AEPD (Spain) - PS/00249/2025
| AEPD - PS/00249/2025 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 4(11) GDPR Article 5(2) GDPR Article 7 GDPR Article 14 GDPR Article 23(4) LOPDGDD Article 66 Spanish Telecommunications Law (11/2022) |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | 04.02.2026 |
| Decided: | |
| Published: | 31.07.2026 |
| Fine: | 10000.0 EUR |
| Parties: | MÁS SOL ENERGÍA 15, S.L. |
| National Case Number/Name: | PS/00249/2025 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Spanish; Castilian |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | bms |
The DPA fined a solar energy company €10,000 for making an unsolicited marketing call without proving valid consent and for failing to provide Article 14 GDPR information.
English Summary
Facts
MÁS SOL ENERGÍA 15, S.L., the controller, is a company that carries out customer acquisition through telephone calls to offer solar panel installation services.
On 18 November 2024, the data subject received a marketing call from an agent acting on behalf of the controller. The agent addressed the data subject by name and asked questions about the type of residence in which he lived. When the data subject asked whether the controller had checked the Robinson List, the agent stated that this was unnecessary because the call was based on a “database”. When the data subject subsequently asked about the source of his personal data, the call ended.
The data subject later contacted the controller’s customer service to enquire about the source of his data and was told that the data had been obtained by its sales department and might originate from his acceptance of cookies. The data subject disputed this, stating that he had never visited the controller’s website. At the time of the call, his telephone number had been registered with the Robinson List since March 2024.
The controller explained that it obtained databases from external marketing providers which guaranteed that the personal data had been lawfully collected. It claimed that the data subject had consented in June 2020 through an online form to the processing of his data, the receipt of marketing communications and the disclosure of his data to third parties.
As evidence, the controller provided a record containing the data subject’s details, an IP address, a timestamp and consent indicators, as well as a generic version of the relevant online form. However, the form was blank and did not contain any information specifically identifying the data subject. The controller also acknowledged that it did not independently verify the validity of the consent provided by its external supplier.
Holding
The DPA held that the controller violated Article 66(1)(b) LGTel and Article 14 GDPR.
First, regarding the commercial call, the DPA considered that the controller had not demonstrated that the data subject had given valid consent within the meaning of Article 4(11) GDPR. The documentation provided did not establish that the data subject personally completed the registration, entered the telephone number or could be linked to the IP address contained in the record. Moreover, the controller did not provide the privacy policy applicable when the alleged consent was obtained, meaning that it could not establish the purposes or third parties covered by that consent.
The DPA recalled that, pursuant to Articles 5(2) and 7 GDPR, it is for the controller to demonstrate that valid consent was obtained. This responsibility could not be transferred to the external data provider through contractual guarantees. The controller remained responsible for establishing a valid legal basis for using the purchased data for its own marketing campaign.
This was particularly relevant because the data subject's telephone number was registered with the Robinson List. Although the registration, and as specific consent was not sufficiently demonstrated, the controller could not rely on the exception under Article 23(4) LOPDGDD. Consequently, the DPA found that the unsolicited call lacked a valid legal basis and violated Article 66(1)(b) LGTel.
Second, the DPA found a violation of Article 14 GDPR. Since the controller had obtained the personal data from a third party, it was required to provide the information listed in Article 14 GDPR. During the call, the agent merely referred to an unspecified “database” and did not adequately inform the data subject about the source of the data, the controller's identity, the legal basis for the processing or his data protection rights. The duration or termination of the call did not relieve the controller of this obligation, and the controller had not demonstrated that the required information was provided through another channel.
The DPA imposed a fine of €5,000 for the violation of Article 66(1)(b) LGTel and a further €5,000 for the violation of Article 14 GDPR, resulting in a total fine of €10,000.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish; Castilian original. Please refer to the Spanish; Castilian original for more details.
Case No.: EXP202416818 (PS/00249/2025)
DECISION IN THE ENFORCEMENT PROCEEDING
Based on the proceedings conducted by the Spanish Data Protection Agency (hereinafter
hereinafter, “AEPD”) and based on the following,
BACKGROUND
FIRST: On November 21, 2024, A.A.A. (hereinafter, the
complainant) filed a complaint with the AEPD.
The complaint is directed against the entity MÁS SOL ENERGÍA 15, S.L., with Tax ID No.
B90346370 (hereinafter “MÁS SOL” or the “respondent”) for the alleged
violation of Law 11/2022 of June 28, the General Telecommunications Law (hereinafter
“LGTel”), and Regulation (EU) 2016/679 of the European Parliament and of the
Council of April 27, 2016, on the Protection of Natural Persons with Regard to the
Processing of Personal Data and on the Free Movement of Such Data (hereinafter
the “GDPR”), and Organic Law 3/2018, of December 5, on Data Protection
Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD).
The complainant states in his complaint that on November 18, 2024, he received
a sales call from the number ***PHONE.1, in which
an agent identified as “B.B.B.” stated that she was calling on behalf of “Mas Sol,”
an enterprise specializing in the installation of solar panels, and that she addressed him by
name and asked whether he lived in an apartment or a single-family home. He notes that, when
the data subject asked whether the company had previously checked the Robinson List, the
caller responded that they were under no obligation to do so because they relied on a “database.”
He adds that, when he tried to ask about the source of his personal data, the call was
unilaterally disconnected. Subsequently, he contacted the enterprise’s
customer service to find out the source of his personal data, and was told
that this information was handled by the sales department and that it presumably
stemmed from his acceptance of cookies—a claim he considers untrue, as he had
ever visited the company’s website or given consent.
The following documentation, among others, is submitted along with the complaint letter:
- Screenshot of the call history from the complainant’s mobile device,
showing an incoming call from the number
***PHONE.1, received on Monday, November 18, 2024, at 1:24 p.m., lasting 46 seconds,
along with an audio recording of the call.
- Certificate from the Robinson List Service, issued in the claimant’s name,
which states that their registration has been active since March 9, 2024.
It indicates that the following numbers are registered on the telephone channel:
***PHONE.2 (since March 9, 2024) and ***PHONE.3 (since
August 29, 2024).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 2/23
SECOND: On November 29, 2024, in accordance with the provisions of
Article 65.4 of the LOPDGDD, this Agency forwarded said
complaint to the respondent so that it could analyze it and respond, within
one-month period, regarding the matters set forth in the complaint.
THIRD: On December 24, 2024, the respondent submitted a written
response in which it stated, in summary, that it conducts telemarketing campaigns
using databases contractually acquired from
specialized third-party enterprises, specifically ***ENTERPRISE.1 or ***ENTERPRISE.2,
which guarantee that the data has been obtained with the
informed consent of the data subjects and in accordance with the regulations.
With regard to the complainant, the respondent indicates that consent was granted on June 30,
2020, at 9:17 p.m. via the website ***WEB.1, providing the IP address and the
supporting document with the consent boxes checked for the
processing of data and the sending of commercial communications, including by third parties.
It also states that calls are managed through the automated platform
***PLATAFORMA.1, based on encrypted lists provided by the supplier, without
any manual intervention in dialing or modifying the data, with
operators to making notes, and the system has protocols for registering
numbers such as “DO NOT CALL” or “OPT-OUT.”
Finally, it notes that it has control mechanisms in place to prevent errors,
based on system automation and the monitoring of these records, with no
incidents having been detected to date; in any case, records marked as
“OPT-OUT” take precedence in the event of a discrepancy.
The following documentation is attached to the letter:
- A generic subscription form for a commercial newsletter, which
collects personal data such as first name, last name, email address, gender,
date of birth, ZIP code, and cell phone number. It includes three
checkboxes with the following text: (i) I have read and accept the terms and conditions
of the site and the Privacy Policy, and I authorize the processing of my
Personal Data for the services offered by the site; (ii) I consent to the processing of
my Personal Data for the purpose of sending advertising communications and for
commercial purposes set forth in Article 2 of the Privacy Policy; and (iii) I consent
to my personal data being disclosed to third parties on our list of
sponsors, as specified in Article 2 of the Privacy
Policy.
The form also reminds the data subject that they may object at any
time to processing for marketing purposes or commercial profiling.
The document is completely blank; it contains no
data entered by any person, so there is no reference whatsoever
to the complainant or their personal data.
- CFR from ***ENTERPRISE.3 stating that the data contained in its database
corresponds to a registration made through the website: ***WEB.1. It includes
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 3/23
a table with personal data: First Name: A.A.A. Last Name: (...) IP Address:
(...) Date/time of registration: 06/30/2020 – 9:17 p.m. Mobile phone number:
***PHONE.2 ZIP code: (...). Consent indicators “dd,” “dm,”
“dmt” (0=NO, 1=YES), with a value of 1 for all three indicators, and that, on the
“registration for a contest or similar” form, the data subject had
checked the consent boxes for marketing, third-party marketing, and
data processing.
FOURTH: On February 21, 2025, in accordance with Article 65 of the
LOPDGDD, the complaint filed by the complainant was accepted for processing.
FIFTH: On February 4, 2026, the Presidency of the Spanish Data
Data Protection agreed to initiate disciplinary proceedings against the respondent
pursuant to the provisions of Articles 63 and 64 of Law 39/2015, of October 1,
on the Common Administrative Procedure of Public Administrations (hereinafter
the LPACAP), for the alleged violation of Article 66.1.b) of the LGTel,
as defined in Article 107.30 of the aforementioned law, with an initial penalty of 5,000
euros (five thousand euros) and for the alleged violation of Article 14 of the GDPR,
as defined in Article 83.5.b of the aforementioned regulation, with an initial penalty of 5,000
euros (five thousand euros).
SIXTH: On February 13, 2026, the respondent filed a brief of
arguments in which it reiterates that the complainant’s consent was validly
obtained and verified through technical records (IP address, date and time, and URL), stating
that on June 30, 2020, at 9:17 p.m., such consent was given via
the website ***WEB.1 and that this type of evidence has previously been deemed
sufficient by the AEPD, citing case EXP202400904, which was resolved on April 24,
2024, with the proceedings closed.
Furthermore, it argues that requiring an unequivocal link between said technical record and the
user’s physical identity constitutes a reversal of the burden of proof and a
disproportionate requirement not provided for in the regulations.
Regarding due diligence, the enterprise states that it has acted with a high standard of care by
contracting with specialized providers (***ENTERPRISE.2 / ***ENTERPRISE.3), with whom
it maintains a contract that guarantees the lawfulness of the data and in which the provider
assumes responsibility for data collection, also providing certifications of
privacy policies that disclose the transfer of data to third parties for
marketing purposes. It maintains that, should there be a defect in the data collection,
responsibility would lie with the supplier and not with the entity, as it acted under
the principle of legitimate expectations and without any indication of irregularity.
Regarding the duty to provide information, it states that the phone call lasted
46 seconds and ended abruptly, which materially prevented it from providing
the required information. It points out that it has information protocols whose
application was thwarted by the interruption of the call and adds that it was not
was not required to prove this point at an earlier stage, which would have left it defenseless.
Along with the written statement of arguments, the following documentation is submitted:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 4/23
- Document 1.—Decision issued by the Director of the Spanish Data Protection Agency
in case EXP202400904, initiated by a
complaint filed on January 10, 2024, regarding the receipt of
from a specific phone line, which includes the background
of the case, the referral to the entity against which the complaint was filed, that entity’s statements
regarding the origin of the personal data, the existence of a contract with a
database provider, and the submission of a certificate confirming the
obtaining of consent via a web form; it was ultimately agreed to close
the complaint and notify the parties.
- Document 2.—Dated December 2, 2024, a notice issued by
***ENTERPRISE.3 detailing the personal data contained in
its database associated with a specific record, including first and
last names, IP address, date and time of registration, cell phone number,
zip code, and consent checkboxes for data processing,
direct marketing, and third-party marketing, indicating that the data comes from
a registration made through the website pocketcoupons.net via
an online form, that information was provided during the process in accordance with
Article 13 of the GDPR, and that the data has been erased from the database.
- Document 3.—Contractual document corresponding to the General
Terms and Conditions of Sale of ***ENTERPRISE.2., version 1/2024, which describes
the enterprise’s identity and activities and sets forth the conditions applicable to
the provision of digital marketing services and the supply of databases,
including the definition of terms, the types of
advertising campaigns, the collection and delivery of leads, Tracking systems, the
obligations of the parties, the processing of personal data, the
, the duration of the contract, and the rules governing property rights.
SEVENTH: On March 3, 2026, a proposed resolution was issued
stating that the Presidency of the Spanish Data Protection Agency should
impose a fine on the entity MÁS SOL for violating Article 66.1.b) of the LGTel,
as defined in Article 107.30 of the aforementioned law, with a fine of 5,000 euros
(five thousand euros) and for the violation of Article 14 of the GDPR, as defined in Article
83.5.b) of the aforementioned Regulation, with a fine of 5,000 euros (five thousand euros).
Notice of this proposed resolution was duly served on the
respondent on March 9, 2026, via the Single Authorized Electronic Address
(DEHÚ) service, and the respondent was granted a period of time to file a response.
There is no record of any response from the respondent to said notification.
EIGHTH: MÁS SOL ENERGÍA 15, S.L., with Tax ID No.: B90346370, is an enterprise with a
turnover of 41 million euros.
Based on the proceedings conducted in this case and the documentation
on file, the following
PROVEN FACTS
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 5/23
First. – MÁS SOL ENERGÍA 15, S.L., with Tax ID No. B90346370, is a
commercial entity that engages in activities related to customer acquisition
through telephone calls to offer solar panel installation services
.
Second. – There is a screenshot of the call history from a
, showing an incoming call to the number ***PHONE.2 from
the number ***PHONE.1, received on November 18, 2024, at 1:24
, lasting 46 seconds.
Third. – An audio file corresponding to the call received from the
number ***PHONE.1 on the indicated date and time is included, the content of which reflects a
telephone conversation initiated by a person who identifies himself as an agent and who
states that they are calling on behalf of “MÁS SOL,” inquiring about the type of
housing occupied by the recipient of the call.
Fourth. – The record shows that MÁS SOL, in its response filed on
dated 12/24/2024 and in its brief of arguments dated 02/13/2026, states that
it conducts commercial prospecting campaigns via telephone calls, that
such campaigns are carried out through an automated dialing system
called ***PLATAFORMA.1, and that the personal data used in these
campaigns comes from the import of lists provided by external enterprises
specializing in advertising and marketing services, ***EMPRESA.1 or ***EMPRESA.2.
Furthermore, in these documents, the entity indicates that, regarding the call
made on 11/18/2024, the personal data used corresponds to a record
associated with the phone number ***PHONE.2.
Fifth. – There is a certificate from the Robinson List Service, issued in the name of
A.A.A., which indicates that his registration has been active since March 9,
2024. This certificate lists the telephone number
***TELÉFONO.2 is listed on the telephone channel, with a registration date of 03/09/2024.
Sixth. – Documentation has been provided consisting of a CFR issued by
***ENTERPRISE.3, dated 12/02/2024, which indicates that its database
contains a record associated with the following personal data: first name A.A.A., last names
(...), mobile phone number ***PHONE.2, ZIP code (...), IP address (...), and
registration date and time 06/30/2020 – 9:17 p.m. The aforementioned documentation includes
a table with indicators regarding consent for data processing,
marketing, and third-party marketing, identified as “dd,” “dm,” and “dmt” (0=NO, 1=
YES), with the value 1 appearing in all three indicators.
Seventh. – There is a generic form for subscribing to a commercial newsletter, which
contains fields for entering personal data and three checkboxes for consent
regarding data processing, the sending of advertising communications, and the transfer of data to
third parties. This form is blank, with no data filled in and
no identifying reference to any specific person.
In particular, the following information is provided next to the checkboxes: (i) I have read and
accept the site’s terms and conditions and Privacy Policy, and I authorize the
processing of my personal data for the services offered by the site; (ii) I accept
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 6/23
the processing of my personal data for the purpose of sending advertising communications
and for the commercial purposes set forth in Article 2 of the Privacy Policy; and (iii)
I consent to the disclosure of my personal data to third parties on our list of
sponsors, as specified in Article 2 of the Privacy Policy.
LEGAL BASIS
I
Jurisdiction
In accordance with the powers granted to each supervisory authority by Article 58.2 of the GDPR
and in accordance with the provisions of Article 114.1.b) of the LGTel, and as
provisions of Articles 47, 48.1, 64.2, and 68.1 of the LOPDGDD, the Presidency of the AEPD has jurisdiction to
resolve this proceeding.
Likewise, Article 63.2 of the LOPDGDD provides that: “Proceedings
handled by the Spanish Data Protection Agency shall be governed by the provisions
of Regulation (EU) 2016/679, this Organic Law, the
adopted to implement it, and, to the extent they do not contradict them, on a
subsidiary basis, by the general rules on administrative procedures.”
Finally, Transitional Provision 4, “Procedures Regarding the Powers Granted to
the Spanish Data Protection Agency by Other Laws,” establishes that: “The
provisions of Title VIII and its implementing regulations shall apply to the
proceedings that the Spanish Data Protection Agency may have to conduct
in the exercise of the powers conferred upon it by other laws.”
II
Summary of the Facts
In the present case, the complainant states that on November 18, 2024, at
1:24 p.m., he received a telemarketing call from the number ***PHONE.1,
made by an agent identified as “B.B.B.” on behalf of “Mas Sol,” who
addressed him by name and began asking questions about his type of residence.
He notes that, when he asked whether they had checked the Robinson List beforehand, the
caller responded that they were under no obligation to perform such a check since
the call was based on a “database,” and adds that, when he asked about the source of
his personal data, the call was unilaterally terminated.
He explains that, after contacting the enterprise’s customer service to
find out the source of his data, he was told that the data had been obtained
was the responsibility of the sales department and that the reason might be the acceptance of
cookies—a claim he considers incorrect since he had never accessed the
website.
Along with his written statement, he provides documentation consisting of a screenshot of the
calls from the complainant’s mobile device, which shows an incoming call on
November 18, 2024, at 1:24 p.m. lasting 46 seconds, as well as an
official certificate from the Robinson List confirming his active registration since March 9,
March 2024 para the telephone numbers ***TELÉFONO.2 and ***TELÉFONO.3.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 7/23
For its part, the respondent submitted a written response to the
notification of proceedings in which it states, in summary, that it makes sales calls and that the
data used in its campaigns originate from the contractual acquisition of a
database from an external enterprise specializing in advertising and marketing
services for enterprises, identified as ***ENTERPRISE.1 or ***ENTERPRISE.2, which
guarantees that the databases are legally compliant, that the data was
collected in accordance with applicable regulations, and that there is proof of the
data subject’s consent to the processing, transfer, and sending of
marketing communications.
It states that, after requesting proof of consent from the provider, the provider submitted
information indicating that the complainant had filled out a form on June 30, 2020,
at 9:17 p.m. on the website ***WEB.1, from the IP address (...), having
checked boxes regarding data processing, direct marketing, and third-party
marketing. It notes that it does not conduct any additional verification of the validity of the
consent, but merely accepts the information provided by the provider.
It also attaches documentation consisting of a generic form for
subscribing to a commercial newsletter—with no data filled in and no reference to the
complainant—and a letter from ***ENTERPRISE.3 that includes a table with data
attributed to the complainant and which asserts that the complainant had given consent on the
aforementioned website for marketing purposes and for the transfer of data to third parties for marketing.
III
Response to the Allegations in the Order to Proceed
First. – Regarding the proof of consent and the evidentiary validity of the
certificate
The complaint invokes the dismissal order issued in case
EXP202400904 as a decisive precedent, arguing that the assessment
made in that case regarding the evidentiary sufficiency of the
data collection certificate would preclude a different assessment in the present proceedings,
pursuant to the principles of legal certainty, legitimate expectations, and the
doctrine of estoppel. Furthermore, it argues that the requirement to unequivocally
link the technical record submitted to the claimant’s identity as a natural person would amount to
a reversal of the burden of proof and the imposition of a verification not required
by the regulations.
This argument cannot be upheld.
This is because the application of the principles of equality, legal certainty, and legitimate
expectations requires the existence of a substantial identity between the cases
being compared, which is not limited to subjective or objective identity, but necessarily
extends to factual and evidentiary identity. The doctrine of one’s own acts does not
support the claim to obtain an identical result in proceedings in which
different bodies of evidence are at issue, nor does it limit the Administration’s authority to
assess, in each specific case, the facts that have actually been established, in particular
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 8/23
when previous decisions are adopted within the framework of prior proceedings and
on the basis of a preliminary assessment.
In this regard, Article 65 of the LOPDGDD governs the acceptance for processing of
complaints and preliminary investigative proceedings, establishing that,
prior to the initiation of disciplinary proceedings, the Spanish Data Protection Agency
Data Protection Agency may conduct investigations to determine whether there are
grounds justifying the initiation of disciplinary proceedings, and may decide,
in light of such investigations, either to dismiss the case or to accept the
complaint and continue the proceedings. In particular, the decision to
dismiss the case issued in file EXP202400904 expressly states that it is not
appropriate to initiate disciplinary proceedings since the
complaint has been addressed and that the processing of the complaint in accordance with the provisions of
Article 65.4 of the LOPDGDD has led to the resolution of the issues
raised. Now, the aforementioned Article 65.4 provides that “If, as a result of
such referral proceedings, the controller or processor
demonstrates that it has taken measures to comply with applicable regulations, the
Spanish Data Protection Agency may refuse to process the complaint,”
which is considered applicable in the aforementioned case, albeit with the caveat that all of this
“is without prejudice to the Agency’s ability, by exercising the investigative and corrective powers
it holds, may carry out actions relating to the data processing referred to
in the complaint.”
From this perspective, the argument that the submission of a certificate of
traceability for the lead—which was taken into consideration in deciding to close the
proceedings in a previous case—would automatically preclude the existence of
reasonable grounds in the present case, is not consistent with the meaning and scope
of Article 65 of the LOPDGDD. The provision does not attribute to the submission of a
specific document an automatic effect of precluding the initiation of
disciplinary proceedings, nor does it prevent the Agency from assessing the need to determine
administrative liability within the framework of disciplinary proceedings.
Furthermore, the fact that the call was made has been substantiated by a record of the
mobile device’s call history and an audio recording, in which the caller
identifies himself as an agent acting on behalf of the entity against which the complaint was filed.
It is also established that the entity MÁS SOL conducts
marketing campaigns via telephone calls and that it obtains the personal data
used in such campaigns through an external provider. Liability
for the processing of personal data is not shifted by the
fact that the data was obtained by a third party; it is incumbent upon the
respondent entity, in its capacity as the controller, to demonstrate the
existence of a valid legal basis that legitimizes the processing carried out.
With regard to the consent invoked, the respondent entity provides
documentation submitted by its external provider consisting of an alleged record
made on June 30, 2020, on the website ***WEB.1, indicating an
IP address, a specific date and time, and a reference to certain consent checkboxes
that were allegedly checked. However, this documentation does not
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 9/23
proves that the complainant provided valid, free, informed,
and unambiguous consent to receive commercial communications.
There is no evidence that the complainant personally completed the registration or that the
personal data was entered by him, nor is there any technical evidence that
unequivocally links the indicated IP address to the
complainant. Nor is there any evidence demonstrating that the complainant’s phone number
was entered by him when filling out the form. The generic
form provided is blank, and the respondent has not provided the privacy policy
in effect at the time the registration allegedly took place, which
makes it impossible to objectively determine the specific purposes for which
and the third parties to whom the data would have been disclosed.
This conclusion does not stem from requiring the respondent to adopt
enhanced or disproportionate verification mechanisms not provided for in the applicable regulations,
but rather from the finding that the evidence provided does not meet the
minimum threshold necessary to demonstrate that consent was in fact
given by the data subject. In accordance with the principle of proactive accountability
established in Article 5(2) of the GDPR, the burden of proving the existence of
valid consent rests entirely with the controller, and
the obligation to demonstrate the absence of the
alleged consent. This is expressly set forth in Article 7 of the GDPR,
, which requires the controller to have adequate safeguards in place to
demonstrate the existence of consent, by stipulating that “Where processing
is based on the data subject’s consent, the controller must be able to
demonstrate that the data subject consented to the processing of their personal data.”
It should also be noted that the defendant itself acknowledges that it does not verify the
validity of the consent provided by its external vendor and that it merely accepts
the files received—a course of action incompatible with the data controller’s
processing to demonstrate the existence of a valid legal basis, in
compliance with the requirements of Article 66.1.b) of the LGTel.
In summary, the argument put forward by the respondent regarding proof
consent and the alleged existence of a binding precedent must be
entirely dismissed, as the existence of valid consent in accordance with the requirements of Article 4.11 of the GDPR has not been established...
Second. – Joint response to points II) and III) of the allegations: regarding
due diligence in the selection of the provider and the alleged exclusive attribution of
liability to the provider for data collection.
The respondent maintains, in essence, that it has acted with due diligence in
the selection of its data providers (***ENTERPRISE.2 / ***ENTERPRISE.3),
relying on the existence of a contract containing warranty clauses and on
certifications regarding privacy policies; and, accordingly, asserts that
any potential irregularity in data collection should be attributed exclusively to the
supplier, as the latter holds technical control over the form and the verification
mechanisms, invoking an alleged legitimate expectation regarding the traceability provided.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 10/23
These arguments cannot be upheld.
Pursuant to Article 4.7 of the GDPR, the controller is the legal entity
that determines the purposes and means of the processing. In the present case, the entity
is the controller, as it decided on the specific purpose of the processing—the
conduct of commercial call campaigns to promote
its own products or services—and determined the essential means for its
execution, including the integration of the data into its system and the use of an
automated dialing platform. The fact that the data comes from an
external provider does not alter this conclusion: the provider merely supplies
contacts, while the decision to use that data in a specific campaign,
at a specific time, and for its own benefit rests exclusively with the
respondent, which assumes the legal status of data controller vis-à-vis the
data subjects and the supervisory authority.
In this context, the existence of a commercial contract with warranty clauses and the
provision of certifications regarding privacy policies are not sufficient to
exclude the liability of the controller, who must verify that
the procedure used to obtain consent complies with the
GDPR. Article 5(2) of the GDPR expressly states that the controller shall be responsible for compliance with the principles of processing and must be able to demonstrate such compliance (accountability), which constitutes a specific and direct obligation that cannot be transferred to a third party merely by entering into a contract.
This conclusion is reinforced by the provisions of Guidelines 5/2020 on
consent, whose points 105 through 108 emphasize that, when processing is based
on consent, the controller must be able to demonstrate that the data subject
for the processing operation (Recital 42), and may choose methods
of verification tailored to its operations, while retaining the obligation to
provide sufficient evidence of how and when consent was obtained, as well as
the information provided to the data subject at that time. The Guidelines further specify
that the obligation to demonstrate consent does not necessarily imply
excessive additional data processing, but it does require having
sufficient evidence to link the consent to the processing and to
the specific data subject.
Applying these requirements to the present case, the due diligence required of the data controller
is not limited to incorporating generic safeguard clauses or accepting
documentation issued by the provider as exclusive proof of lawfulness, but rather
requires that, in each specific case, the data controller be able to demonstrate that the data
used to make the call were obtained on a valid legal basis and
that the consent invoked meets the conditions of Article 4.11 of the GDPR.
However, in the present case, the documentation provided by the
respondent—which originated from the provider—does not sufficiently demonstrate that
the complainant provided valid consent, nor that the complainant was effectively informed
at the time of the alleged collection of consent to obtain
specific and informed consent, nor, in general, that the workflow used met the
relevant criteria for valid consent under the terms set forth.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 11/23
In particular, the respondent bases its standing on an alleged registration on
pocketcoupons.net dated 06/30/2020, referencing an IP address and checkboxes
that were supposedly checked.
However, this documentation does not prove that the complainant personally
carried out said registration or that the data was entered by him, nor does it provide technical evidence
that unequivocally links the IP address to him. Furthermore, the
respondent has not provided the privacy policy in effect at the time of
the data was collected, limiting itself to providing the policy effective as of December 18,
2025, which cannot serve to substantiate the specific information that, if any,
was provided to the data subject, much less that specific consent
had been granted. The respondent has also stated that it does not verify the validity of the
consent submitted by the provider and that it merely accepts the filing systems
received, which is incompatible with the data controller’s obligation to demonstrate,
in a specific case, that the data subject did in fact grant consent and that
he or she was informed at the time the data was collected, in accordance with paragraphs 105 through 108 of
Guidelines 5/2020.
Furthermore, the attempt to shift liability “to the source” on the grounds that
the supplier exercises technical control over the form cannot succeed either. The
administrative charge is not based on a hypothetical “hidden defect” on the part of the provider,
but rather on the respondent entity’s use of personal data to make a
marketing call without having established a valid legal basis for
that specific processing. The provider’s potential liability for its own
activity does not exclude the liability of the entity against which the complaint is filed for the processing it
chooses to carry out, in its capacity as the controller.
Finally, the argument regarding legitimate expectations or the appearance of lawfulness
derived from the provider’s documentation does not undermine the foregoing. Accountability
requires that the data controller be able to demonstrate the legal basis and valid consent in each specific case, and this requirement
becomes particularly relevant when, as in the present case,
there is a prior, express objection documented by the registration of the
affected number in the Robinson List Service, which required the utmost
diligence in verifying that, despite such objection, there was specific consent
that exempted the data controller from consulting that database pursuant to Art. 23.4.
LOPDGDD, a circumstance that does not exist here.
Consequently, the arguments set forth in points II) and
III) must be dismissed, as the respondent has failed to demonstrate the existence of consent
from the data subject for the processing carried out, and the mere existence of
contractual safeguards or the actions of the provider do not allow the defendant to
shift its responsibility for the processing consisting of making the sales call.
Third. – Regarding the alleged absence of a breach of the duty to provide information
set forth in Article 14 of the GDPR
The respondent contends that it was unable to comply with the duty to provide information set forth in
Article 14 of the GDPR as a result of the interruption of the telephone call,
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 12/23
arguing that attributing such a violation would violate the principle of presumption of
innocence and would amount to imposing an impossible obligation of result on it.
This argument cannot be upheld.
The duty to provide information set forth in Article 14 of the GDPR constitutes an
autonomous, positive, and enforceable legal obligation on the part of the controller when personal data has not been obtained directly from the data subject. Compliance with this obligation is not
optional nor is it contingent upon the data subject’s initiative; it is the responsibility of the
controller to ensure and demonstrate that such information has been
effectively provided, in accordance with the principle of accountability
enshrined in Article 5(2) of the GDPR.
In the present case, a review of the telephone call recording reveals
that the caller initially identifies themselves
by stating: “I’m calling from Mas Sol, the solar panel enterprise.” Next, in response to
the complainant’s explicit question regarding prior verification of his inclusion
on the Robinson List, the caller responds verbatim: “I don’t have to check
any of that, sir; I work from a database.” Subsequently, when
the complainant requests clarification regarding the origin of said database, the response
is limited to a generic and imprecise reference, without identifying its
source or providing any relevant additional information.
From the verbatim content of the recording, it is clear that the respondent entity omitted the
legally required information regarding the specific origin of the data subject’s
personal data, limiting itself to an unspecified reference to the existence of “a
database.” Such a reference is manifestly insufficient to fulfill the duty
to provide information imposed by Article 14 of the GDPR, as it does not allow the data subject
to know the source of their data or the context in which it was collected.
Furthermore, during the call, no information was provided regarding the full identity
of the controller, the legal basis justifying the use of the
personal data, or the rights to which the data subject is entitled under
data protection regulations. This omission deprives the complainant of the real and effective
opportunity to exercise his rights and constitutes a substantive nullification of the right to
information, amounting to a full and independent violation of Article 14 of the
GDPR.
Contrary to the respondent’s complaints, the recording does not show any interruption
that would have made it materially impossible to fulfill the duty to provide information. On the
contrary, it is on record that there was sufficient dialogue during which the complainant
directly raised questions regarding the origin and legitimacy of the processing of
his data, without the respondent entity providing the minimum required information
or offering an immediate alternative channel to access it.
The duration of the call or its subsequent termination does not exempt the controller
from complying with this obligation, nor does it allow the lack of
information to be attributed to the data subject’s conduct. The duty to provide information should have been
fulfilled during the course of the initial communication itself, at least in its
essential elements, but this did not occur.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 13/23
Nor has the existence of alternative or
complementary mechanisms been proven that would have allowed the complainant to subsequently access the
information required by Article 14 of the GDPR. The subsequent submission of
informative guidelines or internal protocols does not prove that these were actually
used in the specific call in question that is the subject of this case, nor that the
legally required information was provided by other means within the time frame
established by the regulation.
The respondent also argues that the allegation of this violation would infringe upon
its right to a fair hearing, as this issue was not expressly raised during
the preliminary proceedings phase.
This argument cannot be accepted either.
The subject matter of the proceedings—the making of a telemarketing call and the lawfulness of the
processing of the personal data used—was fully known to the
respondent from the outset of the proceedings. The duty to provide information set forth
in Article 14 of the GDPR is directly linked to the lawfulness of the
processing when the data has not been obtained from the data subject, and therefore
any failure to comply with this duty does not constitute a surprise element nor is it outside the scope of
the investigation.
The referral proceedings governed by Article 65 of the LOPDGDD are intended
to determine the existence of grounds justifying the initiation of
disciplinary proceedings, without any obligation to specify at this
preliminary stage all possible legal violations that may be identified
in light of the body of evidence included in the case file.
In this context, the absence of a specific requirement relating to Article 14 of the
GDPR does not give rise to any substantive lack of defense, especially since the respondent entity
has had access to the complaint and an effective opportunity to present its arguments and
submit the documentation it deemed relevant in the disciplinary proceedings.
In short, in light of the literal content of the call recording and the body
of evidence in the case file, it must be concluded that the respondent
failed to comply with the duty to provide information imposed by Article 14 of the GDPR, without
any violation of its right of defense or any grounds that would exclude or mitigate
its liability.
For all the foregoing reasons, the arguments raised
by the respondent must be dismissed in their entirety, and the disciplinary proceedings must continue, as
the existence of valid consent for making the
marketing call has not been established, nor has compliance with the obligations required by Article
66.1.b) of the LGTel, nor of the duty to provide information imposed by Article 14 of the GDPR,
which applies when personal data has not been obtained directly from the
data subject.
III
Breach of Article 66 of the LGTel
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 14/23
Making unsolicited calls for commercial communication purposes, without
prior consent or without another legal basis for doing so, may
constitute a violation of the provisions of Article 66 of the LGTel, regarding the
“Right to data protection and privacy in relation to
unsolicited communications, traffic and location data, and
subscriber directories,” as paragraph 1.b) provides as follows:
“1. With regard to data protection and privacy in relation
to unsolicited communications, end users of publicly available
interpersonal communications services based on
numbering shall have the following rights: (…)
b) not to receive unsolicited calls for commercial communication purposes,
unless the User has given prior consent to receive this type
of commercial communications, or unless the communication is based on
another legal basis provided for in Article 6(1) of Regulation
(EU) 2016/679 on the processing of personal data.”
Furthermore, Article 66 concludes by stipulating the following in its fifth paragraph:
“5. The provisions of this article are without prejudice to the application of
Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27,
April 2016, and Organic Law 3/2018 of December 5 on Data Protection
and the Guarantee of Digital Rights, and, in particular, the
application of the concept of consent set forth therein.”
Article 66.1.b) of the LGTel regulates the protection of users against
unsolicited communications, establishing as an essential requirement the existence of
a valid legal basis, such as the prior consent of the data subject, or
any other basis set forth in Article 6.1 of the GDPR.
Its purpose is to protect users from intrusive commercial practices that do not
respect their privacy and control over commercial communications. By requiring
prior consent or a valid legal basis, this provision ensures that
enterprises respect users’ rights, thereby preventing
unsolicited commercial communications. In this way, it reinforces the protection framework established
by the GDPR, ensuring a balance between legitimate commercial activities and
the fundamental rights of Users.
The defendant bases the lawfulness of the commercial call on the consent of the
complainant. However, Article 4.11 of the GDPR defines the consent of the
data subject as: any freely given, specific, informed, and
unambiguous indication of the data subject’s wishes by which he or she, either by a statement or by a
clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
Furthermore, Guidelines 5/2020 on consent within the meaning of the GDPR,
provide, in paragraphs 105 through 108, as follows:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 15/23
“105. Recital 42 states that: ‘Where processing is carried out
with the consent of the data subject, the controller
must be able to demonstrate that the data subject has given his or her consent
to the processing operation.’
106. Controllers are free to develop methods
that enable compliance with this provision, tailored to their daily operations. At the
same time, the obligation to demonstrate that a controller
has obtained valid consent must not, in and of itself, result in
excessive additional data processing. This means that data controllers
should have sufficient data to demonstrate a link to the processing (to
show that consent was obtained), but should not collect more
information than is necessary.
107. It is up to the data controller to demonstrate that it obtained
valid consent from the data subject. The GDPR does not prescribe exactly how this
should be done. However, the controller must be able to demonstrate that, in a
specific case, a data subject has given consent. The obligation to
demonstrate consent will exist for as long as the processing activity
involving the data in question continues. Once that activity has ended, evidence of
consent must not be stored beyond what is strictly necessary
to comply with a legal obligation or for the establishment, exercise, or defense
of complaints, in accordance with Article 17(3)(b) and (e).
108. For example, the data controller must maintain a record of the
consent statements received, so that it can demonstrate
how consent was obtained and when such consent was obtained, and
must also demonstrate what information was provided to the data subject at the
time. The controller must also be able to demonstrate that the
data subject was informed and that the controller’s workflow met all the
relevant criteria for valid consent.”
In the present case, it has been established that the entity MÁS SOL conducts
marketing campaigns for its products and services via telephone calls and
receives and uses the information provided by an external vendor.
MÁS SOL’s liability is not negated by the fact that the data
used by MÁS SOL was obtained by a third party.
In this case, MÁS SOL obtained the complainant’s data from its external provider
and made a marketing call to him on November 18, 2024.
Regarding the complainant’s consent, the respondent provides various
documents submitted by the aforementioned third-party provider, consisting of an alleged registration
on the website pocketcoupons.net dated June 30, 2020, via an IP address
IP address, a time, and a reference to consent checkboxes that were allegedly
checked.
However, this documentation does not establish that the complainant provided
valid, free, informed, and unambiguous consent to receive communications
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 16/23
, in accordance with Article 4.11 of the GDPR and Guidelines 5/2020 on
consent, which require that the data controller be able to demonstrate, in each
specific case, that the declaration of consent was given by the data subject.
Consequently, the controller of commercial communications—in this case,
MÁS SOL—must be able to demonstrate that it has obtained the authorization or
consent of the data subject to make commercial calls and must also
show the mechanisms used to obtain it.
The regulation does not establish a specific mechanism for proving that
consent has been obtained, but it does require that the data controller be able to demonstrate that the
User has requested or expressly authorized the commercial calls, and is
therefore free to implement the method and record-keeping system that best suits the
organization’s processes; however, it does require that the party responsible demonstrate
who, when, how, and for what purpose the sales calls were authorized, as well as the
information provided to the User at the time consent was
obtained.
In the present case, it has not been proven that the complainant personally made the
registration, nor that the data was entered by him. There is no evidence
that unequivocally links the IP address to the complainant. No technical
evidence has been provided to demonstrate that the complainant’s phone number (which appears
on the Robinson List) was entered by him when filling out the form.
The form that the claimant allegedly filled out contains checkboxes stating (i)
I have read and accept the site’s terms and conditions and the Privacy Policy, and
I authorize the processing of my personal data for the services offered by the site
(ii) I consent to the processing of my personal data for the sending of
advertising and for the commercial purposes set forth in Article 2 of the
Privacy Policy; and (iii) I consent to my personal data being disclosed to third parties on
our list of sponsors, as specified in Article 2 of the
Privacy Policy. However, the entity against which the complaint was filed does not provide the Privacy Policy in effect at
the time the complainant allegedly entered the data; therefore, it is not
even known what specific purposes the complainant would have consented to or to which
third parties the complainant would have authorized the disclosure of their data.
Furthermore, the respondent acknowledges that it does not verify the validity of the consent
submitted by the Provider and that it merely accepts the files received, which is
incompatible with the data controller’s obligation to demonstrate consent,
in accordance with points 105 through 108 of Guidelines 5/2020.
Consequently, it is considered that the respondent made an
unsolicited commercial call without a valid legal basis, thereby violating
Article 66.1.b) of the LGTel, which recognizes Users’ right not to receive
unsolicited calls for commercial communication purposes, unless there is
prior consent or the legal bases set forth in Article 6.1 of the GDPR apply.
IV
Classification of the violation of Article 66 of the LGTel and characterization of the violation for
purposes of the statute of limitations
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 17/23
The conduct described in the preceding points—making a commercial call
without the data subject’s consent or another legal basis that would permit it—
constitutes a violation of Article 66.1.b) of the LGTel, classified as “serious” pursuant to
Article 107.30 of the aforementioned law:
“30. The violation of the rights of consumers and end users,
as established in Title III and its implementing regulations, including the
rights to number storage, roaming within the European Union, and
international roaming, regarding regulated intra-Community communications and
open access to the Internet.”
For its part, article 113 of the LGTel states that:
“Very serious violations shall be subject to a three-year statute of limitations, serious violations to a two-year statute of limitations, and
minor violations to a one-year statute of limitations.
The statute of limitations for violations shall begin to run from the day on
which they were committed. The statute of limitations shall be interrupted by the initiation, with the knowledge
of the data subject, of the disciplinary proceedings. The statute of limitations period shall resume
if the disciplinary proceedings are suspended for more than one month for
reasons not attributable to the alleged offender. (…)”
V
Penalty for violation of Article 66 of the LGTEL.
In accordance with the provisions of Article 109.1.c) of the LGTEl, this violation
may be punishable by a fine of up to 2 million euros.
Meanwhile, Article 110.1 of the aforementioned law establishes the criteria for
determining the amount of the penalty:
“a) the severity of previous violations committed by the party being
penalized;
b) the damage caused, such as the creation of interference to authorized third parties
, and its remediation;
c) voluntary compliance with any precautionary measures that may be
imposed during the penalty proceedings;
d) refusal or obstruction of access to facilities or of providing the
required information or documentation;
e) cessation of the infringing activity, either prior to or during the processing of the
penalty proceedings;
f) the impact on protected legal interests relating to the use of the public
radio spectrum, public order, public safety, and national security, or
Users’ rights;
g) active and effective cooperation with the competent authority in detecting
or proving the infringing activity.”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 18/23
In accordance with these criteria, it is deemed appropriate to impose on the respondent entity
an administrative penalty of 5,000 euros (five thousand euros) for the violation of
Article 66.1.b) of the LGTel, as defined in Article 107.30 of the aforementioned law.
VI
Failure to comply with Article 14 of the GDPR
Article 14 of the GDPR, regarding “Information to be provided where personal data
have not been obtained from the data subject,” states that:
“1. Where personal data have not been obtained from the data subject, the
controller shall provide the data subject with the following information:
a) the identity and contact details of the controller and, where applicable, of its
representative;
b) the contact details of the data protection officer, where applicable;
c) the purposes of the processing for which the personal data are intended, as well as the
legal basis for the processing;
d) the categories of data being processed;
e) the recipients or categories of recipients of the personal data,
where applicable;
f) where applicable, the controller’s intention to transfer personal data to a
recipient in a third country or to an international organisation, and the existence or
absence of an adequacy decision by the Commission, or, in the case of
transfers referred to in Articles 46 or 47 or Article 49(1), second paragraph,
a reference to the appropriate or suitable safeguards and the means
para obtain a copy of them or the location where they have been made
available.
2. In addition to the information referred to in paragraph 1, the controller
shall provide the data subject with the following information necessary to
ensure fair and transparent processing with respect to the data subject:
a) the period for which the personal data will be stored or, where that
not possible, the criteria used to determine that period;
b) where the processing is based on Article 6(1)(f), the
legitimate interests of the controller or of a third party;
c) the existence of the right to request from the controller access
to personal data concerning the data subject, and to have such data rectified or erased, or
to impose a restriction on its processing, and to object to the processing, as well as to
data portability;
d) where the processing is based on Article 6(1)(a) or
Article 9(2)(a), the existence of the right to withdraw
consent at any time, without affecting the lawfulness of the
processing based on consent prior to its withdrawal;
e) the right to lodge a complaint with a supervisory authority;
f) the source from which the personal data are derived and, where applicable, whether they are derived
from publicly available sources;
g) the existence of automated decision-making, including profiling,
as referred to in Article 22(1) and (4), and, at least in such
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 19/23
cases, meaningful information regarding the logic applied, as well as the
significance and the anticipated consequences of such processing for the
data subject.”
3. The controller shall provide the information specified in
paragraphs 1 and 2:
a) within a reasonable period of time after the personal data are collected, and
no later than one month, taking into account the specific circumstances
in which such data are processed;
b) if the personal data are to be used for communication with the
data subject, no later than the time of the first communication to said
data subject, or c) if the personal data is intended to be disclosed to another recipient, no later than
the time the personal data is first disclosed
(…)”.
Article 14 of the GDPR stipulates that when the data subject’s personal data has not
been collected directly from the data subject, the controller must
provide certain essential information to ensure transparency.
This includes the identity and contact information of the controller,
the purpose of the processing, the legal basis, the categories of data
processed, the source of the data, and the data subject rights, among
other aspects.
This article requires that this information be provided within a
reasonable timeframe, no later than one month and upon first contact with the
data subject, or before the data is disclosed to a third party. Its
primary objective is to ensure that data subjects receive the necessary information
when their personal data is obtained from third parties. This requirement aims to prevent
data subjects from being placed in a vulnerable position due to a lack of knowledge regarding how, by
whom, and for what purpose their data is being used.
Article 14 ensures that the data subject rights are not undermined by
a lack of information, establishing that the controller must act
proactively to provide all relevant information in a timely and
appropriate manner.
In the present case, the respondent obtained the complainant’s data from
***ENTERPRISE.1 / ***ENTERPRISE.2 without complying with the provisions of Article 14 of the
GDPR, as it failed to provide the complainant with the information required by that
article.
The absence of this information not only constitutes a formal violation but also
substantially affects the complainant’s rights by preventing them from exercising
their rights regarding personal data protection with full knowledge of the facts.
Therefore, by failing to provide the information required by Article 14 of the GDPR within the
established time limit, and by failing to ensure that the data subject was aware of the details of the processing
of their personal data, the respondent has breached the obligations imposed
by that article.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 20/23
Based on the evidence currently available at the time of
the resolution of the sanctioning proceeding, it is considered that the facts set forth
violate the provisions of Article 14 of the GDPR
VII
Classification of the violation of Article 14 of the GDPR and assessment for purposes of
the statute of limitations
Article 83(5)(b) provides as follows:
“5. Infringements of the following provisions shall be subject, in accordance
with paragraph 2, to administrative fines of up to 20,000,000 EUR or,
in the case of an enterprise, an amount equivalent to 4%
of the total annual global turnover for the preceding fiscal year,
whichever is higher: (…) b) the data subject rights under Articles 12 through 22;”
In this regard, article 71 of the LOPDGDD establishes that “The following constitute
infractions: the acts and conduct referred to in paragraphs 4, 5, and 6 of
Article 83 of the GDPR, as well as those that are contrary to this Organic Law.”
For the purposes of the statute of limitations, Article 72.1.h) of the LOPDGDD states:
“Article 72. Infractions considered very serious.
1. Pursuant to Article 83(5) of Regulation (EU)
2016/679, the following are considered very serious and shall be subject to a three-year statute of limitations:
infractions that constitute a substantial violation of the articles
mentioned therein and, in particular, the following: (…)
h) Failure to fulfill the duty to inform the data subject about the processing of their
personal data in accordance with the provisions of Articles 13 and 14 of
Regulation (EU) 2016/679 and Article 12 of this Organic Law.”
VIII
Penalty for Violation of Article 14 of the GDPR.
In order to determine the administrative fine to be imposed, the
provisions of Articles 83(1) and 83(2) of the GDPR must be observed, which state:
“1. Each supervisory authority shall ensure that the imposition of
under this article for infringements of
this Regulation referred to in paragraphs 4, 9, and 6 are, in each individual case,
effective, proportionate, and dissuasive.
2. Administrative fines shall be imposed, depending on the circumstances
of each individual case, in addition to or in lieu of the measures
set forth in Article 58(2)(a) through (h) and (j). When deciding on the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 21/23
imposition of an administrative fine and its amount in each individual case, the following shall
be duly taken into account:
a) the nature, gravity, and duration of the violation, taking into account the
nature, scope, or purpose of the processing operation in question,
as well as the number of data subjects affected and the extent of the
damages they have suffered;
b) whether the infringement was intentional or due to negligence;
c) any measures taken by the controller or processor
to mitigate the damages suffered by the data subjects;
d) the degree of responsibility of the controller or processor,
taking into account the technical or organizational measures they have
implemented pursuant to Articles 25 and 32;
e) any previous infringements committed by the controller or processor;
data controller;
f) the degree of cooperation with the supervisory authority to
remedy the breach and mitigate its potential adverse effects;
g) the categories of data affected by the breach;
(h) the manner in which the supervisory authority became aware of the breach, in
particular whether the controller or processor notified the supervisory authority of the breach and, if so,
to what extent;
(i) where measures referred to in Article 58(2) have been
previously ordered against the controller or processor in question
in relation to the same matter, compliance with those measures;
j) adherence to codes of conduct pursuant to Article 40 or to
certification mechanisms approved pursuant to Article 42; and
k) any other aggravating or mitigating factors applicable to the circumstances of the
case, such as financial gains obtained or losses avoided, directly
or indirectly, through the violation.”
For its part, article 76, “Penalties and Corrective Measures,” of the LOPDGDD
provides:
“1. The penalties provided for in paragraphs 4, 5, and 6 of Article 83 of
Regulation (EU) 2016/679 shall be applied taking into account the criteria for
proportionality set forth in paragraph 2 of that article.
2. In accordance with the provisions of Article 83(2)(k) of Regulation (EU)
2016/679, the following may also be taken into account:
a) The ongoing nature of the violation.
b) The connection between the infringer’s activities and the processing
of personal data.
c) The profits obtained as a result of the commission of the violation.
d) The possibility that the data subject’s conduct may have contributed to the
commission of the violation.
e) The existence of a merger by absorption occurring after the commission
of the violation, which cannot be attributed to the absorbing entity.
f) The impact on the rights of minors.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 22/23
g) Having a data protection officer,
where not mandatory.
h) The data controller or processor’s
voluntary submission to alternative dispute resolution mechanisms in cases
where disputes arise between them and the data subject.”
In the present case, recital 1 states that the seriousness of the potential violations and
the consequences their commission has on those affected warrant the imposition of a fine, in addition to the adoption of measures, if appropriate.
The fine imposed must be, in each individual case, effective, proportionate,
and dissuasive, in accordance with the provisions of Article 83(1) of the GDPR.
A balancing of the circumstances set forth in Article 83(2) of the GDPR and Article 76(2) of
the LOPDGDD, allows for the imposition of an administrative penalty of 5,000 euros (five thousand
euros) for the violation committed by breaching the provisions of Article 14
of the GDPR, as defined in Article 83.5.b of said regulation.
Therefore, in accordance with applicable law and having assessed the violations whose
existence has been proven,
the Presidency of the Spanish Data Protection Agency RESOLVES:
FIRST: TO IMPOSE on the entity MÁS SOL ENERGÍA 15, S.L., with Tax ID No. B90346370,
for the following violations, the fines indicated below:
- Violation of Article 66.1.b) of the LGTel, as defined in Article 107.30 of the
aforementioned regulation, a fine of 5,000 euros (five thousand euros).
- Violation of Article 14 of the GDPR, as defined in Article 83(5)(b) of the aforementioned
Regulation, a fine of 5,000 euros (five thousand euros).
SECOND: NOTIFY MÁS SOL ENERGÍA 15, S.L. of this decision.
THIRD: This decision shall become enforceable once the deadline for filing the
optional appeal for reconsideration has expired (one month from the day following the
notification of this decision) without the data subject having exercised this right.
The party subject to the penalty is hereby notified that they must pay the imposed penalty once
this decision becomes enforceable, in accordance with the provisions of Art.
98.1.b) of Law 39/2015, of October 1, on the Common Administrative Procedure of
Public Administrations (hereinafter LPACAP), within the voluntary payment period
set forth in Article 68 of the General Collection Regulation, approved by Royal
Decree 939/2005, dated July 29, in conjunction with Art. 62 of Law 58/2003, dated December 17,
by making a payment and indicating the taxpayer identification number (NIF) of the party subject to the penalty and the
procedure number appearing at the top of this document, into the
restricted account No. IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code:
CAIXESBBXXX), opened in the name of the Spanish Data Protection Agency at
the bank CAIXABANK, S.A..
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 23/23
Otherwise, collection will proceed through enforcement proceedings. Upon receipt of the
notification and once it becomes enforceable, if the enforceability date falls between the
1st and 15th of each month, inclusive, the deadline for voluntary payment will be
until the 20th of the following month or the next business day thereafter; and if it falls between
the 16th and the last day of each month, both inclusive, the payment deadline will be until the 5th
of the second following month or the next business day thereafter.
In accordance with the provisions of Article 50 of the LOPDGDD, this
Resolution shall be made public. Publication shall take place once it has been notified to
the data subjects.
Against this resolution, which concludes the administrative proceedings pursuant to Article 48.6 of the
LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, the
data subjects may, at their discretion, file an appeal for reconsideration with the
Presidency of the Spanish Data Protection Agency within one month
from the day following notification of this resolution, or directly
file an administrative appeal with the Administrative Chamber of the
National Court, in accordance with the provisions of Article 25 and paragraph 5 of
the fourth additional provision of Law 29/1998, of July 13, regulating the
Administrative Jurisdiction, within two months from the
day following notification of this decision, pursuant to Article 46.1 of the aforementioned Law.
Finally, it is noted that, in accordance with the provisions of Article 90.3(a) of the LPACAP,
the final administrative decision may be suspended as a precautionary measure if the
data subject expresses their intention to file a contentious-administrative appeal.
If this is the case, the data subject must formally notify the Spanish Data Protection Agency of this fact by
submitting a written notice to the Spanish Data Protection Agency through
the Agency’s Electronic Registry [https://sedeaepd.gob.es/sede-electronicaweb/],
or through any of the other registries provided for in Art. 16.4 of the aforementioned Law
39/2015, of October 1. The data subject must also provide the Agency with the documentation
proving that the administrative appeal has been effectively filed. If the
Agency is not notified of the filing of the contentious-
administrative appeal within two months from the day following notification of
this decision, it will consider the precautionary suspension to have ended.
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es




