AEPD (Spain) - PS-00389-2024
| AEPD - PS-00389-2024 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 4(1) GDPR Article 4(2) GDPR Article 4(7) GDPR Article 5(1)(c) GDPR Article 58(2)(d) GDPR Article 83(1) GDPR Article 83(2)(a) GDPR Article 83(2)(b) GDPR Article 83(2)(g) GDPR Article 83(5) GDPR Article 83(6) GDPR Annex I RD933/2021 Art.24 LO 4/2015 Art.4.3 RD 933/2021 |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | 22.06.2024 |
| Decided: | 18.07.2025 |
| Published: | |
| Fine: | 70000 EUR |
| Parties: | WORLD 2 MEET, S.L. Data Subject Company.1 |
| National Case Number/Name: | PS-00389-2024 |
| European Case Law Identifier: | n/a |
| Appeal: | Not appealed |
| Original Language(s): | Spanish |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | Ariel |
The DPA imposed a €70.000 fine on a booking platform company for violating Article 5(1)(c) GDPR by unnecessarily requesting the data subjects' ID's.
English Summary
Facts
The Controller offered booking services for tourism villas. As part of the check-in process, it was mandatory to verify the identity of the guests, in accordance with the local regulations. For this purpose, the Controller relied on an external platform operated by a partner, which was responsible for collecting a copy of each guest’s ID. Access to the platform was provided via a private link sent to the guest’s email address, outside the reservation platform. The data subject lodged a complaint regarding the processing of their ID, arguing that receiving the request through a private link posed a risk of unauthorised access and potential exposure of their personal data.
Holding
The DPA found that requiring guests to upload a full copy of their ID through an external platform was unnecessary and disproportionate, violating the GDPR’s data minimisation principle under Article 5(1)(c). A complete ID card contains far more information than what is required by the applicable regulations, such as a photograph, expiration date, CAN, or parents’ names, and collecting this excess data introduces avoidable risks, including identity theft.
Moreover, the DPA noted that an ID card alone does not provide all the information mandated by the applicable regulation and therefore cannot, by itself, fulfil its requirements. The purpose of the mentioned regulation is to safeguard people and property and maintain public order, given the role accommodation facilities may play in criminal activity. However, merely sending a copy of an ID document does not reliably verify a person’s identity and does not achieve this purpose.
The DPA concluded that compliance with the applicable regulation can be achieved in a less intrusive way, for example, by having guests complete a form that collects only the specific data required under the regulation, whether online or in person. Collecting a full copy of an ID document therefore constitutes excessive processing and is not justified for the stated purpose.
Comment
The Controller accepted liability and proceeded to voluntary settlement.
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.
1/21 • File No.: EXP202409634 RESOLUTION TERMINATING THE PROCEEDINGS BY ACKNOWLEDGMENT OF LIABILITY AND VOLUNTARY PAYMENT From the proceedings initiated by the Spanish Data Protection Agency and based on the following BACKGROUND FIRST: On July 18, 2025, the Presidency of the Spanish Data Protection Agency agreed to initiate sanctioning proceedings against WORLD 2 MEET, S.L. (hereinafter, WORLD 2 MEET), by means of the agreement transcribed below: << File No.: EXP202409634 AGREEMENT TO INITIATE SANCTIONING PROCEEDINGS Based on the actions taken by the Spanish Data Protection Agency and the following FACTS FIRST: On June 22, 2024, a complaint was filed with the Spanish Data Protection Agency regarding a possible infringement attributable to WORLD 2 MEET, S.L., with Tax Identification Number B62880992 (hereinafter, WORLD 2 MEET). The facts brought to the attention of this authority are as follows: The complainant states that, through the platform ***PLATFORM.1, they made a reservation for a villa with WORLD 2 MEET along with third parties, and that the platform has requested a copy of the identity document of each guest to register them. They consider this request for excessive information. The complainant indicates that they provided the details of their respective identity documents, but that WORLD 2 MEET is requesting a complete copy of the identity document of each guest, claiming it is necessary to manage the registration and make the appropriate communications to the Civil Guard. However, the complainant believes that providing the information contained in said identity documents is sufficient, without requiring a copy. Along with the written document, the following is provided: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 2/21 - Copy of an email dated June 3, 2024, sent from the email address ***EMAIL.1 to the claimant, which states the following: “Our computer system is linked to the Civil Guard, which belongs to the municipality of ***LOCALIDAD.1, the town to which your reservation at ***DIRECCIÓN.1 corresponds. This information is requested during online check-in because it is sent directly to the security forces on the same day of your arrival” (sic). - Copy of an email dated June 3, 2024, sent to ***EMAIL.1 by the claimant, stating the following: “As mentioned, we will not be sending the photographs as such. Could you please tell us what personal details you need to send you the strictly necessary information? Thank you, and I hope you understand our precautions due to the numerous scams committed using other people's ID cards.” (sic). - Copy of an email dated June 4, 2024, sent by ***EMAIL.1 to the claimant, stating the following: “The data strictly necessary, as I already indicated, to complete the check-in MUST be either the ID card or the PASSPORT of each of the OCCUPANTS, which is the only way we have to identify them to pass them on to the security forces, in this case the Civil Guard of ***LOCATION.1, who require it” (sic). - Copy of an email dated June 5, 2024, sent to ***EMAIL.1 by the claimant, which includes the following information for the four guests who will be staying: ID number, full name, date of birth, and address. - Copy of an email dated June 6, 2024, sent from the email address ***EMAIL.1 to the claimant, responding to the previous email as follows: “This information is not sufficient for the local authorities. We don't request this information arbitrarily. It is linked to the police/civil guard for the registration of guesthouses, as in ANY establishment. Upon arrival, it will not be possible to complete it, since you have booked a villa, not a hotel, and as you will understand, a villa does not have its own reception like a hotel; for this reason, check-in and payment of the ecotax must be done online BEFORE arrival for all guests. If you do not have the passports of the other occupants, you can forward them the link and they can complete it themselves, no problem.” SECOND: In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter LOPDGDD), the aforementioned complaint was forwarded to WORLD 2 MEET so that it could analyze it and inform this Agency, within one month, of the actions taken to comply with the requirements established in the data protection regulations. The notification of the transfer of the claim, which was carried out in accordance with the rules established in Law 39/2015, of October 1, on Administrative Procedure C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 3/21 Common Law of Public Administrations (hereinafter, LPACAP), was made on July 3, 2024, as shown in the acknowledgment of receipt included in the file. THIRD: On August 5, 2024, this Agency received a written response stating the following: "World 2 Meet S.L. is a tour operator that, among other activities, is dedicated to the rental of vacation accommodations under the brand ***COMPANY.1. ***COMPANY.1 operates exclusively online, using both its own digital booking platform ****URL.1 and external distribution channels, such as ***PLATFORM.1. The completion of the traveler entry form, required by regulations on traveler control and public safety, is carried out digitally through an online check-in service available on the ***COMPANY.1 platform. This service is used for all bookings, both direct and those processed through external channels, as in the case of the claimant's booking. ***COMPANY.1 does not have staff at the destination. Check-in and check-out of the accommodations are carried out through a Self-service system. (...) To verify the accuracy of the information provided by guests and validate their identity, they are asked to upload an image of their identity document during the online check-in process. (...) The processing of the image of the guests' identity document is intended to validate their identity and ensure the accuracy of the data recorded on the check-in form, in compliance with the obligation established by Article 4.3 of Royal Decree 933/2021. Guest identity verification is carried out by scanning the MRZ (Machine Readable Zone) code that all identity documents include. The MRZ is a section of identity documents that contains information encoded in a standard format, readable by machines and specialized software. The MRZ follows the standards established by the ICAO (International Civil Aviation Organization), specifically in Document 9303. The information contained in the MRZ varies depending on the country issuing the document identity, but typically includes the type of document (ID card, passport, etc.), the document number and expiry date, nationality, the holder's identifying information, date of birth, and gender. The data obtained from the MRZ is automatically transferred to the entry form, allowing the guest to continue completing it and proceed to sign it (...). C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 4/21 For the assessment of the necessity and proportionality of the processing, the following elements were taken into account: I. Verification of information: Without this processing, ***COMPANY.1 would not be able to verify the accuracy of the information recorded on the entry form, in accordance with the requirements of Article 4.3 of Royal Decree 933/2021. II. Regulatory requirement: The display or provision of the Identity document Provided by the guest is a requirement of Royal Decree 933/2021. This regulation clearly establishes the obligation to verify the information provided by guests by checking their identity documents. III. Particularities of non-face-to-face transactions and lack of viable alternatives: - A system based on the physical display of identity documents by all guests is not viable in an online environment. The nature of digital transactions prevents the physical verification of documents. - The provision in Royal Decree 933/2021 to allow the provision of the identity document, instead of its physical presentation, responds to the specific needs of online transactions. As mentioned in the preamble of the regulation, the update of the regulations applicable to traveler registrations was carried out precisely to avoid "the exclusion of new types of accommodation activities, such as short-term tourist accommodation, which are managed through portals or booking platforms via digital means or the internet." - Although electronic identification technologies exist, their widespread adoption has not yet been achieved, which makes them impractical as the sole solution for traveler control at present. Based on these elements, it was concluded that the processing of guests' identity documents is covered under the provision of Article 6.1.c) of the GDPR, as it is a necessary, appropriate, and relevant measure to comply with the obligation established in Article 6.1.c). 4.3 of Royal Decree 933/2021. (...)" FOURTH: On August 14, 2024, additional information was requested from WORLD 2 MEET, and on August 27, 2024, this Agency received a written response indicating the following: “(...) the following illustrates the details to which ***COMPANY.1 has access as a user of the technology provider's platform, according to the interface available to its agents. On the aforementioned platform, the entire procedure for verifying the validity of the identity document and accuracy of the data recorded in the entry forms is carried out, in accordance with the legal obligation assigned to this party by Article 4.3 of Royal Decree 933/2021 of October 26, which establishes the documentary registration and information obligations for natural or legal persons engaged in accommodation and motor vehicle rental activities, which can be understood as executed in two phases: I. Verification of the validity of the provided identity document, by reading the MRZ code. This party understands that reading a valid MRZ code, in itself, constitutes verification of the validity of the provided identity document and, consequently, of the data it contains, since this code is only included on official identity documents. For this verification, the platform does not store any image of the ID card. I. Manual verification by agents of the accuracy of the data recorded on the check-in forms. After verifying the validity of the identity document, and considering that the service lacks in-person or physical presence at the accommodation, the agents review the accuracy of the data recorded on the check-in form. To do this, they compare the data recorded on the form with the information contained in the identity verification documents provided by the guests. To perform this verification through the platform, it is necessary that the agents be able to view the image of the guests' identity documents, as established in Article 4.3 of Royal Decree 933/2021. (…) It is important to note that the above processes are carried out entirely on the provider's platform, under the usage guidelines and parameters that govern said platform, which are not configurable by ***COMPANY.1. The process for verifying the accuracy of the data recorded on the check-in forms is illustrated below: For each guest, the agent proceeds to manually verify and validate the accuracy of the data that the occupant has entered on the check-in form, following the procedure established by the platform, which is as follows: The image below illustrates the panel that the agents view after verifying the accuracy of the guests' data (validation status "pending"). On the right margin, you can see the guest's completed traveler registration form. (Screenshot attached). 1. To begin verifying the data, the agent clicks on the word "validate." The platform then displays an image of both sides of the ID card and the information contained in the form so the agent can manually verify that both match. Attach the screenshot in the “Identity Validation” section, where you can see that the following data from the ID card is captured: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 6/21 - Occupant's name. - Email. - Telephone. - Date of birth. - Nationality (Country). - Place of birth. - Sex. - Type of document. - ID/Tax ID/National ID number. - Date of issue. - Place of issue. - Country. - Province. - Municipality. - Address. - Postal code. - Expiration date. “On this panel, the agent sees the images of the ID card provided by the guest on the left and the information provided by the guest on the entry form on the right. 1. If the information matches, the agent confirms the accuracy of the entered data and continues the process. If any discrepancies or inconsistencies are detected, the agent has the option to send a message to the guest so they can make the necessary modifications or corrections. 2. Once the accuracy of the entered data has been manually verified, the agent completes the operation, and the platform marks the verification as validated. (Screenshot attached). 3. Since the verification of guest data accuracy is carried out entirely through the platform, no copies of the ID card image are downloaded or stored on any of ***COMPANY.1's systems or devices. 4. According to the platform's configuration, once the guest's identity has been verified and the accuracy of the data on the check-in form has been confirmed, the ID card image is destroyed after check-out. The platform provider does not currently allow configuring the data retention period for guests. SECOND.- Regarding the data obtained and transferred from the MRZ. Regarding the case that is the subject of this request, since it involves reading the MRZ code of National Identity Documents, the following categories of data are captured and transferred to the input log: First and last name, C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 7/21 Document type, Document number, Country, Support number However, it is important to refer to the information provided in previous communications related to this case and addressed to the Spanish Data Protection Agency (AEPD), because: “(…) The information contained in the MRZ varies depending on the country that issued the identity document, but typically includes the type of document (National Identity Document, passport, etc.), the document number and expiry date, the nationality, the holder's identifying information, the date of birth, and the holder's sex.” (…)” (sic). FIFTH: On August 28, 2024, in accordance with Article 65 of the LOPDGDD, the complaint was admitted for processing. SIXTH: According to the report obtained from the AXESOR tool, the entity WORLD 2 MEET is a company incorporated in 2002, with a turnover of €1,104,025,000 in 2023. LEGAL BASIS I Jurisdiction In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR) and as established in Articles 47, 48.1, 64.2 and 68.1 of the Organic Law Pursuant to Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter, LOPDGDD), the Presidency of the Spanish Data Protection Agency is competent to initiate and resolve this procedure. II Procedure Likewise, Article 63.2 of the LOPDGDD establishes that: “The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the implementing regulations issued thereunder, and, insofar as they do not contradict them, subsidiarily, by the general rules on administrative procedures.” In accordance with Article 64 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights), and taking into account the characteristics of the alleged infringement, a sanctioning procedure is initiated. The procedure will have a maximum duration of twelve months from the date of the initiation agreement. After this period, the procedure will expire and, consequently, C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 8/21 the proceedings will be archived, in accordance with the provisions of Article 64 of the LOPDGDD. If no objections are raised to this initiation agreement within the stipulated period, it may be considered a proposed resolution, as established in Article 64.2.f) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP). III Preliminary Issues Article 4.1 of the GDPR defines “personal data” as: “any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.” Article 4.2 of the GDPR defines "processing" as: "any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction." Article 4.7 of the GDPR defines "controller" as: "the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its appointment may be laid down by Union or Member State law." Article 4.8 of the GDPR defines the "processor" as "the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller." In this case, in accordance with Articles 4.1 and 4.2 of the GDPR, personal data processing is taking place, since WORLD 2 MEET, among other processing activities, collects and stores personal data of natural persons, such as: name and surname, national identity card number, address, and email address. WORLD 2 MEET carries out this activity in its capacity as the data controller, as it determines the purposes and means of such processing, pursuant to Article 4.7 of the GDPR. IV. Breach of Obligation. Data Minimization C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 9/21 Article 5.1(c) of the GDPR states: "1. Personal data shall be: (…) (c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimization’);" The principle of data minimization, set out in the aforementioned article, aims to ensure that only the personal data strictly necessary to achieve the legitimate purpose of the processing is processed, preventing the excessive or disproportionate use of personal information. This principle protects the rights and freedoms of data subjects by limiting data processing to what is essential, reducing risks and ensuring the responsible use of personal information. In this case, the claimant, after booking accommodation through WORLD 2 MEET via a web platform, was required to submit, along with the other guests, a copy of their identity document via a link provided by the defendant, in order to complete check-in: “If you don't have the passports of the other occupants, you can forward them the link and they can complete it themselves, no problem.” WORLD 2 MEET confirms in its written response to the transfer of August 5, 2024, to this Agency that, indeed, said request was made for the purpose of performing online check-in, “to verify the accuracy of the information provided by guests and validate their identity, they are asked for an image of their identity document during the online check-in process. (...) The processing of the image of the guests' identity document is intended to validate their identity and ensure the accuracy of the data recorded on the entry form, in compliance with the obligation established by Article 4.3 of Royal Decree 933/2021.” It goes on to explain that “guest identity verification is performed by scanning the MRZ (Machine Readable Zone) code included on all identity documents. The MRZ is a section of the identity document that contains information encoded in a standard format, readable by machines and specialized software. (…) The data obtained from the MRZ is automatically transferred to the check-in form, allowing the guest to continue filling it out and proceed to sign it (...).” WORLD 2 MEET also includes a screenshot of the “Identity Validation” section of the platform used for customer registration, which shows the following data being captured from the ID card: - Occupant's name. - Email address. - Phone number. - Date of birth. - Nationality (Country). C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 10/21 - Place of birth. - Sex. - Type of document. - National Identity Document (DNI/NIF/ID) number. - Date of issue. - Place of issue. - Country. - Province. - Municipality. - Address. - Postal code. - Expiry date. The regulations governing guest registration books and check-in forms in hospitality establishments, as well as the obligation to report the information contained in these forms to the State Security Forces and Corps, are primarily comprised of Organic Law 4/2015, of March 30, on the protection of public safety (hereinafter, LO 4/2015), and Royal Decree 933/2021, of October 26, which establishes the documentary registration and information requirements for individuals or legal entities engaged in accommodation and motor vehicle rental activities (hereinafter, RD 933/2021). Article 24 of Organic Law 4/2015 states the following in its first paragraph: “Natural or legal persons engaged in activities relevant to public safety, such as those related to accommodation (…) shall be subject to the obligations of documentary registration and information under the terms established by the applicable regulations.” These obligations are currently established by Royal Decree 933/2021, to which the claim refers, with Annex I.a), paragraph 3, specifying the guest data that must be included in the so-called “Registration Sheet” that the entity responsible for the hotel must provide to the State Security Forces and Corps when dealing with professional hospitality establishments. Specifically, the following traveler information is legally required: a) Name. b) First surname. c) Second surname. d) Sex. e) Identity document number. f) Document support number. g) Type of document (National Identity Card, passport, Foreigner Identity Card). h) Nationality. i) Date of birth. j) Usual place of residence. – Full address. – City/Town. – Country. k) Home telephone number. l) Mobile telephone number. m) Email address. n) Number of guests. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 11/21 o) Relationship between guests (if any of them are minors). Therefore, requesting a copy of a national identity card or passport violates the principle of data minimization, established in Article 5.1.c) of the GDPR, and constitutes excessive data processing. This is because the complete national identity card contains more data than required under applicable regulations, such as the photograph, the document's expiry date, the CAN (National Identification Code), or the parents' names. Furthermore, providing a copy of personal documentation implies, among other things, an unnecessary risk of identity theft, which must be avoided or, at the at least, effectively mitigated. Additionally, it should be noted that the National Identity Document (DNI) does not contain all the information requested in Annex I of Royal Decree 933/2021, and therefore, on its own, is not a valid means of complying with the said regulation. In this regard, it should be pointed out that the purpose of Royal Decree 933/2021 is “the protection of persons and property and the maintenance of public order” given the “special relevance” of “lodging logistics” “in the modus operandi of criminals,” as stated in the Preamble to the regulation. Therefore, sending a copy of the document does not allow for definitive verification of the person's identity and, consequently, lacks the necessary suitability to fulfill the purpose of the regulation. Regarding the collection of data required by Royal Decree 933/2021, which applies to individuals or legal entities engaged in accommodation activities, the Spanish Data Protection Agency (AEPD) considers that it may be sufficient for individuals to provide or complete a form that collects only the data required in sections A.3 and B.3 of Annex I of the Royal Decree (“Data to be provided in the exercise of accommodation activities,” sections A.3, A.4, B.3, and B.4). This form can be completed online or in person at the accommodation establishment. Article 4.3 of Royal Decree 933/2021 stipulates that: “The forms and forms will be provided by the accommodation or vehicle rental establishment, which will be responsible for the accuracy of the data recorded therein, ensuring that they match the documents or systems that prove the identity of the individuals, which must be presented or provided by the users of these services.” In this regard, the authentication of data collected via a form, in cases of in-person collection, could be as simple as visually verifying the correspondence between the data provided and the identity document presented. In the case of online data collection without in-person assistance, this verification can be carried out using mechanisms such as digital certificates. It is also possible to verify that the data and information provided matches the data associated with the payment method used. Similarly, among the possible measures, security codes can be sent to the telephone numbers or email addresses of guests required to provide identification, as authentication factors. These are data that form part of the information C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 12/21 that the accommodation provider must collect from users of accommodation services in accordance with Royal Decree 933/2021. And all of this is without prejudice to the existence of other alternatives that, in balance with the GDPR and, more specifically, with the principle of data minimization provided for in Article 5.1 c) of said regulation, could be analyzed and considered valid. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 12/21 Therefore, the collection of the claimant's identity document copy, including all the information contained therein, as well as the capture of data from the ID card, carried out by WORLD 2 MEET, could be considered, without prejudice to the outcome of the investigation, as excessive processing of personal data that is irrelevant and unnecessary for the specific purpose of the processing, contrary to the principles of data protection, specifically the principle of "data minimization," regulated in Article 5.1.c) of the GDPR. Therefore, in accordance with the evidence available at this time, and in accordance with the initiation of sanctioning proceedings, it is considered that the known facts could constitute an infringement attributable to WORLD 2 MEET, for violation of the aforementioned article. V Classification of the infringement of Article 5.1.c) of the GDPR and its classification for the purposes of the statute of limitations Article 83.5 of the GDPR classifies as an administrative infringement the violation of the following articles, which shall be sanctioned, in accordance with paragraph 2, with administrative fines of up to EUR 20,000,000 or, in the case of an undertaking, up to 4% of its total global annual turnover of the preceding financial year, whichever is higher: "(a) the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7 and 9; (b) the rights of data subjects pursuant to Articles 12 to 22; (c) transfers of personal data to a recipient in a third country or to an international organisation pursuant to Articles 44 to 49; (d) any obligation in by virtue of the law of Member States adopted pursuant to Chapter IX; (e) failure to comply with a decision or a temporary or permanent limitation on the processing or the suspension of data flows by the supervisory authority pursuant to Article 58(2), or failure to provide access in violation of Article 58(1). For its part, the LOPDGDD, in its Article 71, Infringements, states that: “The acts and conduct referred to in paragraphs 4, 5 and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law, constitute infringements.” C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 13/21 For the sole purpose of establishing the statute of limitations, Article 72.1 of the LOPDGDD (Spanish Data Protection Act) establishes the following: "In accordance with the provisions of Article 83.5 of Regulation (EU) 2016/679, the following infringements are considered very serious and shall be subject to a three-year statute of limitations: "a) The processing of personal data in violation of the principles and safeguards established in Article 5 of Regulation (EU) 2016/679." " VI Proposed Sanction In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR must be observed. These provisions state: “1. Each supervisory authority shall ensure that the imposition of administrative fines under this Article for infringements of this Regulation referred to in paragraphs 4, 9 and 6 is, in each individual case, effective, proportionate and dissuasive. 2. Administrative fines shall be imposed, depending on the circumstances of each individual case, as an additional measure to, or in lieu of, the measures provided for in Article 58(2)(a) to (h) and (j). When deciding on the imposition of an administrative fine and its amount in each individual case, due consideration shall be given to: (a) the nature, seriousness and duration of the infringement, taking into account the nature, scope or purpose of the processing operation concerned as well as the number of data subjects affected and the level of damage suffered; b) the intentionality or negligence of the infringement; c) any measures taken by the controller or processor to remedy the damage suffered by the data subjects; d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures implemented pursuant to Articles 25 and 32; e) any previous infringements committed by the controller or processor; f) the degree of cooperation with the supervisory authority in order to remedy the infringement and mitigate its possible adverse effects; g) the categories of personal data affected by the infringement; h) how the supervisory authority became aware of the infringement, in particular whether and, if so, to what extent the controller or processor notified the infringement; i) where the measures referred to in Article 58(2) have been previously ordered against the controller or processor concerned in relation to the same matter, compliance with those measures; j) adherence to codes of conduct pursuant to Article 40 or to approved certification mechanisms pursuant to Article 42, and C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 14/21 k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement. For its part, Article 76, “Sanctions and Corrective Measures,” of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) provides: “1. The sanctions provided for in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the criteria for determining the severity of the sanction established in paragraph 2 of the aforementioned article. 2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account: a) The continuing nature of the infringement.” b) The connection between the infringer's activity and the processing of personal data. c) The benefits obtained as a result of committing the infringement. d) The possibility that the affected party's conduct could have induced the commission of the infringement. e) The existence of a merger by acquisition subsequent to the commission of the infringement, which cannot be attributed to the acquiring entity. f) The impact on the rights of minors. g) Having a data protection officer, when not mandatory. h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms in cases where disputes arise between them and any interested party. In this case, considering the seriousness of the potential infringement, and especially the consequences for those affected, a fine would be appropriate, in addition to the adoption of measures, if applicable. The fine imposed must be effective, proportionate, and dissuasive in each individual case, in accordance with Article 83.1 of the GDPR. To guarantee these principles, WORLD 2 MEET's turnover of €1,104,025,000 in 2023 is considered. For the purposes of deciding on the imposition of an administrative fine and its amount, based on the evidence available at this time, a decision has been made to initiate proceedings. sanctioning authority, and without prejudice to the outcome of the investigation, it is considered appropriate to determine the sanction to be imposed in accordance with the following circumstances, as set forth in the aforementioned provisions. Preliminary considerations are based on the following circumstances: - The nature, seriousness, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage suffered (Article 83.2(a) of the GDPR): WORLD 2 MEET requested on June 4, 2024, a copy of both sides of the identity document, with the inherent risk this entails for the claimant as a client of said accommodation. - Intentionality/Negligence in the infringement (Article Article 83.2, letter b) of the GDPR): The complainant's request for an alternative means of identification with WORLD 2 MEET was not addressed. In this case, the specific intent is evident in WORLD 2 MEET's refusal when the client offered to provide only the data strictly necessary for check-in: "Please reply to this email specifying which data you require from the respective ID cards to complete the strictly legal check-in." WORLD 2 MEET responded by stating that "the data strictly necessary, as I already indicated, to complete the check-in is MANDATORY, either the ID card or the PASSPORT of each OCCUPANTS, which is the only way we have to identify them for law enforcement." Therefore, despite the complainant proposing an alternative method and raising objections to said processing and doubts regarding its compliance with current regulations, WORLD 2 MEET insisted on collecting a full copy of the ID card, which implies a presumed intention to follow a practice that may not be in line with legal requirements. - The categories of personal data affected by the infringement (Article 83.2, letter g) of the GDPR): The numerical identifier of the ID card, together with the verification character corresponding to the tax identification number, unequivocally identifies a natural person. This quality makes it particularly sensitive data because, insofar as its processing is not accompanied by the technical and organizational measures necessary to guarantee that the person identifying it is indeed its holder, a third party can easily impersonate a natural person, or, in other words, can commit identity fraud, with the risks this entails for the privacy, honor, and assets of the victim. Therefore, this circumstance is taken into account when determining the sanction to be imposed. Furthermore, the following are considered The following factors, considered aggravating circumstances, are relevant: - The connection between the offender's activity and the processing of personal data (Article 76.2, letter b), of the LOPDGDD): WORLD 2 MEET is accustomed to the continuous processing of personal data of clients staying at its establishment. The balance of the circumstances contemplated in Article 83.2 of the GDPR and Article 76.2 of the LOPDGDD, with respect to the infringement committed by violating the provisions of Article 5.1.c) of the GDPR, allows for an initial administrative fine of €70,000.00. VII Corrective Measures C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 16/21 If the infringement is confirmed, the resolution issued may establish corrective measures. that the infringing entity must adopt to end the non-compliance with personal data protection legislation, in this case Article 5.1.c) of the GDPR, in accordance with the provisions of Article 58.2.d) of the GDPR, according to which each supervisory authority may “require the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specific manner and within a specified period…” Thus, the responsible entity may be required to adapt its actions to the personal data protection regulations, to the extent expressed in the previous Legal Grounds. This document establishes the alleged infringement committed and the facts that could give rise to this possible breach of data protection regulations, from which the measures to be adopted are clearly inferred, without prejudice to the specific type of procedures, mechanisms, or instruments for implementing them. to the sanctioned party, since it is the data controller who fully knows their organization and must decide, based on proactive responsibility and a risk-based approach, how to comply with the GDPR and the LOPDGDD. However, in this case, regardless of the above, in accordance with the evidence currently available regarding the initiation of sanction proceedings, the resolution adopted may require WORLD 2 MEET to, within 1 month from the date of the final resolution of these proceedings becoming enforceable, adopt the following measures: - Modify its registration system so that providing a copy or image of guests' identity documents is no longer a requirement for accommodation. - Delete/remove all images/copies of identity documents collected to date. The imposition of this measure is compatible with the The sanction consists of an administrative fine, as provided for in Article 83.2 of the GDPR. Please note that failure to comply with any order to adopt measures imposed by this agency in the resolution of this sanctioning procedure may be considered an administrative infringement in accordance with the GDPR, specifically classified as an infringement in Articles 83.5 and 83.6, and such conduct may lead to the initiation of further administrative sanctioning proceedings. Furthermore, please remember that neither acknowledgment of the infringement committed nor, where applicable, voluntary payment of the proposed amounts, exempts you from the obligation to adopt the appropriate measures to cease the conduct or correct the effects of the infringement committed and to demonstrate to this Spanish Data Protection Agency (AEPD) compliance with the requirements of the GDPR. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 17/21 the infringement committed and to demonstrate to this AEPD compliance with the requirements of the AEPD. that obligation. Therefore, in light of the foregoing, the President of the Spanish Data Protection Agency hereby RESOLVES: FIRST: TO INITIATE SANCTIONING PROCEEDINGS against WORLD 2 MEET, S.L., with Tax Identification Number (NIF) B62880992, for the alleged infringement of Article 5.1.c) of the GDPR, as defined in Article 83.5 of the GDPR. SECOND: TO APPOINT A.A.A. as investigating officer and B.B.B. as secretary, indicating that they may be challenged, if necessary, in accordance with Articles 23 and 24 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector (LRJSP). THIRD: TO INCLUDE in the file, for evidentiary purposes, the The claim filed by the claimant and its supporting documentation, as well as the documents obtained and generated by the General Sub-Directorate for Data Inspection in the preliminary proceedings prior to the commencement of these disciplinary proceedings. FOURTH: THAT for the purposes set forth in Article 64.2 b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, the application for a sanction would be an administrative fine of €70,000.00, without prejudice to the outcome of the investigation. FIFTH: NOTIFY WORLD 2 MEET, S.L., with Tax Identification Number (NIF) B62880992, of this agreement, granting it a period of ten business days to submit any allegations and present any evidence it deems appropriate. In its written allegations, it must provide its Tax Identification Number (NIF) and the procedure number shown in the heading of this document. In accordance with the provisions of Article 85 of the LPACAP (Law on Administrative Procedure of Public Administrations), it may acknowledge its responsibility within the period granted for submitting allegations to this initiation agreement; this will entail a 20% reduction of the penalty to be imposed in this procedure. With the application of this reduction, the penalty would be set at €56,000.00, and the procedure will be resolved with the imposition of this penalty. Likewise, you may, at any time prior to the resolution of these proceedings, make voluntary payment of the proposed penalty, which will result in a 20% reduction. With this reduction, the penalty will be set at €56,000.00, and payment will terminate the proceedings, without prejudice to the imposition of any other applicable measures. The reduction for voluntary payment of the penalty is cumulative with the reduction applicable for acknowledging responsibility, provided that this acknowledgment is made within the period granted for submitting arguments upon the initiation of the proceedings. The voluntary payment of the amount referred to in the preceding paragraph may be made at any time prior to the resolution. In C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 18/21 In this case, if both reductions were to be applied, the amount of the penalty would be set at €42,000.00. In any case, the effectiveness of either of the aforementioned reductions will be conditional upon the withdrawal or waiver of any administrative action or appeal against the penalty. Should you choose to make voluntary payment of either of the amounts indicated above (€56,000.00 or €42,000.00), you must do so by depositing the funds into account number IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX) held in the name of the Spanish Data Protection Agency at CAIXABANK, S.A., indicating in the payment details the reference number of the procedure shown in the heading of this document and the reason for the reduction in the amount you are claiming. You must also send proof of payment to the General Sub-Directorate of Inspection. Finally, please note that, in accordance with Article 112.1 of the LPACAP, no administrative appeal may be filed against this decision. 1479-141024 Lorenzo Cotino Hueso President of the Spanish Data Protection Agency >> SECOND: On August 5, 2025, WORLD 2 MEET paid the fine of €42,000.00, taking advantage of the two reductions stipulated in the initial agreement transcribed above. This implies acknowledgment of responsibility in relation to the facts referred to in the initial agreement and their legal classification. THIRD: The initial agreement transcribed above indicated that, should the infringement be confirmed, the controller could be ordered to adopt appropriate measures to bring its actions into compliance with the regulations mentioned in this act, in accordance with Article 58.2(d) of the GDPR, which states that each supervisory authority may "require the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specific manner and within a specified time frame...". Having acknowledged responsibility for the infringement, the measures included in the initial agreement should be imposed. LEGAL BASIS I Jurisdiction In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and as established in Articles 47, 48.1, 64.2 and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter LOPDGDD), the Presidency of the Spanish Data Protection Agency is competent to resolve this procedure. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 19/21 Likewise, Article 63.2 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) stipulates that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the implementing regulations issued thereunder, and, insofar as they do not contradict them, subsidiarily, by the general rules on administrative procedures." II Termination of the Procedure Article 85 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), under the heading “Termination of Sanctioning Procedures,” provides the following: “1. Once a sanctioning procedure has been initiated, if the offender acknowledges their responsibility, the procedure may be resolved by imposing the corresponding sanction. 2. When the sanction is solely monetary, or when a monetary sanction and a non-monetary sanction are applicable but the impropriety of the latter has been justified, voluntary payment by the alleged offender, at any time prior to the resolution, will result in the termination of the procedure, except with regard to restoring the altered situation or determining compensation for damages caused by the commission of the infraction. 3. In both In cases where the sanction is solely monetary, the competent body for resolving the proceedings shall apply reductions of at least 20% on the proposed sanction amount, and these reductions may be combined. These reductions must be specified in the notification initiating the proceedings, and their effectiveness is conditional upon the withdrawal or waiver of any administrative action or appeal against the sanction. The percentage reduction provided for in this section may be increased by regulation. III Voluntary Payment and Acknowledgment of Responsibility In accordance with the provisions of Article 85 of the LPACAP, the notified initiation agreement informed the appellant of the possibility of acknowledging responsibility and making voluntary payment of the proposed sanction, which would entail two combinable reductions of 20% each. With the application of these two reductions, the penalty would be set at €42,000.00 and its payment would imply the termination of the proceedings, without prejudice to the imposition of the corresponding measures. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 20/21 Following notification of the aforementioned initiation agreement, WORLD 2 MEET has proceeded to acknowledge responsibility and voluntarily pay the penalty, taking advantage of the two reductions provided for. In accordance with section 3 of article 85 LPACAP, the effectiveness of the aforementioned reductions will be conditional upon the withdrawal or waiver of any action or appeal through administrative channels against the penalty. It should be noted that, in accordance with the provisions of the LPACAP (Law on the Common Administrative Procedure of Public Administrations), as well as the jurisprudence of the Supreme Court on this matter, the exercise of voluntary payment by the alleged offender does not exempt the administration from the obligation to resolve and notify all proceedings, regardless of how they were initiated. Likewise, Article 88 of the aforementioned law establishes that the resolution concluding the proceedings will decide all issues raised by the interested parties and any other issues arising therefrom. Therefore, in accordance with the applicable legislation and having assessed the criteria for determining the severity of the sanctions, the President of the Spanish Data Protection Agency resolves: FIRST: To declare the commission of the infringements and to confirm the sanctions determined in the operative part of the initial agreement transcribed in this resolution. The sum of the aforementioned amounts totals €70,000.00. Following WORLD 2 MEET, S.L.'s prompt payment and acknowledgment of liability, a 40% reduction of the aforementioned total is applied, pursuant to Article 85 of the LPACAP (Law on Administrative Procedure of Public Administrations), resulting in a final amount of €42,000.00. The effectiveness of these reductions is contingent upon the withdrawal or waiver of any administrative action or appeal. SECOND: To declare the termination of procedure EXP202409634, in accordance with the provisions of Article 85 of the LPACAP. THIRD: ORDER WORLD 2 MEET, S.L. to notify the Agency, within one month of this resolution becoming final and enforceable, of the adoption of the measures described in the legal grounds of the initial agreement transcribed in this resolution. FOURTH: NOTIFY WORLD 2 MEET, S.L. of this resolution. FIFTH: In accordance with Article 85 of the LPACAP, which conditions the reduction for voluntary payment and acknowledgment of liability on the withdrawal or waiver of any action or appeal through administrative channels, this resolution will become final and fully enforceable upon notification. In accordance with Article 50 of the LOPDGDD, this resolution will be made public. Publication will take place once the resolution becomes final and enforceable through administrative channels. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 21/21 This resolution, which concludes the administrative process as stipulated by art. Pursuant to Article 114.1.c) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, interested parties may file an administrative appeal with the Administrative Chamber of the National Court, in accordance with the provisions of Article 25 and paragraph 5 of the fourth additional provision of Law 29/1998, of July 13, regulating the Administrative Jurisdiction, within two months from the day following notification of this act, as provided for in Article 46.1 of the aforementioned Law. However, in accordance with the provisions of Article 90.3.a) of the LPACAP, the final administrative decision may be provisionally suspended if the interested party expresses their intention to file an administrative appeal. If this is the case, the interested party must formally notify the Spanish Data Protection Agency in writing, submitting it through the Agency's Electronic Registry [https://sedeaepd.gob.es/sede-electronica-web/], or through any of the other registries provided for in Article 16.4 of Law 39/2015, of October 1. They must also provide the Agency with documentation proving the effective filing of the administrative appeal. If the Agency does not receive notification of the filing of the administrative appeal within two months from the day following notification of this resolution, the precautionary suspension will be terminated. ... 1259-180725 Lorenzo Cotino Hueso President of the Spanish Data Protection Agency 6 Jorge Juan Street www.aepd.es 28001 – Madrid sedeaepd.gob.es




