AEPD (Spain) - PS-00020-2025: Difference between revisions

From GDPRhub
No edit summary
m Fixed link
 
Line 11: Line 11:


|Original_Source_Name_1=AEPD
|Original_Source_Name_1=AEPD
|Original_Source_Link_1=https://www.aepd.es/documento/ps-00026-2025.pdf
|Original_Source_Link_1=https://www.aepd.es/documento/ps-00020-2025.pdf
|Original_Source_Language_1=Spanish
|Original_Source_Language_1=Spanish
|Original_Source_Language__Code_1=ES
|Original_Source_Language__Code_1=ES

Latest revision as of 09:54, 16 July 2026

AEPD - PS-00020-2025
Authority: AEPD (Spain)
Jurisdiction: Spain
Relevant Law: Article 5(1)(f) GDPR
Article 35 GDPR
Article 58(2) GDPR
Type: Investigation
Outcome: Violation Found
Started:
Decided:
Published: 01.07.2026
Fine: 200,000 EUR
Parties: Alkora S.A.U.
National Case Number/Name: PS-00020-2025
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Spanish
Original Source: AEPD (in ES)
Initial Contributor: bms

The DPA fined an insurance broker €200,000 after a ransomware attack exposed data of around 40,000 people. The DPA found that the broker implemented insufficient security measures and failed to carry out a DPIA.

English Summary

Facts

Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices.

The controller first estimated that 25,000 persons were affected. It later stated that the incident had affected around 40,000 persons, including 75 minors. The incident affected confidentiality, availability and integrity. The attacker encrypted systems and exfiltrated between 3.5 and 4 TB of information from the document management server.

The affected data included identification and contact data, ID numbers, dates of birth, financial and insurance data, bank account numbers, health data, employee data and access credentials. The controller also processed data relating to minors in accident claims. A data subject complained to the DPA after being informed that their personal data had been exposed. The data subject was concerned about identity theft and requested additional information from the controller.

During the investigation, the DPA found that the controller had known that its IT systems faced an extreme cybercrime risk before the breach. The forensic report could not determine the initial entry point because the servers had been encrypted, but it showed that attackers could move laterally through the infrastructure, obtain privileged access, install tools, exfiltrate data and encrypt systems.

The controller had carried out a risk analysis in 2019, but this document concluded that no DPIA was necessary. After the breach, a later analysis found that a DPIA was necessary for treatments involving health data and minors. The controller did not prove that it had carried out the required DPIA.

Holding

The DPA held that the controller violated Article 5(1)(f) GDPR. It considered that the controller had failed to ensure the integrity and confidentiality of the personal data under its responsibility. The DPA emphasised that the principle in Article 5(1)(f) GDPR is not limited to the existence of isolated security measures. Rather, the controller must implement adequate technical and organisational measures capable of ensuring that personal data is protected against unauthorised or unlawful processing, loss, destruction or damage.

The DPA rejected the controller’s argument that the attack was an external criminal act that could not be attributed to it. The DPA found that the controller was aware of an extreme cyber risk and that its internal vulnerabilities and security posture allowed the attackers to move through the systems, access personal data and encrypt files. The DPA therefore considered that the controller’s measures were clearly insufficient.

The DPA also held that the controller violated Article 35 GDPR. The controller processed high-risk categories of data, including health data and data concerning minors. In these circumstances, it should have carried out a DPIA before the processing. The DPA found that the controller’s 2019 risk analysis wrongly concluded that no high risk existed, while its later documentation acknowledged that a DPIA was necessary.

The DPA proposed a fine of €150,000 for the infringement of Article 5(1)(f) GDPR and €100,000 for the infringement of Article 35 GDPR, totalling €250,000. The controller paid voluntarily without acknowledging liability, obtaining a 20% reduction under Spanish Administrative Law (39/2015). The final payable amount was therefore €200,000.

The DPA also ordered the controller, under Article 58(2)(d) GDPR, to prove within three months from the enforceability of the decision that it had carried out the mandatory DPIA required under Article 35 GDPR.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.

Case No.: EXP202400624

DECISION TO TERMINATE THE PROCEEDINGS DUE TO VOLUNTARY PAYMENT

Regarding the proceedings conducted by the Spanish Data Protection Agency and based
on the following

BACKGROUND
FIRST: On April 15, 2025, the Presidency of the Spanish Data Protection Agency decided
to initiate disciplinary proceedings against ALKORA EBS CORREDURIA DE SEGUROS Y
REASEGUROS SAU (hereinafter, ALKORA).
Following notification of the decision to initiate proceedings and after analyzing the
arguments submitted, a proposed resolution was issued on February 16, 2026, the text of
which is transcribed below:
<<
Case No.: EXP202400624
PROPOSED RESOLUTION ON DISCIPLINARY PROCEEDINGS
Regarding the proceedings conducted by the Spanish Data Protection Agency and based
on the following:
Contents BACKGROUND..................................................................................................................3
FIRST: On April 22, 2023, this Agency was notified of a data breach involving ALKORA
EBS CORREDURIA DE SEGUROS Y REASEGUROS SAU, with Tax ID No.
A01051747 (hereinafter, ALKORA) .............................................................................................3
SECOND: On December 27, 2023, a complaint was filed with the Spanish Data
Protection Agency regarding the previously reported data breach of personal data...........5
THIRD: Pursuant to Article 65.4 of Organic Law 3/2018, of December 5, on Data
Protection and the Guarantee of Digital Rights (hereinafter LOPDGDD), said complaint
was forwarded to ALKORA so that it could analyze it and inform this Agency, within one
month, of the actions taken to comply with the requirements set forth in data protection
regulations .......................................................................................................................................7
FOURTH: On March 27, 2024, in accordance with Article 65 of the LOPDGDD, the
complaint was accepted for processing ....................................................................................20
6 Jorge Juan
Street, 28001 –
Madrid2/76
www.aepd.es
sedeaepd.gob.es
FIFTH: The Subdirectorate General for Data Inspection conducted preliminary
investigative proceedings to clarify the facts in question, pursuant to the functions
assigned to supervisory authorities under Article 57.1 and the powers granted under
Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation,
hereinafter GDPR), and in accordance with the provisions of Title VIII of the LOPDGDD
........................................................................................................................................................20
Origin and Development of the Data Breach.......................................................................21
Number of individuals affected: .............................................................................................22
Types of data:...........................................................................................................................23
Risk Analysis and Impact Assessment (RA and IIA)..........................................................28
Technical security measures prior to a breach ...................................................................29
Reactive technical measures: ................................................................................................33
Training activities related to personal data protection: ......................................................34
Organizational measures following the breach ...................................................................35
SIXTH: On April 15, 2025, the Presidency of the Spanish Data Protection Agency agreed
to initiate sanctioning proceedings against the respondent, in accordance with the
provisions of Articles 63 and 64 of Law 39/2015, of October 1, on the Common
Administrative Procedure of Public Administrations (hereinafter, LPACAP), for the
alleged violation of Article 5.1.f) of the GDPR and Article 35 of the GDPR, as defined in
Article 83.5 of the GDPR and Article 83.4 of the GDPR, respectively.................................35
SEVENTH: After being notified of the aforementioned decision to initiate proceedings in
accordance with the provisions of Law 39/2015, of October 1, on the Common
Administrative Procedure of Public Administrations (hereinafter, LPACAP), on May 6,
2025, ALKORA filed a written statement of defense in which, in summary, it stated that
........................................................................................................................................................36
EIGHTH: On October 17, 2025, an expert report submitted by ALKORA was received, in
accordance with what was announced in its written statement of defense regarding the
decision to initiate disciplinary proceedings.............................................................................36
NINTH: According to the report retrieved from the AXESOR tool on February 8, 2026,
ALKORA is an enterprise incorporated in 1989, with a turnover of 24,007,236 euros in
2024................................................................................................................................................36
TENTH: A list of the documents on file in the proceedings is attached as an annex .......36
PROVEN FACTS ..............................................................................................................................36
LEGAL GROUNDS ..........................................................................................................................46
I Jurisdiction...................................................................................................................................46
II Preliminary Issues ....................................................................................................................47
III Objections to the Decision to Initiate Proceedings .............................................................48
6 Jorge Juan
Street, 28001 –
Madrid3/76
www.aepd.es
sedeaepd.gob.es
IV Breach of Obligation. Integrity and Confidentiality.............................................................63
V Classification of the violation of Article 5.1.f) of the GDPR and determination for the
purposes of the statute of limitations ........................................................................................74
VI Proposed sanction for the violation of Article 5(1)(f) of the GDPR..................................74
VII .....Failure to Comply. Data Protection Impact Assessment
.........................................................................................................................................................78
VIII Classification of the violation of Article 35 of the GDPR and determination of the
statute of limitations .....................................................................................................................85
IX Proposed sanction for the violation of Article 35 of the GDPR ........................................86
X Adoption of measures..............................................................................................................89
PROPOSED RESOLUTION............................................................................................................89
ANNEX ...............................................................................................................................................91
BACKGROUND
FIRST: On April 22, 2023, this Agency was notified of a personal data breach involving
ALKORA EBS CORREDURIA DE SEGUROS Y REASEGUROS SAU, with Tax ID No.
A01051747 (hereinafter, ALKORA).
The facts brought to the attention of this authority were as follows:
“On Friday, April 21, at the start of the workday, unauthorized access was detected; the
perpetrators hacked and encrypted the servers, databases, and email systems, and
infected all of the enterprise’s computers. They left a document/note in all users’ folders
stating that the systems had been hacked and urging users to contact them via a link. The
incident was reported to the police.”
“The source of the incident was: External: Others, unrelated to the controller and processor
What might have happened? You may select multiple options: Cyberincident: Encrypted
device / data hijacking
As a result of the incident, the following have been affected: Confidentiality, Availability
Specifically regarding the data affected by the breach of confidentiality.
Is the data securely encrypted, anonymized, or protected in such a way that it is
unintelligible to anyone who may have gained access, or that individuals cannot be
identified? No
Refers specifically to the data affected by the availability breach. Has the availability of the
personal data been restored so that it can be processed normally? Not yet, but it will be
restored shortly”
“Select the types of data that have been affected…: Basic data (e.g., first name, last name,
date of birth), National ID number, Foreign Resident ID number, passport, and/or any other
identification document; payment method data (bank card, etc.);
6 Jorge Juan
Street, 28001 –
Madrid4/76
www.aepd.es
sedeaepd.gob.es
location data, contact information, health data (exclusively for employees, limited to what is
essential for the employment relationship), access or identification credentials (User name
and/or password).”
“Are there any minors among the affected individuals?: No
Are there members of vulnerable groups among the affected individuals, such as survivors
of gender-based violence or those at risk of social exclusion?: No
The affected individuals fall into the following categories: Customers/Citizens,
Subscribers/Prospective Customers, Employees
In total, how many people have had their data affected by the personal data breach? (If you
do not know the exact number, provide an estimate) 25,000”
“Indicate the date the data breach was detected, defined as the date on which the
controller became certain that personal data had been compromised: 04/21/2023
Do you know the date the breach began? The exact date: Indicate the
start date of the breach: 04/21/2023
The breach was detected through: A report from a member of the controller’s or
processor’s organization”
“Has the breach been communicated to the affected individuals under the conditions
described above? To be decided”
“Has the controller designated a DPO? No”
On May 17, 2023, this Agency received a second letter from ALKORA with the intention of
“amending a previous notification to provide relevant information,” in which the information
initially provided remained the same as in the letter dated April 22, 2023, with the exception
of:
“What might have happened? You may select multiple options: Documentation lost, stolen,
or left in an insecure location; Cyber incident: Encrypted device / data hijacking; Cyber
incident: Identity theft (phishing) / compromise of User or Administrator account; Cyber
incident: Unauthorized access to data in an information system (corporate or online
service). As a result of the incident, the following have been affected: Confidentiality,
Availability, Integrity”
“Specifically regarding the data affected by the integrity breach. Select the most
appropriate option: Data altered, but with no evidence of illegal or improper use. What
might have happened? You may select multiple options: Identity theft, Falling victim to
phishing or spamming campaigns, Loss of control over personal data
To what extent could the identified consequences affect individuals? Individuals will not be
affected or may experience some very limited and reversible inconveniences that they will
overcome without any problem (time spent re-entering information, annoyances, irritations,
etc.)”
“How do you assess the probability that the aforementioned harm will materialize for the
affected individuals with the indicated severity? Low
6 Jorge Juan
Street, 28001 –
Madrid5/76
www.aepd.es
sedeaepd.gob.es
* Enter a brief description of what happened... On the night of Thursday, April 20, through
Friday, April 21, 2023, ALKORA experienced service interruptions in its local production
environment. On Friday, April 21, technical staff encountered an encrypted information
system. Both employee workstations and servers were affected. Consequently, all IT
services dependent on those servers were unavailable. On April 21, a report was filed with
the national police, and the report was expanded the following day to include ALKORA’s
subsidiaries among those affected by the cybersecurity incident. The services of
***ENTERPRISE.1 were contracted on April 21 to analyze the scope of the attack and
confirm whether a data exfiltration had occurred. The results of the commissioned expert
report reveal that the attacker is (...). The encryption of the servers directly impacts the
integrity and availability of the enterprise’s systems and applications. Furthermore, the data
exfiltration impacts the confidentiality of the enterprise’s sensitive documents, as well as
customers’ personal data. The expert report concludes that a TOTAL OF 3.5/4 TB of
information has been EXFILTRATED. Those affected have been notified. ALKORA is
currently operating at 100% capacity thanks to the restoration of the backup it had
outsourced to the cloud.”
“Are there minors among the affected individuals? Yes”
“Do you know the date the breach began? Approximately / Estimated. Indicate the start
date of the breach: 04/16/2023”
“Indicate the date the breach was resolved: 05/17/2023”
“Has the breach been communicated to the affected individuals under the conditions
described above? Yes
Date of notification: 04/26/2023 Number of
people notified: 25,000
Method of notification: Personal communication sent to each affected individual (postcard,
email, text message, or similar)”
“Has the controller designated a DPO? Yes”
SECOND: On December 27, 2023, a complaint was filed with the Spanish Data Protection
Agency regarding the previously reported data breach involving personal data.
The facts brought to the attention of this authority were as follows:
“… On May 11, 2023, my insurance company, ALKORA, notified me that it had suffered a
cyberattack on April 21, 2023, and that it had filed a report and notified the Spanish Data
Protection Agency… I was informed that my personal data had been exposed. Concerned
that my personal data might be used illegally, I went to the National Police station nearest
my home, where I was told that I could not file a report until the crime had actually been
committed. I need guidance on how to refute the presumption that I was the one who
committed the act, when in reality it was the person who illegally possesses my data (for
6 Jorge Juan
Street, 28001 –
Madrid6/76
www.aepd.es
sedeaepd.gob.es
example, to apply for a loan in my name) and that I have been a victim of identity theft
resulting from cybersecurity breaches.”
Attached to the complaint are the following:
- A copy of an email sent on May 24, 2023, by the complainant to ALKORA, with the
subject line “Request to File a Security Breach Report” and the following content:
“Good morning, Regarding the email received on May 11, 2023 (which I have
attached), stating that you had suffered a security breach, and as someone affected
by it, I would like to request a copy of the report you filed, to which you refer in the
aforementioned letter. I look forward to hearing from you. Sincerely”
Below is an email with the following content: “On April 21, ALKORA’s computer
systems were the victim of a security breach resulting from an external cyberattack.
Upon detecting the breach, we activated all established security mechanisms and
protocols, immediately notifying the Spanish Data Protection Authority and filing the
corresponding report with the authorities to investigate the incident.
Additionally, we notified all customers we were able to reach of this situation;
however, in some cases, this was hindered by the encryption of a portion of our
database resulting from the cyberattack. Therefore, as soon as we were able to
access your data, we contacted you to inform you of this incident.
As of today, as part of the ongoing investigations, we can confirm that, in addition
to the encryption of your personal data, there has been a data breach involving the
Professional Liability insurance policy application forms; consequently, these forms
have been compromised or are accessible to unauthorized third parties.
In light of this, we strongly recommend that you exercise extreme caution in your
day-to-day digital transactions and activities: in particular, be on the lookout for
phishing attempts—be wary of suspicious emails, phone calls, and messages that
may be attempts to trick you into revealing personal or banking information. We
also ask that you report any communication purporting to be from us—whether by
phone or email—that does not follow our usual format.
As for ALKORA’s operations, we are returning to 100% operational capacity
following a few days of mandatory system shutdown to ensure our customers’
security and enable specialized teams to investigate the security breach. You may
therefore contact your usual account manager as usual for any transactions.
We want to assure you that we are making every effort to resolve this incident as
quickly as possible, with full guarantees, and by prioritizing the security of our
clients at all times, sparing no expense or resources. We are confident of a prompt
resolution of the matter and will strive to maintain open communication with you to
keep you informed of any developments in this regard. You may also request, if
you wish,
6 Jorge Juan
Street, 28001 –
Madrid7/76
www.aepd.es
sedeaepd.gob.es
about this incident via the following email address: seguridad.rcp@alkora.es
Sincerely, ALKORA SECURITY”
- Copy of an email received on May 25, 2023, by the complainant from ALKORA, in
response to the previous message, with the following content: “Good morning,
Following the work being carried out by the teams of professionals handling this
matter, we can confirm that the document server from which the data exfiltration
occurred did not contain any of your documents.
On the other servers—for which we cannot confirm that a data breach occurred—
the only personal data on record would be your first and last names and your ID
number.
Regarding your request for a copy of the police report filed, please note that we
regret that we cannot comply with your request, as it is a document of
confidentiality for the enterprise. However, we are providing you with the address of
the police station where the report was filed: ***ADDRESS.1.
Sincerely, ALKORA SECURITY”
THIRD: In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on Data
Protection and the Guarantee of Digital Rights (hereinafter LOPDGDD), said complaint was
forwarded to ALKORA so that it could analyze it and inform this Agency, within one month,
of the actions taken to comply with the requirements set forth in data protection regulations.
The notification of the referral of the complaint, which was carried out in accordance with
the provisions of Law 39/2015, of October 1, on the Common Administrative Procedure of
Public Administrations (hereinafter LPACAP), was issued on January 15, 2024, as
evidenced by the acknowledgment of receipt on file.
On February 14, 2024, this Agency received a written response stating:
- “(…)”
d) Approximately 25,000 individuals were affected, solely at the national level
(Spain)”
- “They may have been affected; however, as we indicated, the encryption of all
servers by (...) has limited our ability to analyze the data:
1. Basic information on individual customers, corporate customers (policyholders,
insured parties, beneficiaries), potential customers, and staff: First name, last
name, date of birth, National ID number (DNI), Foreign Resident ID number (NIE),
passport, and/or any other identification document; economic or financial data
(excluding payment methods); contact information; health data (exclusively for
employees, limited to what is essential for the employment relationship); and
access or identification credentials (User name and/or password).
2. Health data of individual customers with life insurance and/or accident insurance.”
6 Jorge Juan
Street, 28001 –
Madrid8/76
www.aepd.es
sedeaepd.gob.es
- “Among the possible consequences for those affected by the data breach, we can
highlight potential identity theft and blackmail or extortion.”
- “(…).”
- The security measures implemented prior to the incident are as follows:
(…)
AVAILABILITY OF INFORMATION
Attached as Annex V is the Risk Analysis conducted on September 19, 2019, from which
the security measures referred to in this section are derived.”
In this regard, Annex V attached to ALKORA’s letter dated February 14, 2024, stated:
(…)
- Regarding the copy of the Record of Processing Activities where the incident
occurred, ALKORA states:
o Regarding “LABOR AND HR”: “Categories
of data subjects: Employees”
“Identifying data: National ID number or Tax ID number, First and last
names, Postal or email address, Phone number, Handwritten signature,
Social Security number or mutual insurance number”
Special categories of data: Digitized fingerprint (biometric data) Other
type of data Characteristics Personal, Academic
and professional, Details of employment,
Transactions of goods and services.”
o Regarding “INSURANCE BROKERAGE FOR INDIVIDUALS”:
“Identifying information: ID number or Tax ID number, first and last names,
mailing or email address, phone number, handwritten signature
Special categories of data: N/A
Other types of data: Personal data, academic and professional information,
transactions involving goods and services, social circumstances,
commercial information, economic, financial, and insurance information”
o Regarding “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR
INDIVIDUALS”:
6 Jorge Juan
Street, 28001 –
Madrid9/76
www.aepd.es
sedeaepd.gob.es
“Identifying data: National ID number (DNI) or Tax ID number (NIF), first and
last names, mailing or email address, phone number, handwritten signature
Special categories of data: Health
Other types of data: Personal data, academic and professional information,
transactions involving goods and services, social circumstances, economic,
financial, and insurance information”
o Regarding “INSURANCE CLAIMS”:
“Identifying information: National ID number (DNI) or Tax ID number (NIF),
first and last names, mailing or email address, phone number, handwritten
signature, image
Special categories of data: Health
Other types of data: Personal data, academic and professional information,
transactions involving goods and services, social circumstances, economic,
financial, and insurance information”
o Regarding “TAX AND ACCOUNTING”:
“Identifying information: ID number or tax ID number, first and last names,
mailing or email address, phone number
Special categories of data: N/A Other
types of data: N/A”
- As a result of the incident, the following security measures had already been
implemented:
• (…)
Additionally, at that time, Alkora was in the process of strengthening the
security of its systems by implementing the following security measures:
• (…)
Attached to the written response to the referral is:
- Appendix I: Police report dated April 22, 2023
- Appendix II: Notification of the data breach to the AEPD, dated April 22, 2023
- Appendix III: Supplementary notification of the data breach to the AEPD, dated May
17, 2023
- Appendix IV: Notification of the data breach to INCIBE, dated May 18, 2023
- Appendix V: Risk Analysis dated September 19, 2019, from which the security
measures referred to in the section on information availability are derived
The document attached as Annex V is unsigned; it indicates that it is “Version: 0.1,” dated
September 19, 2019, and it contains the following:
- Regarding “Filing System 1: EMPLOYMENT AND HR”:
6 Jorge Juan
Street, 28001 –
Madrid10/76
www.aepd.es
sedeaepd.gob.es
o It is considered that the identifying data and other specified data subject to
processing have an initial risk rating of “Low.”
o Regarding “Data Protection (Integrity and Confidentiality),” it states that
“There are adequate measures in place to protect the data against
unauthorized processing and loss or destruction in accordance with the
provisions of this document,” an initial risk of “Medium” is assigned, and the
measures detailed are “Ensuring that adequate technical and organizational
measures have been implemented to protect the data through the
corresponding periodic annual verification,” after which a final risk of “Very
low” is assigned.
o Regarding “Processing Risks,” it is indicated that “THE PROCESSING
HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the
data subject rights and freedoms,” an initial risk of “Medium” is assigned,
and the measures are detailed as follows: “It has been verified that the risk
analysis conducted does not identify any threats with a probability of high
risk to the data subject rights and freedoms,” after which a final risk of “Low”
is assigned.
o Regarding “Access to special categories of data,” it is stated that “There are
no special categories of data,” and therefore an initial and final risk rating of
“Very Low” is assigned.
- Regarding “Filing System 2: INSURANCE BROKERAGE FOR INDIVIDUALS”:
o It is considered that the identifying data and other specified data subject to
processing have an initial risk of “Low.”
o Regarding “Data Protection (Integrity and Confidentiality),” it is indicated
that “There are adequate measures in place to protect the data against
unauthorized processing and loss or destruction, in accordance with the
provisions of this document,” an initial risk of “Medium” is assigned, and the
measures are detailed as follows: “Ensure that adequate technical and
organizational measures have been implemented to protect the data
through the corresponding periodic annual verification,” after which a final
risk of “Very low” is assigned.
o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS
BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data
subject rights and freedoms,” an initial risk of “Medium” is assigned, and the
measures are detailed as follows: “It has been verified that the risk analysis
conducted does not identify any threats with a probability of high risk to the
data subject rights and freedoms,” after which a final risk of “Low” is
assigned.
o Regarding “Access to special categories of data,” it is stated that “There are
no special categories of data,” and therefore an initial and final risk rating of
“Very Low” is assigned.
- Regarding “Filing System 3: LIFE AND ACCIDENT INSURANCE BROKERAGE
FOR INDIVIDUALS”:
6 Jorge Juan
Street, 28001 –
Madrid11/76
www.aepd.es
sedeaepd.gob.es
o It is considered that the identifying data and other specified data subject to
processing have an initial risk of “Low.” However, health data is assigned
an initial risk of “High.”
o Regarding “Data Protection (Integrity and Confidentiality),” it is stated that
“There are adequate measures in place to protect the data against
unauthorized processing and loss or destruction, in accordance with the
provisions of this document,” it is assigned an initial risk of “Medium,” and
the measures are detailed as follows: “Ensure that adequate technical and
organizational measures have been implemented to protect the data
through the corresponding periodic annual verification,” after which a final
risk of “Low” is assigned
o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS
BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data
subject rights and freedoms,” an initial risk rating of “Medium” is assigned,
and the measures detailed are: “It has been verified that the risk analysis
conducted does not identify any threats with a probability of high risk to the
data subject rights and freedoms,” after which a final risk rating of “Low” is
assigned.
o Regarding “Access to Special Categories of Data,” it is stated that “There
are additional security measures in accordance with the provisions of
section 4.4 of this document”; an initial risk rating of “Medium” is assigned,
and the measures are detailed as follows: “An up-to-date record must be
maintained of personnel with access to special categories of personal data.
It is recommended to strengthen these measures with two-factor
authentication, encryption…”, after which a final risk rating of “Very low” is
assigned.
- Regarding “Filing System 4: INSURANCE CLAIMS”:
o It is considered that the identifying data and other specified data subject to
processing have an initial risk of “Low.” However, health data is assigned
an initial risk of “High.”
o As for “Data Protection (Integrity and Confidentiality),” it is stated that
“There are adequate measures in place to protect the data against
unauthorized processing and loss or destruction, in accordance with the
provisions of this document,” it is assigned an initial risk of “Medium,” and
the measures are detailed as follows: “Ensure that adequate technical and
organizational measures have been implemented to protect the data
through the corresponding periodic annual verification,” after which a final
risk of “Low” is assigned.
o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS
BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data
subject rights and freedoms,” an initial risk of “Medium” is assigned, and the
measures are detailed as follows: “It has been verified that the risk analysis
conducted does not identify any threats with a high probability of risk to the
data subject rights and freedoms,” after which a final risk of “Low” is
assigned.
6 Jorge Juan
Street, 28001 –
Madrid12/76
www.aepd.es
sedeaepd.gob.es
o Regarding “Access to special categories of data,” it is stated that
“ADDITIONAL security measures are in place in accordance with the
provisions of section 4.4 of this document”; an initial risk rating of “Medium”
is assigned, and the measures are detailed as follows: “An up-to-date
record must be maintained of personnel with access to special categories of
data. It is recommended to strengthen these measures with two-factor
authentication, encryption…”, after which a final risk rating of “Very low” is
assigned.
- Regarding “Filing System 5: TAX AND ACCOUNTING”:
o The identifying data subject to processing is considered to have an initial
risk of “Low.”
o As for “Data Protection (Integrity and Confidentiality),” it is stated that
“There are adequate measures in place to protect the data against
unauthorized processing and loss or destruction, in accordance with the
provisions of this document,” an initial risk of “Medium” is assigned, and the
measures are detailed as follows: “Ensure that adequate technical and
organizational measures have been implemented to protect the data
through the corresponding periodic annual verification,” after which a final
risk of “Low” is assigned
o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS
BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data
subject rights and freedoms,” an initial risk of “Medium” is assigned, and the
measures are detailed as follows: “It has been verified that the risk analysis
conducted does not identify any threats with a high probability of risk to the
data subject rights and freedoms,” after which a final risk of “Low” is
assigned.
o Regarding “Access to special categories of data,” it is stated that “There are
no special categories of data,” and therefore an initial and final risk rating of
“Very Low” is assigned.
- In section “4.4. SECURITY BY DESIGN AND BY DEFAULT” of the
document, the following measures are detailed to ensure data availability:
o (…)
- “Processing of data on children under 14 years of age” is mentioned as a specific
processing activity, indicating that “DATA PROCESSING on children under 14
years of age is carried out only in cases of school accidents”; it is assigned a
medium initial risk, and the measures indicated are “Ensure that the measures
referred to in section 4.4 are adopted through the corresponding periodic annual
verification,” after which a final risk of “Low” is indicated.
- In the section on “ORGANIZATION,” it is stated that a data protection officer is not
required, “because the enterprise’s main activity] CONSISTS of processing
personal data but NOT on a LARGE SCALE, nor is it regulated under Art. 34 of the
LOPDGDD.” It is also stated that a data protection officer is not required.
6 Jorge Juan
Street, 28001 –
Madrid13/76
www.aepd.es
sedeaepd.gob.es
(DPIA) because “the processing does not pose a high risk to the rights and
freedoms of natural persons.”
FOURTH: On March 27, 2024, in accordance with Article 65 of the LOPDGDD, the
complaint was accepted for processing.
FIFTH: The Subdirectorate General for Data Inspection proceeded to conduct preliminary
investigative actions to clarify the facts in question, by virtue of the functions assigned to
supervisory authorities under Article 57.1 and the powers granted under Article 58.1 of
Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in
accordance with the provisions of Title VIII of the LOPDGDD.
As a result of the actions taken, the following facts have come to light:
Origin and development of the data breach:
ALKORA includes in Annex I of its letter dated July 9, 2024, in response to this Agency’s
request, the forensic report prepared by the enterprise
***ENTERPRISE.1, Version V 1.0 dated May 3, 2023, unsigned, which states that due to
the encryption of the information on the servers, “The method of intrusion, as well as the
point of entry, remain undetermined.”
That forensic report states that “The encryption of all servers has limited the ability to
analyze the data, thereby preventing the collection of evidence regarding the initial
intrusion,” and that certain system deficiencies have limited the scope of the forensic
analysis:
“Several factors have contributed to limiting the investigative capacity of the
***ENTERPRISE.1 team:
• (…)
However, the forensic report identifies some of the actions carried out by the attacking
group following the initial intrusion, consisting of:
- access to the messaging management server: “(…)”
- reconnaissance from that server to gather information about domain
administrators, elevate their User privileges, and move throughout the rest of the
system: “(…)”
It also indicates that the encryption of the Active Directory domain controllers does not
allow for a detailed account of the attacker’s privilege escalation process, but it determines
that the following events took place over the next three days:
- privilege escalation
- access to the local administrator account (…) ***SERVER.1, which grants the
highest privileges on the system
6 Jorge Juan
Street, 28001 –
Madrid14/76
www.aepd.es
sedeaepd.gob.es
- installation and execution of the program ***PROGRAM.1, despite being blocked
twice by ***PROGRAM.2; the attacker manages to conceal their activity and avoid
further blocks by the antivirus
- installation of the program ***PROGRAM.3
- data exfiltration
- encryption of servers and workstations The forensic
report also states:
“The attackers were able to move freely throughout ALKORA’s infrastructure (…).”
“The ransomware is deployed manually on ***SERVER.1 and automatically on the
workstations (…).”
This Agency wishes to note that, in its letter dated February 14, 2024, in response to the
referral of the complaint outlined in the second background section, ALKORA stated that
recovery efforts began on April 25, database recovery took place between April 26 and 30,
and that its systems were brought back online between April 27 and May 26, 2023.
Number of people affected:
In Annex II of its letter dated July 9, 2024, in response to a request from this Agency,
ALKORA provides the emails exchanged with INCIBE, to which it reported on May 18,
2023, the exfiltration of between 3.5 and 4 TB of data, although it does not specify what
portion of that volume corresponds to personal data.
Among other documents, a copy of an email dated May 18, 2023, from ALKORA
toincidencias@incibe-cert.es is provided, with the following content: “Good afternoon, We
hereby wish to inform INCIBE of the security breach detected at ALKORA EBS
CORREDURIA DE SEGUROS Y REASEGUROS SAU (and its subsidiaries SANCHEZ
CASTAÑON S.L. and VERSPIEREN AGENCIA DE
SUSCRIPCION SAU) on April 21. (…) … the threat involves both the total loss of said data
and its sale and disclosure. The encryption of the servers directly impacts the integrity and
availability of the enterprise’s systems and applications. Furthermore, the data exfiltration
compromises the confidentiality of the enterprise’s sensitive documents, as well as
customers’ personal data. All of ALKORA’s servers and systems were affected by the
attack. The expert report concludes that a TOTAL OF BETWEEN 3.5 AND 4 TB of
information has been EXFILTRATED—that is, all the information that was on the document
management server. (…) As of the date of this writing, ALKORA is operating at 100%
capacity thanks to the restoration of the backup it had outsourced to the cloud.”
In the data breaches submitted to this Agency on April 22 and May 17, 2023, ALKORA
stated:
- that it had suffered a breach of confidentiality, availability, and integrity due to a
cyberattack;
6 Jorge Juan
Street, 28001 –
Madrid15/76
www.aepd.es
sedeaepd.gob.es
- that the affected activity involved the processing of data belonging to approximately
25,000 individuals, including minors;
- that the data was not encrypted.
Subsequently, in its letter dated July 9, 2024, ALKORA raised the approximate number of
affected individuals to 40,000:
“The total number of individuals affected by the breach of which we are aware is around
40,000. Initially, following the breach, the number of affected individuals was estimated at
25,000, as information from the databases was unavailable due to their unavailability. Once
the databases were gradually restored, we were able to determine that a larger number of
people were affected. We then proceeded to notify those affected of the breach either
directly or, in the case of group policies, through the policyholders, using the channels
mentioned in this letter.
Data on minors is processed solely in connection with the handling of accident claims,
which were stored in PDF files in network folders on the server but are not recorded in
Alkora’s databases; Over the past four years, Alkora has processed only 75 accident
claims, which include only the minor’s first name, last name, date of birth, and general
information about the circumstances of the accident.”
When asked about the number of minors affected, ALKORA reiterated in its letter dated
December 23, 2024, in response to a request from this Agency:
“[…] these files were stored as PDFs in network folders on the server but were not
recorded in Alkora’s databases. Over the past four years, Alkora EBS Correduría de
Seguros y Reaseguros, S.A.U. has processed only 75 accident claims, representing a
total of 75 minors affected by the data breach […]”
Types of data:
In its letter dated February 14, 2024, in response to the referral of the complaint, ALKORA
stated that the types of personal data affected were:
“1. Basic data of individual customers, corporate customers (policyholders, insured
parties, beneficiaries), potential customers, and staff:
First name, last name, date of birth, National ID number, Foreign Resident ID number,
passport, and/or any other identification document; economic or financial data
(excluding payment methods); contact information; health data (exclusively for
employees, limited to what is essential for the employment relationship); and access or
identification credentials (User name and/or password).
2. Health data of individual customers with life insurance and/or accident insurance
policies.”
ALKORA provided, as a Risk Analysis (RA), in Annex V of its letter dated
February 14, 2024, the document “RISK ANALYSIS OF ALKORA EBS CORREDURÍA DE
SEGUROS, S.A.U. BASED ON REGULATION (EU) 2016/679,”
6 Jorge Juan
Street, 28001 –
Madrid16/76
www.aepd.es
sedeaepd.gob.es
dated September 19, 2019, which included the RAT (Record of Processing Activities),
detailing five “filing systems”:
Filing
system
No.
Name Data Subjects Purposes
1 LABOR AND HR - Employees
- Human Resources
- Payroll Management
- Work Hours Tracking
and Monitoring
2
INSURANCE
BROKERAGE FOR
INDIVIDUALS
- Policyholder
- Insured
- Beneficiary
- Economic, financial,
and insurance services
- Advertising and Business
Development
3
LIFE AND
ACCIDENT
INSURANCE
BROKERAGE FOR
INDIVIDUALS
- Policyholder
- Insured
- Beneficiary
- Economic, financial,
and insurance services
- Advertising and Business
Development
4 INSURANCE
CLAIMS - Insured
- Claims processing and
tracking
- Social assistance management
5 TAX AND
ACCOUNTI
NG
- Clients
and users
- Suppliers
- Client management, accounting,
tax, and administrative matters
When asked about the types of data included in the generic terms “Personal
Characteristics” and “Social Circumstances” used in the RAT, ALKORA provided details in
its letter dated July 9, 2024:
“We have provided tables breaking down the types of data related to personal data and
social circumstances for each of the filing systems in the submitted RAT:
EMPLOYMENT AND HR
Other Types of Data Personal characteristics: marital status,
family, date of birth, place of
birth, age, sex, nationality
INSURANCE BROKERAGE FOR INDIVIDUALS
Other types of data Personal : date of
birth, age.
Social circumstances: housing
characteristics, residence, property, and
possessions (only for home insurance)
LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS
6 Jorge Juan
Street, 28001 –
Madrid17/76
www.aepd.es
sedeaepd.gob.es
Other types of data Personal : date of
6 Jorge Juan
Street, 28001 –
Madrid18/76
www.aepd.es
sedeaepd.gob.es
birth, place of birth, age,
gender, nationality.
INSURANCE CLAIMS
Other types of data Personal characteristics: marital status,
family, date of birth, place of birth, age,
sex, nationality. Social circumstances:
characteristics of housing, residence,
property, and
possessions (only in the case of home
insurance)
3.2. Processing operations involving bank account numbers of customers, potential
customers, and employees
Bank account numbers are included only in the following processing activities:
• Payment of payroll and personnel expenses: “Labor and HR” filing system
• Customer collections: “Tax and Accounting” filing system.
3.3. Processing operations, if any, that include information on bank cards:
Alkora only uses duly authorized corporate cards for the payment of living expenses,
transportation, and/or corporate travel (the “Labor and HR” filing system+). There are no
other processing operations.”
Based on ALKORA’s statements in Annex V (Risk Analysis of September 19, 2019) of its
letter dated February 14, 2024, and on the statements in its letter dated July 9, 2024, it
appears that its data processing activities included at least the following types of data:
- National ID Number or Tax ID Number (all filing systems)
- First and last names (all filing systems)
- Mailing or email address (all filing systems)
- Phone number (all filing systems)
- Image (filing system “INSURANCE CLAIMS”)
- Handwritten signature (“LABOR AND HR”; “INSURANCE BROKERAGE FOR
INDIVIDUALS”; “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR
INDIVIDUALS”; “INSURANCE CLAIMS” filing systems)
- Social Security or mutual insurance number (filing system “LABOR AND HR”)
- Health (filing systems “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR
INDIVIDUALS”; “INSURANCE CLAIMS”)
- Marital status (filing systems “EMPLOYMENT AND HR”; “INSURANCE CLAIMS”)
- Family (filing systems “EMPLOYMENT AND HR”; “INSURANCE CLAIMS”)
- Date of Birth (filing systems “EMPLOYMENT AND HR”; “INSURANCE
BROKERAGE FOR INDIVIDUALS”; “LIFE AND ACCIDENT INSURANCE
BROKERAGE FOR INDIVIDUALS”; “INSURANCE CLAIMS”)
6 Jorge Juan
Street, 28001 –
Madrid19/76
www.aepd.es
sedeaepd.gob.es
- Place of birth (filing systems “EMPLOYMENT AND HR”; “LIFE AND ACCIDENT
INSURANCE BROKERAGE FOR INDIVIDUALS”; “INSURANCE CLAIMS”)
- Age (filing systems “LABOR AND HR”; “INSURANCE BROKERAGE FOR
INDIVIDUALS”; “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR
INDIVIDUALS”; “INSURANCE CLAIMS”)
- Gender (filing systems “LABOR AND HR”; “INSURANCE BROKERAGE FOR
LIFE AND ACCIDENT INSURANCE FOR INDIVIDUALS”; “INSURANCE
CLAIMS”)
- Nationality (filing systems “LABOR AND HR”; “LIFE AND ACCIDENT
INSURANCE BROKERAGE FOR INDIVIDUALS”; “INSURANCE CLAIMS”)
- Characteristics of lodging, housing, properties, and possessions in home
insurance (filing systems “INSURANCE BROKERAGE FOR INDIVIDUALS,”
“INSURANCE CLAIMS”)
- Academics and Professionals (filing systems “EMPLOYMENT AND HR”;
“INSURANCE BROKERAGE FOR INDIVIDUALS”; “LIFE AND ACCIDENT
INSURANCE BROKERAGE FOR INDIVIDUALS”)
- Commercial information (filing systems “INSURANCE BROKERAGE FOR
INDIVIDUALS”; “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR
INDIVIDUALS”)
- Employment details (filing systems “LABOR AND HR”; “LIFE AND ACCIDENT
INSURANCE BROKERAGE FOR INDIVIDUALS”; “INSURANCE CLAIMS”)
- Economic, financial, and insurance filing systems (filing systems: “LABOR AND
HR”; “INSURANCE BROKERAGE FOR INDIVIDUALS”; “LIFE AND ACCIDENT
INSURANCE BROKERAGE FOR INDIVIDUALS”; “INSURANCE CLAIMS”)
- Bank account number (filing systems “LABOR AND HR,” “TAX AND
ACCOUNTING”)
- Corporate bank card numbers (“LABOR AND HR” filing system)
The aforementioned Risk Analysis indicated that the following “SPECIFIC PROCESSING”
was carried out (p. 64):
- Concept: “Processing of data on children under 14 years of age” – Application:
“Data on children under 14 years of age is processed only in the event of school-
related claims”
Regarding the processing of minors’ data, ALKORA stated in its letter dated July 9, 2024:
“Data on minors is processed solely in the handling of accident claims […] which
include only the minor’s first name, last name, date of birth, and general information
regarding the circumstances of the accident.”
On page 415 of Annex VII of the letter dated July 9, 2024, a copy is attached of a
presentation on a data protection and information security training session conducted in
2024 by ALKORA, which included the following:
6 Jorge Juan
Street, 28001 –
Madrid20/76
www.aepd.es
sedeaepd.gob.es
“What personal data does Grupo Alkora process as the ‘Controller’?
• Individual customers: National ID number or Tax ID number, first and last names,
contact information (address, phone number, email), signature, personal and
professional characteristics, social circumstances, commercial, economic, financial,
and insurance information, and health-related data (life and accident insurance).”
Meanwhile, on page 22 of Annex I to ALKORA’s brief dated July 9, 2024, the forensic
report dated May 3, 2023, stated:
“Analysis of lateral movement during the attack period has shown that the attackers
were able to move freely throughout the entire information system by compromising
privileged accounts, such as domain administrators.”
And on page 33 of that same report:
“The encryption of the servers directly impacts the integrity and availability of the
enterprise’s systems and applications. Furthermore, the exfiltration of data impacts the
confidentiality of the enterprise’s sensitive documents, as well as customers’ personal
data.”
“The integrity and availability of all systems and services have been impacted.”
In ALKORA’s 2024 training activities, on page 415 of Annex VII of its submission dated July
9, 2024, the processing of personal data was mentioned: “Individual customers: National ID
number or Tax ID number, first and last names, contact information (address, phone
number, email), signature, personal and professional characteristics, social circumstances,
commercial, economic, financial, and insurance information, and health-related data (life
and accident insurance).”
As mentioned above:
- The RAT provided as Annex V to the letter dated February 14, 2024, in response
to the referral of the complaint, listed five “filing systems” processed by ALKORA.
- The postal or email address and telephone number appeared in all “filing systems,”
1 through 5.
- The signature appeared in the filing systems 1 through 4.
- ALKORA stated in its letter dated July 9, 2024, that the checking account number
was included in the filing system 5 for the purpose of collecting payments from
customers.
The claimant stated in the complaint that she was a client of ALKORA, which implies that
she must have been an insured party, policyholder, or beneficiary—or all of the above—
from which it follows that she must have been included in at least one of the “filing systems”
2 (insurance brokerage for individuals) or 3 (life and accident insurance brokerage for
individuals), in addition to being included in File 5 (tax and accounting).
From Annex I of ALKORA’s submission dated July 9, 2024, which includes the forensic
report dated May 3, 2023 (pages 22 and 33 of the document, including all annexes), it
follows that
6 Jorge Juan
Street, 28001 –
Madrid21/76
www.aepd.es
sedeaepd.gob.es
the data breach affected customers’ personal data and that the attackers gained access to
all of it.
Along with the complaint, the complainant provided the email she sent to ALKORA on May
24, 2023, in which she stated that she received notification of the breach on May 11 and
requested a copy of the police report mentioned therein. ALKORA responded the following
day, denying the request for a copy of the police report (although it provided the report
number) and further stated:
“Following the work being carried out by the teams of professionals handling this
matter, we can confirm that there were no documents belonging to you on the
document server from which the data exfiltration occurred.
On the other servers—for which we cannot confirm that a data breach occurred—the
only personal data on record would be your first and last names and your national ID
number.”
From the information extracted from Annex V of the response to the referral of the
complaint and from its letter dated July 9, 2024, and its annexes, it can be inferred that the
breach may have affected the other types of data included in both the “filing system” and
the “file” 2 and 3, and at least, among other things, the complainant’s signature, phone
number, mailing address and/or email address, and bank account number—and not just
her first and last names and ID number, as ALKORA informed her on May 25, 2023.
Risk Analysis and Data Protection Impact Assessment (R&DPIA):
As mentioned above, filing systems numbers 3 and 4 involved the processing of health
data, and filing systems numbers 1 and 5 involved the processing of bank account
numbers.
The Risk Analysis provided as Annex V to the letter dated February 14, 2024, in response
to the referral of the complaint, lists, among others, the following sections under
“REGULATORY COMPLIANCE” (file number in parentheses):
Security Policy (1; 2; 3; 4; 5)
- Processing Risks: “The processing has been analyzed, and there is no
likelihood of a high risk to the data subject rights and freedoms.”
Security Policy (3; 4)
- Impact Assessment: “The processing has been analyzed in accordance
with the Report on the Need to Conduct an Impact Assessment, and there is no
likelihood of a high risk to the data subject rights and freedoms.”
The “ORGANIZATION” section of the aforementioned Risk Analysis stated: “[A DPIA is not
required because] the processing does not pose a high risk to the rights and freedoms of
natural persons.”
6 Jorge Juan
Street, 28001 –
Madrid22/76
www.aepd.es
sedeaepd.gob.es
ALKORA also provides, as Annex III to its letter dated July 9, 2024 (pages 52–119 of the
document including all annexes), an unsigned Risk Analysis (RA), version 2.0 dated
November 1, 2023, which was prepared after the data breach, in which it reclassifies the
initial and final risks for filing systems 3 and 4—which involve the processing of health
data—as “High”; this RA maintains the initial and final risks associated with the processing
of filing systems 1 and 5—which include banking data—as “Medium” and “Low,”
respectively.
This new AR also mentions the need to conduct a Data Protection Impact Assessment
(DPIA) for files 3 and 4. ALKORA also provides, as Annex IV to its letter dated July 9, 2024
(pages 120–130 of the document containing all annexes), an unsigned report, version 2.0
dated November 1, 2023, on the need to conduct impact assessments, which concludes
that such assessments are necessary for the “Health and Life Insurance Brokerage” and
“Claims” filing systems due to the processing of special categories of data and data on
vulnerable groups:
“Conclusions:
At least two of the criteria established in the AEPD’s list of processing activities are met in
the “Health and Life Insurance Brokerage” and “Claims” filing systems, as they involve data
on vulnerable groups, such as minors, as well as special categories of data—‘health
data’—therefore making it necessary to conduct a Data Protection Impact Assessment on
the aforementioned processing activities, as they could pose a high risk to the data subject
rights and freedoms. Likewise, Alkora prepared a report on the need to appoint a data
protection officer, in which it analyzed whether or not large-scale processing of personal
data is taking place; the analysis was inconclusive due to the lack of clarity in the criteria
established by WP 243. However, since at least two of the AEPD’s criteria are already met,
we consider it necessary to conduct a Data Protection Impact Assessment (DPIA)
regarding the processing of minors’ data and health data in the relevant filing systems.”
There is no record in this case file that ALKORA provided this Agency with the
aforementioned DPIA reports.
Technical security measures prior to the breach:
ALKORA submitted, as Annex V to its brief dated July 9, 2024 (pp. 131–221 of the
document including all annexes), an unsigned internal audit report on its information
systems, version v0.04 dated February 20, 2022 (prior to the breach). The IT services risk
assessment table in that report, on page 194, indicated an “Extreme” risk (marked in red)
for the information systems and web portals with respect to cybercrimes.
It follows from that report that ALKORA:
- Due to (…).
- Relyed on the protection (…).
- Did not consider it a source of risk (…).
- Considered it sufficient (…).
- Created virtual servers (…).
- I considered the installed antivirus software (…).
6 Jorge Juan
Street, 28001 –
Madrid23/76
www.aepd.es
sedeaepd.gob.es
- I considered the solutions adopted (…) to be adequate: “(…)”
- I considered that no significant improvements could be made in (…).
- It had a (…) service which, according to the forensic report (Annex I of ALKORA’s
brief dated July 9, 2024), was not effective.
The internal audit report provided as Annex V to ALKORA’s brief dated July 9, 2024 (page
167 of the document including all annexes), stated:
(…)
Regarding the antivirus software, the forensic report submitted as Annex I to ALKORA’s
brief dated July 9, 2024 (pp. 2–44 of the document containing all annexes), indicated that
the ***PROGRAMA.2 antivirus software that was installed did not issue any alerts during
the encryption of at least one of the workstations.
The recommendations in the aforementioned forensic report revealed that ALKORA could
have implemented additional measures, which are described on pages 35 through 37 of
the document including all annexes, and which the report recommends be adopted as a
“High” priority:
- (…)
In addition, the forensic report recommends the adoption of twenty-two other measures,
which it classifies as “Medium” and “Low” priorities.
ALKORA also provides, as Annex V b of its submission dated July 9, 2024 (pages 222–318
of the document including all annexes), an unsigned “pentesting” (penetration testing of its
computer system) audit report, Version 1.0, dated July 9, 2024.
The penetration test, conducted by ***SISTEMA.1, revealed that: “The security audit
revealed a number of vulnerabilities and weaknesses which, when jointly exploited, would
enable the entire domain to be compromised by gaining domain Administrator privileges,
with access only to the internal network.” (unofficial translation: “The security audit revealed
a series of vulnerabilities and weaknesses that, when exploited together, would have
allowed the entire domain to be compromised by obtaining domain administrator privileges,
with access only to the internal network”).
Section 3.4 of Annex V b (password audit) stated that (…)
The aforementioned audit highlighted eight “high” severity vulnerabilities:
- (…)
And 10 “medium” vulnerabilities:
- (…)
6 Jorge Juan
Street, 28001 –
Madrid24/76
www.aepd.es
sedeaepd.gob.es
Reactive technical measures:
The internal audit report provided as Annex V to ALKORA’s letter dated July 9, 2024,
highlighted some of the reactive measures adopted by ALKORA following the breach:
- (…)
ALKORA also submitted, as Annex V(c) to its brief dated July 9, 2024 (pp. 319–324 of the
document containing all annexes), an unsigned internal incident resolution report dated
April 10, 2024, following the penetration test, in which it stated (…).
When asked about the level of network segmentation ((…)), ALKORA states in its brief
dated December 23, 2024, that:
“(…)”
Training activities related to personal data protection:
ALKORA provides an internal audit report on its information systems as Annex V to its
letter dated July 9, 2024 (pages 131–221 of the document, including all annexes), prior to
the breach, which indicated that it did not provide cybersecurity training on a widespread
basis, but only to employees who requested it, and that it did so because of its reliance on
antivirus software.
ALKORA refers (pp. 30–32 of its brief dated July 9, 2024) to the documentation provided in
Annex VII of that brief, relating to training programs that included topics on personal data
protection.
Among these, four continuing education reports are provided (pp. 327–389 of the
document, including all annexes), which ALKORA stated it had completed prior to the data
breach (from 2020 to 2023). These reports pertain to its insurance training program, which,
as indicated in the reports, the company is required to provide under:
- Royal Decree 764/2010, of June 11, implementing Law 26/2006, of July 17, on
private insurance and reinsurance mediation regarding statistical, accounting, and
business information, and professional competence.
- Resolution of February 18, 2011, of the General Directorate of Insurance and
Pension Funds, establishing the requirements and basic principles of training
programs for insurance intermediaries, reinsurance brokers, and other persons
directly involved in private insurance and reinsurance mediation.
The annual reports for the years 2020 through 2022 included a section (in 2020, a 20-hour
program covering six topics, and in 2021 and 2022, a
26-hour program covering five topics) on regulatory compliance related to personal data
protection. The reports mention attendance at these training activities but do not mention
their evaluation.
6 Jorge Juan
Street, 28001 –
Madrid25/76
www.aepd.es
sedeaepd.gob.es
The 2020 and 2022 reports mention that “In addition to this program, some team members
have also participated in other training activities,” for which they provide a list but do not
specify the number of participants or their professional profiles.
The 2023 report describes a training program attended by 20 people, 15 of whom
successfully completed it, with a total course load of 25 hours for Level II staff (15 hours for
Level III staff) that includes one module (number 3) titled “Data Protection Regulations” and
another (number 7) titled “Network Security,” out of a total of seven modules.
ALKORA also provides, as Annex VII e of its brief dated July 9, 2024 (pages 390–405 of
the document containing all annexes), a January 2024 report regarding a 2-hour training
session on personal data protection, which includes the results of an assessment test taken
by 139 participants, and the content of which ALKORA provides as a PowerPoint
presentation (Annex VII f, pp. 406–430 of the document containing all annexes).
Additionally, ALKORA provides, from Annex VII g through Annex VII r of its submission
dated July 9, 2024 (pages 431 through 465 of the document with all annexes), copies of
several emails, which it states were distributed by the IT department to ALKORA staff,
containing cybersecurity awareness content, including one warning of a phishing attempt
detected at the company in the weeks leading up to the breach.
Organizational measures taken after the breach:
In the annexes to the letter dated July 9, 2024, ALKORA provides documentation regarding
the adoption or modification of organizational measures following the breach:
- Attached as Annex VII s (pages 466–473 of the document containing all annexes)
is a document titled “Data Protection Policy,” version 1.0 dated November 7, 2023,
unsigned.
- Attached as Annex VII t (pages 474–589 of the document containing all annexes)
is a document titled “Information Systems Security Policy,” version 1.0 dated
November 7, 2023, unsigned.
- Attached as Annex VII u (pages 590–595 of the document with all annexes) is a
document titled “Annex to the Protocol on Best Practices for Personal Data
Protection and Information Security,” version v.1 dated March 1, 2024, unsigned.
- Attached as Annex VII v (pages 596–600 of the document containing all annexes)
is a document titled “Procedure for Protecting Filing Systems Containing Personal
Data with a Password,” version v2, dated May 2024, unsigned.
6 Jorge Juan
Street, 28001 –
Madrid26/76
www.aepd.es
sedeaepd.gob.es
SIXTH: On April 15, 2025, the Presidency of the Spanish Data Protection Agency decided
to initiate disciplinary proceedings against the respondent, in accordance with the
provisions of Articles 63 and 64 of Law 39/2015, of October 1, on the Common
Administrative Procedure of Public Administrations (hereinafter, LPACAP), for the alleged
violation of Article 5.1.f) of the GDPR and Article 35 of the GDPR, as defined in Article 83.5
of the GDPR and Article 83.4 of the GDPR, respectively.
SEVENTH: After being notified of the aforementioned decision to initiate proceedings in
accordance with the provisions of Law 39/2015, of October 1, on the Common
Administrative Procedure of Public Administrations (hereinafter, LPACAP), on May 6, 2025,
ALKORA submitted a written statement of defense in which, in summary, it asserted that:
- There had been no violation of Article 5.1.f) of the GDPR
- An impact assessment was not required (Art. 35 GDPR)
- Therehad any culpability and should be applied the principle of
proportionality
It was also noted that a request had been made for an expert technical report to verify the
adequacy of the security measures implemented by the brokerage at the time of the
security breach, which would be submitted as soon as it was issued by the external expert
who had been commissioned.
Accompanying the arguments was an external legal report analyzing the entity’s decision
not to conduct a Data Protection Impact Assessment (DPIA).
EIGHTH: On October 17, 2025, an expert report submitted by ALKORA was received, as
announced in its written response to the decision to initiate disciplinary proceedings.
NINTH: According to the report retrieved from the AXESOR tool on February 8, 2026,
ALKORA is an enterprise incorporated in 1989, with a turnover of €24,007,236 in 2024.
TENTH: A list of the documents on file in this proceeding is attached as an annex.
Based on the proceedings conducted in this case and the documentation in the case file,
the following facts have been established:
PROVEN FACTS
FIRST: ALKORA was the victim of a ransomware attack, the sequence of events of which,
according to the company’s report, was as follows:
(…)
Regarding the details of the attack, as reported by ALKORA:
6 Jorge Juan
Street, 28001 –
Madrid27/76
www.aepd.es
sedeaepd.gob.es
• (…)
According to ALKORA:
- (…)
SECOND: The forensic report provided by ALKORA, which analyzes the breach, identifies
some of the actions carried out by the attacking group following the initial intrusion,
consisting of:
- access to the messaging management server: “(…)”
- reconnaissance from that server to gather information about domain
administrators, elevate their User privileges, and move throughout the rest of the
system: “(…)”
It also indicates that over the next three days the following occurred:
- privilege escalation
- access to the local administration account (…) ***SERVER.1, which grants the
highest privileges on the system
- Installation and execution of the program ***PROGRAM.1, despite being blocked
twice by ***PROGRAM.2; the attacker manages to hide and avoid further blocking
by the antivirus
- Installation of the ***PROGRAM.3 program
- data exfiltration
- Encryption of servers and workstations The forensic
report also states:
“The attackers were able to move freely throughout ALKORA’s infrastructure (…).”
“The ransomware is deployed manually on ***SERVER.1 and automatically on the
workstations (…)”
According to the forensic report:
“Analysis of lateral movement during the attack period has shown that the attackers
were able to move freely throughout the entire information system by compromising
privileged accounts, such as domain administrators.”
THIRD: Regarding the circumstances preceding the attack that may have contributed to its
success, ALKORA notes the following:
- “(…)”
These are measures that, therefore, did not exist prior to the incident but were, on the
contrary, adopted in response to it.
6 Jorge Juan
Street, 28001 –
Madrid28/76
www.aepd.es
sedeaepd.gob.es
FOURTH: According to the information provided by ALKORA and included in the case file,
certain system deficiencies have affected the investigation of the attack itself:
“Several factors have contributed to limiting the investigative capacity of the
***ENTERPRISE.1 team:
• (…)
FIFTH: In the data breach notifications submitted to this Agency on April 22 and May 17,
2023, ALKORA stated:
- that it had suffered a breach of confidentiality, availability, and integrity due to a
cyberattack;
- that the affected activity involved the processing of data belonging to approximately
25,000 individuals, including minors;
- that the data was not encrypted.
Subsequently, in its letter dated July 9, 2024, ALKORA revised the approximate number of
affected individuals to 40,000.
According to the forensic report provided by ALKORA:
“The encryption of the servers directly impacts the integrity and availability of the
enterprise’s systems and applications. Furthermore, the data exfiltration impacts the
confidentiality of the enterprise’s sensitive documents, as well as customers’ personal
data.”
“The integrity and availability of all systems and services have been impacted.”
SIXTH: Regarding the types of data, in its letter dated February 14, 2024, in response to
the referral of the complaint, ALKORA stated that the types of personal data affected were:
“1. Basic data of individual customers, corporate customers (policyholders, insured
parties, beneficiaries), potential customers, and staff:
First name, last name, date of birth, National ID number, Foreign Resident ID number,
passport, and/or any other identification document; economic or financial data
(excluding payment methods); contact information; health data (exclusively for
employees, limited to what is essential for the employment relationship); and access or
identification credentials (User name and/or password).
2. Health data of individual customers with life insurance and/or accident insurance
policies.”
Meanwhile, on page 22 of Annex I to ALKORA’s brief dated July 9, 2024, the forensic
report dated May 3, 2023, stated:
“Analysis of lateral movement during the attack period has shown that the attackers
were able to move freely throughout the
6 Jorge Juan
Street, 28001 –
Madrid29/76
www.aepd.es
sedeaepd.gob.es
entire information system by compromising privileged accounts such as domain
administrators.”
SEVENTH: ALKORA also provides, as Annex V(b) to its brief dated July 9, 2024 (pages
222–318 of the document including all annexes), an unsigned “pentesting” (penetration
testing of its computer system) audit report, Version 1.0, dated July 9, 2024.
The penetration test, conducted by ***SISTEMA.1, revealed that: “The security audit
revealed a number of vulnerabilities and weaknesses which, when jointly exploited, would
enable the entire domain to be compromised by gaining domain administrator privileges,
with access only to the internal network.” (unofficial translation: “The security audit revealed
a series of vulnerabilities and weaknesses that, when exploited together, would have
allowed the entire domain to be compromised by obtaining domain administrator privileges,
with access only to the internal network”).
Section 3.4 of Annex V b (password audit) indicated that (…).
The aforementioned audit highlighted eight “high” severity vulnerabilities:
- (…)
And 10 “medium” vulnerabilities:
- (…)
EIGHTH: When asked about the level of network segmentation ((...)), ALKORA states in its
letter dated December 23, 2024, that:
(…)
NINTH: In the Risk Analysis conducted by ALKORA on September 19, 2019, version 0.1,
submitted as Annex V to ALKORA’s letter dated February 14, 2024, in response to the
referral of the complaint, five files are listed: “LABOR AND HR,” “INSURANCE
BROKERAGE FOR INDIVIDUALS,” “LIFE AND ACCIDENT INSURANCE BROKERAGE
FOR INDIVIDUALS,” “INSURANCE CLAIMS,” and “TAX AND ACCOUNTING.”
Regarding the “LABOR AND HR” filing system, the
following is stated: “Categories of data
subjects: Employees”
“Identifying data: National ID number (DNI) or Tax ID number (NIF), first and
last names, mailing or email address, phone number, handwritten signature,
Social Security number or mutual insurance number
Special categories of data: Digitized fingerprint (biometric data) Other
type of data Characteristics Personal, Academic
and professional, Details of employment,
Transactions of goods and services.”
6 Jorge Juan
Street, 28001 –
Madrid30/76
www.aepd.es
sedeaepd.gob.es
Regarding “INSURANCE BROKERAGE FOR INDIVIDUALS”:
“Identifying information: ID number or Tax ID number, first and last names,
mailing or email address, phone number, handwritten signature
Special categories of data: N/A
Other types of data: Personal data, academic and professional information,
transactions involving goods and services, social circumstances,
commercial information, economic, financial, and insurance information”
Regarding “ “BROKERAGE INSURANCE INSURANCE LIFE
LIFE AND ACCIDENT FOR INDIVIDUALS”:
“Identifying information: ID number or tax ID number, first and last names,
mailing or email address, phone number, handwritten signature
Special categories of data: Health
Other types of data: Personal data, academic and professional information,
transactions involving goods and services, social, economic, financial, and
insurance-related circumstances”
Regarding “INSURANCE CLAIMS”:
“Identifying information: National ID number (DNI) or Tax ID number (NIF),
first and last names, mailing or email address, phone number, handwritten
signature, image
Special categories of data: Health
Other types of data: Personal data, academic and professional information,
transactions involving goods and services, social circumstances, economic,
financial, and insurance information”
Regarding “TAX AND ACCOUNTING”:
“Identifying information: ID number or tax ID number, first and last names,
mailing or email address, phone number
Special categories of data: N/A Other
types of data: N/A”
Regarding the risks associated with each filing system, the aforementioned Risk Analysis
states:
- Regarding “Filing System 1: EMPLOYMENT AND HR”:
o The identifying data and other specified data subject to processing are
considered to have an initial “Low” risk.
o Regarding “Data Protection (Integrity and Confidentiality),” it is stated that
“There are adequate measures in place to protect data against
unauthorized processing and loss or destruction, in accordance with the
provisions of this section of the document,” an initial risk level of “Medium”
is assigned, and the measures detailed are “Ensuring that adequate
technical and organizational measures have been implemented to protect
the data through the corresponding periodic annual verification,” after which
a final risk level of “Very low” is assigned.
6 Jorge Juan
Street, 28001 –
Madrid31/76
www.aepd.es
sedeaepd.gob.es
o Regarding “Processing Risks,” it is indicated that “THE PROCESSING
HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the
data subject rights and freedoms,” an initial risk of “Medium” is assigned,
and the measures are detailed as follows: “It has been verified that the risk
analysis conducted does not identify any threats with a probability of high
risk to the data subject rights and freedoms,” after which a final risk of “Low”
is assigned.
o Regarding “Access to special categories of data,” it is stated that “There are
no special categories of data,” and therefore it is assigned an initial and final
risk rating of “Very Low.”
- Regarding “Filing System 2: INSURANCE BROKERAGE FOR INDIVIDUALS”:
o It is considered that the identifying data and other specified data subject to
processing have an initial risk of “Low.”
o Regarding “Data Protection (Integrity and Confidentiality),” it is indicated
that “There are adequate measures in place to protect the data against
unauthorized processing and loss or destruction, in accordance with the
provisions of this document,” an initial risk of “Medium” is assigned, and the
measures are detailed as follows: “Ensure that adequate technical and
organizational measures have been implemented to protect the data
through the corresponding periodic annual verification,” after which a final
risk of “Very low” is assigned.
o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS
BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data
subject rights and freedoms,” an initial risk of “Medium” is assigned, and the
measures are detailed as follows: “It has been verified that the risk analysis
conducted does not identify any threats with a high probability of risk to the
data subject rights and freedoms,” after which a final risk of “Low” is
assigned.
o Regarding “Access to special categories of data,” it is stated that “There are
no special categories of data,” and therefore an initial and final risk rating of
“Very Low” is assigned.
- Regarding “Filing System 3: LIFE AND ACCIDENT INSURANCE BROKERAGE
FOR INDIVIDUALS”:
o It is considered that the identifying data and other specified data subject to
processing have an initial risk of “Low.” However, health data is assigned
an initial risk of “High.”
o Regarding “Data Protection (Integrity and Confidentiality),” it is stated that
“There are adequate measures in place to protect the data against
unauthorized processing and loss or destruction, in accordance with the
provisions of this document,” it is assigned an initial risk of “Medium,” and
the measures are detailed as follows: “Ensure that adequate technical and
organizational measures have been implemented to protect the data
through the corresponding periodic annual verification,” after which a final
risk of “Low” is assigned
6 Jorge Juan
Street, 28001 –
Madrid32/76
www.aepd.es
sedeaepd.gob.es
o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS
BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data
subject rights and freedoms,” an initial risk of “Medium” is assigned, and the
measures are detailed as follows: “It has been verified that the risk analysis
conducted does not identify any threats with a high probability of risk to the
data subject rights and freedoms,” after which a final risk of “Low” is
assigned.
o Regarding “Access to special categories of data,” it is stated that
“ADDITIONAL security measures are in place in accordance with the
provisions of section 4.4 of this document”; an initial risk rating of “Medium”
is assigned, and the measures are detailed as follows: “An up-to-date
record must be maintained of personnel with access to special categories of
data. It is recommended to strengthen these measures with two-factor
authentication, encryption…,” after which a final risk rating of “Very low” is
assigned.
- Regarding “Filing System 4: INSURANCE CLAIMS”:
o It is considered that the identifying data and other specified data subject to
processing have an initial risk of “Low.” However, health data is assigned
an initial risk of “High.”
o As for “Data Protection (Integrity and Confidentiality),” it is stated that
“There are adequate measures in place to protect the data against
unauthorized processing and loss or destruction, in accordance with the
provisions of this document,” it is assigned an initial risk of “Medium,” and
the measures are detailed as follows: “Ensure that adequate technical and
organizational measures have been implemented to protect the data
through the corresponding periodic annual verification,” after which a final
risk of “Low” is assigned.
o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS
BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data
subject rights and freedoms,” an initial risk of “Medium” is assigned, and the
measures are detailed as follows: “It has been verified that the risk analysis
conducted does not identify any threats with a high probability of risk to the
data subject rights and freedoms,” after which a final risk of “Low” is
assigned.
o Regarding “Access to special categories of data,” it is stated that
“ADDITIONAL security measures are in place in accordance with the
provisions of section 4.4 of this document”; an initial risk rating of “Medium”
is assigned, and the measures are detailed as follows: “An up-to-date
record must be maintained of personnel with access to special categories of
data. It is recommended to strengthen these measures with two-factor
authentication, encryption…”, after which a final risk rating of “Very low” is
assigned.
- Regarding “Filing System 5: TAX AND ACCOUNTING”:
o The identifying data subject to processing is considered to have an initial
risk of “Low.”
6 Jorge Juan
Street, 28001 –
Madrid33/76
www.aepd.es
sedeaepd.gob.es
o As for “Data Protection (Integrity and Confidentiality),” it is stated that
“There are adequate measures in place to protect the data against
unauthorized processing and loss or destruction, in accordance with the
provisions of this document,” an initial risk of “Medium” is assigned, and the
measures are detailed as follows: “Ensure that adequate technical and
organizational measures have been implemented to protect the data
through the corresponding periodic annual verification,” after which a final
risk of “Low” is assigned
o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS
BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data
subject rights and freedoms,” an initial risk of “Medium” is assigned, and the
measures are detailed as follows: “It has been verified that the risk analysis
conducted does not identify any threats with a high probability of risk to the
data subject rights and freedoms,” after which a final risk of “Low” is
assigned.
o Regarding “Access to special categories of data,” it is stated that “There are
no special categories of data,” and therefore an initial and final risk rating of
“Very Low” is assigned.
- “Processing of data of children under 14 years of age” is mentioned as a specific
processing activity, indicating that “Data processing of children under 14 years of
age is carried out only in cases of school accidents”; an initial risk of “Medium” is
assigned, and the measures indicated are “Ensure that the measures referred to in
section 4.4 through the corresponding periodic annual verification,” after which a
final risk of “Low” is indicated.
This document also includes the following sections under “REGULATORY COMPLIANCE”
(file number in parentheses):
Security Policy (1; 2; 3; 4; 5)
- Processing Risks: “The processing has been analyzed, and there is no
likelihood of a high risk to the data subject rights and freedoms.”
Security Policy (3; 4)
- Impact Assessment: “The processing has been analyzed in accordance
with the Report on the Need to Conduct an Impact Assessment, and there is no
likelihood of a high risk to the data subject rights and freedoms.”
The “ORGANIZATION” section of the aforementioned Risk Analysis stated: “[A DPIA is not
required because] the processing does not pose a high risk to the rights and freedoms of
natural persons.”
TENTH: In the unsigned Risk Analysis provided by ALKORA, version 2.0 dated November
1, 2023, submitted as Annex III to its letter of July 9, 2024, the initial and final risks for filing
systems 3 and 4 are reclassified as “High,” which
6 Jorge Juan
Street, 28001 –
Madrid34/76
www.aepd.es
sedeaepd.gob.es
These include the processing of health data; this risk assessment maintains the initial and
final risks associated with the processing of filing systems 1 and 5—which contain banking
data—at “Medium” and “Low,” respectively.
This new risk analysis mentions the need to conduct a Data Protection Impact Assessment
(DPIA) for filing systems 3 and 4.
ELEVENTH: In ALKORA’s unsigned report, version 2.0 dated November 1, 2023, on the
need to conduct impact assessments, which ALKORA provides as Annex IV to its letter
dated July 9, 2024, it is concluded that DPIA are necessary for the “Health and Life
Insurance Brokerage” and “Claims” filing systems due to the processing of special
categories of data and data on vulnerable groups:
“Conclusions:
At least two of the criteria established in the AEPD’s list of processing activities are met in
the “Health and Life Insurance Brokerage” and “Claims” filing systems, as they involve data
on vulnerable groups, such as minors, as well as special categories of data—‘health
data’—therefore making it necessary to conduct a Data Protection Impact Assessment on
the aforementioned processing activities, as they could pose a high risk to the data subject
rights and freedoms. Likewise, Alkora prepared a report on the need to appoint a data
protection officer, in which it analyzed whether or not large-scale processing of personal
data is taking place; the analysis was inconclusive due to the lack of clarity in the criteria
established by WP 243. However, since at least two of the AEPD’s criteria are already met,
we consider it necessary to conduct a Data Protection Impact Assessment (DPIA)
regarding the processing of minors’ data and health data in the relevant filing systems.”
TWELFTH: Based on the information contained in the case file and that provided by
ALKORA, there is no record that a Data Protection Impact Assessment has been
conducted.
LEGAL GROUNDS
I
Jurisdiction
In accordance with the powers granted to each supervisory authority under Article 58(2) of
Regulation (EU) 2016/679 (GDPR), and as established in Articles 47, 48(1), 64(2), and
68(1) of Organic Law 3/2018 of December 5 on Data Protection and the Guarantee of
Digital Rights (hereinafter, LOPDGDD), the Presidency of the Spanish Data Protection
Agency has jurisdiction to rule on this proceeding.
Likewise, Article 63.2 of the LOPDGDD provides that: “Proceedings handled by the
Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU)
2016/679, this Organic Law, the
6 Jorge Juan
Street, 28001 –
Madrid35/76
www.aepd.es
sedeaepd.gob.es
issued in implementation thereof and, to the extent they do not contradict them, on a
subsidiary basis, by the general rules on administrative procedures.”
II
Preliminary Issues
Article 4(1) of the GDPR defines “personal data” as: “any information relating to an
identified or identifiable natural person (‘the data subject’); an identifiable natural person is
one whose identity can be determined, directly or indirectly, in particular by reference to an
identifier such as a name, an identification number, location data, an online identifier, or
one or more factors specific to the physical, physiological, genetic, mental, economic,
cultural, or social identity of that person.”
Article 4(2) of the GDPR defines “processing” as: “any operation or set of operations
performed on personal data or sets of personal data, whether by automated means or not,
such as collection, recording, organization, structuring, storage, adaptation or alteration,
retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making
available, alignment or combination, restriction, erasure, or destruction.”
Article 4(7) of the GDPR defines the “controller” or “data controller” as: “the natural or legal
person, public authority, agency, or other body which, alone or jointly with others,
determines the purposes and means of the processing; if Union or Member State law
determines the purposes and means of the processing, the controller or the specific criteria
for its designation may be established by Union or Member State law.” In turn, article
4.8) of the GDPR defines the “processor” as the natural or legal person, public authority,
agency, or other body that engages in personal data processing on behalf of the controller.
In the present case, in accordance with the provisions of Articles 4(1) and 4(2) of the
GDPR, the processing of personal data has taken place, since ALKORA carries out, among
other processing activities, the collection and storage of personal data of natural persons:
national ID number or tax ID number, first and last names, mailing or email address,
telephone number, image, handwritten signature, social security or mutual insurance
number, health data, marital status, family information, date and place of birth, age, sex,
nationality, housing and property data, academic and professional data, commercial
information, employment data, economic, financial, and insurance data, and bank account
number.
ALKORA carries out this activity in its capacity as the controller, as it is the entity that
determines the purposes and means of such activity, pursuant to Article 4.7 of the GDPR.
6 Jorge Juan
Street, 28001 –
Madrid36/76
www.aepd.es
sedeaepd.gob.es
III
Objections to the Notice of Initiation
With regard to the arguments raised in the decision to initiate these disciplinary
proceedings, we will address them in the order set forth by ALKORA.
FIRST. Regarding the absence of a violation of Article 5(1)(f) of the GDPR
ALKORA argues that the mere existence of vulnerabilities does not, in and of itself,
constitute proof of a violation of Article 5(1)(f) in conjunction with Article 32 of the GDPR.
Furthermore, article 32 of the GDPR requires the controller to adopt “appropriate technical
and organizational measures to ensure a level of security appropriate to the risk,” without
requiring absolute security or imposing an obligation to achieve a specific result. Moreover,
there is no list of mandatory measures; rather, the choice of appropriate and reasonable
measures is left to the discretion of the controller.
ALKORA understands that the technical reports provided demonstrate, precisely, the
existence of an active policy for reviewing, detecting, and rectifying vulnerabilities, which
shows the entity’s diligence in managing the security of the personal data processed. The
fact that the vulnerabilities were identified and subsequently corrected reinforces—rather
than undermines—compliance with the principle of proactive responsibility set forth in
Article 5(2) of the GDPR. It was a reactive report in response to a security breach. The aim
is to identify potential improvements, but until then, the level of security was more than
acceptable.
Furthermore, a violation can only be concluded to exist when it is proven that the measures
adopted were manifestly insufficient in light of the actual and foreseeable risk, which must
be assessed ex post but by applying ex ante criteria—that is, those that were reasonable at
the time of processing.
ALKORA argues that, in the regulatory authority’s notice of initiation, the Agency merely
transcribes several technical reports submitted that allegedly demonstrate that the
measures adopted prior to the breach were insufficient; however, the Agency does not
explain why they were insufficient or to what extent. It makes no evaluative judgment
whatsoever, which constitutes a clear lack of reasoning. It does not even address whether
the hypothetical vulnerabilities mentioned in the decision to initiate the sanction are linked
to the breach in question or whether their proper implementation could have prevented it.
The Agency does not state to what extent those hypothetical vulnerabilities affected the
breach or whether, had they been implemented, the breach could have been prevented.
ALKORA argues that, in the present case, the insurance brokerage designed and carried
out—prior to the security incident occurring—a structured risk analysis tailored to the nature
of the processing operations, the type of data processed—primarily identifying, contact, and
contractual data—and the volume and profile of the data subjects. This risk analysis,
developed in accordance with
6 Jorge Juan
Street, 28001 –
Madrid37/76
www.aepd.es
sedeaepd.gob.es
methodologies accepted in the field of cybersecurity and data protection—enabled the
entity to identify potential threats, establish impact scenarios, and adopt security measures
that were proportionate and tailored to the operational environment.
It notes that, thanks to this preliminary analysis, the brokerage had in place access control
mechanisms, network segmentation, robust password policies, access monitoring
protocols, and a contingency plan that was activated immediately upon detection of the
incident. All of this enabled the security breach to be detected and contained quickly.
Consequently, it cannot be considered that there was a violation of Article
5.1.f) of the GDPR simply because a breach occurred or because technical reports issued
by external experts at ALKORA’s instance highlight certain areas for improvement (this is
the purpose of such reports, and all of them identify room for improvement—but this cannot
be called negligence; rather, it is active responsibility and continuous risk assessment).
In this case, the entity has rigorously applied the principle of active responsibility at all
stages of processing. It has documented its processing activities in the record provided for
in Article 30, conducted risk analyses in accordance with recognized methodologies,
implemented security policies, trained its staff, and appointed a data protection officer in
accordance with Article 37 of the GDPR.
In this regard, prior to the occurrence of the breach, the organization states that it had
implemented the following technical measures:
- (…)
Furthermore, upon the occurrence of a data breach, the organization activated its
notification protocols, assessed the impact, notified the AEPD within the legal deadline, and
took immediate corrective measures.
Among these measures, it requested a technical report specifically intended to identify
potential risks and determine possible improvements that could be implemented within the
organization. This report is the sole basis on which the Agency has imposed a penalty on
ALKORA, which the company finds surprising because that report was requested in
defense of the principle of proactive responsibility, precisely for the purpose of detecting
vulnerabilities and thereby enabling improvement. The company points out that all systems
have vulnerabilities and are subject to improvement, but this does not imply that the
measures were insufficient given the nature of the data processed. To argue that the mere
occurrence of a breach demonstrates the inadequacy of the security measures
implemented by the affected entity is tantamount to imposing strict liability on it in an area
where, as is well known, such an obligation would be impossible to fulfill.
In this regard, first, this Agency wishes to point out that the purpose of the present
enforcement proceeding is to determine ALKORA’s liability for a possible violation of Article
5(1)(f) of the GDPR and Article 35 of the GDPR, exclusively.
6 Jorge Juan
Street, 28001 –
Madrid38/76
www.aepd.es
sedeaepd.gob.es
The principle set forth in Article 5(1)(f) imposes on the controller of any processing of
personal data the obligation—the guarantee—to prevent unauthorized or unlawful
processing of such data, as well as its loss or destruction. In other words, a controller must
not process personal data if it is unable to guarantee the confidentiality and integrity of such
data, prevent third parties from accessing data that does not concern them, and prevent the
loss or destruction of such data. In this regard, controllers must ensure the integrity and
confidentiality of the personal data being processed through technical and organizational
measures of all kinds.
Compliance with this requirement would therefore be demonstrated by: (i) the adoption and
implementation of technical and organizational measures of all kinds aimed at ensuring the
confidentiality and integrity of the personal data being processed; and (ii) the absence of
any instances of loss of confidentiality or integrity of the personal data being processed.
Failure to comply, on the other hand, would result from the absence of measures or failure
to comply with those adopted, as well as a loss of confidentiality of the data being
processed.
When a breach of confidentiality occurs, unauthorized access to personal data by a third
party means that such data may be used for unknown, even fraudulent, purposes, resulting
in a total and absolute loss of control over it. This loss of control over one’s own personal
data constitutes a violation of the fundamental right to data protection recognized in Article
18.4 of the Spanish Constitution, as the Constitutional Court has stated (Judgement
292/2000, dated November 30, 2000): “The fundamental right to data protection seeks to
guarantee individuals the power to control their personal data, its use, and its destination,
with the purpose of preventing its unlawful trafficking, which is harmful to the dignity and
rights of the data subject (…).
The guarantee established by the legal system will be achieved through the application of
appropriate technical or organizational measures of all kinds. These are not strictly or
solely security measures. There are diverse and numerous technical and organizational
measures—other than security measures—that the controller may implement as a means
of ensuring this principle. In this regard, the AEPD’s Guide on “Risk Management and
Impact Assessment in Personal Data Processing” states that, “(…), it must be emphasized
that addressing the risks that personal data processing may pose to individuals’ rights and
freedoms cannot be limited to applying security measures exclusively. Therefore, security
risk management is just one of the activities involved in managing risks to rights and
freedoms and must be subordinate to the latter. Furthermore, from the perspective of the
GDPR, mitigation measures must be aimed at reducing the impact and likelihood of data
breaches affecting the data subject.”
If only security measures were taken into account in relation to Article 5(1)(f) of the GDPR,
this would amount to oversimplifying the essence of the GDPR, compliance with which is
not limited to the implementation of technical and organizational security measures; in our
case, it would mean reducing the guarantee required by the principles of integrity and
confidentiality to one achieved solely through measures of
6 Jorge Juan
Street, 28001 –
Madrid39/76
www.aepd.es
sedeaepd.gob.es
security. Of course, the appropriate technical or organizational measures referred to in
Article 5.1.f) of the GDPR may be security measures, but they are not the only ones. A
violation of this provision—a breach of confidentiality or integrity—can occur even in the
absence of any security measures or despite their inadequacy.
This legal requirement constitutes an obligation of result, the breach of which constitutes
a result-based infringement. The Supreme Administrative Court ruling of May 13, 2024,
issued in Appeal No. 0002336/2021, states this (emphasis added).
On this basis, the plaintiff entity, in its capacity as the data controller, is held liable
for breaching the duty of confidentiality and integrity under Article 5.1.f) of the
GDPR, given the outcome of those nine complaints, which indicate that it had not
ensured adequate security in the processing of personal data, as evidenced by the
identity theft that occurred. Ultimately, a third party was able to access the personal
data of the line holders without the existing security measures being able to prevent
it. Constituting, in short, further evidence that the security measures in place at the
time the events occurred were inadequate, is the established fact that a change
was made to those measures, as highlighted in the fifteenth established fact in the
contested decision, according to which: “VDF has subsequently subsequently
implemented measures and developed action plans to prevent fraud involving
duplicate SIM cards, focusing on four lines of action (…)”. Therefore, Vodafone, as
the entity responsible for ensuring the integrity and confidentiality of the personal
data processed, and given that, in the nine reported cases, security measures were
ultimately insufficient, must be held liable for the alleged violation of Article 5.1.f) of
Regulation (EU) 2016/679.
Article 5(1)(f) of the GDPR strictly requires that confidentiality and integrity be guaranteed,
and its application necessitates a loss of confidentiality and/or integrity—that is, a specific
outcome.
In the present case, the absence of specific security measures designed specifically to
ensure confidentiality—namely, encryption and pseudonymization (or anonymization)—is
what led to the breach of the confidentiality of personal data. If the data had been
encrypted, anonymized, or pseudonymized, the criminals would have only obtained
unintelligible information.
On the contrary, the measures adopted should have taken into account the “real and
foreseeable” risk—in ALKORA’s words—to the rights and freedoms of the data subjects at
the time of processing; in this case, the measures implemented by ALKORA were not
adequate given the risk to the data subject rights and freedoms, which resulted in a breach
of the confidentiality of such data.
The GDPR takes a proactive approach, requiring controllers to analyze the risks involved in
and to which the processing of personal data is exposed, in order to implement
6 Jorge Juan
Street, 28001 –
Madrid40/76
www.aepd.es
sedeaepd.gob.es
appropriate measures based on those risks. It also requires the ongoing assessment of
such risks in order to monitor and update the measures in place.
This implies that it is not merely a matter of assessing the measures to be implemented at
a given moment—whether before or after such processing takes place—in relation to the
actual and foreseeable risk to the data subject rights and freedoms. Rather, it also involves
continuously reviewing those risks in order to adapt those measures at every stage of the
processing.
The GDPR does not provide a list of measures that apply based on the data being
processed; rather, it stipulates that the controller and processor must implement technical
and organizational measures appropriate to the risk posed by the processing, taking into
account the state of the art, the costs of implementation, the nature, scope, context, and
purposes of the processing, and the likelihood and severity of the risks to the rights and
freedoms of data subjects.
In this regard, Recital 83 of the GDPR states that:
“(83) In order to maintain security and prevent the processing from infringing the provisions
of this Regulation, the controller or processor must assess the risks inherent in the
processing and implement measures to mitigate them, such as encryption. These
measures must ensure an appropriate level of security, including confidentiality, taking into
account the state of the art and the cost of implementation in relation to the risks and the
nature of the personal data to be protected. When assessing the risk to data security,
consideration must be given to the risks arising from the processing of personal data, such
as the accidental or unlawful destruction, loss, or alteration of personal data transmitted,
stored, or otherwise processed, or the unauthorized disclosure of or access to such data,
which may, in particular, result in physical, material, or non-material damage.”
In accordance with Recital 74 of the GDPR, the controller is responsible for demonstrating
that the measures adopted are effective:
“The controller must be held accountable for any processing of personal data carried out by
the controller or on the controller’s behalf. In particular, the controller must be required to
implement appropriate and effective measures and must be able to demonstrate the
compliance of processing activities with this Regulation, including the effectiveness of the
measures. Such measures must take into account the nature, scope, context, and purpose
of the processing, as well as the risk to the rights and freedoms of natural persons.”
These technical and organizational measures are included as part of the principle of
proactive accountability, which requires the controller to conduct a prior assessment of the
risk that the processing of personal data may pose, based on which the appropriate
measures will be adopted.
The GDPR seeks to anticipate infringements or violations of rights in order to prevent them.
This proactive approach to the “ongoing implementation” of the measures
6 Jorge Juan
Street, 28001 –
Madrid41/76
www.aepd.es
sedeaepd.gob.es
implies that they are not static but dynamic; it is up to the controller to determine at all times
which measures are necessary to ensure the confidentiality, integrity, and availability of
personal data and to mitigate or erase risks to individuals’ rights. The first step is to conduct
a “risk analysis” to assess the threats.
It is the controller or processor who must demonstrate this diligence through a robust and
effective internal control system. Therefore, a mere formal demonstration of compliance will
not suffice; rather, this principle requires a preemptive, conscious, diligent, and proactive
approach on the part of organizations regarding all personal data processing activities they
carry out.
The adoption of these measures—or the manner in which they are applied—will depend on
factors that must be taken into account in each case, such as the type of processing and
the risk that such processing poses to the data subject rights and freedoms. Consequently,
due diligence must be tailored to the level of data protection risks and the characteristics of
the organization.
The concept of due diligence can be defined as “the degree of prudence, activity, or
diligence that can reasonably be expected—and with which a prudent and reasonable
organization normally acts—under specific circumstances; it is not measured by an
absolute standard, but rather depends on the relative facts of the case in question.”
Therefore, due diligence is an ongoing process of monitoring and preventing the negative
effects of an organization’s activities on data protection.
In the present case, at the time the agreement to initiate these disciplinary proceedings was
signed, there was no evidence that ALKORA had acted in a proactive manner with regard
to the potential risks and rights of data subjects in connection with the processing.
On October 17, 2025, ALKORA submitted to this Agency an expert report dated October
15, 2025, in which, after analyzing the status of the systems prior to the incident and the
post-incident audit report, it concludes that the measures adopted prior to the incident were
appropriate.
In this regard, it is noteworthy that ALKORA, through a self-prepared report submitted
months after the incident occurred, seeks to refute the information it had previously
provided—both in the breach notifications submitted to the AEPD and in the various
technical reports submitted during the course of the preliminary investigative proceedings.
It is also noteworthy that, in its written arguments submitted in response to the decision to
initiate proceedings, ALKORA indicated that it had access control mechanisms, network
segmentation, robust password policies, access monitoring protocols, and a contingency
plan that was activated immediately upon detection of the incident. All of this enabled the
security breach to be detected and contained quickly.
6 Jorge Juan
Street, 28001 –
Madrid42/76
www.aepd.es
sedeaepd.gob.es
Regarding this argument, let us recall the information provided by ALKORA, which is on
record and appears in the “Proven Facts” section of this Proposed Resolution:
- Regarding the onset of the breach and its detection:
(…)
• Subsequently, reconnaissance activities began to gather information about
the domain administrators, in order to elevate their User privileges and
move throughout the rest of the system: “(…)”.
It also indicates that over the next three days the following occurred:
- privilege escalation
- access to the account for administration account
(…)
***SERVER.1, which grants the highest privileges on the system
- installation and execution of the program ***PROGRAM.1,
despite the lock in two instances by on the
***PROGRAM.2; the attacker manages to hide and avoid further
blocking by the antivirus
- installation of the program ***PROGRAM.3
- data exfiltration
- encryption of servers and workstations
In short, the breach began on April 16 with access to the server, followed by three days of
reconnaissance, privilege escalation, and access to the local administrator account—with
the highest privileges—installation of the malicious program ***PROGRAM.1—bypassing
antivirus blocks, installing the program ***PROGRAM.3, exfiltrating data, and encrypting it.
All of this occurred without ALKORA detecting this malicious activity until April 21—five
days later.
- Regarding network segmentation, note that the forensic report also states:
“The attackers were able to move freely throughout ALKORA’s infrastructure (…).”
“The ransomware is deployed manually on ***SERVER.1 and automatically on the
workstations (…)”
According to that forensic report:
“Analysis of lateral movement during the attack period has shown that the
attackers were able to move freely throughout the entire information system by
compromising privileged accounts, such as domain administrators.”
6 Jorge Juan
Street, 28001 –
Madrid43/76
www.aepd.es
sedeaepd.gob.es
Furthermore, when asked about the level of network segmentation ((...)), ALKORA
stated in its letter dated December 23, 2024, that:
(…)
- Regarding the password policy, which ALKORA describes as robust, it should be
noted that ALKORA also provides, as Annex V b of its submission dated July 9,
2024, a “pentesting” (penetration testing of its computer system) audit report,
Version 1.0 dated July 9, 2024, according to which:
“The security audit revealed a series of vulnerabilities and weaknesses that, when
exploited in combination, would have allowed the entire domain to be compromised
by obtaining domain administrator privileges, with access limited to the internal
network.”
Section 3.4 of that Annex V b (password audit) stated that
(…).
- Regarding access monitoring, it should be noted that, with respect to the
circumstances preceding the attack that may have been related to its success,
ALKORA states the following:
• (…)
In other words, basic measures such as multi-factor authentication, strengthening
access controls, or updating antivirus software were implemented only after the
attack.
Finally, regarding the occurrence of the data breach in confidentiality, it is worth noting that
in the personal data breach notifications submitted to this Agency on April 22 and May 17,
2023, ALKORA stated:
- that it had suffered a breach of confidentiality, availability, and integrity due to a
cyberattack;
- that the affected activity involved the processing of data belonging to approximately
25,000 individuals, including minors;
- that the data was not encrypted.
Subsequently, in its letter dated July 9, 2024, ALKORA revised the approximate number of
affected individuals to 40,000.
It is also important to note that, according to the forensic report provided by ALKORA:
“The encryption of the servers directly impacts the integrity and availability of the
enterprise’s systems and applications. Furthermore, the data exfiltration impacts the
confidentiality of the enterprise’s sensitive documents, as well as customers’ personal
data.”
6 Jorge Juan
Street, 28001 –
Madrid44/76
www.aepd.es
sedeaepd.gob.es
“The integrity and availability of all systems and services have been compromised.”
It should also be noted that the “pentesting” (penetration testing of its IT system) audit
report dated July 9, 2024—that is, after the breach—highlights eight “high” severity
vulnerabilities:
- (…)
And 10 “medium” vulnerabilities:
- (…)
Finally, ALKORA states that, to date, no actual harm has been caused to the rights and
freedoms of the data subjects, and the best proof of this is that the sole complaint received
neither proves nor even alleges that any harm was suffered as a result of the security
breach.
In this regard, this Agency wishes to point out that the fact that ALKORA is unaware of
whether any actual harm to the data subject rights and freedoms occurred does not mean
that no harm occurred at all. In any case, the fact that there was no evidence that any harm
had occurred is one of the circumstances that this authority has taken into account when
determining the proposed penalty, pursuant to the provisions of Article 83(2) of the GDPR.
Likewise, it is worth recalling the Constitutional Court’s ruling in STC 292/2000, which
states that “the fundamental right to data protection seeks to guarantee individuals the
power to control their personal data, its use, and its destination, with the aim of preventing
its unlawful trafficking, which is harmful to the dignity and rights of the data subject. (…)
The right to data protection guarantees individuals the power to dispose of such data;
furthermore, the content of the fundamental right to data protection consists of the power to
dispose of and control personal data, which empowers the individual to decide which of
those data to provide to a third party—whether the State or a private individual—or which
data that third party may collect, and which also allows the individual to know who
possesses such personal data and for what purpose, and to object to such possession or
use. These powers of control and disposal over personal data—which constitute part of the
content of the fundamental right to data protection—are legally embodied in the right to
consent to the collection, acquisition, and access to personal data, as well as its
subsequent storage and processing, and its possible use or uses, by a third party, whether
the State or a private individual. And this right to consent to the disclosure and
processing—whether computerized or not—of personal data requires, as indispensable
complements, on the one hand, the right to know at all times who has access to that
personal data and for what purpose it is being used, and, on the other hand, the right to
object to such possession and use. (…)
Thus, this power of control over one’s own data disappears when the confidentiality of the
data being processed is breached, as has occurred in this case.
6 Jorge Juan
Street, 28001 –
Madrid45/76
www.aepd.es
sedeaepd.gob.es
Also noteworthy is the CJEU judgment of September 4, 2023, rendered in Case C-655/23,
which states that “60 In particular, the Court of Justice has emphasized that from the
illustrative list of ‘damages’ or ‘harm’ that data subjects may suffer, set forth in the first
sentence of Recital 85 first sentence, of the GDPR, it follows that the EU legislature
intended to include within these two concepts, in particular, the mere ‘loss of control’ over
the personal data of those data subjects as a result of a breach of that Regulation, even
where there has been no specific misuse of the data in question. Such a loss of control
may be sufficient to cause “non-pecuniary damage” within the meaning of Article 82(1) of
that Regulation, provided that the data subject demonstrates that he or she has actually
suffered such damage, however minimal, without the concept of “non-pecuniary damage”
requiring proof of the existence of additional tangible negative consequences (see, to that
effect, the judgement of October 4, 2024, Agentsia po vpisvaniyata, C-200/23,
EU:C:2024:827, paragraphs 145, 150, and 156, and the case law cited there). (emphasis
added).
Therefore, it follows from the foregoing that the harm to the data subjects’ right to data
protection lies in the loss of control over that data itself; a loss of control that inevitably
occurs when the confidentiality of their personal data is compromised through access to it
by unauthorized third parties.
For all of the foregoing reasons, the argument raised is dismissed.
SECOND. Regarding the non-requirement of an impact assessment (Art. 35 GDPR)
ALKORA has attached, as Document No. 1 to its written response to the order initiating
these proceedings, the report issued by ***ENTERPRISE.2, dated December 11, 2023,
whose conclusions stated that:
- “Following a comprehensive assessment of the factors involved in Alkora’s processing
activities, it is concluded that the circumstances requiring a Data Protection Impact
Assessment do not apply in this case.”
It states that this conclusion was reached because the mere processing of all such data
does not automatically trigger the obligation to conduct a Data Protection Impact
Assessment (DPIA) when, as was the case here, the processing was residual and linked to
very specific purposes that, in and of themselves, did not pose a high risk to the interests
and data subject rights.
In this regard, this Agency wishes to express its disagreement with the above statement. In
the present case, the issue is not that ALKORA should have conducted a Data Protection
Impact Assessment (DPIA) due to residual processing linked to very specific purposes, but
rather that this Agency considers that, due to its regular business activities, ALKORA was
carrying out processing that, taken as a whole, poses a high risk to the data subject rights
and freedoms.
6 Jorge Juan
Street, 28001 –
Madrid46/76
www.aepd.es
sedeaepd.gob.es
ALKORA states that the decision not to conduct a DPIA was based on the following
considerations:
- The processing of health data and data on minors in the context of ALKORA’s claims
management is incidental, ancillary, and limited to very specific situations in which such
information is necessary to process a complaint in the interest of the insured or beneficiary.
This is not a massive or systematic processing operation, nor is it central to the entity’s
core business activity; the entity does not engage in any large-scale processing of such
data, nor does it carry out systematic monitoring of data subjects, nor does it engage in
profiling or automated decision-making processes that affect the rights and freedoms of
natural persons. The processing does not follow an intensive, mass, or persistent
approach, but is strictly limited to cases in which the data subject has suffered personal
injury or a minor has been affected, and such information is required to file a complaint for
the corresponding compensation with the insurance company. In this regard, the
brokerage’s activity falls within the scope of insurance mediation, and the processing of
sensitive data does not form part of the core of its business activity, as required by the
European Data Protection Board (EDPB) to consider that a high-risk scenario exists that
would require a Data Protection Impact Assessment (DPIA).
In this regard, this Agency wishes to point out that Article 35 of the GDPR does not require
a DPIA to be conducted solely in cases involving large-scale processing, systematic
monitoring, profiling, automated decision-making, or anything of that nature. Nor does this
Agency consider that ALKORA engages in such processing.
However, this Agency wishes to reiterate that Article 35 of the GDPR requires a DPIA to be
conducted when the processing of personal data is likely to result in a high risk to the data
subject rights and freedoms, as in the present case, where data on minors affected by an
accident, employees’ biometric data, and customers’ health, economic, financial, and bank
account information are processed, among others, including data that cannot be changed
(such as ID or tax identification numbers, date of birth) or is very difficult to change
(address)—all of which, when combined, may pose a high risk to data subjects if
compromised.
- ALKORA notes that, in accordance with the Art 29 Working Party (now the EDPB)
Guidelines on Data Protection Impact Assessments (WP248 rev.01), the requirement for a
DPIA arises when several risk factors are present cumulatively: it is not sufficient that
special categories of data are processed if such processing is not carried out on a large
scale or systematically. The residual and exceptional nature of the processing in this case
precludes the existence of a “high risk” to the data subject rights and freedoms.
In this regard, this Agency reiterates that Article 35 of the GDPR does not require a Data
Protection Impact Assessment (DPIA) to be conducted solely in cases involving mass
processing, systematic monitoring, profiling, automated decision-making, or anything of that
nature. Nor does it consider that ALKORA engages in such processing. Nor is the issue
that ALKORA should conduct a DPIA for residual processing linked to very specific
purposes; rather, this Agency considers that, due to its
6 Jorge Juan
Street, 28001 –
Madrid47/76
www.aepd.es
sedeaepd.gob.es
regular activities, ALKORA was carrying out processing that, taken as a whole, poses a
high risk to the data subject rights and freedoms.
Article 35 of the GDPR requires a DPIA to be conducted when the processing of personal
data may pose a high risk to the rights and freedoms of data subjects, as in the present
case, in which data on minors affected by an accident, employees’ biometric data, and
customers’ health, economic, financial, and bank account information are processed,
among others, including data that cannot be changed (such as national ID or tax ID
numbers, date of birth) or is very difficult to change (address)—all of which, when
combined, may pose a high risk to data subjects if compromised.
Specifically, ALKORA argues that the aforementioned WP248 lists nine criteria “in order to
provide a more specific set of processing operations that require a DPIA due to their
inherent high risk, taking into account the specific elements of Article 35(1) and Article 35,
paragraph 3, subparagraphs (a) through (c), the list to be adopted at the national level
pursuant to article 35, paragraph 4, and recitals 71, 75, and 91, as well as other references
in the GDPR to processing operations that
“are likely to result in a high risk,” none of which apply to the ALKORA case.
In this regard, this Agency wishes to point out that the aforementioned list refers to
activities that are likely to result in a high risk, but it is by no means an exhaustive list.
Furthermore, among the listed circumstances are “4. Sensitive data or highly personal data:
this includes the special categories of personal data defined in Article 9 (for example,
information about individuals’ political opinions), as well as personal data relating to
criminal convictions and offenses as defined in Article 10” and “6. The linking or combining
of datasets, for example, from two or more data processing operations carried out for
different purposes or by different controllers in a manner that exceeds the data subject’s
reasonable expectations,” both of which apply in the present case, as explained above.
In any case, Article 35 of the GDPR requires a Data Protection Impact Assessment (DPIA)
to be conducted when the processing of personal data is likely to result in a high risk to the
rights and freedoms of data subjects, as in the present case, where data on minors affected
by an accident, employees’ biometric data, and customers’ health, economic, financial, and
bank account number data are processed, among others, including data that cannot be
changed (such as national ID or tax ID numbers, date of birth) or is very difficult to change
(address)—all of which, when combined, may pose a high risk to the data subjects if
compromised.
- ALKORA states that it processes the data of policyholders and beneficiaries in
accordance with the legal and contractual obligations required of it as an insurance
intermediary. It does not use this data for any purpose other than strict compliance with the
obligations legally assigned to it as an insurance distributor. And it is no coincidence that,
unlike insurance companies, insurance brokerages are not required to appoint a DPO.
6 Jorge Juan
Street, 28001 –
Madrid48/76
www.aepd.es
sedeaepd.gob.es
This is due to the clear purpose limitation on the processing activities they carry out.
In this regard, this Agency wishes to note that it does not consider that ALKORA processes
personal data for any purpose other than the provision of services as an insurance
company, but it does consider that the fact that such enterprises are not required to appoint
a DPO has nothing to do with the possibility that the data processing carried out by
ALKORA does not pose a high risk to the data subject rights and freedoms, which must be
analyzed on a case-by-case basis pursuant to Article 35 of the GDPR.
- ALKORA argues that appropriate technical and organizational measures, proportionate to
the risk, have been adopted, including:
o (…)
And that these measures significantly reduce the level of potential risk that could arise from
the processing, to a threshold at which conducting a DPIA in accordance with Article 35 of
the GDPR is not required.
This Agency views the adoption of such measures favorably but considers that, even with
these measures in place, the risk to the data subject rights and freedoms remains high,
given that ALKORA handles data on minors affected by an accident, employees’ biometric
data, and customers’ health, economic, financial, and bank account information, among
other data, including data that cannot be changed (such as national ID or tax ID numbers,
date of birth) or is very difficult to change (address), all of which, when combined, could
pose a high risk to the data subjects if compromised.
- ALKORA cites the list published by the AEPD of processing activities that require a Data
Protection Impact Assessment (DPIA). It notes that the processing described is not
included in that list, nor in the EDPB’s positive or negative lists, which reinforces the
conclusion that there is no legal obligation per se to conduct the assessment.
In this regard, this Agency wishes to point out that such a list is neither exhaustive nor
definitive. It is reiterated that Article 35 of the GDPR requires a DPIA to be conducted when
the processing of personal data may pose a high risk to data subject rights and freedoms,
as in the present case, where data on minors affected by an accident, employees’ biometric
data, and customers’ health, economic, financial, and bank account information are
processed, among others, including data that cannot be changed (such as ID or tax
identification numbers, date of birth) or is very difficult to change (address)—all of which,
when combined, may pose a high risk to the data subjects if compromised.
Finally, ALKORA argues that, although it was ultimately decided—with proper justification—
not to conduct a data protection impact assessment (DPIA) of the processing activities, an
analysis was indeed carried out of the main risks that could arise from those processing
activities. And that, while the advisability of conducting a DPIA was initially assessed, a
thorough analysis of the context, nature, and scope of the processing led
6 Jorge Juan
Street, 28001 –
Madrid49/76
www.aepd.es
sedeaepd.gob.es
to the conclusion that the conditions required by Article 35 of the GDPR for it to be
mandatory were not met.
In this regard, this Agency wishes to point out that, although the enterprise conducted an
analysis of the potential risks, it considers that said analysis was inadequate, since in this
case the data being processed includes that of minors affected by an accident, employees’
biometric data, and customers’ health, economic, and financial data as well as bank
account numbers, among other information—including data that cannot be changed (such
as national ID or tax ID numbers, date of birth) or is very difficult to change (address)— all
of which, when combined, could pose a high risk to the data subjects if compromised.
For all of the foregoing reasons, this argument is dismissed.
THIRD. Regarding the absence of fault and the application of the principle of
proportionality.
ALKORA argues that even in the hypothetical case that a formal deficiency were found in
the security measures or in the risk assessment, this could not be considered a serious
infringement, but rather, if anything, an action that should be rectified through corrective
measures or a warning, in line with the principle of proportionality and based on Article
58(2)(b) of the GDPR. Furthermore, ALKORA has demonstrated active cooperation with
this Agency at all times and a commitment to continuous improvement in the area of data
protection.
In this regard, this Agency wishes to point out that failing to have risk-appropriate measures
in place to ensure the confidentiality of the data being processed, as well as failing to
conduct an impact assessment when the processing carried out may pose a high risk to the
data subject rights and freedoms, constitutes a serious infringement for the purposes of the
GDPR; therefore, a fine may be imposed, if applicable. Consequently, this argument is
rejected.
IV
Failure to Comply. Integrity and Confidentiality Article
5(1)(f) of the GDPR states:
"1. Personal data shall be:
(…)
f) processed in a manner that ensures appropriate security of the personal data, including
protection against unauthorized or unlawful processing and against accidental loss,
destruction, or damage, through the implementation of appropriate technical or
organizational measures (‘integrity and confidentiality’).”
The principle of confidentiality set forth in Article 5.1(f) of the GDPR requires controllers to
ensure that personal data is processed in a manner that guarantees the confidentiality of
such data, preventing unauthorized access, misuse, or disclosure to unauthorized third
parties. This requires implementing appropriate technical and organizational measures of
all kinds to
6 Jorge Juan
Street, 28001 –
Madrid50/76
www.aepd.es
sedeaepd.gob.es
protect the data against potential data breaches, whether external or internal. These
measures must be adequate to prevent risks to the rights and freedoms of natural persons
arising from the processing from materializing, and must be reviewed and updated
periodically to ensure their effectiveness.
In this case, as Annex I to its July 9, 2024, response to this Agency’s request, ALKORA
submitted the forensic report prepared by the enterprise ***EMPRESA.1, Version V 1.0
dated May 3, 2023, which was unsigned, which stated that, due to the encryption of the
information on the servers, “The method of intrusion, as well as the point of entry, remain
undetermined,” that “The encryption of all servers has limited the capacity for analysis,
thereby preventing the collection of evidence of the initial intrusion,” and that certain system
deficiencies have limited the forensic analysis team’s investigative capacity:
“Several factors have contributed to limiting the investigative capacity of the
***ENTERPRISE.1 team:
• (…)
However, during the investigation conducted by this Agency following the aforementioned
breach suffered by ALKORA in April 2023, the security measures that the enterprise had in
place before and after the breach were identified.
In its letter dated February 14, 2024, in response to the referral of the complaint, ALKORA
outlined a series of security measures implemented prior to the incident to protect the
confidentiality, integrity, and availability of the personal data in its possession. In that letter,
ALKORA also indicated that, as a result of the incident, other security measures had been
adopted and that it was in the process of strengthening the security of its systems by
implementing additional security measures.
As Annex V to its letter dated July 9, 2024 (pp. 131–221 of the document containing all
annexes), ALKORA submitted an unsigned internal audit report on its information systems,
version v0.04 dated February 20, 2022 (prior to the breach). The IT services risk
assessment table in that report, on page 194, indicated an “Extreme” risk (marked in red)
for information systems and web portals with regard to cybercrimes. In other words,
ALKORA was aware that the risk of suffering a cyberattack was extreme.
However, it is clear from that report that ALKORA:
- Due to (…).
- Relyed on the protection (…).
- Did not consider it a source of risk (…).
- Considered it sufficient (…).
- Created virtual servers (…).
- I considered the installed antivirus software (…).
- I considered the solutions adopted (…) to be adequate: “(…)”
- I considered that no significant improvements could be made in (…).”
6 Jorge Juan
Street, 28001 –
Madrid51/76
www.aepd.es
sedeaepd.gob.es
- It had a (…) service which, according to the forensic report (Annex I of ALKORA’s
brief dated July 9, 2024), was not effective.
The February 2022 internal audit report, submitted as Annex V to ALKORA’s brief dated
July 9, 2024 (page 167 of the document including all annexes), stated:
(…)
Regarding the antivirus software, the forensic report submitted as Annex I to ALKORA’s
brief dated July 9, 2024 (pp. 2–44 of the document containing all annexes), indicated that
the ***PROGRAMA.2 antivirus software that was installed did not issue any alerts during
the encryption of at least one of the workstations.
The recommendations in the aforementioned forensic report revealed that ALKORA could
have implemented additional measures, which are described on pages 35 through 37 of
the document including all appendices, and which the report recommended be adopted as
a “High” priority:
- (…)
In addition, the forensic report recommended the adoption of twenty-two other measures,
which it classified as “Medium” and “Low” priorities.
ALKORA also provides, as Annex V b of its submission dated July 9, 2024 (pages 222–318
of the document including all annexes), an unsigned “pentesting” audit report (penetration
test of its computer system), Version 1.0 dated July 9, 2024.
The penetration test, conducted by ***SISTEMA.1, revealed that: “The security audit
revealed a number of vulnerabilities and weaknesses which, when jointly exploited, would
enable the entire domain to be compromised by gaining domain Administrator privileges,
with access only to the internal network.” (unofficial translation: “The security audit revealed
a series of vulnerabilities and weaknesses that, when exploited together, would have
allowed the entire domain to be compromised by obtaining domain administrator privileges,
with access only to the internal network”).
Section 3.4 of Annex V b (password audit) indicated that (...)
The aforementioned audit highlighted eight “high” severity vulnerabilities:
- (…)
And 10 “medium” vulnerabilities:
- (…)
The internal audit report provided as Annex V b of ALKORA’s letter dated July 9, 2024,
highlighted some of the reactive measures adopted by ALKORA following the breach:
6 Jorge Juan
Street, 28001 –
Madrid52/76
www.aepd.es
sedeaepd.gob.es
- (…)
ALKORA also submitted, as Annex V c of its brief dated July 9, 2024 (pp. 319–324 of the
document containing all annexes), an unsigned internal incident resolution report following
the penetration test, Version 1.0 dated July 9, 2024, in which it stated (…).
Regarding training activities, ALKORA submitted an internal audit report on its information
systems as Annex V(a) to its brief dated July 9, 2024 (pp. 131–221 of the document
containing all annexes), prior to the breach, which indicated that it did not provide
cybersecurity training on a widespread basis, but only to employees who requested it, and
that it did so because of its reliance on antivirus software. However, ALKORA has provided
(pp. 30–32 of its brief dated July 9, 2024) a reference to the documentation included in
Annex VII of that brief, relating to training programs that covered topics on personal data
protection.
Additionally, ALKORA provided, from Annex VII g through Annex VII r of its brief dated July
9, 2024 (pages 431–465 of the document including all annexes), copies of several emails,
which it states were distributed by the IT department to ALKORA staff, containing
cybersecurity awareness content, including one warning of a phishing attempt detected at
the company in the weeks leading up to the breach.
Finally, in the annexes to its submission dated July 9, 2024, ALKORA provided
documentation regarding the adoption or modification of organizational measures following
the breach:
From the foregoing, it can be concluded that prior to the breach in question, ALKORA had a
series of measures in place that were deemed sufficient in its 2022 internal audit, even
though it has been demonstrated that they were not, as reflected in the external reports
prepared after the incident in question, all of which has resulted in a loss of confidentiality
and availability of the personal data that ALKORA processed as the controller.
The foregoing is not undermined by the information now provided by ALKORA in a report
received on October 17, 2025, after the present disciplinary proceedings had already been
initiated:
- Passwords.
o During the preliminary investigation, the following information was obtained:
“ALKORA also provides (…) a ‘pentesting’ audit report (penetration test of
its computer system) dated April 2024. The penetration test, conducted by
***SISTEMA.1, revealed the existence of prior vulnerabilities—most of
which stemmed from default configurations—which, if exploited in
combination, would allow the entire domain to be compromised by gaining
administrator privileges, as well as a low level of internal security.
6 Jorge Juan
Street, 28001 –
Madrid53/76
www.aepd.es
sedeaepd.gob.es
Section 3.4 of Annex V b (password audit) indicates that the enterprise was
able to uncover 54% of the passwords for active accounts, including two
domain administrator accounts. Many of the uncovered passwords were
basic and easy to guess, with some Users having similar or even identical
passwords.”
It also states: “The audit highlighted 8 ‘high’ severity vulnerabilities: (…)
(…).
The report now provided states the following: “As part of the security
strategy, as of November 2022, the system includes the following
measures: Secure passwords. Secure user passwords are established
within the domain. These passwords are currently set to 8 characters,
including a number and a special character. Although the password length
may not seem ideal, the requirement to include a number and a special
character, combined with the fact that they are linked within the domain,
ensures adequate security.”
This does not invalidate the facts that came to light during the previous
proceedings.
- Equipment Always Up to Date.
o According to the previous investigative proceedings: “Technical security
measures prior to the breach: ALKORA provides (…) an internal audit
report on its information systems, dated November 2022 (prior to the
breach). The IT services risk assessment table in that report, on page 194
of [10], indicates an “Extreme” risk (marked in red) for information systems
and web portals regarding cybercrimes. (…) It did not consider this a
source of risk (…).
According to the report now provided by ALKORA: “The equipment is
constantly kept up to date thanks to ***SERVER.2 in Alkora’s infrastructure.
System security is key.
***SERVER.2 (…). This is a requirement for all enterprises, but it applies
solely and exclusively to ***SYSTEM.2 systems (which also allow for
system updates). It is a major security measure.”
This does not refute the findings of the investigation. Although the 2022
audit asserts that the equipment is constantly updated “thanks to
***SERVER.2,” ALKORA does not justify the existence of equipment with
outdated operating systems, nor the existence of virtual servers without
security restrictions (…), especially when the risk of credential compromise
was high.
- Antivirus:
o According to the preliminary investigation findings: “Technical security
measures prior to the breach: (…) It is clear from that report (…) Due to (…)
(…)”
6 Jorge Juan
Street, 28001 –
Madrid54/76
www.aepd.es
sedeaepd.gob.es
Also, “that internal audit report (…) indicates: (…) (…).
As well as: “the forensic report prepared by the enterprise
***ENTERPRISE.1 (…) (…).
The report now provided merely states: “A powerful antivirus program is in
place (…) This is desirable and necessary in all enterprises, but
unfortunately it does not help detect attacks such as the one suffered.”
Once again, ALKORA provides no justification for the absence of this
security measure at the time of the breach, a measure as basic as the
previous ones.
- Perimeter firewall:
o According to the preliminary investigation findings, as stated in the report
provided: “Alkora (…) relied on the protection (…) and did not have (…).”
o According to the forensic report now provided: “There is a perimeter firewall
(…) one of the most important components and the best security measure
an enterprise can adopt.”
o However, no information is provided about this software.
Installation date? Provider? Technical specifications? Is it in-house, or is it
still a third-party service (perhaps still managed by their ISP, as before)?
This is not information that can be considered to undermine the findings.
- Data encryption:
o According to the report provided: “The databases for all applications have
all access passwords encrypted to prevent unauthorized access by third
parties (…).”
The fact that the application passwords are now encrypted does not prove
that they were encrypted at the time, but, above all, it does not prove that
the information in the databases was encrypted.
o This is without prejudice to the fact that, in its breach notifications, ALKORA
initially indicated that the data was not encrypted. Also in ALKORA’s report:
“Server encryption directly impacts the integrity and availability of the
enterprise’s systems and applications. Furthermore, the data exfiltration
impacts the confidentiality of the enterprise’s sensitive documents, as well
as customers’ personal data. (…) The integrity and availability of all
systems and services have been impacted.”
ALKORA does not in any way confirm, nor does it provide details regarding,
the encryption of the information at the time of the breach that would
contradict what was established in previous proceedings.
6 Jorge Juan
Street, 28001 –
Madrid55/76
www.aepd.es
sedeaepd.gob.es
In other words, ALKORA does not at any point confirm that the data was
encrypted, and therefore does not confirm that the attackers did not have
access to it.
The report submitted in October 2025 refers to a subsequent audit from April 2024
(penetration test), regarding which it states the following:
- “A penetration test was outsourced in April 2024 to verify that the systems are
stable and that security has been improved. In this case, seven critical
vulnerabilities were identified, but the system PRESENTS NO CRITICAL
VULNERABILITIES to external parties,” and it bases its entire subsequent
argument on the fact that the vulnerabilities are internal, not external.
As well as: “The above is important. It is common for vulnerabilities to exist
INTERNALLY within a reliable IT department, given that several Users have access
and high-level credentials (IT Department), but the important thing is that there
have been ZERO critical vulnerabilities resulting from external attacks.”
However, it should be noted that, once the system has been breached, the
vulnerabilities to consider are no longer external but internal—which, as indicated
by the forensic report and the penetration test, were abundant. Furthermore,
external protection is not substantiated, as the organization continues to use the
same policy of weak passwords, devices running obsolete operating systems, a
firewall managed by its ISP, etc. In fact, the forensic report indicated that once
inside the system, attackers were able to move laterally, change passwords, create
new User accounts, encrypt devices, evade detection by antivirus software, and
more.
Indeed, social engineering greatly facilitates the circumvention of external
measures, after which experienced attackers move freely within the system thanks
to internal vulnerabilities (7 high and 10 medium), which is precisely what occurred
in this breach.
In short, the information now presented by ALKORA does not invalidate any of the findings
from the previous investigative proceedings, which form the basis for the initiation of this
disciplinary proceeding, based on the documentation provided by ALKORA itself. The
security measures were clearly insufficient, and there is evidence that the attackers gained
access to the personal data being processed, as they managed to encrypt the filing
systems.
Therefore, in accordance with the established facts currently available at the time of this
proposed resolution of the disciplinary proceeding, it is considered that the known facts
constitute a violation attributable to ALKORA, for breaching Article 5.1.f) of the GDPR.
6 Jorge Juan
Street, 28001 –
Madrid56/76
www.aepd.es
sedeaepd.gob.es
V
Classification of the Infringement of Article 5(1)(f) of the GDPR and Determination for
Statute of Limitations Purposes
Article 83(5) of the GDPR classifies the violation of the following articles as an
administrative infraction, which shall be sanctioned, in accordance with paragraph 2, with
administrative fines of up to 20,000,000 EUR or, in the case of an enterprise, an amount
equivalent to up to 4% of the total worldwide annual turnover in the preceding financial
year, whichever is higher:
“a) the basic principles of processing, including the conditions for consent pursuant to
Articles 5, 6, 7, and 9;”
For its part, article 71 of the LOPDGDD, “Infractions,” states that:
“The acts and conduct referred to in paragraphs 4,
5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this
organic law.”
For the sole purpose of the statute of limitations, article 72.1 of the LOPDGDD establishes
the following:
“Pursuant to Recital 83(5) of Regulation (EU) 2016/679, infringements that constitute a
substantial violation of the articles mentioned therein, and in particular the following, are
considered very serious and shall be subject to a three-year statute of limitations:
a) The processing of personal data in violation of the principles and safeguards established
in Article 5 of Regulation (EU) 2016/679.”
VI
Proposed Penalty for the Violation of Article 5.1.f) of the GDPR
In order to determine the administrative fine to be imposed, the provisions of Articles 83(1)
and 83(2) of the GDPR must be observed, which state:
“1. Each supervisory authority shall ensure that the imposition of administrative fines
pursuant to this article for the infringements of this Regulation referred to in paragraphs 4,
9, and 6 is, in each individual case, effective, proportionate, and dissuasive.
2. Administrative fines shall be imposed, depending on the circumstances of each
individual case, in addition to or in lieu of the measures referred to in Article 58(2)(a)
through (h) and (j). When deciding whether to impose an administrative fine and its amount
in each individual case, due account shall be taken of:
a) the nature, gravity, and duration of the violation, taking into account the nature, scope,
or purpose of the processing operation in question, as well as the number of data subjects
affected and the extent of the harm they have suffered;
b) whether the infringement was intentional or due to negligence;
6 Jorge Juan
Street, 28001 –
Madrid57/76
www.aepd.es
sedeaepd.gob.es
c) any measures taken by the controller or processor to mitigate the damage suffered by
the data subjects;
d) the degree of responsibility of the controller or processor, taking into account the
technical or organizational measures they have implemented pursuant to Articles 25 and
32;
e) any previous infringements committed by the controller or processor;
f) the degree of cooperation with the supervisory authority to remedy the infringement and
mitigate its potential adverse effects;
g) the categories of data affected by the breach;
h) the manner in which the supervisory authority became aware of the breach, in particular
whether the controller or processor reported the breach and, if so, to what extent;
i) where the measures referred to in Article 58(2) have previously been ordered against the
controller or processor concerned in relation to the same matter, compliance with those
measures;
j) adherence to codes of conduct pursuant to Article 40 or to certification mechanisms
approved in accordance with Article 42; and
k) any other aggravating or mitigating factors applicable to the circumstances of the case,
such as the financial benefits obtained or the losses avoided, directly or indirectly, as a
result of the violation.”
For its part, article 76, “Sanctions and Corrective Measures,” of the LOPDGDD provides:
“1. The penalties provided for in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU)
2016/679 shall be applied taking into account the criteria for determining the level of the
penalty set forth in paragraph 2 of that article.
2. In accordance with the provisions of Article 83(2)(k) of Regulation (EU) 2016/679, the
following may also be taken into account:
a) The ongoing nature of the violation.
b) The connection between the infringer’s activities and the processing of personal data.
c) The benefits obtained as a result of the infringement.
d) The possibility that the data subject’s conduct may have contributed to the commission
of the violation.
e) The existence of a merger by absorption that occurred after the infringement was
committed, for which the acquiring entity cannot be held liable.
f) The impact on the rights of minors.
g) Having a data protection officer, even when not required by law.
h) The voluntary submission by the controller or processor to alternative dispute resolution
mechanisms in cases where disputes arise between them and any data subject.”
In the present case, in recital of the seriousness of the potential violations, with particular
regard to the consequences their commission has on those affected, the imposition of a
fine would be appropriate.
The fine imposed must be, in each individual case, effective, proportionate, and dissuasive,
in accordance with the provisions of Article 83(1) of the GDPR. To ensure
6 Jorge Juan
Street, 28001 –
Madrid58/76
www.aepd.es
sedeaepd.gob.es
these principles, ALKORA’s annual turnover (€24,007,236 in 2024) is taken into account as
a preliminary matter.
For the purposes of deciding on the imposition of an administrative fine and its amount, in
accordance with the established facts currently available in this draft resolution of the
disciplinary proceeding, it is considered appropriate to determine the penalty to be imposed
based on the following circumstances, as set forth in the aforementioned provisions.
As a preliminary matter, it is determined that the following circumstances exist:
• The nature, gravity, and duration of the violation, taking into account the
nature, scope, or purpose of the processing operation in question, as well as the
number of data subjects affected and the extent of the damages they have suffered
(Article 83(2)(a) of the GDPR): for failing to implement security measures appropriate
to the risk of a data breach such as the one that occurred in this case, which involved
personal data such as national ID number or tax ID number, first and last names,
mailing or email address, phone number, image, handwritten signature, social
security or mutual insurance number, health data, marital status, family information,
date and place of birth, age, sex, nationality, housing and property data, academic
and professional data, commercial information, employment data, economic, financial,
and insurance data, and bank account numbers, of 40,000 individuals (including
employees, customers and Users, suppliers, and policyholders, insured parties, and
beneficiaries of its insurance policies).
The fact that various types of personal data belonging to the data subjects are being
processed is also taken into account when determining the severity of the penalty.
The combined effect of all these different types of personal data means that the
potential consequences—the impact of the risk materializing for the data subjects—
are of greater significance.
Furthermore, given the large volume of data involved—some of which cannot be
changed (such as ID or tax identification numbers and dates of birth) or cannot be
changed easily (such as mailing addresses)—the risk to the rights and freedoms of
the data subjects and the potential impact on them is even greater, not to mention
that any loss of access to or control over their personal data may be irreversible.
• Intent or negligence in the breach (Article 83(2)(b) of the GDPR): No particular
negligence or intent is apparent that would be noteworthy and that would lead to
assessing this circumstance differently from a neutral assessment, in accordance with
Guidelines 04/2022.
• The categories of personal data affected by the breach (Article 83(2)(g) of the
GDPR): In this case, ALKORA processes health data of the policyholder, the insured,
and the beneficiary of its insurance policies, as well as biometric data of its
employees (fingerprints). It also processes economic and financial data, as well as
bank account numbers, of the policyholder, insured person, and beneficiary of its
insurance policies; all of which, in the absence of adequate security measures, posed
a greater risk to the rights and freedoms of the data subject.
6 Jorge Juan
Street, 28001 –
Madrid59/76
www.aepd.es
sedeaepd.gob.es
Finally, ALKORA also processes national ID numbers (DNI) or tax identification
numbers (NIF). The numerical identifier of the DNI, together with the verification
character corresponding to the tax identification number, unambiguously identifies a
natural person. This characteristic makes it particularly sensitive data because, to the
extent that its processing is not accompanied by the necessary technical and
organizational measures to ensure that the person identifying themselves with it is
truly the data subject, a third party can easily impersonate a natural person—or, in
other words, commit identity fraud—with the risks that this entails for the privacy,
reputation, and assets of the person being impersonated.
Likewise, the following aggravating factors are considered:
• The connection between the offender’s activity and the processing of personal
data (Article 76.2(b) of the LOPDGDD): ALKORA is an insurance brokerage with
thousands of clients that, in order to carry out its business, requires the continuous
processing of personal data.
• The impact on the rights of minors (Article 76.2(f) of the LOPDGDD): As
stated in its submission dated July 9, 2024, ALKORA processes data on minors when
handling accident claims files, which include the minor’s first name, last name, date of
birth, and general information about the circumstances of the accident. ALKORA had
processed 75 such cases over the past four years.
Likewise, the following mitigating factors are considered:
• “Any other aggravating or mitigating factors applicable to the circumstances of
the case, such as financial benefits obtained or losses avoided, directly or indirectly,
through the infringement” (Article 83(2)(k) of the GDPR): The assessment of
ALKORA’s conduct in this case requires consideration of the actions taken by the
entity to comply with the provisions of the GDPR and the LOPDGDD, in accordance
with the principle of continuous improvement.
Without overlooking the fact that such continuous improvement is an obligation
incumbent upon controllers, it is deemed appropriate to consider the attitude
demonstrated by ALKORA, which, throughout the proceedings, has reported on the
implementation of various measures aimed at complying with data protection
regulations.
After weighing the circumstances set forth in Article 83(2) of the GDPR and Article 76(2) of
the LOPDGDD, with respect to the violation committed by breaching the provisions of
Article 5(1)(f) of the GDPR, it is proposed that an administrative fine of 150,000.00 euros be
imposed.
6 Jorge Juan
Street, 28001 –
Madrid60/76
www.aepd.es
sedeaepd.gob.es
VII
Failure to Comply. Data Protection Impact Assessment
The data protection impact assessment is regulated by Article 35 of the GDPR in the
following terms:
"1. Where a type of processing, in particular where new technologies are used, is likely, by
virtue of its nature, scope, context, or purpose, to result in a high risk to the rights and
freedoms of natural persons, the controller shall, prior to the processing, conduct an
assessment of the impact of the processing operations on data protection. A single
assessment may address a series of similar processing operations that entail similar high
risks.
2. The controller shall seek the advice of the data protection officer, if one has been
appointed, when conducting the data protection impact assessment.
3. The data protection impact assessment referred to in paragraph 1 shall be required in
particular in the case of:
a) a systematic and comprehensive evaluation of personal aspects of natural persons
based on automated processing, such as profiling, and on the basis of which decisions are
made that produce legal effects on natural persons or similarly significantly affect them;
b) large-scale processing of special categories of data referred to in Article 9(1) or of
personal data relating to criminal convictions and offenses referred to in Article 10; or
c) systematic large-scale monitoring of a public area.
4. The supervisory authority shall establish and publish a list of the types of processing
operations that require a data protection impact assessment in accordance with paragraph
1. The supervisory authority shall communicate those lists to the Committee referred to in
Article 68.
5. The supervisory authority may also establish and publish a list of the types of processing
that do not require data protection impact assessments. The supervisory authority shall
communicate those lists to the Committee.
6. Before adopting the lists referred to in paragraphs 4 and 5, the competent supervisory
authority shall apply the consistency mechanism provided for in article 63 if those lists
include processing activities related to the offering of goods or services to data subjects or
to the monitoring of their behavior in several Member States, or processing activities that
may substantially affect the free flow of personal data within the Union.
7. The assessment shall include at least:
a) a systematic description of the intended processing operations and the purposes of the
processing, including, where applicable, the legitimate interest pursued by the controller;
6 Jorge Juan
Street, 28001 –
Madrid61/76
www.aepd.es
sedeaepd.gob.es
b) an assessment of the necessity and proportionality of the processing operations in
relation to their purpose;
c) an assessment of the risks to the data subject rights and freedoms referred to in
paragraph 1; and
d) the measures envisaged to address the risks, including safeguards, security measures,
and mechanisms to ensure data protection and to demonstrate compliance with this
Regulation, taking into account the rights and legitimate interests of the data subjects and
other individuals concerned.
8. Compliance by the relevant controllers or processors with approved codes of conduct
referred to in Article 40 shall be taken into due account when assessing the impact of the
processing operations carried out by such controllers or processors, in particular for the
purposes of the data protection impact assessment.
9. Where appropriate, the controller shall seek the views of data subjects or their
representatives regarding the intended processing, without prejudice to the protection of
public or commercial interests or the security of processing operations.
10. Where processing pursuant to Article 6(1)(c) or (e) has its legal basis in Union law or in
the law of the Member State applicable to the controller, and such law regulates the
specific processing operation or set of operations in question, and a data protection impact
assessment has already been carried out as part of a general impact assessment in the
context of the adoption of that legal basis, paragraphs 1 through 7 shall not apply unless
Member States deem it necessary to conduct such an assessment prior to the processing
activities.
11. Where necessary, the controller shall assess whether the processing is in accordance
with the data protection impact assessment, at least where there is a change in the risk
posed by the processing operations."
The need to conduct a data protection impact assessment (DPIA) stems from the principle
of proactive accountability set forth in the GDPR itself, and it is an essential tool for
ensuring that entities with certain characteristics in their data processing manage and
process personal data responsibly, securely, and in compliance with applicable regulations,
thereby protecting the rights of data subjects and strengthening trust in their operations.
The purpose of the DPIA, as set forth in Article 35 of the GDPR, is multifaceted and
focuses on ensuring data protection for natural persons’ personal data.
Among these purposes, the following are particularly noteworthy:
- Identifying and assessing potential risks to individuals’ rights and freedoms that
could arise as a result of the processing of personal data. This is particularly
important when new technologies are used or large-scale data processing is
carried out.
6 Jorge Juan
Street, 28001 –
Madrid62/76
www.aepd.es
sedeaepd.gob.es
- Helping organizations comply with the GDPR, as it ensures that regulatory
requirements related to data protection by design and by default are met.
- Implementing risk mitigation measures. Based on the identified risks, the DPIA
guides organizations in implementing appropriate measures to mitigate those risks.
This may include adjustments to how personal data is collected, stored,
processed, or shared.
- Prevent potential harm and/or data breaches, as through proactive risk
identification and mitigation, the EIPD helps prevent data breaches and other harm
that could result from the improper processing of personal data, which may lead to
legal consequences.
In the present case, on February 14, 2024, this Agency received a written response to the
referral of the complaint, to which the Risk Analysis dated September 19, 2019, version 0.1,
was attached as Annex V.
This document lists five filing systems: “LABOR AND HR,” “INSURANCE BROKERAGE
FOR INDIVIDUALS,” “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR
INDIVIDUALS,” “INSURANCE CLAIMS,” and “TAX AND ACCOUNTING.”
Regarding the “LABOR AND HR” filing system, the following is
indicated: “Categories of data subjects:
Employees”
“Identifying data: National ID number (DNI) or Tax ID number (NIF), first and
last names, mailing or email address, phone number, handwritten signature,
Social Security number or mutual insurance number
Special categories of data: Digitized fingerprint (biometric data) Other
type of data Characteristics Personal, Academic
and professional, Details of employment,
Transactions of goods and services.”
Regarding “INSURANCE BROKERAGE FOR INDIVIDUALS”:
“Identifying information: ID number or Tax ID number, first and last names,
mailing or email address, phone number, handwritten signature
Special categories of data: N/A
Other types of data: Personal data, academic and professional information,
transactions involving goods and services, social circumstances,
commercial information, economic, financial, and insurance information”
Regarding “LIFE AND ACCIDENT INSURANCE BROKERAGE FOR INDIVIDUALS”:
“Identifying data: National ID number (DNI) or Tax ID number (NIF), first and
last names, mailing or email address, phone number, handwritten signature
Special categories of data: Health
6 Jorge Juan
Street, 28001 –
Madrid63/76
www.aepd.es
sedeaepd.gob.es
Other types of data: Personal data, academic and professional information,
transactions involving goods and services, social circumstances, economic,
financial, and insurance information”
Regarding “INSURANCE CLAIMS”:
“Identifying information: National ID number (DNI) or Tax ID number (NIF),
first and last names, mailing or email address, phone number, handwritten
signature, image
Special categories of data: Health
Other types of data: Personal data, academic and professional information,
transactions involving goods and services, social circumstances, economic,
financial, and insurance information”
Regarding “TAX AND ACCOUNTING”:
“Identifying information: ID number or tax ID number, first and last names,
mailing or email address, phone number
Special categories of data: N/A Other
types of data: N/A”
Regarding the risks associated with each filing system, the aforementioned Risk Analysis
states:
- Regarding “Filing System 1: EMPLOYMENT AND HR”:
o The identifying data and other specified data subject to processing are
considered to have an initial “Low” risk.
o Regarding “Data Protection (Integrity and Confidentiality),” it is indicated
that “There are adequate measures in place to protect the data against
unauthorized processing and loss or destruction, in accordance with the
provisions of this document,” an initial risk of “Medium” is assigned, and the
measures detailed are “Ensuring that adequate technical and organizational
measures have been implemented to protect the data through the
corresponding periodic annual verification,” after which a final risk of “Very
Low” is assigned.
o Regarding “Processing Risks,” it is indicated that “THE PROCESSING
HAS BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the
data subject rights and freedoms,” an initial risk of “Medium” is assigned,
and the measures are detailed as follows: “It has been verified that the risk
analysis conducted does not identify any threats with a probability of high
risk to the data subject rights and freedoms,” after which a final risk of “Low”
is assigned.
o Regarding “Access to special categories of data,” it is stated that “There are
no special categories of data,” and therefore it is assigned an initial and final
risk rating of “Very Low.”
- Regarding “Filing System 2: INSURANCE BROKERAGE FOR INDIVIDUALS”:
o It is considered that the identifying data and other specified data subject to
processing have an initial risk of “Low.”
6 Jorge Juan
Street, 28001 –
Madrid64/76
www.aepd.es
sedeaepd.gob.es
o Regarding “Data Protection (Integrity and Confidentiality),” it is indicated
that “There are adequate measures in place to protect the data against
unauthorized processing and loss or destruction, in accordance with the
provisions of this document,” an initial risk of “Medium” is assigned, and the
measures are detailed as follows: “Ensure that adequate technical and
organizational measures have been implemented to protect the data
through the corresponding periodic annual verification,” after which a final
risk of “Very low” is assigned.
o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS
BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data
subject rights and freedoms,” an initial risk of “Medium” is assigned, and the
measures are detailed as follows: “It has been verified that the risk analysis
conducted does not identify any threats with a probability of high risk to the
data subject rights and freedoms,” after which a final risk of “Low” is
assigned.
o Regarding “Access to special categories of data,” it is stated that “There are
no special categories of data,” and therefore an initial and final risk rating of
“Very Low” is assigned.
- Regarding “Filing System 3: LIFE AND ACCIDENT INSURANCE BROKERAGE
FOR INDIVIDUALS”:
o It is considered that the identifying data and other specified data subject to
processing have an initial risk of “Low.” However, health data are assigned
an initial risk of “High.”
o Regarding “Data Protection (Integrity and Confidentiality),” it is stated that
“There are adequate measures in place to protect data against
unauthorized processing and loss or destruction, in accordance with the
provisions of this section of the document,” an initial risk level of “Medium”
is assigned, and the measures detailed are “Ensuring that appropriate
technical and organizational measures have been implemented to protect
the data through the corresponding periodic annual verification,” after which
a final risk level of “Low” is assigned
o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS
BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data
subject rights and freedoms,” an initial risk of “Medium” is assigned, and the
measures are detailed as follows: “It has been verified that the risk analysis
conducted does not identify any threats with a high probability of risk to the
data subject rights and freedoms,” after which a final risk of “Low” is
assigned.
o Regarding “Access to special categories of data,” it is stated that
“ADDITIONAL security measures EXIST in accordance with the provisions
of section 4.4 of this document”; an initial risk rating of “Medium” is
assigned, and the measures are detailed as follows: “An up-to-date record
must be maintained of personnel with access to special categories of data.
It is recommended to strengthen measures with two-factor
6 Jorge Juan
Street, 28001 –
Madrid65/76
www.aepd.es
sedeaepd.gob.es
authentication, encryption…,” after which a final risk rating of “Very low” is
assigned.
- Regarding “Filing System 4: INSURANCE CLAIMS”:
o The identifying data and other specified data subject to processing are
considered to have an initial risk of “Low.” However, health data is assigned
an initial risk of “High.”
o Regarding “Data Protection (Integrity and Confidentiality),” it is stated that
“There are adequate measures in place to protect the data against
unauthorized processing and loss or destruction, in accordance with the
provisions of this document,” it is assigned an initial risk of “Medium,” and
the measures are detailed as follows: “Ensure that adequate technical and
organizational measures have been implemented to protect the data
through the corresponding periodic annual verification,” after which a final
risk of “Low” is assigned.
o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS
BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data
subject rights and freedoms,” an initial risk of “Medium” is assigned, and the
measures are detailed as follows: “It has been verified that the risk analysis
conducted does not identify any threats with a high probability of risk to the
data subject rights and freedoms,” after which a final risk of “Low” is
assigned.
o Regarding “Access to special categories of data,” it is stated that
“ADDITIONAL security measures are in place in accordance with the
provisions of section 4.4 of this document”; an initial risk rating of “Medium”
is assigned, and the measures are detailed as follows: “An up-to-date
record must be maintained of personnel with access to special categories of
data. It is recommended to strengthen these measures with two-factor
authentication, encryption…”, after which a final risk rating of “Very low” is
assigned.
- Regarding “Filing System 5: TAX AND ACCOUNTING”:
o The identifying data subject to processing is considered to have an initial
risk of “Low.”
o As for “Data Protection (Integrity and Confidentiality),” it is stated that
“There are adequate measures in place to protect the data against
unauthorized processing and loss or destruction, in accordance with the
provisions of this document,” an initial risk of “Medium” is assigned, and the
measures are detailed as follows: “Ensure that adequate technical and
organizational measures have been implemented to protect the data
through the corresponding periodic annual verification,” after which a final
risk of “Low” is assigned
o Regarding “Processing Risks,” it is indicated that “THE PROCESSING HAS
BEEN ANALYSED and there is NO likelihood of a HIGH RISK to the data
subject rights and freedoms,” an initial risk of “Medium” is assigned, and the
measures are detailed as follows: “It has been verified that the risk analysis
conducted does not identify the
6 Jorge Juan
Street, 28001 –
Madrid66/76
www.aepd.es
sedeaepd.gob.es
existence of threats with a probability of high risk to the data subject rights
and freedoms,” after which a final risk rating of “Low” is assigned.
o Regarding “Access to special categories of data,” it is stated that “There are
no special categories of data,” and therefore an initial and final risk rating of
“Very Low” is assigned.
- “Processing of data of children under 14 years of age” is mentioned as a specific
processing activity, indicating that “Data processing of children under 14 years of
age is carried out only in cases of school accidents”; an initial risk level of “Medium”
is assigned, and the measures indicated are “Ensure that the measures referred to
in section 4.4 are adopted through the corresponding periodic annual verification
audit.” Following this, a final risk rating of “Low” is indicated.
In other words, although ALKORA processed its customers’ health data and its employees’
biometric data, as well as its customers’ economic, financial, and bank account
information—all of which, without adequate security measures, posed a greater risk to the
data subject rights and freedoms—it had not considered that there might be a high risk to
the data subjects. Nor had it even been taken into account that various types of personal
data belonging to the data subjects were being processed, which, when combined, would
make the potential consequences—the impact of the risk materializing for the data
subjects—more significant. Furthermore, some of this data could not be changed (such as
ID numbers or tax identification numbers and dates of birth) or could not be changed easily
(such as mailing addresses), which meant that the risk to the rights and freedoms of the
data subjects and the potential impact on them would be even greater, not to mention that
a potential loss of access to and control over their personal data could be irreversible.
The aforementioned Risk Analysis, provided as Annex V to the letter dated February 14,
2024, in response to the referral of the complaint, included, among others, the following
sections under “REGULATORY COMPLIANCE” (file number in parentheses):
Security Policy (1; 2; 3; 4; 5)
- Processing Risks: “The processing has been analyzed, and there is no
likelihood of a high risk to the data subject rights and freedoms.”
Security Policy (3; 4)
- Impact Assessment: “The processing has been analyzed in accordance
with the Report on the Need to Conduct an Impact Assessment, and there is no
likelihood of a high risk to the data subject rights and freedoms.”
The “ORGANIZATION” section of the aforementioned Risk Analysis stated: “[A DPIA is not
required because] the processing does not pose a high risk to the rights and freedoms of
natural persons.”
6 Jorge Juan
Street, 28001 –
Madrid67/76
www.aepd.es
sedeaepd.gob.es
ALKORA also provided, as Annex III to its letter dated July 9, 2024 (pages 52–119 of the
document including all annexes), an unsigned Risk Analysis (RA), version 2.0 dated
November 1, 2023, which was prepared after the data breach, in which it reclassifies the
initial and final risks for filing systems 3 and 4—which involve the processing of health
data—as “High”; this RA maintains the initial and final risks associated with the processing
of filing systems 1 and 5—which include banking data—as “Medium” and “Low,”
respectively.
This new risk analysis also mentions the need to conduct a Data Protection Impact
Assessment (DPIA) for filing systems 3 and 4. ALKORA also provides, as Annex IV to its
letter dated July 9, 2024 (pages 120–130 of the document containing all annexes), an
unsigned report, version 2.0 dated November 1, 2023, on the need to conduct impact
assessments, which concludes that such assessments are necessary for the “Health and
Life Insurance Brokerage” and “Claims” filing systems due to the processing of special
categories of data and data on vulnerable groups:
“Conclusions:
At least two of the criteria established in the AEPD’s list of processing activities are met in
the “Health and Life Insurance Brokerage” and “Claims” filing systems, as they involve data
on vulnerable groups, such as minors, as well as special categories of data—‘health
data’—therefore making it necessary to conduct a Data Protection Impact Assessment on
the aforementioned processing activities, as they could pose a high risk to the data subject
rights and freedoms. Likewise, Alkora prepared a report on the need to appoint a data
protection officer, in which it analyzed whether or not large-scale processing of personal
data is taking place; the analysis was inconclusive due to the lack of clarity in the criteria
established by WP 243. However, since at least two of the AEPD’s criteria are already met,
we consider it necessary to conduct a Data Protection Impact Assessment (DPIA)
regarding the processing of minors’ data and health data in the relevant filing systems.”
However, there is no record in this case file that ALKORA provided this Agency with the
aforementioned DPIA reports.
Therefore, based on the established facts currently available in this proposal for a
resolution on disciplinary proceedings, it is considered that the known facts constitute a
violation attributable to ALKORA for breaching Article 35 of the GDPR.
VIII
Classification of the violation of Article 35 of the GDPR and determination of the
statute of limitations
Article 83(4) of the GDPR classifies violations of the following articles as administrative
offenses, which shall be penalized, in accordance with paragraph 2, with administrative
fines of up to 10,000,000 EUR or, in the case of an enterprise, an amount equivalent to up
to 2% of the total annual global turnover for the previous fiscal year, whichever is higher:
6 Jorge Juan
Street, 28001 –
Madrid68/76
www.aepd.es
sedeaepd.gob.es
“a) the obligations of the controller and the processor under Articles 8, 11, 25 through 39,
42, and 43.”
For its part, article 71 of the LOPDGDD, “Infractions,” states that:
“The acts and conduct referred to in paragraphs 4,
5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this
Organic Law.”
For the sole purpose of the statute of limitations, article 73 of the LOPDGDD establishes
the following:
“Pursuant to Recital 83(4) of Regulation (EU) 2016/679, infringements that constitute a
substantial violation of the articles mentioned therein—and, in particular, the following—are
considered serious and shall be subject to a two-year statute of limitations:
t) The processing of personal data without having carried out an assessment of the impact
of the processing operations on data protection in cases where such an assessment is
required.”
IX
Proposed Penalty for the Violation of Article 35 of the GDPR
In order to determine the administrative fine to be imposed, the provisions of Articles 83(1)
and 83(2) of the GDPR must be observed, which state:
“1. Each supervisory authority shall ensure that the administrative fines imposed pursuant
to this article for the infringements of this Regulation referred to in paragraphs 4, 9, and 6
are, in each individual case, effective, proportionate, and dissuasive.
2. Administrative fines shall be imposed, depending on the circumstances of each
individual case, in addition to or in lieu of the measures referred to in Article 58(2)(a)
through (h) and (j). When deciding whether to impose an administrative fine and its amount
in each individual case, due account shall be taken of:
a) the nature, gravity, and duration of the violation, taking into account the nature, scope,
or purpose of the processing operation in question, as well as the number of data subjects
affected and the extent of the harm they have suffered;
b) whether the infringement was intentional or due to negligence;
c) any measures taken by the controller or processor to mitigate the damage suffered by
the data subjects;
d) the degree of responsibility of the controller or processor, taking into account the
technical or organizational measures they have implemented pursuant to Articles 25 and
32;
e) any previous infringements committed by the controller or processor;
f) the degree of cooperation with the supervisory authority to remedy the infringement and
mitigate its potential adverse effects;
g) the categories of personal data affected by the breach;
6 Jorge Juan
Street, 28001 –
Madrid69/76
www.aepd.es
sedeaepd.gob.es
h) the manner in which the supervisory authority became aware of the breach, in particular
whether the controller or processor reported the breach and, if so, to what extent;
i) where the measures referred to in Article 58(2) have previously been ordered against the
controller or processor concerned in relation to the same matter, compliance with those
measures;
j) adherence to codes of conduct pursuant to Article 40 or to certification mechanisms
approved in accordance with Article 42; and
k) any other aggravating or mitigating factors applicable to the circumstances of the case,
such as the financial benefits obtained or the losses avoided, directly or indirectly, as a
result of the violation.”
For its part, article 76, “Sanctions and Corrective Measures,” of the LOPDGDD provides:
“1. The penalties provided for in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU)
2016/679 shall be applied taking into account the criteria for determining the level of the
penalty set forth in paragraph 2 of that article.
2. In accordance with the provisions of Article 83(2)(k) of Regulation (EU) 2016/679, the
following may also be taken into account:
a) The ongoing nature of the infringement.
b) The connection between the infringer’s activities and the processing of personal data.
c) The benefits obtained as a result of the infringement.
d) The possibility that the data subject’s conduct may have contributed to the commission
of the violation.
e) The existence of a merger by absorption that occurred after the infringement was
committed, for which the acquiring entity cannot be held liable.
f) The impact on the rights of minors.
g) Having a data protection officer, even when not required by law.
h) The voluntary submission by the controller or processor to alternative dispute resolution
mechanisms in cases where disputes arise between them and any data subject.”
In the present case, in recital of the seriousness of the potential violations, with particular
regard to the consequences their commission has on those affected, the imposition of a
fine would be appropriate.
The fine imposed must, in each individual case, be effective, proportionate, and dissuasive,
in accordance with the provisions of Article 83(1) of the GDPR. To ensure these principles
are upheld, ALKORA’s annual turnover (€24,007,236 in 2024) is taken into account as a
preliminary consideration.
For the purposes of deciding on the imposition of an administrative fine and its amount, in
accordance with the established facts currently available in this proposed resolution of the
disciplinary proceeding, it is considered appropriate to determine the penalty to be imposed
based on the following circumstances, as set forth in the aforementioned provisions.
6 Jorge Juan
Street, 28001 –
Madrid70/76
www.aepd.es
sedeaepd.gob.es
First, it is determined that the following circumstances exist:
• The nature, gravity, and duration of the infringement, taking into account the
nature, scope, or purpose of the processing operation in question, as well as the
number of data subjects affected and the extent of the damage they have suffered
(Article 83(2)(a) of the GDPR): failure to conduct a data protection impact
assessment, despite it being required given the high risk that the processing of their
personal data posed to the rights and freedoms of ALKORA’s 56,000 customers
(https://www.alkora.es/cifras-alkora/).
The fact that various types of personal data belonging to the data subjects are being
processed is also taken into account when determining the penalty. The combined
effect of all these different types of personal data means that the potential
consequences—the impact of the risk materializing for the data subjects—are of
greater significance.
Furthermore, given the large volume of data involved—some of which cannot be
changed (such as national ID numbers, tax identification numbers, and dates of birth)
or cannot be changed easily (such as mailing addresses)—the risk to the rights and
freedoms of the data subjects and the potential impact on them is even greater, not to
mention that any loss of access to or control over their personal data may be
irreversible.
• Intent or negligence in the breach (Article 83(2)(b) of the GDPR): No particular
negligence or intent is apparent that would be noteworthy and that would lead to
assessing this circumstance differently from a neutral assessment, in accordance with
Guidelines 04/2022.
• The categories of personal data affected by the breach (Article 83(2)(g) of the
GDPR): In this case, ALKORA processes health data of the policyholder, the insured,
and the beneficiary of its insurance policies, as well as biometric data of its
employees (fingerprints). It also processes economic and financial data, as well as
bank account numbers, of the policyholder, insured person, and beneficiary of its
insurance policies; all of which, in the absence of adequate security measures, posed
a greater risk to the rights and freedoms of the data subject.
Finally, ALKORA also processes the DNI or NIF number. The numerical identifier of
the DNI, together with the check digit corresponding to the tax identification number,
unambiguously identifies a natural person. This characteristic makes it particularly
sensitive data because, to the extent that its processing is not accompanied by the
necessary technical and organizational measures to ensure that the person
identifying themselves with it is actually the holder, a third party can easily
impersonate a natural person—or, in other words, commit identity fraud—with the
risks that this entails for the privacy, reputation, and assets of the person being
impersonated.
Likewise, the following aggravating factors are considered:
6 Jorge Juan
Street, 28001 –
Madrid71/76
www.aepd.es
sedeaepd.gob.es
• The connection between the offender’s activity and the processing of personal
data (Article 76.2(b) of the LOPDGDD): ALKORA is an insurance brokerage with
thousands of clients that, in order to carry out its business, requires the continuous
processing of personal data.
• The impact on the rights of minors (Article 76.2(f) of the LOPDGDD): As
stated in its submission dated July 9, 2024, ALKORA processes data on minors when
handling accident claims files, which include the minor’s first name, last name, date of
birth, and general information about the circumstances of the accident. Furthermore,
over the past four years, ALKORA has processed 75 such cases.
After weighing the circumstances set forth in Article 83.2 of the GDPR and Article 76.2 of
the LOPDGDD, with respect to the violation of Article 35 of the GDPR, an administrative
fine of 100,000.00 euros is proposed.
X
Adoption of Measures
If the violation is confirmed, it may be decided to require the controller to adopt appropriate
measures to bring its actions into compliance with the regulations mentioned in this
decision, in accordance with the provisions of the aforementioned article 58(2)(d) of the
GDPR, pursuant to which each supervisory authority may “order the controller or processor
to bring processing operations into compliance with the provisions of this Regulation, where
appropriate, in a specific manner and within a specified time limit…”. The imposition of this
measure is compatible with the administrative fine, as provided for in Art. 83(2) of the
GDPR.
Thus, it is proposed that the decision to be adopted require ALKORA, within 3 months
from the date on which the final decision concluding this proceeding becomes enforceable,
to take the following measures:
- Provide evidence of the preparation of the mandatory data protection impact
assessment required by Article 35 of the GDPR.
Please be advised that failure to comply with any order to adopt measures imposed by this
agency in the penalty decision may be considered an administrative violation under the
provisions of the GDPR, classified as a violation in Articles 83(5) and 83(6), and such
conduct may lead to the initiation of further administrative penalty proceedings.
In light of the foregoing, the following is hereby issued:
PROPOSED DECISION
That the Presidency of the Spanish Data Protection Agency impose a sanction on ALKORA
EBS CORREDURIA DE SEGUROS Y REASEGUROS SAU, with Tax ID No.
6 Jorge Juan
Street, 28001 –
Madrid72/76
www.aepd.es
sedeaepd.gob.es
A01051747, for a violation of Article 5(1)(f) of the GDPR, as defined in Article
83.5 of the GDPR, with a fine of 150,000.00 (one hundred fifty thousand euros) and for a
violation of Article 35 of the GDPR, as defined in Article 83.4, with a fine of 100,000.00 €
(one hundred thousand euros).
That the Presidency of the Spanish Data Protection Agency order ALKORA EBS
CORREDURIA DE SEGUROS Y REASEGUROS SAU, with Tax ID No.
A01051747, to provide proof, pursuant to Article 58(2)(d) of the GDPR, within a maximum
period of 3 months, that it has complied with the requirement to conduct the mandatory
data protection impact assessment mandated by Article 35 of the GDPR.
Furthermore, in accordance with the provisions of Article 85.2 of the LPACAP, you are
hereby informed that you may, at any time prior to the resolution of this proceeding,
voluntarily pay the proposed fine, which will result in a 20% reduction of the amount
thereof. With the application of this reduction, the fine would be set at 200,000.00 euros,
and its payment will result in the termination of the proceedings, without prejudice to the
imposition of the corresponding measures. The effectiveness of this reduction is conditional
upon the withdrawal or waiver of any administrative action or appeal against the fine.
Should you choose to proceed with the voluntary payment of the amount specified above,
in accordance with the provisions of the aforementioned Article 85.2, you must make the
payment by depositing the funds into the restricted account with IBAN: ES00-0000-0000-
0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX) held in the name of the Spanish Data
Protection Agency at CAIXABANK, S.A., indicating in the payment description the
reference number of the proceeding shown in the header of this document and the
reason—voluntary payment to reduce the amount of the penalty. You must also send proof
of payment to the Subdirectorate General for Inspection so that the case may be closed.
Accordingly, you are hereby notified of the foregoing, and the procedure is set forth so that,
within TEN DAYS, you may present any arguments in your defense and submit any
documents and information you deem relevant, in accordance with Article 89.2 of the
LPACAP.
926-250625
R.R.R. INSPECTOR/INVESTIGATOR
6 Jorge Juan
Street, 28001 –
Madrid73/76
www.aepd.es
sedeaepd.gob.es
ATTACHMENT
Table of Contents for Case
EXP202400624 (…)
>>
SECOND: On February 18, 2026, ALKORA paid the penalty in the amount of 200,000.00
euros, taking advantage of the reduction provided for in the draft resolution transcribed
above.
THIRD: The draft decision transcribed above established the facts constituting the
infringement and proposed that the Presidency require the controller to adopt appropriate
measures to bring its actions into compliance with the regulations, in accordance with the
provisions of the aforementioned article 58(2)(d) of the GDPR, according to which each
supervisory authority may “order the controller or processor to bring processing operations
into compliance with the provisions of this Regulation, where appropriate, in a specific
manner and within a specified time limit…”.
LEGAL GROUNDS
I
Jurisdiction
In accordance with the powers granted to each supervisory authority by Article 58(2) of
Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and
pursuant to the provisions of Articles 47, 48(1), 64(2), and 68(1) of Organic Law 3/2018 of
December 5 on Data Protection and the Guarantee of Digital Rights (hereinafter
LOPDGDD), the Presidency of the Spanish Data Protection Agency has jurisdiction to rule
on this proceeding.
Likewise, article 63.2 of the LOPDGDD provides that: “Proceedings handled by the
Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU)
2016/679, this Organic Law, the implementing regulations issued thereunder, and, to the
extent they do not conflict with the foregoing, on a subsidiary basis, by the general rules on
administrative proceedings."
II
Conclusion of the Procedure
Article 85 of Law 39/2015, of October 1, on the Common Administrative Procedure of
Public Administrations (hereinafter LPACAP), under the heading “Termination of
Sanctioning Proceedings,” provides as follows:
“1. Once disciplinary proceedings have been initiated, if the offender acknowledges liability,
the proceedings may be concluded by imposing the appropriate penalty.
6 Jorge Juan
Street, 28001 –
Madrid74/76
www.aepd.es
sedeaepd.gob.es
2. When the penalty is solely monetary in nature, or when both a monetary penalty and a
non-monetary penalty may be imposed but the latter has been found to be inappropriate,
voluntary payment by the alleged offender, at any time prior to the final decision, shall
result in the termination of the proceedings, except with respect to the restoration of the
altered situation or the determination of compensation for damages caused by the
commission of the violation.
3. In both cases, when the penalty is solely monetary in nature, the body competent to
resolve the proceedings shall apply reductions of at least 20% on the amount of the
proposed penalty, which may be cumulative. These reductions must be specified in the
notice of initiation of proceedings, and their effectiveness shall be conditional upon the
withdrawal or waiver of any administrative action or appeal against the penalty.
The reduction percentage provided for in this section may be increased by regulation.”
III
Voluntary Payment
In accordance with the provisions of the aforementioned Article 85 of the LPACAP, the
notified proposed resolution allowed you to make a voluntary payment of the proposed
penalty, which would result in a 20% reduction of its amount. With the application of this
reduction, the penalty would be set at 200,000.00 euros, and its payment would result in
the termination of the proceedings, without prejudice to the imposition of the corresponding
measures.
Following the aforementioned proposed resolution, and before this authority issued a final
decision, ALKORA, on February 18, 2026, proceeded to make the voluntary payment,
availing itself of the 20% reduction. In accordance with Article 85(3) of the LPACAP, the
effectiveness of the aforementioned reduction is conditional upon the withdrawal or waiver
of any administrative action or appeal against the penalty.
It should be noted that, in accordance with the provisions of the LPACAP, as well as the
case law of the Supreme Court on this matter, the alleged liable party’s voluntary payment
does not exempt the administration from its obligation to resolve and notify all proceedings,
regardless of how they were initiated. Similarly, Article 88 of the aforementioned law
establishes that the decision bringing the proceedings to a close shall rule on all issues
raised by the data subjects and any other issues arising therefrom.
Therefore, in accordance with applicable law and after evaluating the criteria for
determining the severity of the sanctions, the Presidency of the Spanish Data Protection
Agency RESOLVES:
FIRST: TO DECLARE that the violations have been committed and TO CONFIRM the
sanctions set forth in the operative part of the proposed resolution transcribed in this
resolution.
6 Jorge Juan
Street, 28001 –
Madrid75/76
www.aepd.es
sedeaepd.gob.es
The sum of the aforementioned amounts totals 250,000.00 euros.
Since ALKORA EBS CORREDURIA DE SEGUROS Y REASEGUROS SAU has made a
voluntary payment—albeit without acknowledging liability—the total amount is hereby
reduced by 20% pursuant to Article 85 of the LPCAP, resulting in a final amount of
200,000.00 euros.
The effectiveness of the aforementioned reduction is conditional, in any case, upon the
withdrawal or waiver of any administrative action or appeal.
SECOND: DECLARE the termination of proceeding EXP202400624, in accordance with
the provisions of Article 85 of the LPCAP.
Third party: ORDER ALKORA EBS CORREDURIA DE SEGUROS Y
REASEGUROS SAU para que en el plazo de 3 meses desde que la presente resolución
sea firme y ejecutiva, notifique a la Agencia la adopción de las medidas descritas en los
fundamentos de derecho de la propuesta de resolución transcrita en la presente
resolución.
FOURTH: NOTIFY ALKORA EBS CORREDURIA DE SEGUROS Y REASEGUROS SAU
of this resolution.
FIFTH: In accordance with the provisions of Article 85 of the LPACAP, which makes the
reduction for voluntary payment conditional upon the withdrawal or waiver of any
administrative action or appeal, this resolution shall be final in administrative proceedings
and fully enforceable as of the date of its notification.
In accordance with the provisions of Article 50 of the LOPDGDD, this Resolution shall be
made public. Publication shall take place once the resolution has been notified to the data
subjects.
Against this resolution, which concludes the administrative proceedings as provided for in
Article 114.1.c) of Law 39/2015, of October 1, on the Common Administrative Procedure of
Public Administrations, the data subjects may file an administrative appeal with the
Administrative Chamber of the National Court, in accordance with the provisions of Article
25 and paragraph 5 of the fourth additional provision of Law 29/1998, of July 13, regulating
Contentious-Administrative Jurisdiction, within two months from the day following
notification of this decision, as provided for in Article 46.1 of the aforementioned Law.
However, in accordance with Article 90.3(a) of the LPACAP, the final administrative
decision may be provisionally suspended if the data subject expresses their intention to file
a contentious-administrative appeal. If this is the case, the data subject must formally notify
the Spanish Data Protection Agency in writing, submitting the notice through the Agency’s
Electronic Registry [https://sedeaepd.gob.es/sede-electronica-web/], or through any of the
other registries provided for in Art. 16.4 of the aforementioned Law 39/2015 of October 1.
The interested party must also submit to the Agency the documentation
6 Jorge Juan
Street, 28001 –
Madrid76/76
www.aepd.es
sedeaepd.gob.es
proving that the administrative appeal has been effectively filed. If the Agency is not notified
of the filing of the administrative appeal within two months from the day following
notification of this decision, it will consider the provisional suspension to have ended.
1331-101025
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency