality Article 5(1)(f) of the GDPR states: "1. Personal data shall be: (…) f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, through the implementation of appropriate technical or organizational measures (‘integrity and confidentiality’).” The principle of confidentiality set forth in Article 5.1(f) of the GDPR requires controllers to ensure that personal data is processed in a manner that guarantees the confidentiality of such data, preventing unauthorized access, misuse, or disclosure to unauthorized third parties. This requires implementing appropriate technical and organizational measures of all kinds to 6 Jorge Juan Street, 28001 – Madrid50/76 www.aepd.es sedeaepd.gob.es protect the data against potential data breaches, whether external or internal. These measures must be adequate to prevent risks to the rights and freedoms of natural persons arising from the processing from materializing, and must be reviewed and updated periodically to ensure their effectiveness. In this case, as Annex I to its July 9, 2024, response to this Agency’s request, ALKORA submitted the forensic report prepared by the enterprise ***EMPRESA.1, Version V 1.0 dated May 3, 2023, which was unsigned, which stated that, due to the encryption of the information on the servers, “The method of intrusion, as well as the point of entry, remain undetermined,” that “The encryption of all servers has limited the capacity for analysis, thereby preventing the collection of evidence of the initial intrusion,” and that certain system deficiencies have limited the forensic analysis team’s investigative capacity: “Several factors have contributed to limiting the investigative capacity of the ***ENTERPRISE.1 team: • (…) However, during the investigation conducted by this Agency following the aforementioned breach suffered by ALKORA in April 2023, the security measures that the enterprise had in place before and after the breach were identified. In its letter dated February 14, 2024, in response to the referral of the complaint, ALKORA outlined a series of security measures implemented prior to the incident to protect the confidentiality, integrity, and availability of the personal data in its possession. In that letter, ALKORA also indicated that, as a result of the incident, other security measures had been adopted and that it was in the process of strengthening the security of its systems by implementing additional security measures. As Annex V to its letter dated July 9, 2024 (pp. 131–221 of the document containing all annexes), ALKORA submitted an unsigned internal audit report on its information systems, version v0.04 dated February 20, 2022 (prior to the breach). The IT services risk assessment table in that report, on page 194, indicated an “Extreme” risk (marked in red) for information systems and web portals with regard to cybercrimes. In other words, ALKORA was aware that the risk of suffering a cyberattack was extreme. However, it is clear from that report that ALKORA: - Due to (…). - Relyed on the protection (…). - Did not consider it a source of risk (…). - Considered it sufficient (…). - Created virtual servers (…). - I considered the installed antivirus software (…). - I considered the solutions adopted (…) to be adequate: “(…)” - I considered that no significant improvements could be made in (…).” 6 Jorge Juan Street, 28001 – Madrid51/76 www.aepd.es sedeaepd.gob.es - It had a (…) service which, according to the forensic report (Annex I of ALKORA’s brief dated July 9, 2024), was not effective. The February 2022 internal audit report, submitted as Annex V to ALKORA’s brief dated July 9, 2024 (page 167 of the document including all annexes), stated: (…) Regarding the antivirus software, the forensic report submitted as Annex I to ALKORA’s brief dated July 9, 2024 (pp. 2–44 of the document containing all annexes), indicated that the ***PROGRAMA.2 antivirus software that was installed did not issue any alerts during the encryption of at least one of the workstations. The recommendations in the aforementioned forensic report revealed that ALKORA could have implemented additional measures, which are described on pages 35 through 37 of the document including all appendices, and which the report recommended be adopted as a “High” priority: - (…) In addition, the forensic report recommended the adoption of twenty-two other measures, which it classified as “Medium” and “Low” priorities. ALKORA also provides, as Annex V b of its submission dated July 9, 2024 (pages 222–318 of the document including all annexes), an unsigned “pentesting” audit report (penetration test of its computer system), Version 1.0 dated July 9, 2024. The penetration test, conducted by ***SISTEMA.1, revealed that: “The security audit revealed a number of vulnerabilities and weaknesses which, when jointly exploited, would enable the entire domain to be compromised by gaining domain Administrator privileges, with access only to the internal network.” (unofficial translation: “The security audit revealed a series of vulnerabilities and weaknesses that, when exploited together, would have allowed the entire domain to be compromised by obtaining domain administrator privileges, with access only to the internal network”). Section 3.4 of Annex V b (password audit) indicated that (...) The aforementioned audit highlighted eight “high” severity vulnerabilities: - (…) And 10 “medium” vulnerabilities: - (…) The internal audit report provided as Annex V b of ALKORA’s letter dated July 9, 2024, highlighted some of the reactive measures adopted by ALKORA following the breach: 6 Jorge Juan Street, 28001 – Madrid52/76 www.aepd.es sedeaepd.gob.es - (…) ALKORA also submitted, as Annex V c of its brief dated July 9, 2024 (pp. 319–324 of the document containing all annexes), an unsigned internal incident resolution report following the penetration test, Version 1.0 dated July 9, 2024, in which it stated (…). Regarding training activities, ALKORA submitted an internal audit report on its information systems as Annex V(a) to its brief dated July 9, 2024 (pp. 131–221 of the document containing all annexes), prior to the breach, which indicated that it did not provide cybersecurity training on a widespread basis, but only to employees who requested it, and that it did so because of its reliance on antivirus software. However, ALKORA has provided (pp. 30–32 of its brief dated July 9, 2024) a reference to the documentation included in Annex VII of that brief, relating to training programs that covered topics on personal data protection. Additionally, ALKORA provided, from Annex VII g through Annex VII r of its brief dated July 9, 2024 (pages 431–465 of the document including all annexes), copies of several emails, which it states were distributed by the IT department to ALKORA staff, containing cybersecurity awareness content, including one warning of a phishing attempt detected at the company in the weeks leading up to the breach. Finally, in the annexes to its submission dated July 9, 2024, ALKORA provided documentation regarding the adoption or modification of organizational measures following the breach: From the foregoing, it can be concluded that prior to the breach in question, ALKORA had a series of measures in place that were deemed sufficient in its 2022 internal audit, even though it has been demonstrated that they were not, as reflected in the external reports prepared after the incident in question, all of which has resulted in a loss of confidentiality and availability of the personal data that ALKORA processed as the controller. The foregoing is not undermined by the information now provided by ALKORA in a report received on October 17, 2025, after the present disciplinary proceedings had already been initiated: - Passwords. o During the preliminary investigation, the following information was obtained: “ALKORA also provides (…) a ‘pentesting’ audit report (penetration test of its computer system) dated April 2024. The penetration test, conducted by ***SISTEMA.1, revealed the existence of prior vulnerabilities—most of which stemmed from default configurations—which, if exploited in combination, would allow the entire domain to be compromised by gaining administrator privileges, as well as a low level of internal security. 6 Jorge Juan Street, 28001 – Madrid53/76 www.aepd.es sedeaepd.gob.es Section 3.4 of Annex V b (password audit) indicates that the enterprise was able to uncover 54% of the passwords for active accounts, including two domain administrator accounts. Many of the uncovered passwords were basic and easy to guess, with some Users having similar or even identical passwords.” It also states: “The audit highlighted 8 ‘high’ severity vulnerabilities: (…) (…). The report now provided states the following: “As part of the security strategy, as of November 2022, the system includes the following measures: Secure passwords. Secure user passwords are established within the domain. These passwords are currently set to 8 characters, including a number and a special character. Although the password length may not seem ideal, the requirement to include a number and a special character, combined with the fact that they are linked within the domain, ensures adequate security.” This does not invalidate the facts that came to light during the previous proceedings. - Equipment Always Up to Date. o According to the previous investigative proceedings: “Technical security measures prior to the breach: ALKORA provides (…) an internal audit report on its information systems, dated November 2022 (prior to the breach). The IT services risk assessment table in that report, on page 194 of [10], indicates an “Extreme” risk (marked in red) for information systems and web portals regarding cybercrimes. (…) It did not consider this a source of risk (…). According to the report now provided by ALKORA: “The equipment is constantly kept up to date thanks to ***SERVER.2 in Alkora’s infrastructure. System security is key. ***SERVER.2 (…). This is a requirement for all enterprises, but it applies solely and exclusively to ***SYSTEM.2 systems (which also allow for system updates). It is a major security measure.” This does not refute the findings of the investigation. Although the 2022 audit asserts that the equipment is constantly updated “thanks to ***SERVER.2,” ALKORA does not justify the existence of equipment with outdated operating systems, nor the existence of virtual servers without security restrictions (…), especially when the risk of credential compromise was high. - Antivirus: o According to the preliminary investigation findings: “Technical security measures prior to the breach: (…) It is clear from that report (…) Due to (…) (…)” 6 Jorge Juan Street, 28001 – Madrid54/76 www.aepd.es sedeaepd.gob.es Also, “that internal audit report (…) indicates: (…) (…). As well as: “the forensic report prepared by the enterprise ***ENTERPRISE.1 (…) (…). The report now provided merely states: “A powerful antivirus program is in place (…) This is desirable and necessary in all enterprises, but unfortunately it does not help detect attacks such as the one suffered.” Once again, ALKORA provides no justification for the absence of this security measure at the time of the breach, a measure as basic as the previous ones. - Perimeter firewall: o According to the preliminary investigation findings, as stated in the report provided: “Alkora (…) relied on the protection (…) and did not have (…).” o According to the forensic report now provided: “There is a perimeter firewall (…) one of the most important components and the best security measure an enterprise can adopt.” o However, no information is provided about this software. Installation date? Provider? Technical specifications? Is it in-house, or is it still a third-party service (perhaps still managed by their ISP, as before)? This is not information that can be considered to undermine the findings. - Data encryption: o According to the report provided: “The databases for all applications have all access passwords encrypted to prevent unauthorized access by third parties (…).” The fact that the application passwords are now encrypted does not prove that they were encrypted at the time, but, above all, it does not prove that the information in the databases was encrypted. o This is without prejudice to the fact that, in its breach notifications, ALKORA initially indicated that the data was not encrypted. Also in ALKORA’s report: “Server encryption directly impacts the integrity and availability of the enterprise’s systems and applications. Furthermore, the data exfiltration impacts the confidentiality of the enterprise’s sensitive documents, as well as customers’ personal data. (…) The integrity and availability of all systems and services have been impacted.” ALKORA does not in any way confirm, nor does it provide details regarding, the encryption of the information at the time of the breach that would contradict what was established in previous proceedings. 6 Jorge Juan Street, 28001 – Madrid55/76 www.aepd.es sedeaepd.gob.es In other words, ALKORA does not at any point confirm that the data was encrypted, and therefore does not confirm that the attackers did not have access to it. The report submitted in October 2025 refers to a subsequent audit from April 2024 (penetration test), regarding which it states the following: - “A penetration test was outsourced in April 2024 to verify that the systems are stable and that security has been improved. In this case, seven critical vulnerabilities were identified, but the system PRESENTS NO CRITICAL VULNERABILITIES to external parties,” and it bases its entire subsequent argument on the fact that the vulnerabilities are internal, not external. As well as: “The above is important. It is common for vulnerabilities to exist INTERNALLY within a reliable IT department, given that several Users have access and high-level credentials (IT Department), but the important thing is that there have been ZERO critical vulnerabilities resulting from external attacks.” However, it should be noted that, once the system has been breached, the vulnerabilities to consider are no longer external but internal—which, as indicated by the forensic report and the penetration test, were abundant. Furthermore, external protection is not substantiated, as the organization continues to use the same policy of weak passwords, devices running obsolete operating systems, a firewall managed by its ISP, etc. In fact, the forensic report indicated that once inside the system, attackers were able to move laterally, change passwords, create new User accounts, encrypt devices, evade detection by antivirus software, and more. Indeed, social engineering greatly facilitates the circumvention of external measures, after which experienced attackers move freely within the system thanks to internal vulnerabilities (7 high and 10 medium), which is precisely what occurred in this breach. In short, the information now presented by ALKORA does not invalidate any of the findings from the previous investigative proceedings, which form the basis for the initiation of this disciplinary proceeding, based on the documentation provided by ALKORA itself. The security measures were clearly insufficient, and there is evidence that the attackers gained access to the personal data being processed, as they managed to encrypt the filing systems. Therefore, in accordance with the established facts currently available at the time of this proposed resolution of the disciplinary proceeding, it is considered that the known facts constitute a violation attributable to ALKORA, for breaching Article 5.1.f) of the GDPR. 6 Jorge Juan Street, 28001 – Madrid56/76 www.aepd.es sedeaepd.gob.es V Classification of the Infringement of Article 5(1)(f) of the GDPR and Determination for Statute of Limitations Purposes Article 83(5) of the GDPR classifies the violation of the following articles as an administrative infraction, which shall be sanctioned, in accordance with paragraph 2, with administrative fines of up to 20,000,000 EUR or, in the case of an enterprise, an amount equivalent to up to 4% of the total worldwide annual turnover in the preceding financial year, whichever is higher: “a) the basic principles of processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9;” For its part, article 71 of the LOPDGDD, “Infractions,” states that: “The acts and conduct referred to in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this organic law.” For the sole purpose of the statute of limitations, article 72.1 of the LOPDGDD establishes the following: “Pursuant to Recital 83(5) of Regulation (EU) 2016/679, infringements that constitute a substantial violation of the articles mentioned therein, and in particular the following, are considered very serious and shall be subject to a three-year statute of limitations: a) The processing of personal data in violation of the principles and safeguards established in Article 5 of Regulation (EU) 2016/679.” VI Proposed Penalty for the Violation of Article 5.1.f) of the GDPR In order to determine the administrative fine to be imposed, the provisions of Articles 83(1) and 83(2) of the GDPR must be observed, which state: “1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this article for the infringements of this Regulation referred to in paragraphs 4, 9, and 6 is, in each individual case, effective, proportionate, and dissuasive. 2. Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or in lieu of the measures referred to in Article 58(2)(a) through (h) and (j). When deciding whether to impose an administrative fine and its amount in each individual case, due account shall be taken of: a) the nature, gravity, and duration of the violation, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the extent of the harm they have suffered; b) whether the infringement was intentional or due to negligence; 6 Jorge Juan Street, 28001 – Madrid57/76 www.aepd.es sedeaepd.gob.es c) any measures taken by the controller or processor to mitigate the damage suffered by the data subjects; d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures they have implemented pursuant to Articles 25 and 32; e) any previous infringements committed by the controller or processor; f) the degree of cooperation with the supervisory authority to remedy the infringement and mitigate its potential adverse effects; g) the categories of data affected by the breach; h) the manner in which the supervisory authority became aware of the breach, in particular whether the controller or processor reported the breach and, if so, to what extent; i) where the measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned in relation to the same matter, compliance with those measures; j) adherence to codes of conduct pursuant to Article 40 or to certification mechanisms approved in accordance with Article 42; and k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as the financial benefits obtained or the losses avoided, directly or indirectly, as a result of the violation.” For its part, article 76, “Sanctions and Corrective Measures,” of the LOPDGDD provides: “1. The penalties provided for in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the criteria for determining the level of the penalty set forth in paragraph 2 of that article. 2. In accordance with the provisions of Article 83(2)(k) of Regulation (EU) 2016/679, the following may also be taken into account: a) The ongoing nature of the violation. b) The connection between the infringer’s activities and the processing of personal data. c) The benefits obtained as a result of the infringement. d) The possibility that the data subject’s conduct may have contributed to the commission of the violation. e) The existence of a merger by absorption that occurred after the infringement was committed, for which the acquiring entity cannot be held liable. f) The impact on the rights of minors. g) Having a data protection officer, even when not required by law. h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms in cases where disputes arise between them and any data subject.” In the present case, in recital of the seriousness of the potential violations, with particular regard to the consequences their commission has on those affected, the imposition of a fine would be appropriate. The fine imposed must be, in each individual case, effective, proportionate, and dissuasive, in accordance with the provisions of Article 83(1) of the GDPR. To ensure 6 Jorge Juan Street, 28001 – Madrid58/76 www.aepd.es sedeaepd.gob.es these principles, ALKORA’s annual turnover (€24,007,236 in 2024) is taken into account as a preliminary matter. For the purposes of deciding on the imposition of an administrative fine and its amount, in accordance with the established facts currently available in this draft resolution of the disciplinary proceeding, it is considered appropriate to determine the penalty to be imposed based on the following circumstances, as set forth in the aforementioned provisions. As a preliminary matter, it is determined that the following circumstances exist: • The nature, gravity, and duration of the violation, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the extent of the damages they have suffered (Article 83(2)(a) of the GDPR): for failing to implement security measures appropriate to the risk of a data breach such as the one that occurred in this case, which involved personal data such as national ID number or tax ID number, first and last names, mailing or email address, phone number, image, handwritten signature, social security or mutual insurance number, health data, marital status, family information, date and place of birth, age, sex, nationality, housing and property data, academic and professional data, commercial information, employment data, economic, financial, and insurance data, and bank account numbers, of 40,000 individuals (including employees, customers and Users, suppliers, and policyholders, insured parties, and beneficiaries of its insurance policies). The fact that various types of personal data belonging to the data subjects are being processed is also taken into account when determining the severity of the penalty. The combined effect of all these different types of personal data means that the potential consequences—the impact of the risk materializing for the data subjects— are of greater significance. Furthermore, given the large volume of data involved—some of which cannot be changed (such as ID or tax identification numbers and dates of birth) or cannot be changed easily (such as mailing addresses)—the risk to the rights and freedoms of the data subjects and the potential impact on them is even greater, not to mention that any loss of access to or control over their personal data may be irreversible. • Intent or negligence in the breach (Article 83(2)(b) of the GDPR): No particular negligence or intent is apparent that would be noteworthy and that would lead to assessing this circumstance differently from a neutral assessment, in accordance with Guidelines 04/2022. • The categories of personal data affected by the breach (Article 83(2)(g) of the GDPR): In this case, ALKORA processes health data of the policyholder, the insured, and the beneficiary of its insurance policies, as well as biometric data of its employees (fingerprints). It also processes economic and financial data, as well as bank account numbers, of the policyholder, insured person, and beneficiary of its insurance policies; all of which, in the absence of adequate security measures, posed a greater risk to the rights and freedoms of the data subject. 6 Jorge Juan Street, 28001 – Madrid59/76 www.aepd.es sedeaepd.gob.es Finally, ALKORA also processes national ID numbers (DNI) or tax identification numbers (NIF). The numerical identifier of the DNI, together with the verification character corresponding to the tax identification number, unambiguously identifies a natural person. This characteristic makes it particularly sensitive data because, to the extent that its processing is not accompanied by the necessary technical and organizational measures to ensure that the person identifying themselves with it is truly the data subject, a third party can easily impersonate a natural person—or, in other words, commit identity fraud—with the risks that this entails for the privacy, reputation, and assets of the person being impersonated. Likewise, the following aggravating factors are considered: • The connection between the offender’s activity and the processing of personal data (Article 76.2(b) of the LOPDGDD): ALKORA is an insurance brokerage with thousands of clients that, in order to carry out its business, requires the continuous processing of personal data. • The impact on the rights of minors (Article 76.2(f) of the LOPDGDD): As stated in its submission dated July 9, 2024, ALKORA processes data on minors when handling accident claims files, which include the minor’s first name, last name, date of birth, and general information about the circumstances of the accident. ALKORA had processed 75 such cases over the past four years. Likewise, the following mitigating factors are considered: • “Any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement” (Article 83(2)(k) of the GDPR): The assessment of ALKORA’s conduct in this case requires consideration of the actions taken by the entity to comply with the provisions of the GDPR and the LOPDGDD, in accordance with the principle of continuous improvement. Without overlooking the fact that such continuous improvement is an obligation incumbent upon controllers, it is deemed appropriate to consider the attitude demonstrated by ALKORA, which, throughout the proceedings, has reported on the implementation of various measures aimed at complying with data protection regulations. After weighing the circumstances set forth in Article 83(2) of the GDPR and Article 76(2) of the LOPDGDD, with respect to the violation committed by breaching the provisions of Article 5(1)(f) of the GDPR, it is proposed that an administrative fine of 150,000.00 euros be imposed. 6 Jorge Juan Street, 28001 – Madrid60/76 www.aepd.es sedeaepd.gob.es VII Failure to Comply. Data Protection Impact Assessment The data protection impact assessment is regulated by Article 35 of the GDPR in the following terms: "1. Where a type of processing, in particular where new technologies are used, is likely, by virtue of its nature, scope, context, or purpose, to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, conduct an assessment of the impact of the processing operations on data protection. A single assessment may address a series of similar processing operations that entail similar high risks. 2. The controller shall seek the advice of the data protection officer, if one has been appointed, when conducting the data protection impact assessment. 3. The data protection impact assessment referred to in paragraph 1 shall be required in particular in the case of: a) a systematic and comprehensive evaluation of personal aspects of natural persons based on automated processing, such as profiling, and on the basis of which decisions are made that produce legal effects on natural persons or similarly significantly affect them; b) large-scale processing of special categories of data referred to in Article 9(1) or of personal data relating to criminal convictions and offenses referred to in Article 10; or c) systematic large-scale monitoring of a public area. 4. The supervisory authority shall establish and publish a list of the types of processing operations that require a data protection impact assessment in accordance with paragraph 1. The supervisory authority shall communicate those lists to the Committee referred to in Article 68. 5. The supervisory authority may also establish and publish a list of the types of processing that do not require data protection impact assessments. The supervisory authority shall communicate those lists to the Committee. 6. Before adopting the lists referred to in paragraphs 4 and 5, the competent supervisory authority shall apply the consistency mechanism provided for in article 63 if those lists include processing activities related to the offering of goods or services to data subjects or to the monitoring of their behavior in several Member States, or processing activities that may substantially affect the free flow of personal data within the Union. 7. The assessment shall include at least: a) a systematic description of the intended processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller; 6 Jorge Juan Street, 28001 – Madrid61/76 www.aepd.es sedeaepd.gob.es b) an assessment of the necessity and proportionality of the processing operations in relation to their purpose; c) an assessment of the risks to the data subject rights and freedoms referred to in paragraph 1; and d) the measures envisaged to address the risks, including safeguards, security measures, and mechanisms to ensure data protection and to demonstrate compliance with this Regulation, taking into account the rights and legitimate interests of the data subjects and other individuals concerned. 8. Compliance by the relevant controllers or processors with approved codes of conduct referred to in Article 40 shall be taken into due account when assessing the impact of the processing operations carried out by such controllers or processors, in particular for the purposes of the data protection impact assessment. 9. Where appropriate, the controller shall seek the views of data subjects or their representatives regarding the intended processing, without prejudice to the protection of public or commercial interests or the security of processing operations. 10. Where processing pursuant to Article 6(1)(c) or (e) has its legal basis in Union law or in the law of the Member State applicable to the controller, and such law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 through 7 shall not apply unless Member States deem it necessary to conduct such an assessment prior to the processing activities. 11. Where necessary, the controller shall assess whether the processing is in accordance with the data protection impact assessment, at least where there is a change in the risk posed by the processing operations." The need to conduct a data protection impact assessment (DPIA) stems from the principle of proactive accountability set forth in the GDPR itself, and it is an essential tool for ensuring that entities with certain characteristics in their data processing manage and process personal data responsibly, securely, and in compliance with applicable regulations, thereby protecting the rights of data subjects and strengthening trust in their operations. The purpose of the DPIA, as set forth in Article 35 of the GDPR, is multifaceted and focuses on ensuring data protection for natural persons’ personal data. Among these purposes, the following are particularly noteworthy: - Identifying and assessing potential risks to individuals’ rights and freedoms that could arise as a result of the processing of personal data. This is particularly important when new technologies are used or large-scale data processing is carried out. 6 Jorge Juan Street, 28001 – Madrid62/76 www.aepd.es sedeaepd.gob.es - Helping organizations comply with the GDPR, as it ensures that regulatory requirements related to data protection by design and by default are met. - Implementing risk mitigation measures. Based on the identified risks, the DPIA guides organizations in implementing appropriate measures to mitigate those risks. This may include adjustments to how personal data is collected, stored, processed, or shared. - Prevent potential harm and/or data breaches, as through proactive risk identification and mitigation, the EIPD helps prevent data breaches and other harm that could result from the improper processing of personal data, which may lead to legal consequences. In the present case, on February 14, 2024, this Agency received a written response to the referral of the complaint, to which the Risk Analysis dated September 19, 2019, version 0.1, was attached as Annex V. This document lists five filing systems: “LABOR AND HR,” “INSURANCE BROKERAGE FOR INDIVIDUALS,” “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS,” “INSURANCE CLAIMS,” and “TAX AND ACCOUNTING.” Regarding the “LABOR AND HR” filing system, the following is indicated: “Categories of data subjects: Employees” “Identifying data: National ID number (DNI) or Tax ID number (NIF), first and last names, mailing or email address, phone number, handwritten signature, Social Security number or mutual insurance number Special categories of data: Digitized fingerprint (biometric data) Other type of data Characteristics Personal, Academic and professional, Details of employment, Transactions of goods and services.” Regarding “INSURANCE BROKERAGE FOR INDIVIDUALS”: “Identifying information: ID number or Tax ID number, first and last names, mailing or email address, phone number, handwritten signature Special categories of data: N/A Other types of data: Personal data, academic and professional information, transactions involving goods and services, social circumstances, commercial information, economic, financial, and insurance information” Regarding “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS”: “Identifying data: National ID number (DNI) or Tax ID number (NIF), first and last names, mailing or email address, phone number, handwritten signature Special categories of data: Health 6 Jorge Juan Street, 28001 – Madrid63/76 www.aepd.es sedeaepd.gob.es Other types of data: Personal data, academic and professional information, transactions involving goods and services, social circumstances, economic, financial, and insurance information” Regarding “INSURANCE CLAIMS”: “Identifying information: National ID number (DNI) or Tax ID number (NIF), first and last names, mailing or email address, phone number, handwritten signature, image Special categories of data: Health Other types of data: Personal data, academic and professional information, transactions involving goods and services, social circumstances, economic, financial, and insurance information” Regarding “TAX AND ACCOUNTING”: “Identifying information: ID number or tax ID number, first and last names, mailing or email address, phone number Special categories of data: N/A Other types of data: N/A” Regarding the risks associated with each filing system, the aforementioned Risk Analysis states: - Regarding “Filing System 1: EMPLOYMENT AND HR”: o The identifying data and other specified data subject to processing are considered to have an initial “Low” risk. o Regarding “Data Protection (Integrity and Confidentiality),” it is indicated that “There are adequate measures in place to protect the data against unauthorized processing and loss or destruction, in accordance with the provisions of this document,” an initial risk of “Medium” is assigned, and the measures detailed are “Ensuring that adequate technical and organizational measures have been implemented to protect the data through the corresponding periodic annual verification,” after which a final risk of “Very Low” is assigned. o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data subject rights and freedoms,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “It has been verified that the risk analysis conducted does not identify any threats with a probability of high risk to the data subject rights and freedoms,” after which a final risk of “Low” is assigned. o Regarding “Access to special categories of data,” it is stated that “There are no special categories of data,” and therefore it is assigned an initial and final risk rating of “Very Low.” - Regarding “Filing System 2: INSURANCE BROKERAGE FOR INDIVIDUALS”: o It is considered that the identifying data and other specified data subject to processing have an initial risk of “Low.” 6 Jorge Juan Street, 28001 – Madrid64/76 www.aepd.es sedeaepd.gob.es o Regarding “Data Protection (Integrity and Confidentiality),” it is indicated that “There are adequate measures in place to protect the data against unauthorized processing and loss or destruction, in accordance with the provisions of this document,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “Ensure that adequate technical and organizational measures have been implemented to protect the data through the corresponding periodic annual verification,” after which a final risk of “Very low” is assigned. o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data subject rights and freedoms,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “It has been verified that the risk analysis conducted does not identify any threats with a probability of high risk to the data subject rights and freedoms,” after which a final risk of “Low” is assigned. o Regarding “Access to special categories of data,” it is stated that “There are no special categories of data,” and therefore an initial and final risk rating of “Very Low” is assigned. - Regarding “Filing System 3: LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS”: o It is considered that the identifying data and other specified data subject to processing have an initial risk of “Low.” However, health data are assigned an initial risk of “High.” o Regarding “Data Protection (Integrity and Confidentiality),” it is stated that “There are adequate measures in place to protect data against unauthorized processing and loss or destruction, in accordance with the provisions of this section of the document,” an initial risk level of “Medium” is assigned, and the measures detailed are “Ensuring that appropriate technical and organizational measures have been implemented to protect the data through the corresponding periodic annual verification,” after which a final risk level of “Low” is assigned o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data subject rights and freedoms,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “It has been verified that the risk analysis conducted does not identify any threats with a high probability of risk to the data subject rights and freedoms,” after which a final risk of “Low” is assigned. o Regarding “Access to special categories of data,” it is stated that “ADDITIONAL security measures EXIST in accordance with the provisions of section 4.4 of this document”; an initial risk rating of “Medium” is assigned, and the measures are detailed as follows: “An up-to-date record must be maintained of personnel with access to special categories of data. It is recommended to strengthen measures with two-factor 6 Jorge Juan Street, 28001 – Madrid65/76 www.aepd.es sedeaepd.gob.es authentication, encryption…,” after which a final risk rating of “Very low” is assigned. - Regarding “Filing System 4: INSURANCE CLAIMS”: o The identifying data and other specified data subject to processing are considered to have an initial risk of “Low.” However, health data is assigned an initial risk of “High.” o Regarding “Data Protection (Integrity and Confidentiality),” it is stated that “There are adequate measures in place to protect the data against unauthorized processing and loss or destruction, in accordance with the provisions of this document,” it is assigned an initial risk of “Medium,” and the measures are detailed as follows: “Ensure that adequate technical and organizational measures have been implemented to protect the data through the corresponding periodic annual verification,” after which a final risk of “Low” is assigned. o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data subject rights and freedoms,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “It has been verified that the risk analysis conducted does not identify any threats with a high probability of risk to the data subject rights and freedoms,” after which a final risk of “Low” is assigned. o Regarding “Access to special categories of data,” it is stated that “ADDITIONAL security measures are in place in accordance with the provisions of section 4.4 of this document”; an initial risk rating of “Medium” is assigned, and the measures are detailed as follows: “An up-to-date record must be maintained of personnel with access to special categories of data. It is recommended to strengthen these measures with two-factor authentication, encryption…”, after which a final risk rating of “Very low” is assigned. - Regarding “Filing System 5: TAX AND ACCOUNTING”: o The identifying data subject to processing is considered to have an initial risk of “Low.” o As for “Data Protection (Integrity and Confidentiality),” it is stated that “There are adequate measures in place to protect the data against unauthorized processing and loss or destruction, in accordance with the provisions of this document,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “Ensure that adequate technical and organizational measures have been implemented to protect the data through the corresponding periodic annual verification,” after which a final risk of “Low” is assigned o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data subject rights and freedoms,” an initial risk of “Medium” is assigned, and the measures are detailed as follows: “It has been verified that the risk analysis conducted does not identify the 6 Jorge Juan Street, 28001 – Madrid66/76 www.aepd.es sedeaepd.gob.es existence of threats with a probability of high risk to the data subject rights and freedoms,” after which a final risk rating of “Low” is assigned. o Regarding “Access to special categories of data,” it is stated that “There are no special categories of data,” and therefore an initial and final risk rating of “Very Low” is assigned. - “Processing of data of children under 14 years of age” is mentioned as a specific processing activity, indicating that “Data processing of children under 14 years of age is carried out only in cases of school accidents”; an initial risk level of “Medium” is assigned, and the measures indicated are “Ensure that the measures referred to in section 4.4 are adopted through the corresponding periodic annual verification audit.” Following this, a final risk rating of “Low” is indicated. In other words, although ALKORA processed its customers’ health data and its employees’ biometric data, as well as its customers’ economic, financial, and bank account information—all of which, without adequate security measures, posed a greater risk to the data subject rights and freedoms—it had not considered that there might be a high risk to the data subjects. Nor had it even been taken into account that various types of personal data belonging to the data subjects were being processed, which, when combined, would make the potential consequences—the impact of the risk materializing for the data subjects—more significant. Furthermore, some of this data could not be changed (such as ID numbers or tax identification numbers and dates of birth) or could not be changed easily (such as mailing addresses), which meant that the risk to the rights and freedoms of the data subjects and the potential impact on them would be even greater, not to mention that a potential loss of access to and control over their personal data could be irreversible. The aforementioned Risk Analysis, provided as Annex V to the letter dated February 14, 2024, in response to the referral of the complaint, included, among others, the following sections under “REGULATORY COMPLIANCE” (file number in parentheses): Security Policy (1; 2; 3; 4; 5) - Processing Risks: “The processing has been analyzed, and there is no likelihood of a high risk to the data subject rights and freedoms.” Security Policy (3; 4) - Impact Assessment: “The processing has been analyzed in accordance with the Report on the Need to Conduct an Impact Assessment, and there is no likelihood of a high risk to the data subject rights and freedoms.” The “ORGANIZATION” section of the aforementioned Risk Analysis stated: “[A DPIA is not required because] the processing does not pose a high risk to the rights and freedoms of natural persons.” 6 Jorge Juan Street, 28001 – Madrid67/76 www.aepd.es sedeaepd.gob.es ALKORA also provided, as Annex III to its letter dated July 9, 2024 (pages 52–119 of the document including all annexes), an unsigned Risk Analysis (RA), version 2.0 dated November 1, 2023, which was prepared after the data breach, in which it reclassifies the initial and final risks for filing systems 3 and 4—which involve the processing of health data—as “High”; this RA maintains the initial and final risks associated with the processing of filing systems 1 and 5—which include banking data—as “Medium” and “Low,” respectively. This new risk analysis also mentions the need to conduct a Data Protection Impact Assessment (DPIA) for filing systems 3 and 4. ALKORA also provides, as Annex IV to its letter dated July 9, 2024 (pages 120–130 of the document containing all annexes), an unsigned report, version 2.0 dated November 1, 2023, on the need to conduct impact assessments, which concludes that such assessments are necessary for the “Health and Life Insurance Brokerage” and “Claims” filing systems due to the processing of special categories of data and data on vulnerable groups: “Conclusions: At least two of the criteria established in the AEPD’s list of processing activities are met in the “Health and Life Insurance Brokerage” and “Claims” filing systems, as they involve data on vulnerable groups, such as minors, as well as special categories of data—‘health data’—therefore making it necessary to conduct a Data Protection Impact Assessment on the aforementioned processing activities, as they could pose a high risk to the data subject rights and freedoms. Likewise, Alkora prepared a report on the need to appoint a data protection officer, in which it analyzed whether or not large-scale processing of personal data is taking place; the analysis was inconclusive due to the lack of clarity in the criteria established by WP 243. However, since at least two of the AEPD’s criteria are already met, we consider it necessary to conduct a Data Protection Impact Assessment (DPIA) regarding the processing of minors’ data and health data in the relevant filing systems.” However, there is no record in this case file that ALKORA provided this Agency with the aforementioned DPIA reports. Therefore, based on the established facts currently available in this proposal for a resolution on disciplinary proceedings, it is considered that the known facts constitute a violation attributable to ALKORA for breaching Article 35 of the GDPR. VIII Classification of the violation of Article 35 of the GDPR and determination of the statute of limitations Article 83(4) of the GDPR classifies violations of the following articles as administrative offenses, which shall be penalized, in accordance with paragraph 2, with administrative fines of up to 10,000,000 EUR or, in the case of an enterprise, an amount equivalent to up to 2% of the total annual global turnover for the previous fiscal year, whichever is higher: 6 Jorge Juan Street, 28001 – Madrid68/76 www.aepd.es sedeaepd.gob.es “a) the obligations of the controller and the processor under Articles 8, 11, 25 through 39, 42, and 43.” For its part, article 71 of the LOPDGDD, “Infractions,” states that: “The acts and conduct referred to in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law.” For the sole purpose of the statute of limitations, article 73 of the LOPDGDD establishes the following: “Pursuant to Recital 83(4) of Regulation (EU) 2016/679, infringements that constitute a substantial violation of the articles mentioned therein—and, in particular, the following—are considered serious and shall be subject to a two-year statute of limitations: t) The processing of personal data without having carried out an assessment of the impact of the processing operations on data protection in cases where such an assessment is required.” IX Proposed Penalty for the Violation of Article 35 of the GDPR In order to determine the administrative fine to be imposed, the provisions of Articles 83(1) and 83(2) of the GDPR must be observed, which state: “1. Each supervisory authority shall ensure that the administrative fines imposed pursuant to this article for the infringements of this Regulation referred to in paragraphs 4, 9, and 6 are, in each individual case, effective, proportionate, and dissuasive. 2. Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or in lieu of the measures referred to in Article 58(2)(a) through (h) and (j). When deciding whether to impose an administrative fine and its amount in each individual case, due account shall be taken of: a) the nature, gravity, and duration of the violation, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the extent of the harm they have suffered; b) whether the infringement was intentional or due to negligence; c) any measures taken by the controller or processor to mitigate the damage suffered by the data subjects; d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures they have implemented pursuant to Articles 25 and 32; e) any previous infringements committed by the controller or processor; f) the degree of cooperation with the supervisory authority to remedy the infringement and mitigate its potential adverse effects; g) the categories of personal data affected by the breach; 6 Jorge Juan Street, 28001 – Madrid69/76 www.aepd.es sedeaepd.gob.es h) the manner in which the supervisory authority became aware of the breach, in particular whether the controller or processor reported the breach and, if so, to what extent; i) where the measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned in relation to the same matter, compliance with those measures; j) adherence to codes of conduct pursuant to Article 40 or to certification mechanisms approved in accordance with Article 42; and k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as the financial benefits obtained or the losses avoided, directly or indirectly, as a result of the violation.” For its part, article 76, “Sanctions and Corrective Measures,” of the LOPDGDD provides: “1. The penalties provided for in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the criteria for determining the level of the penalty set forth in paragraph 2 of that article. 2. In accordance with the provisions of Article 83(2)(k) of Regulation (EU) 2016/679, the following may also be taken into account: a) The ongoing nature of the infringement. b) The connection between the infringer’s activities and the processing of personal data. c) The benefits obtained as a result of the infringement. d) The possibility that the data subject’s conduct may have contributed to the commission of the violation. e) The existence of a merger by absorption that occurred after the infringement was committed, for which the acquiring entity cannot be held liable. f) The impact on the rights of minors. g) Having a data protection officer, even when not required by law. h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms in cases where disputes arise between them and any data subject.” In the present case, in recital of the seriousness of the potential violations, with particular regard to the consequences their commission has on those affected, the imposition of a fine would be appropriate. The fine imposed must, in each individual case, be effective, proportionate, and dissuasive, in accordance with the provisions of Article 83(1) of the GDPR. To ensure these principles are upheld, ALKORA’s annual turnover (€24,007,236 in 2024) is taken into account as a preliminary consideration. For the purposes of deciding on the imposition of an administrative fine and its amount, in accordance with the established facts currently available in this proposed resolution of the disciplinary proceeding, it is considered appropriate to determine the penalty to be imposed based on the following circumstances, as set forth in the aforementioned provisions. 6 Jorge Juan Street, 28001 – Madrid70/76 www.aepd.es sedeaepd.gob.es First, it is determined that the following circumstances exist: • The nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the extent of the damage they have suffered (Article 83(2)(a) of the GDPR): failure to conduct a data protection impact assessment, despite it being required given the high risk that the processing of their personal data posed to the rights and freedoms of ALKORA’s 56,000 customers (https://www.alkora.es/cifras-alkora/). The fact that various types of personal data belonging to the data subjects are being processed is also taken into account when determining the penalty. The combined effect of all these different types of personal data means that the potential consequences—the impact of the risk materializing for the data subjects—are of greater significance. Furthermore, given the large volume of data involved—some of which cannot be changed (such as national ID numbers, tax identification numbers, and dates of birth) or cannot be changed easily (such as mailing addresses)—the risk to the rights and freedoms of the data subjects and the potential impact on them is even greater, not to mention that any loss of access to or control over their personal data may be irreversible. • Intent or negligence in the breach (Article 83(2)(b) of the GDPR): No particular negligence or intent is apparent that would be noteworthy and that would lead to assessing this circumstance differently from a neutral assessment, in accordance with Guidelines 04/2022. • The categories of personal data affected by the breach (Article 83(2)(g) of the GDPR): In this case, ALKORA processes health data of the policyholder, the insured, and the beneficiary of its insurance policies, as well as biometric data of its employees (fingerprints). It also processes economic and financial data, as well as bank account numbers, of the policyholder, insured person, and beneficiary of its insurance policies; all of which, in the absence of adequate security measures, posed a greater risk to the rights and freedoms of the data subject. Finally, ALKORA also processes the DNI or NIF number. The numerical identifier of the DNI, together with the check digit corresponding to the tax identification number, unambiguously identifies a natural person. This characteristic makes it particularly sensitive data because, to the extent that its processing is not accompanied by the necessary technical and organizational measures to ensure that the person identifying themselves with it is actually the holder, a third party can easily impersonate a natural person—or, in other words, commit identity fraud—with the risks that this entails for the privacy, reputation, and assets of the person being impersonated. Likewise, the following aggravating factors are considered: 6 Jorge Juan Street, 28001 – Madrid71/76 www.aepd.es sedeaepd.gob.es • The connection between the offender’s activity and the processing of personal data (Article 76.2(b) of the LOPDGDD): ALKORA is an insurance brokerage with thousands of clients that, in order to carry out its business, requires the continuous processing of personal data. • The impact on the rights of minors (Article 76.2(f) of the LOPDGDD): As stated in its submission dated July 9, 2024, ALKORA processes data on minors when handling accident claims files, which include the minor’s first name, last name, date of birth, and general information about the circumstances of the accident. Furthermore, over the past four years, ALKORA has processed 75 such cases. After weighing the circumstances set forth in Article 83.2 of the GDPR and Article 76.2 of the LOPDGDD, with respect to the violation of Article 35 of the GDPR, an administrative fine of 100,000.00 euros is proposed. X Adoption of Measures If the violation is confirmed, it may be decided to require the controller to adopt appropriate measures to bring its actions into compliance with the regulations mentioned in this decision, in accordance with the provisions of the aforementioned article 58(2)(d) of the GDPR, pursuant to which each supervisory authority may “order the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specific manner and within a specified time limit…”. The imposition of this measure is compatible with the administrative fine, as provided for in Art. 83(2) of the GDPR. Thus, it is proposed that the decision to be adopted require ALKORA, within 3 months from the date on which the final decision concluding this proceeding becomes enforceable, to take the following measures: - Provide evidence of the preparation of the mandatory data protection impact assessment required by Article 35 of the GDPR. Please be advised that failure to comply with any order to adopt measures imposed by this agency in the penalty decision may be considered an administrative violation under the provisions of the GDPR, classified as a violation in Articles 83(5) and 83(6), and such conduct may lead to the initiation of further administrative penalty proceedings. In light of the foregoing, the following is hereby issued: PROPOSED DECISION That the Presidency of the Spanish Data Protection Agency impose a sanction on ALKORA EBS CORREDURIA DE SEGUROS Y REASEGUROS SAU, with Tax ID No. 6 Jorge Juan Street, 28001 – Madrid72/76 www.aepd.es sedeaepd.gob.es A01051747, for a violation of Article 5(1)(f) of the GDPR, as defined in Article 83.5 of the GDPR, with a fine of 150,000.00 (one hundred fifty thousand euros) and for a violation of Article 35 of the GDPR, as defined in Article 83.4, with a fine of 100,000.00 € (one hundred thousand euros). That the Presidency of the Spanish Data Protection Agency order ALKORA EBS CORREDURIA DE SEGUROS Y REASEGUROS SAU, with Tax ID No. A01051747, to provide proof, pursuant to Article 58(2)(d) of the GDPR, within a maximum period of 3 months, that it has complied with the requirement to conduct the mandatory data protection impact assessment mandated by Article 35 of the GDPR. Furthermore, in accordance with the provisions of Article 85.2 of the LPACAP, you are hereby informed that you may, at any time prior to the resolution of this proceeding, voluntarily pay the proposed fine, which will result in a 20% reduction of the amount thereof. With the application of this reduction, the fine would be set at 200,000.00 euros, and its payment will result in the termination of the proceedings, without prejudice to the imposition of the corresponding measures. The effectiveness of this reduction is conditional upon the withdrawal or waiver of any administrative action or appeal against the fine. Should you choose to proceed with the voluntary payment of the amount specified above, in accordance with the provisions of the aforementioned Article 85.2, you must make the payment by depositing the funds into the restricted account with IBAN: ES00-0000-0000- 0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX) held in the name of the Spanish Data Protection Agency at CAIXABANK, S.A., indicating in the payment description the reference number of the proceeding shown in the header of this document and the reason—voluntary payment to reduce the amount of the penalty. You must also send proof of payment to the Subdirectorate General for Inspection so that the case may be closed. Accordingly, you are hereby notified of the foregoing, and the procedure is set forth so that, within TEN DAYS, you may present any arguments in your defense and submit any documents and information you deem relevant, in accordance with Article 89.2 of the LPACAP. 926-250625 R.R.R. INSPECTOR/INVESTIGATOR 6 Jorge Juan Street, 28001 – Madrid73/76 www.aepd.es sedeaepd.gob.es ATTACHMENT Table of Contents for Case EXP202400624 (…) >> SECOND: On February 18, 2026, ALKORA paid the penalty in the amount of 200,000.00 euros, taking advantage of the reduction provided for in the draft resolution transcribed above. THIRD: The draft decision transcribed above established the facts constituting the infringement and proposed that the Presidency require the controller to adopt appropriate measures to bring its actions into compliance with the regulations, in accordance with the provisions of the aforementioned article 58(2)(d) of the GDPR, according to which each supervisory authority may “order the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specific manner and within a specified time limit…”. LEGAL GROUNDS I Jurisdiction In accordance with the powers granted to each supervisory authority by Article 58(2) of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and pursuant to the provisions of Articles 47, 48(1), 64(2), and 68(1) of Organic Law 3/2018 of December 5 on Data Protection and the Guarantee of Digital Rights (hereinafter LOPDGDD), the Presidency of the Spanish Data Protection Agency has jurisdiction to rule on this proceeding. Likewise, article 63.2 of the LOPDGDD provides that: “Proceedings handled by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, this Organic Law, the implementing regulations issued thereunder, and, to the extent they do not conflict with the foregoing, on a subsidiary basis, by the general rules on administrative proceedings." II Conclusion of the Procedure Article 85 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), under the heading “Termination of Sanctioning Proceedings,” provides as follows: “1. Once disciplinary proceedings have been initiated, if the offender acknowledges liability, the proceedings may be concluded by imposing the appropriate penalty. 6 Jorge Juan Street, 28001 – Madrid74/76 www.aepd.es sedeaepd.gob.es 2. When the penalty is solely monetary in nature, or when both a monetary penalty and a non-monetary penalty may be imposed but the latter has been found to be inappropriate, voluntary payment by the alleged offender, at any time prior to the final decision, shall result in the termination of the proceedings, except with respect to the restoration of the altered situation or the determination of compensation for damages caused by the commission of the violation. 3. In both cases, when the penalty is solely monetary in nature, the body competent to resolve the proceedings shall apply reductions of at least 20% on the amount of the proposed penalty, which may be cumulative. These reductions must be specified in the notice of initiation of proceedings, and their effectiveness shall be conditional upon the withdrawal or waiver of any administrative action or appeal against the penalty. The reduction percentage provided for in this section may be increased by regulation.” III Voluntary Payment In accordance with the provisions of the aforementioned Article 85 of the LPACAP, the notified proposed resolution allowed you to make a voluntary payment of the proposed penalty, which would result in a 20% reduction of its amount. With the application of this reduction, the penalty would be set at 200,000.00 euros, and its payment would result in the termination of the proceedings, without prejudice to the imposition of the corresponding measures. Following the aforementioned proposed resolution, and before this authority issued a final decision, ALKORA, on February 18, 2026, proceeded to make the voluntary payment, availing itself of the 20% reduction. In accordance with Article 85(3) of the LPACAP, the effectiveness of the aforementioned reduction is conditional upon the withdrawal or waiver of any administrative action or appeal against the penalty. It should be noted that, in accordance with the provisions of the LPACAP, as well as the case law of the Supreme Court on this matter, the alleged liable party’s voluntary payment does not exempt the administration from its obligation to resolve and notify all proceedings, regardless of how they were initiated. Similarly, Article 88 of the aforementioned law establishes that the decision bringing the proceedings to a close shall rule on all issues raised by the data subjects and any other issues arising therefrom. Therefore, in accordance with applicable law and after evaluating the criteria for determining the severity of the sanctions, the Presidency of the Spanish Data Protection Agency RESOLVES: FIRST: TO DECLARE that the violations have been committed and TO CONFIRM the sanctions set forth in the operative part of the proposed resolution transcribed in this resolution. 6 Jorge Juan Street, 28001 – Madrid75/76 www.aepd.es sedeaepd.gob.es The sum of the aforementioned amounts totals 250,000.00 euros. Since ALKORA EBS CORREDURIA DE SEGUROS Y REASEGUROS SAU has made a voluntary payment—albeit without acknowledging liability—the total amount is hereby reduced by 20% pursuant to Article 85 of the LPCAP, resulting in a final amount of 200,000.00 euros. The effectiveness of the aforementioned reduction is conditional, in any case, upon the withdrawal or waiver of any administrative action or appeal. SECOND: DECLARE the termination of proceeding EXP202400624, in accordance with the provisions of Article 85 of the LPCAP. Third party: ORDER ALKORA EBS CORREDURIA DE SEGUROS Y REASEGUROS SAU para que en el plazo de 3 meses desde que la presente resolución sea firme y ejecutiva, notifique a la Agencia la adopción de las medidas descritas en los fundamentos de derecho de la propuesta de resolución transcrita en la presente resolución. FOURTH: NOTIFY ALKORA EBS CORREDURIA DE SEGUROS Y REASEGUROS SAU of this resolution. FIFTH: In accordance with the provisions of Article 85 of the LPACAP, which makes the reduction for voluntary payment conditional upon the withdrawal or waiver of any administrative action or appeal, this resolution shall be final in administrative proceedings and fully enforceable as of the date of its notification. In accordance with the provisions of Article 50 of the LOPDGDD, this Resolution shall be made public. Publication shall take place once the resolution has been notified to the data subjects. Against this resolution, which concludes the administrative proceedings as provided for in Article 114.1.c) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, the data subjects may file an administrative appeal with the Administrative Chamber of the National Court, in accordance with the provisions of Article 25 and paragraph 5 of the fourth additional provision of Law 29/1998, of July 13, regulating Contentious-Administrative Jurisdiction, within two months from the day following notification of this decision, as provided for in Article 46.1 of the aforementioned Law. However, in accordance with Article 90.3(a) of the LPACAP, the final administrative decision may be provisionally suspended if the data subject expresses their intention to file a contentious-administrative appeal. If this is the case, the data subject must formally notify the Spanish Data Protection Agency in writing, submitting the notice through the Agency’s Electronic Registry [https://sedeaepd.gob.es/sede-electronica-web/], or through any of the other registries provided for in Art. 16.4 of the aforementioned Law 39/2015 of October 1. The interested party must also submit to the Agency the documentation 6 Jorge Juan Street, 28001 – Madrid76/76 www.aepd.es sedeaepd.gob.es proving that the administrative appeal has been effectively filed. If the Agency is not notified of the filing of the administrative appeal within two months from the day following notification of this decision, it will consider the provisional suspension to have ended. 1331-101025 Lorenzo Cotino Hueso President of the Spanish Data Protection Agency




