AN - SAN 3154/2026: Difference between revisions

From GDPRhub
Created page with "{{COURTdecisionBOX |Jurisdiction=Spain |Court-BG-Color= |Courtlogo=Courts_logo1.png |Court_Abbrevation=AN |Court_Original_Name=Audiciencia Nacional |Court_English_Name=National Court |Court_With_Country=AN (Spain) |Case_Number_Name=SAN 3154/2026 |ECLI=ECLI:ES:AN:2026:3154 |Original_Source_Name_1=Cendoj |Original_Source_Link_1=https://www.poderjudicial.es/search/AN/openDocument/f0c803f2dd5f80a0a0a8778d75e36f0d/20260729 |Original_Source_Language_1=Spanish; Castilian |O..."
 
No edit summary
Line 129: Line 129:
During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business.
During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business.


The DPA found that the information provided on the website was excessively generic and did not comply with [[Article 13 GDPR|Article 13 GDPR]]. It imposed a €5,000 fine and ordered the controller to bring its website into compliance.
The DPA found that the information provided on the website was excessively generic and did not comply with [[Article 13 GDPR]]. It imposed a €5,000 fine and ordered the controller to bring its website into compliance.


The DPA also concluded that the controller’s processing activities required the appointment of a DPO under [[Article 37 GDPR|Article 37(1)(b) GDPR]]. It imposed a further €20,000 fine and ordered the controller to appoint a DPO.
The DPA also concluded that the controller’s processing activities required the appointment of a DPO under [[Article 37 GDPR|Article 37(1)(b) GDPR]]. It imposed a further €20,000 fine and ordered the controller to appoint a DPO.


The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented the corrective measures.
The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented the corrective measures.
=== Holding ===
=== Holding ===
The High Court dismissed the appeal and upheld the total fine of €25,000.
The High Court dismissed the appeal and upheld the total fine of €25,000.


Regarding [[Article 13 GDPR|Article 13 GDPR]], the Court found that the controller’s privacy information was excessively generic and did not clearly explain the purposes, legal bases and relevant circumstances of the processing. It also held that the DPA was not limited to investigating only the exact issues identified in the initial complaint. The €5,000 fine was proportionate despite the controller’s subsequent corrective action.
Regarding [[Article 13 GDPR]], the Court found that the controller’s privacy information was excessively generic and did not clearly explain the purposes, legal bases and relevant circumstances of the processing. It also held that the DPA was not limited to investigating only the exact issues identified in the initial complaint. The €5,000 fine was proportionate despite the controller’s subsequent corrective action.


Regarding [[Article 37 GDPR|Article 37(1)(b) GDPR]], the Court held that the controller was required to appoint a DPO. Although its primary business was the provision of restaurant services, the processing of customer data was inseparable from its online ordering, marketing, loyalty and customer-management activities.
Regarding [[Article 37 GDPR|Article 37(1)(b) GDPR]], the Court held that the controller was required to appoint a DPO. Although its primary business was the provision of restaurant services, the processing of customer data was inseparable from its online ordering, marketing, loyalty and customer-management activities.


The processing also involved regular and systematic monitoring, as the controller continuously collected data such as customer preferences, browsing history, IP addresses, cookies and geolocation for commercial and operational purposes. Considering the number of data subjects, the volume and variety of data, the duration of the processing and its nationwide scope, the Court concluded that the processing was carried out on a large scale.
The processing also involved regular and systematic monitoring, as the controller continuously collected data such as customer preferences, browsing history, IP addresses, cookies and geolocation for commercial and operational purposes. Considering the number of data subjects, the volume and variety of data, the duration of the processing and its nationwide scope, the Court concluded that the processing was carried out on a large scale.
== Comment ==
== Comment ==
''Share your comments here!''
''Share your comments here!''

Revision as of 06:46, 3 August 2026

AN - SAN 3154/2026
Court: AN (Spain)
Jurisdiction: Spain
Relevant Law: Article 13 GDPR
Article 37(1)(b) GDPR
Article 58(2)(d) GDPR
Article 83 GDPR
Article 34 LOPDGDD
Article 73 LOPDGDD
Article 74 LOPDGDD
Decided: 16.07.2026
Published:
Parties: KFC Restaurants Spain, S.L.U.
AEPD
National Case Number/Name: SAN 3154/2026
European Case Law Identifier: ECLI:ES:AN:2026:3154
Appeal from:
Appeal to: Unknown
Original Language(s): Spanish; Castilian
Original Source: Cendoj (in Spanish; Castilian)
Initial Contributor: bms

The High Court upheld €25,000 in fines against KFC for providing insufficiently specific privacy information and failing to appoint a DPO despite carrying out large-scale, regular and systematic monitoring.

English Summary

Facts

In May 2021, a data subject lodged a complaint with the Spanish Data Protection Authority against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website.

The data subject claimed that the privacy information applicable to users in the EEA was not easily accessible, as the main privacy link led to a global policy. The data subject also alleged that users could not create an account without apparently accepting promotional communications, that the registration form did not correctly link to the privacy policy and that the controller had not appointed a data protection officer.

The complaint further identified deficiencies in the privacy information, including insufficient details about the identity of the controller, recipients, international transfers and retention periods.

During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business.

The DPA found that the information provided on the website was excessively generic and did not comply with Article 13 GDPR. It imposed a €5,000 fine and ordered the controller to bring its website into compliance.

The DPA also concluded that the controller’s processing activities required the appointment of a DPO under Article 37(1)(b) GDPR. It imposed a further €20,000 fine and ordered the controller to appoint a DPO.

The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented the corrective measures.

Holding

The High Court dismissed the appeal and upheld the total fine of €25,000.

Regarding Article 13 GDPR, the Court found that the controller’s privacy information was excessively generic and did not clearly explain the purposes, legal bases and relevant circumstances of the processing. It also held that the DPA was not limited to investigating only the exact issues identified in the initial complaint. The €5,000 fine was proportionate despite the controller’s subsequent corrective action.

Regarding Article 37(1)(b) GDPR, the Court held that the controller was required to appoint a DPO. Although its primary business was the provision of restaurant services, the processing of customer data was inseparable from its online ordering, marketing, loyalty and customer-management activities.

The processing also involved regular and systematic monitoring, as the controller continuously collected data such as customer preferences, browsing history, IP addresses, cookies and geolocation for commercial and operational purposes. Considering the number of data subjects, the volume and variety of data, the duration of the processing and its nationwide scope, the Court concluded that the processing was carried out on a large scale.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Spanish; Castilian original. Please refer to the Spanish; Castilian original for more details.

Case No.: SAN 3154/2026 - ECLI:ES:AN:2026:3154
Cendoj ID: 28079230012026100385
Court: National Court. Contentious-Administrative Chamber
Location: Madrid
Section: 1
Date: 07/16/2026
Appeal No.: 420/2023
Decision No.: 402/2026
Proceeding: Ordinary proceeding
Presiding Judge: AMALIA BASANTA RODRIGUEZ
Type of Decision: Judgement
NATIONAL COURT
ADMINISTRATIVE LITIGATION CHAMBER
1ST Section
MADRID
JUDGMENT: 00402 / 2026
PASEO DE LA CASTELLANA 14
Phone: 914007284
Emailelectrónico:audiencianacional.salacontencioso.s1@justicia.es
COMMON PROCESSING SERVICE
Team/User: RMG
Form: N40000 JUDGMENT FREE TEXT ART. 206.1.3 LEC
N.I.G.: 28079 23 3 2023 0005208
Procedure: PO ORDINARY PROCEDURE 0000420 / 2023
Re: THE DATA PROTECTION AGENCY
From: KFC RESTAURANTS SPAIN, S.L.
Lawyer
SOLICITOR: Mr./Ms. IGNACIO LOPEZ CHOCARRO
Against: THE SPANISH AGENCY FOR INSTITUTIONAL DATA PROTECTION
STATE LAWYER
JUDGMENT
HONORABLE PRESIDING JUDGE
FERNANDO LUIS RUIZ PIÑEIRO
HONORABLE JUSTICES
AMALIA BASANTA RODRÍGUEZ
LUIS HELMUTH MOYA MEYER
RICARDO FERNÁNDEZ CARBALLO-CALERO
PRESIDING JUDGE: MS. AMALIA BASANTA RODRÍGUEZ
1
CASE LAW
Madrid, July 16, 2026.
Having examined the administrative appeal filed with this Administrative Chamber of the
National Court, filed by Court Attorney Mr. IGNACIO LOPEZ CHOCARRO, on behalf of
and with representation for the entity “KFC RESTAURANTS SPAIN, S.L.U.,” against the Decision dated February 13,
2023 by the Director of the Spanish Data Protection Agency, dismissing the appeal for reconsideration
filed against another decision dated June 8, 2022, which imposed on said entity a fine of 5,000 E
for a violation of Article 13 of the GDPR in relation to Article 83(5)(b), classified as minor under Article 74(1)(a) of the
LOPDPGDD, and a second fine of 20,000 E for a violation of Article 37 of the GDPR, classified as serious
under Article 73 of the LOPDPGDD (PS/00140/2022).
And against the decision of the Director of the Spanish Data Protection Agency, dated June 23, 2023
—Case No. NUM000—, requiring KFC RESTAURANTS SPAIN, S.L. to demonstrate, within TEN BUSINESS DAYS
, demonstrate that it had adopted the appropriate corrective measures consisting of bringing the
website www.kfc.es <WWW.kfc.es/> to the provisions of Article 13 of the GDPR, as well as the appointment of
a data protection officer.
The defendant was the General State Administration, assisted and represented by the STATE LAWYER.
The amount in dispute was set at 25,000 euros.
The presiding judge of this Section was Ms. Amalia Basanta Rodríguez, who expresses the opinion of
the Chamber.
FACTS OF THE CASE
FIRST.—The contested act is the Resolution of February 13, 2023, issued by the Director of the Spanish
Data Protection Agency, dismissing the appeal filed against another resolution dated June 8,
2022, which imposed a fine of 5,000 E on said entity for a violation of Article 13 of the GDPR in relation to
Article 83.5(b), classified as minor under Article 74. 1(a) of the LOPDPGDD, and a second fine of 20,000 E for
a violation of Article 37 of the GDPR, classified as serious under Article 73 of the LOPDPGDD (PS/00140/2022).
And against the decision of the Director of the Spanish Data Protection Agency, dated June 23, 2023—
case file NUM000—requiring KFC RESTAURANTS SPAIN, S.L. to demonstrate, within TEN
WORKING DAYS, demonstrate that it had adopted the appropriate corrective measures consisting of bringing
the website www.kfc.es <WWW.kfc.es/> to the provisions of Article 13 of the GDPR, as well as the appointment
of a data protection officer.
SECOND.—An administrative appeal was filed with the Administrative Litigation Chamber of
this National Court; after the appeal was admitted for processing and the administrative record was requested, the
case was referred to the appellant so that he could formalize the complaint, which he did on June 14, 2023, requesting in the
petition that the appeal be granted, with the annulment of the contested decision and, consequently, the penalties
imposed; and, in the alternative, in the event that the decision is not revoked:
- That the penalty imposed in the amount of TWENTY THOUSAND EUROS (20,000 euros) for non-compliance with
Article 37.1(b) of the GDPR, taking into account the absence and misapplication of the aggravating factors that
the AEPD considers in the decision challenged by this complaint.
-With regard to the penalty of FIVE THOUSAND EUROS (5,000 euros), that the proceedings be returned to the
investigative phase so that the AEPD may initiate a warning procedure, in accordance
Organic Law 3/2018, given that a warning is no longer considered a sanction but rather an
autonomous procedure intended for situations such as the one set forth in the present case.
In a letter dated July 14, 2023, the appellant expanded the appeal to include the AEPD’s request of June 23, 2023: “…
so that, within TEN BUSINESS DAYS from the day following notification of this letter,
the appellant may demonstrate to this Agency that it has adopted the appropriate corrective measures, in accordance with the provisions of
the aforementioned resolution” (NUM000).
THIRD PARTY.—Once the complaint was filed, it was forwarded to the Lawyer, along with the
administrative file, so that he could file a response; and, after said response was formalized on August 2, 2023,
he requested in his pleading that the appellant’s claims be dismissed and that costs be awarded.
FOURTH.—After the complaint was answered, the case proceeded to the evidentiary phase; the proposed evidence was presented and admitted on
the plaintiff’s instance, with the result on record; once the proceedings were concluded, the case file was
2
CASE LAW
were ready for judgement, and a date was set for deliberation and ruling on July 7 of this year, on which date,
indeed, deliberation took place and a judgement was issued.
LEGAL GROUNDS
FIRST.—The subject of this case is the challenge to the Resolution of February 13, 2023, issued by the Director of the
Spanish Data Protection Agency, which dismisses the appeal filed against another resolution dated
June 8, 2022, which imposed a fine of 5,000 E on said entity for a violation of Article 13 of the
GDPR in relation to Article 83.5(b), classified as minor under Article 74. 1(a) of the LOPDPGDD, and a second
penalty of 20,000 E for a violation of Article 37 of the GDPR, classified as serious under Article 73 of the LOPDPGDD
(PS/00140/2022).
And against the decision of the Director of the Spanish Data Protection Agency, dated June 23, 2023—
case file NUM000—requiring KFC RESTAURANTS SPAIN, S.L. to demonstrate, within TEN
BUSINESS DAYS, demonstrate that it had adopted the appropriate corrective measures consisting of bringing
the website www.kfc.es <WWW.kfc.es/> to the provisions of Art 13 of the GDPR, as well as the appointment
of a data protection officer.
The aforementioned AEPD Resolution of February 13, 2023, stated:
“BACKGROUND
FIRST: On May 28, 2021, this Agency received a complaint filed by Mr. Valeriano ... against
the entity KFC RESTAURANTS SPAIN, S.L., … owner of the website https://www.kfc.es, for the alleged
violation of data protection regulations…
The complaint stated the following:
"The enterprise KFC Restaurants Spain SL does not comply with the GDPR guidelines on its website https://www.kfc.es.
All violations are detailed below:
- The GDPR-compliant privacy policy for EEA Users is not easily accessible
(https://www.kfc.es/multimarcas), as the publicly visible privacy policy link at the
bottom of the website leads to one for the U.S. (https://www.kfc.es/privacidad).
- When creating an account on the website (https://www.kfc.es/cuenta/registro), registration is not possible without
checking the box “I accept the terms and conditions of use to receive special offers and promotions
from KFC and its franchisees”—in other words, you are required to receive special offers and promotions.
At no point is the privacy policy mentioned or linked to, nor is its acceptance required at the time of
registration; the only reference is to “terms and conditions of use,” which leads to a legal notice.
- The respondent is an entity that engages in advertising and commercial prospecting activities, and it carries out
data processing based on the preferences of data subjects or performs activities that involve
profiling of data subjects in accordance with its cookie policy and privacy policy; therefore, it is
required to have a data protection officer, but does not.
- In the privacy policy: (a) the recipients of personal information are not specified; (b) the
details of the data controller (company name, tax ID number, registered office) are not provided; (c)
the possibility of international data transfers is mentioned, but the data subject is not informed of the
existence of adequacy decisions, safeguards, binding corporate rules, or specific situations
that apply. Only generic phrases such as “adequate safeguards” are used. Nor is the procedure explained
for obtaining a copy of this information or of the data that was provided; (d) the data storage period is not specified;
generic phrases such as “for as long as necessary” are used.....
THIRD PARTY: On August 20, 2021, the respondent submitted a written response to the request
made..., in which, among other things, it stated:
“a. The website www.kfc.es provides data protection information in two layers: The first layer is located
at the URL www.kfc.es/privacy and includes information on the processing of personal data carried out
by the company’s various brands, detailing, among other things, the following: a) The type of information processed;
b) The purposes of the processing; c) The automated processing that may be carried out; d) The categories
of data recipients; e) Options and control over the information; f) How the data is stored and protected;
g) A link to the privacy policy for the European Economic Area and the United Kingdom; h) Information
regarding the privacy of minors; i) Contact information. 
3
CASE LAW
The second layer is located at the URL www.kfc.es/multimarcas and provides details—supplementing the information in the first
layer, the remaining information required by Article 13 of the GDPR:
a. Legal basis for processing; b. Data storage and transfer; c. Information on the rights
of data subjects and how to exercise them; d. Contact information; e. Appendices detailing
the categories of data processed, the purposes of the processing, and the legal bases for
such processing.
This second layer is directly accessible at the bottom of the page via “Privacy Notice,” which
links to the URL www.kfc.es/multimarcas containing specific information for residents of the EEA and the United
Kingdom and includes the remaining information required by Article 13 of the GDPR.
Similarly, the Privacy Policy must include the following statement at the top to direct
users to the specific jurisdictional disclosures: “Please see our
global Privacy Policy below, which applies to your jurisdiction. See Section 7, Jurisdictional Disclosures, to
find additional privacy information specific to your state or country.”
The absence of this statement constitutes an omission with respect to our global privacy policies, which
we will correct along with the other changes and improvements to be made as a result of this complaint.
Implementation date: these changes will be implemented by September 30, 2021.
b.- Inability to create an account without agreeing to receive special offers and promotions:
The website account creation page is designed to allow users to create accounts without having to
agree to receive special offers and promotions. However, due to an error or glitch in the form’s configuration,
the text for both acceptance checkboxes includes authorization to
receive special offers and promotions.
The text of the first checkbox is correct; this corresponds to the User’s express consent
to receive offers and promotions from KFC and is optional to check.
The text of the second checkbox should only reflect acceptance of the terms, conditions of use, and
the privacy policy; however, the phrase “to receive special offers and promotions” was included by mistake
when it should have read “I accept the terms and conditions of use and the privacy policy to register at
www.kfc.es,” and it is required to be checked. Although the text of the checkbox indicates that the authorization refers to
receiving offers and promotions, the internal processing of the authorization is limited to consent for
the creation of the User account.
Once the error is detected, KFC will correct and modify it so that the text in
the checkboxes corresponds to the authorizations. Implementation date: these changes have already been
applied.
A screenshot of the account creation form is attached.—Appendix II.
c.—The form does not provide a link to the privacy policies, since these must be
accepted in order to create an account.
The link on the web account creation form is designed to provide access to the terms and
conditions of use and the privacy policy.
However, due to an error or glitch in the hyperlink configuration, it points to the Legal Notice instead
of the correct documents.
Once the error is detected, KFC will correct and modify it so that the hyperlink
points to the terms and conditions of use. Implementation date: these changes have already been implemented.
d.- No Data Protection Officer has been appointed, given that the entity engages in
advertising and commercial prospecting activities and performs data processing based on the preferences
of the data subjects or carries out activities that involve profiling them.
At KFC, we interpret that, given the nature of the data processing carried out, we are not
required to appoint a data protection officer, since we do not fall
under any of the specific cases established by Article 37.1 of the GDPR....
e.- In the privacy policies:
The recipients of personal data are not specified.
The general privacy policy available at www.kfc.es/privacidad includes, in Section 4,
information regarding how User information is shared, and in Section 7, the
4
CASE LAW
regarding the disclosure of data to public authorities based on the
User’s state or country of residence. Section 4 of the privacy policy describes up to 10 different categories
of data recipients.
In this regard, Article 13(1)(e) of the GDPR states that the controller must inform
the recipients or categories of recipients of personal data, where applicable.
Similarly, the AEPD itself, in its Guide to Compliance with the Duty to Inform, under the heading
7.4 Recipients, states the following: “When there is a plan to lawfully transfer or disclose the
personal data that is collected, information must be provided regarding the identity of the recipients, if they are clearly
predetermined, or the categories of recipients, if they are not predetermined.”
In this case, given that this is a general privacy policy that applies to all brands and across
different territories, the recipients are not predetermined; therefore, only information is provided
regarding the categories of recipients to whom the data may be disclosed, including the purpose or
reason for such disclosure.
We understand that the information provided in the general privacy policy complies with the requirements of
Article 13.1(e) of the GDPR regarding the provision of information concerning the categories of recipients.
Regarding the Absence of Details on the Data Protection Officer. In this case, due to the
general nature of both privacy policies included on the website www.kfc.es—the general policy applicable to all
jurisdictions and the specific policy for residents of the EEA, the UK, and Switzerland—the identification of the controller
can be found in the Legal Notice.
We acknowledge this omission and will implement this improvement to provide greater clarity and transparency to
the information provided in the privacy policies, by redirecting Users to the Legal Notice within the
privacy policy to identify the controller in each territory, including Spain. These
changes will be implemented by the end of September 2021.
The possibility of international data transfers is detailed, but the data subject is not informed
of the existence of adequacy decisions, safeguards, binding corporate rules, or specific situations
that apply.
The privacy notice specific to the EEA and the United Kingdom informs users of the possibility of
international transfers and includes a statement that, if such transfers occur, KFC will ensure that:
a) personal information is transferred to countries recognized as offering an equivalent level of protection; or
b) the transfer is carried out in accordance with appropriate safeguards, such as the standard data protection clauses adopted by the European Commission. Notwithstanding these measures, the country and jurisdiction
to which the data is transferred may provide a lower level of data protection than that provided for in
EEA or UK law.
Although this information may seem too general, we take note of this and will make improvements to
provide greater clarity and transparency in the information provided in the privacy policy, redirecting
users to the contact information for each data controller in each territory so they can request
additional information regarding any international transfers that may take place and the appropriate safeguards
used to ensure an adequate level of security for such transfers.
A screenshot of the information provided regarding international transfers is attached as
Appendix III. Implementation date: these changes will be implemented by September 30, 2021.
d. The data storage period is not specified.
Section 6 of the privacy policy available at www.kfc.es/privacidad includes information
regarding the data retention period.
Article 13.1(a) of the GDPR states that the controller must provide information on the period during
which personal data will be stored or, where this is not possible, the criteria used to determine
that period.
In this case, given that this is a general privacy policy that applies to all brands and across
different territories, the data retention periods are not predetermined; therefore, only
information regarding the criteria for data storage is provided, stating that it will be stored
“for as long as is reasonably necessary to maintain the Service, comply with legal and accounting obligations,
and for the other purposes described in this Policy, or as required or permitted by law.”
5
CASE LAW
Information regarding the data retention period is attached as Annex IV. Therefore, we understand
that the information provided in the general privacy policy complies with the requirements of Article 13.1
(a) of the GDPR
regarding the provision of information concerning data storage periods or the criteria for
establishing such periods.
However, while this information may seem too generic, we take note and
will make an improvement to provide greater clarity and transparency to the information provided in the
privacy policy; we will include more specific storage criteria or storage periods in the
privacy notice specific to the EEA and the UK. Implementation date: these changes will be implemented by September
30, 2021..... 
FIFTH: On November 30, 2021, and February 9, 2022, ... a complaint was filed against the respondent, who was requested to provide further information regarding:
a.) a list of the entity’s activities that involve the processing of personal data, specifically
detailing whether customer data is processed for advertising purposes;
b).- For each activity, the following must be provided: the number of customer records processed, the range of
data elements for each customer that are subject to processing, the duration for which each customer’s data is processed,
and details regarding how long such data is retained in its information systems; the geographic or territorial scope
of the processing, specifying whether its systems process data relating to customers from a specific
territorial area or from the entire national territory; and
c) a summary of the analyses conducted by the entity to assess the need to appoint a DPO,
indicating whether a DPO has been appointed and, if so, whether this appointment has been communicated and published.
SIXTH: On March 1, 2022, and March 10, 2022, the respondent entity sent ... two separate response letters... in
which, among other things, it reported on the following aspects:
“An extract from the Record of Processing Activities (RAT) is provided, which reflects all the
processing activities carried out by KFC in connection with advertising activities involving customers,
specifying the number of customers whose data is processed and the type of data processed for each
activity, as well as the duration for which such data is processed.
In this regard, KFC has a data storage schedule and an internal protocol for
storage and erasure of personal data once it is no longer necessary. It should be noted that
KFC does not, under any circumstances, perform profiling; processing activities related
to the sending of commercial information are carried out based on the User’s consent (opt-in system)
and without user segmentation.
Processing activities related to advertising are always carried out with the User’s
prior consent, unlike processing activities related to fulfilling
user orders, which are carried out on the basis of the performance of a contract.
The geographic scope of the processing activities is Spain, with data management centralized
for the entire national territory.
Regarding the analyses conducted by your organization to assess the need to appoint a DPO, please indicate whether you have
appointed one and, if so, whether this has been communicated and published:
In this regard, KFC has determined that there is no obligation to appoint a DPO, since
the processing activities carried out do not fall within the scope of Article 37 of the GDPR, nor is the entity
among those required to do so under Article 34 of the LOPDGDD.
Similarly, data protection compliance management has been handled by
in-house staff specializing in data protection—specifically, from the UK, through Samantha Sayers,
Global Privacy Lead Counsel—and by external expert consultants in each of the countries where
the company operates.
However, as previously indicated, we will periodically evaluate internally the
need to designate such a role, based on potential operational changes as well as the launch of
new business lines that may involve the incorporation of new processing activities,
in order to provide greater assurances of compliance to our clients and Users regarding
activities and procedures in the processing of personal data, particularly if processing activities
for profiling were to be initiated....
6
CASE LAW
III.— Pursuant to the aforementioned request, the required documentation is hereby submitted to this Agency as
follows: A copy of an excerpt from the Register of Processing Activities related to customers and for
advertising purposes, as Annex I; and a copy of the Internal Analysis conducted to assess the need to appoint a DPO
as Annex II.
SEVENTH: On March 21, 2022, this Agency accessed the “Privacy Policy” on the
website, www.kfc.es, the following characteristics were observed:
a).- Regarding the obtaining of Users’ consent for the processing of their personal data:
1. Through the link: <<CREATE Your Account>>, located at the top of the home page, the website redirects to
a new page, https://www.kfc.es/cuenta/registro, where the User can register on the website and is
asked to provide their first name, last name, phone number, email address, and credit card number.
To submit the form, the User must click the option: _ I accept the <<TERMS
of Use>>.
There is also the option to voluntarily sign up to receive special offers and promotions
by clicking the option _ I want to sign up to receive special offers, sweepstakes, and promotions from
KFC and/or its franchisees. For more information, visit our <<PRIVACY Policy>>. <<Create my
Pollo Pollo account>>.
2. By clicking the link: <<Start Order>>, located at the top of the home page, the website redirects
to a new page <HTTPS://www.kfc.es/store-selection> where you can select your order and choose
whether to have it delivered to your home or pick it up at the restaurant.
Once the order has been selected, to process it, the website redirects the User to a new page https://
www.kfc.es/checkout, where the User must enter their personal data: first name, last name, phone number,
email address, and credit card number.
To submit the form, the User must click the option: _ I accept the <<TERMS
of Use>>.
Users also have the option to voluntarily sign up to receive special offers and promotions
by clicking the option _ I want to sign up to receive special offers, sweepstakes, and promotions from
KFC and/or its franchisees. For more information, visit our <<PRIVACY Policy>>. <<Order Now>>
3. Through the link: <<Work with Us>>, located in the menu at the top right, the
website redirects you to a new page at https://www.kfc.es/nosotros/trabaja-en-kfc where the User can sign up or register
to receive job offers via the link:
<HTTPS://kfc.epreselec.com/General/Alta.aspx>
Once the user has entered their personal data—first name, last name, email address, and ID number—they must
check the following boxes:
I am not a robot.
I have read, understand, and accept the <<PRIVACY Policy>>
There is also a banner with the following information:
Basic Data Protection Information: Data Controller: KFC IBERIA; Purposes: To include in the enterprise’s
candidate database the information from the resume you provide when creating your account with us
to use it in future recruitment processes for which your profile may be a good fit; Legal Basis: Consent
of the data subject; Recipients: We will not disclose your data to third parties except where legally required and to the enterprises
listed in the additional information.
4. Finally, you also have the option to provide personal data to the company through the
subscription page for special offers and promotions, https://www.kfc.es/subscripcion, where the
User must provide their first name, last name, and email address.
Before submitting the subscription form, the user must click to accept the following option:
“I want to sign up to receive special offers, sweepstakes, and promotions from KFC and/or its franchisees.”
For more information, visit our <<PRIVACY Policy>>.
b).- Regarding the "Privacy Policy":
1. If you access the “Terms of Use” clauses of the website via the links provided in the
various forms or via the link at the bottom of the home page, the website redirects you
7
CASE LAW
to a new page at https://www.kfc.es/nota-legal, which provides information on, among other things, the
following aspects:
(...) Contact: The websites are owned and operated by KFC Restaurant Spain S.L., an enterprise registered
in Spain, with its registered office at Serrano Galvache 56, Edificio Madroño, 3rd Floor, KFC, Madrid,
28033. Tax ID (CIF): B86281599. Para contact us, please call +34 917 68 07 30.
Registration: Data Protection: We will collect, store, and process your personal data in accordance
with our privacy Policy. Please read our <<PRIVACY Policy>> to ensure that
you are satisfied with and understand its contents before creating an account.
Terms and Conditions for Orders Placed via Mobile:
Data Protection: We will collect, store, and process your personal data in accordance with
our <<PRIVACY Policy>>. Please read our privacy policy to ensure that you are
satisfied with and understand its contents before creating an account.
If you are not satisfied with the service you have received, please contact us at
clientes@kfc.es or +34 91 904 18 81 (...).
2. If you access the website’s “Privacy Policy” through the links provided in the various
forms or via the link at the bottom of the home page, the website redirects you to a new
page, https://www.kfc.es/privacy,where it provides information on, among other things, the following
aspects:
"About the personal information they collect; How they use personal information; What information may be
collected automatically; How they share the information collected; About the options and control over
the information collected; How they store and protect the information; About the applicable laws of
Europe, the following is expressly stated:
"When we have an establishment in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, or
are processing personal data related to individuals located in the EEA, the United Kingdom, or Switzerland,
please <<CLICK here>> for additional information about our data privacy practices; Regarding
children’s privacy; Regarding links to other websites and services; How to contact the
website administrators; and regarding changes to the privacy policy (...)”. 
3. If you access the website’s “Privacy Notice” via the link at the bottom of the
homepage, the website redirects you to a new page, https://www.kfc.es/multimarcas,where it provides
specific information regarding the processing of personal data collected in the EEA, the United Kingdom, or Switzerland, and
among
this information is the following:
"Regarding the Controller: KFC Spain: KFC Restaurants Spain, S.L., with Tax ID B86281599 and
registered address at Calle Serrano Galvache (Pq. Empresarial Pq. Norte), 56 - Edif. Olmo, 5th Floor, Madrid, Madrid.
Email: clientes@kfc.es. Phone: 91 904 18 81. Regarding the legal basis for data processing
. Based on the consent provided and the right to withdraw your consent at any time,
where consent has been given. Regarding the storage and data transfers within the EEA and the
United Kingdom. Regarding the individual rights of EEA residents and how to exercise them, and the right to
file a complaint with your local authority. How to contact the website controller.
In addition to the information provided in the “Privacy Policy” and the “Privacy Notice,” two
appendices are attached containing the following information:
- Appendix 1 details the categories of personal information collected, as well as the legal
basis for processing personal information and the recipients of such
personal information.
- Appendix 2 lists the categories of personal information collected and how that information is used.
The table also lists the legal basis for processing personal information and the
recipients of such
personal information....
PROVEN FACTS.
... First: Regarding the lawfulness of the processing of personal data obtained on the website www.kfc.es
<www.kfc.es/>:
8
CASE LAW
On the website www.kfc.es, Users can enter their personal data through various
procedures:
a) to create a user account;
b) to register as a job seeker with the company;
c) to place an online order for its products; and
d) to receive promotional offers.
Before submitting a form for any of these procedures containing personal data, you
must first provide consent for the processing of such data; you may
access the website’s “Privacy Policy” via the link: “Terms of
Use”—“Privacy Policy (General)”—“Privacy Notice” (Exclusive to the EEA and the United Kingdom).
The four forms mentioned above also offer the option to voluntarily sign up to receive
periodic promotional offers from the brand.
The “Privacy Policy” for the website in question is divided into three documents:
a) Website Terms of Use;
b) A generic privacy policy for all countries; and
c) A specific privacy policy for the countries of the European Economic Area (EEA), the United Kingdom, and
Switzerland.
In the first document, “Terms of Use” (https://www.kfc.es/nota-legal), the following is stated regarding the
data protection policy for the personal data collected:
"(...) Data protection: We will collect, store, and process your personal data in accordance
with our Privacy Policy. Please read our Privacy Policy to ensure that you are
satisfied with and understand its content before creating an account (...)".
If you access the “Privacy Policy” on the website www.kfc.es via the link https://www.kfc.es/privacidad, ?
"generic policy for all countries," the following introduction appears:
"KFC® ("KFC," "we," "our," or "us") is committed to protecting your privacy. This KFC
Privacy Policy (this “Policy”) applies to our websites, online experiences, and mobile Apps
for mobile devices running Apple iOS, Windows, or Android that link to the Policy (collectively,
our “Sites”), and describes how we collect, use, and disclose your personal information when
you visit our Sites or our in-store restaurants and kiosks, or otherwise interact with us
(collectively, our “Service”).
By accessing or using our Service, you indicate that you have read, understood, and agree to our collection,
storage, use, and disclosure of your personal information as described in this Policy and in our
Terms of Use, available on our site.
For more information about the privacy practices of other enterprises within Yum Brands, Inc. (“Yum
Brands”) (the “Brands”), visit: Yum Brands Privacy Policy. PIZZA HUT® Privacy Policy.
TACO BELL® Privacy Policy. THE HABIT® Privacy Policy. Regarding the purposes for which
the collected personal data will be used, among others, the following is stated:
"(...) 2. HOW WE USE PERSONAL INFORMATION:
(...) We may also use your information to personalize your experience with us and promote
our rewards or loyalty programs.
We also use this information to provide you with the Service across all our operations, which
includes supporting your in-store experience when you interact with our franchisee-owned
locations (...).
4. HOW WE SHARE YOUR INFORMATION
We may share, sell, or disclose your information in the instances described below. For
more information about your options regarding your information, see “Your Options and Control Over
Your Information.”
9
JURISDICTION
Other Brands: We may share personal information with our parent enterprise, Yum Brands, and other
Yum Brands enterprises and our affiliates, which may use your information in a manner similar to that
described in this Policy. (...)
Promotional Partners: We may share limited information with third parties with whom we partner to
provide contests and sweepstakes, or other joint promotional activities. Typically, these partners will be
clearly identified in the contest rules or promotional materials.
Selected Strategic Business and Marketing Partners: We may share limited data with
our preferred strategic business and marketing partners so that they can provide you with information
and marketing messages about products or services that may interest you. These parties may use your
information in accordance with their own privacy policies.
Online advertising partners: We may share information with third-party online advertising partners
or allow these partners to collect information from you directly on our Sites to facilitate
online advertising.
For more information, please see our Cookies and Ads Policy, available on our Site.
(...)
Other instances in which we may share your personal information:
Service providers and consultants: Personal information may be shared with third-party vendors and
other service providers who provide services to us or on our behalf. This may include vendors
and distributors involved in marketing or advertising activities or that provide
mail or email services, tax and accounting services, product compliance, delivery services,
payment processing, data enrichment services, fraud prevention, web hosting, or
analytics services.
With respect to any of the above, we may share information with other parties in an
aggregated or anonymized form that does not reasonably identify you."
If you access the supplemental Privacy Policy for countries, the EEA, and the United Kingdom on the website www.kcf.es,
via the link, https://www.kfc.es/multimarcas, you can read the following regarding the purposes for which the
personal data collected will be used and the legal basis for such
processing:
"This Privacy Notice for the EEA and the United Kingdom supplements the information contained in our
Privacy Policy and applies solely to individuals residing in the European Economic Area
("you") and to the Sites and Services available in the EEA, as well as in the United Kingdom, that link to this
Privacy Notice).
Unless expressly stated otherwise, all terms have the same meaning as
defined in our Privacy Policy or as otherwise defined in the EU General Data Protection
Regulation 2016/679 of the European Parliament and of the Council (“GDPR”).
Appendix 1 details the categories of personal information we collect about you
and how we use that information when you use the Service, as well as the legal basis on which we
rely to process personal information and the recipients of such information.
In addition, the table in Annex 2 details the categories of personal information that
we collect about you automatically and how we use that information. The table also lists
the legal basis on which we rely to process personal information and the recipients of such
personal information.
APPENDIX 1
a).- Profile information such as your name, phone number, date of birth, and profile photo.
a.1. We may use this information to set up and authenticate your account on the Service: The processing is
necessary to fulfill a contract with you and to take steps prior to entering into a contract with you.
a.2. We may use this information to communicate with you, including sending communications
related to the Service: The processing is necessary to fulfill a contract with you.
a.3. We may use this information to send you marketing communications in accordance with your
preferences: We will only use your personal information in this way to the extent that you have given us your
consent to do so. 
10
CASE LAW
a.4. We may use this information to handle inquiries and complaints made by you or about you
in connection with the Service: The processing is necessary for our legitimate interests, specifically to
administer the Service and communicate with you effectively to respond to your inquiries or complaints.
b.) Information about payments and transactions, including payment information (such as your credit
or debit card details or bank account information), and the time, date, and amount of the transactions.
b.1.— We use this information to facilitate transactions and provide you with the Service: The processing is
necessary to fulfill a contract with you.
b.2.— We use this information for customer service: The processing is necessary to fulfill a contract
with you.
b.3.—We use this information to detect and prevent fraud: Processing is necessary for our
legitimate interests, specifically the detection and prevention of fraud.
c.) Location Data
c.1. We use GPS technology to determine your current location in order to provide you with relevant content
and show where that content was created: Processing is necessary for our legitimate interests,
specifically to administer the Service. We will only use your personal information in this way
to the extent that you have given us your consent to do so.
d).- Comments, chat, and feedback
d.1. When you contact us directly (e.g., by email, phone,
mail, or through an online form or online chat), we may record your comments and feedback:
Processing is necessary for our legitimate interests, specifically to respond to your question or
comment, to evaluate and improve our products and services, and to inform our marketing and
advertising.
e).- Information received from third parties, such as social media platforms. If you interact with the Service through a
social media platform, we may receive information from that platform, such as your name, profile information, and any other
information that you allow the platform to share with third parties. The data we receive depends
on your privacy settings on the social media platform.
e.1.— We may use this information to authenticate you and grant you access to the Service: Processing is
necessary to fulfill a contract with you.
e.2.- We may use this information to customize how the Service is displayed to you (such as the language in which it is
presented): The processing is necessary for our legitimate interests, specifically to tailor the Service
so that it is more relevant to our Users.
f.) Usage information, such as the amount of time you spend using our products, your results when using
our products, any issues you encounter while using our products, and any other
information generated by the products regarding how you use our products.
f.1.- We may use this information to analyze how the Service works, troubleshoot issues with
the Service, improve the Service, and develop new products and services: The processing is necessary for
our legitimate interests, specifically to improve our products and services, address any errors
in our products and services, and develop new products and services.
f.2.— We may use this information to develop new products and features available through
the Service or to improve the Service in any way: The processing is necessary for our legitimate
interest, specifically to develop and improve the Service.
g.)—All personal information listed above.
g.1.—We may use all the personal information we collect to operate, maintain, and provide you with
the features and functionality of the Service, communicate with you, monitor and improve the Service and the
business, and develop new products and services: The processing is
necessary for our legitimate interests, specifically to manage and improve the Service.
APPENDIX 2
a).- Information about how you access and use the Service. For example, how often you access the
Service, the time at which you access the Service and how long you use it, the approximate location from
which you access the Service, whether you access the Service from multiple devices, and other actions you take on the Service.
11
LEGAL BASIS
a.1.— We may use information about how you use and connect to the Service to present the Service on your
device: The processing is necessary for our legitimate interests, specifically to tailor the Service
to the User.
a.2.— We may use this information to identify products and Services that may be of interest to you for
marketing purposes: The processing is necessary for our legitimate interests, specifically to provide
information about our direct marketing.
a.3.- We may use this information to monitor and improve the Service and our business, troubleshoot issues,
and provide updates on the development of new products and services: The processing is necessary for our
legitimate interests, specifically to monitor and troubleshoot issues with the Service and improve the Service overall.
b).- Log files and information about your device. We also collect information about the tablet,
smartphone, or other electronic device you use to connect to the Service. This information may
include details about the device type, the device’s unique identification numbers, operating
systems, browsers, and applications connected to the Service via the device, your mobile network, IP
address, and your device’s phone number (if applicable).
b.1.— We may use information about how you use and connect to the Service to present the Service on your
device: The processing is necessary for our legitimate interests, specifically to tailor the Service
to the User.
b.2.- We may use this information to identify products and Services that may be of interest to you for
marketing purposes: The processing is necessary for our legitimate interests, specifically to provide
information about our direct marketing.
b.3.- We may use this information to monitor and improve the Service and our business, prevent and detect
fraud, troubleshoot issues, and provide information on the development of new products and services: The processing
is necessary for our legitimate interests, specifically to monitor and troubleshoot issues with the
Service and to improve the Service in general.
Second: Regarding the “Privacy Policy” on the website www.kfc.es <WWW.kfc.es/>:
On the website in question, the information provided to Users regarding
the processing of their personal data is made available through the following documents posted on the
website: a) document: “Terms of Use” or “Legal Notice,” https://www.kfc.es/nota-legal; b) document: “Privacy
Policy,” https://www.kfc.es/privacidad, and c) document: “Privacy Notice,” https://www.kfc.es/
multimarcas.
All of these are accessible from the various forms (listed in the previous section) and through the
links at the bottom of the home page.
The information provided in the various documents listed above is as follows:
A).- In the “Terms of Use” or “Legal Notice” document (<HTTPS://www.kfc.es/nota-legal>), you can find
the following information regarding the processing of the personal data collected:
REGISTRATION: “(...) Data protection: We will collect, store, and process your personal data in
accordance with our Privacy Policy. Please read our Privacy Policy to ensure that
you are satisfied with and understand its contents before creating an account.
B).- In the “Privacy Policy” document (<HTTPS://www.kfc.es/privacidad>), you can find the
following information regarding the processing of the personal data collected: 1. what type of
information they collect 2. how they use the personal information they collect 3. what information they collect
automatically 4.
how they share the information collected. 5. Options and control regarding the information collected. 6.
How the information is stored and protected. 7. Jurisdictional disclosures. 8. Children’s privacy. 9.
Links to other websites and services. 10. How to contact the controller.
C).- In the “Privacy Notice” document (<HTTPS://www.kfc.es/multimarcas>), we can find, among
other things, the following information regarding the processing of the personal data collected:
The controller is identified as: KFC Restaurants Spain, S.L. ...
The legal basis for processing in the EEA and the United Kingdom is stated as:
12
JURISDICTION
The table in Annex 1 sets forth the categories of personal information they collect, as well as the
legal basis and the recipients of such personal information.
The table in Annex 2 sets forth the categories of personal information they collect automatically.
The table also lists the legal basis on which they process personal data and the
recipients of such personal data.
Information is provided regarding data storage and transfers.
Information is provided regarding the individual rights of EEA residents: Right to object. Right of access.
Right to rectification. Right to erasure. You also have the right to file a complaint with your
Data Protection Authority.
Information regarding the storage of personal data is provided: For individuals residing in the EEA
we store personal data for no longer than is necessary to fulfill the purposes for which
we collect the data, such as delivering your order, maintaining our service, complying
with our legal obligations, and resolving disputes. We will store your personal data in accordance
with applicable statutory limitation periods, as required by the tax and accounting regulations of each
EEA country. Upon the expiration of these periods, or upon your request, the data will be erased
or anonymized so that it can no longer be used to identify you, unless we are legally authorized or required
to perform storage of the personal data for a longer period." 
LEGAL BASIS
II.-
a).- Regarding the lawfulness of the processing of personal data obtained from the website www.kfc.es <WWW.kfc.es/>:
After reiterating the ESTABLISHED FACTS, the AEPD’s Resolution states:
“In the present case, given that the ‘Privacy Policy’ on the website www.kfc.es describes the
purposes of personal data processing and specifies the legal basis for each one, the
processing of data for these purposes would not constitute further processing.
Furthermore, it must be taken into account that the entity against which the complaint was filed states the following in its defense:
"The purposes indicated in the privacy policy for which a sanction is proposed describe potential situations
and do not imply that they are actually carried out, or that they are carried out in a
fully lawful manner, as will be explained; and most importantly, such further processing activities for which a sanction is proposed
are not included in the Register of Processing Activities already submitted to the AEPD...”
Therefore, in the present case, based on the evidence currently available, it is considered
that the description of the purposes of personal data processing, together with the legal basis for
each of them, does not correspond to further processing and thus does not contradict the provisions
in Article 6.1 of the GDPR, without implying an assessment of the adequacy of the legal basis
set forth in the privacy policy for each of the different processing operations, as this is not the subject of the present
proceeding.”
"III.—
a.— Regarding the “Privacy Policy” on the website www.kfc.es <WWW.kfc.es/>:
As has been verified, on the website in question, the information provided to Users
regarding the processing of their personal data is made available through the following
documents posted on the website: a) document: “Terms of Use” or “Legal Notice,” https://www.kfc.es/nota-
legal; b) document: “Privacy Policy,” https://www.kfc.es/privacy, and c) document:
“Privacy Notice,” https://www.kfc.es/multimarcas. All of these are accessible from the various
forms (listed in the previous section) and via the links at the bottom of the
homepage. The information provided in the various documents listed above is as
follows:
A).- In the “Terms of Use” or “Legal Notice” document (<HTTPS://www.kfc.es/nota-legal>), you can find
the following information regarding the processing of personal data collected:
REGISTRATION: “(...) Data protection: We will collect, store, and process your personal data in
accordance with our Privacy Policy. Please read our Privacy Policy to ensure that
you are satisfied with and understand its contents before creating an account.
13
CASE LAW
B).- In the "Privacy Policy" document (<HTTPS://www.kfc.es/privacidad>), we can find the
following information regarding the processing of the personal data collected: 1. what type of
information they collect 2. how they use the personal information they collect 3. what information they collect
automatically 4. how they share the information collected. 5. Options and control regarding the
information collected. 6. How they store and protect the information 7. Jurisdictional disclosures
8. Children’s privacy 9. Links to other websites and services 10. How to contact the
controller.
C).- In the “Privacy Notice” document (<HTTPS://www.kfc.es/multimarcas>), we can find, among
other things, the following information regarding the processing of the personal data collected:
Regarding the controller, the following is stated:
KFC Restaurants Spain, S.L. ...
Regarding the legal basis for processing in the EEA and the United Kingdom, the following is stated:
The table in Annex 1 sets forth the categories of personal information they collect, as well as the
legal basis and the recipients of such personal information. The table in Annex 2 sets out the categories
of personal information they collect automatically. The table also lists the legal basis on
which they rely to process personal information and the recipients of such personal information.
Information is provided regarding data storage and transfer.
Information is provided regarding the individual rights of EEA residents: Right to object. Right of access.
Right to rectification. Right to erasure. You also have the right to file a complaint with your
Data Protection Authority.
Information regarding the storage of personal data is provided:
For individuals residing in the EEA, we store personal data for as long as
necessary to fulfill the purposes for which we collect the data, such as delivering your
order, maintaining our service, complying with our legal obligations, and resolving
disputes. We will store your personal data in accordance with the applicable statutory limitation periods,
as well as the tax and accounting regulations of each EEA country. Upon the expiration of these
periods, or upon your request, the data will be erased or anonymized so that it can no longer be used to
identify you, unless we are legally authorized or required to perform storage of the personal data for
a longer period.
In this case, we must also take into account that the privacy policy on the website
www.kfc.es does not provide precise information regarding the purposes of data processing, as it uses
such as “we may use…,” without the respondent having substantiated the reason why
such language was necessary, as required by the Transparency Guidelines pursuant to
Regulation (EU) 2016/679 of the Article 29 Working Party, last revised and adopted on April 11, 2018, which
stipulate the following:
“13. The use of terms such as ‘may,’ ‘could,’ ‘some,’ ‘frequently,’ and ‘possible’ should be avoided.
When controllers choose to use vague language, they must be able to demonstrate, in
accordance with the principle of proactive accountability, why the use of such language could not be avoided and why
it does not undermine the fairness of the processing. (...)”
III.-
b).- Classification and characterization of the violation Regarding the information that the controller
must provide to the data subject when data is collected from them.
Recital 60 of the GDPR states:
“The principles of fair and transparent processing require that the data subject be informed of the existence of
the processing operation and its purpose. The controller must provide the data subject with any
additional information
necessary to ensure fair and transparent processing, taking into account the
specific circumstances and context in which the personal data are processed. The data subject must also be informed
of the existence of profiling and the consequences of such profiling. If
personal data are obtained from the data subjects, they must also be informed as to whether they are required to
provide such data and of the consequences of failing to do so. Such information may be provided in
combination with standardized icons that offer, in an easily visible, intelligible, and clearly
14
CASE LAW
legible manner, an adequate overview of the intended processing. Icons presented in electronic
format must be machine-readable.”
Recital 61 of the GDPR states the following:
“Information regarding the processing of their personal data must be provided to data subjects at the time
it is collected from them or, if collected from another source, within a reasonable period of time, depending on the
circumstances of the case. If personal data may be lawfully disclosed to another recipient, the
data subject must be informed at the time the data is first disclosed to that recipient. The controller
who intends to perform processing on the data for a purpose other than that for which it was collected must
provide the data subject, prior to such further processing, with information regarding that other purpose and any other
necessary information. When the source of the personal data cannot be provided to the data subject because
multiple sources were used, general information must be provided.
For its part, Article 13 of the GDPR details the information that must be provided to the data subject when their
personal data is collected directly from them, establishing the following:
“1. When personal data relating to a data subject are obtained from the data subject, the controller shall, at the
time the data are obtained, provide the data subject with: a) the identity and contact details of the controller and, where
applicable, of the controller’s representative; b) the contact details of the data protection officer, if any; c)
the purposes of the processing for which the personal data are intended and the legal basis for the processing; d) where
the processing is based on Article 6(1)(f), the legitimate interests of the controller or of a
third party; e) the recipients or categories of recipients of the personal data, where applicable; f) where
case, the controller’s intention to transfer personal data to a third country or an international organisation
and the existence or absence of a Commission adequacy decision, or, in the case of transfers
referred to in Articles 46 or 47 or the second paragraph of Article 49(1), a reference to the
adequate or appropriate safeguards and the means of obtaining a copy of them or the fact that they have been provided.
2. In addition to the information referred to in paragraph 1, the controller shall provide the
data subject, at the time the personal data are collected, the following information necessary to
ensure fair and transparent data processing:
(a) the period for which the personal data will be stored or, where this is not possible, the criteria used
to determine that period; b) the existence of the right to request from the controller access to
the personal data concerning the data subject, and their rectification or erasure, or the restriction of their processing,
or to object to the processing, as well as the right to data portability; c) where the processing
is based on Article 6(1)(a) or Article 9(2)(a), the existence of the right
to withdraw consent at any time, without this affecting the lawfulness of the processing based on
consent prior to its withdrawal; d) the right to lodge a complaint with a supervisory authority; e) whether the provision of personal data is a legal or contractual requirement, or a requirement necessary
to enter into a contract, and whether the data subject is obliged to provide the personal data and is informed
of the possible consequences of failing to provide such data; f) the existence of automated decision-making,
including profiling, as referred to in Article 22(1) and (4), and, at least in such cases,
meaningful information about the logic involved, as well as the significance and the envisaged consequences of
such processing for the data subject." 
Well, according to Article 13.1(c) of the GDPR, users must be informed of the purposes of the
processing to which their personal data will be put and the applicable legal basis for such processing (Art. 6 GDPR),
avoiding practices such as including overly generic or unspecific purposes that could lead
to further processing that exceeds the data subject’s reasonable expectations.
If we access the website’s “Privacy Policy” at www.kfc.es <WWW.kfc.es/> (https://www.kfc.es/
privacy), we can read, regarding the purposes for which the collected personal data will be used,
among other things, the following:
"(...) to personalize your experience with us and promote our rewards or loyalty programs
(...)",
"(...) share, sell, or disclose your information with: Other Brands: We may share personal information
with our parent enterprise: Yum Brands and other Yum Brands enterprises and our subsidiaries, which may
use your information in a manner similar to that described in this Policy.
Or, for example, when the entity states that it may share the personal data collected with its
third-party service providers. This is stated in a generic and abstract manner, without identifying the service providers or the
legal basis on which it relies:
15
CASE LAW
“(...) to share with third-party service providers (...).
Based on the legal grounds set forth above, the facts indicated in the previous section
constitute a violation of Article 13 of the GDPR.
III.-
c.- Penalty Imposed. This violation may be penalized with a fine of up to €20,000,000, or,
in the case of an enterprise, an amount equivalent to a maximum of 4% of the total
of the preceding financial year, whichever is higher, in accordance with Article
83(5)(b) of the GDPR.
In this regard, Article 74(a) of the LOPDGDD considers the following to be a minor violation, for the purposes of the statute of limitations: “Failure to comply
with the principle of transparency of information or the data subject’s right to information by failing to provide all
the information required by Articles 13 and 14 of Regulation (EU) 2016/679.”
Taking into account the circumstances of the case, with respect to the violation committed by breaching the provisions
of Article 13 of the GDPR, an initial fine of 5,000 euros (five thousand euros) is hereby imposed.
III.-
d.- Measures
In accordance with Article 58(2) of the GDPR, the corrective measure to be imposed on the website owner
is that it take the necessary measures to bring the website it owns (www.kfc.es) into
compliance with current regulations, bringing it into line with the provisions of Article 13 of the GDPR....
IV.-
a.- Regarding the absence of a data protection officer....
IV.-
b).- Classification and characterization of the violation
Regarding whether or not it is necessary to appoint a data protection officer, Article 37 of the GDPR stipulates
the following:
“1. The controller and the processor shall designate a data protection officer whenever
: ...
b) the core activities of the controller or processor consist of processing operations which,
due to their nature, scope, and/or purpose, require regular and systematic monitoring of data subjects on
a large scale...”.
In the case at hand, the applicable provision would be Article 37(1)(b) of the GDPR, where three elements must be examined:
“core activities,” “regular and systematic monitoring,” and “large scale.”
It is true that these are indeterminate legal concepts, but they have been clarified through the
various opinions and rulings of the Art 29 Working Party:
Regarding what constitutes a core activity, WP-243 (Guidelines on Data Protection Officers—
DPOs) states that:
“Article 37(1)(b) and (c) of the GDPR refer to the ‘core activities of the controller or the
processor,” and thus, as Recital 97 of the GDPR specifies, the main activities of a
controller are related to “its primary activities and are not related to the processing
of personal data as ancillary activities.”
‘Core activities’ may be considered the key operations necessary to achieve the objectives of the
controller or processor. However, ‘core activities’ should not be interpreted
as exclusive when data processing is an inseparable part of the activity of the controller or
processor.
For example, the main activity of a hospital is to provide health care. However, a hospital could not
provide healthcare safely and effectively without processing data concerning health, such as
patients’ medical records. Therefore, the processing of such data must be considered one of the
core activities of any hospital, and hospitals must, consequently, appoint a DPO.
Another example would be a private security enterprise that conducts surveillance of a number of
private shopping centers and public spaces. Surveillance is the core activity, which in turn is inextricably linked
16
CASE LAW
inextricably linked to the processing of personal data. Therefore, this enterprise must also appoint
a DPO.
Furthermore, all enterprises carry out certain activities, such as paying their
employees or performing routine IT support tasks.
Such activities are examples of support functions necessary for the organization’s main activity or business.
Although these activities are necessary or essential, they are normally considered
ancillary functions and not the main activity.”
The second issue is habitual and systematic monitoring, which WP 243 determines is “not limited to the
online environment, and online Tracking should be considered only one example of monitoring the behavior
of data subjects.”
The Art 29 Working Party interprets “habitual” to have one or more of the following meanings:
a) continuous or occurring at specific intervals over a specific period;
b) recurring or repeated at predetermined times or taking place constantly or periodically.
The Working Party interprets “systematic” to mean one or more of the following:
a) occurring in accordance with a system;
b) preestablished, organized, or methodical;
c) taking place as part of an overall data collection plan;
d) carried out as part of a strategy.
As an example, it cites data-driven marketing activities, such as location tracking—for example, through mobile apps, loyalty programs, or behavioral advertising.
Thus, in the case under review, it meets the criterion of being routine and in accordance with a data collection plan
to obtain customer data and expand its business reach. One need only glance at its privacy policy,
which shows that it collects all kinds of data, including the IP address (a key point of
location), browsing history, and User preferences, as well as data derived from cookies—including
Tracking cookies—geolocation data, and billing data, among others.
And they collect this data on a regular basis, as they need it to provide their services and improve the performance
of their business.
Among other things, the privacy policy states that the data is used for statistical and service-related purposes.
Third, it must be determined whether the processing is on a large scale; regarding this, WP 243 establishes certain criteria, “recommending
that the following factors, in particular, be taken into account when determining whether the processing is carried out
on a large scale:
a) the number of data subjects affected, either as a specific figure or as a proportion of the
relevant population;
b) the volume of data or the variety of data elements being processed;
c) the duration or permanence of the data processing activity;
d). the geographic scope of the processing activity.
It cites as an example of “large-scale” processing “the processing of real-time geolocation data of customers
of an international fast-food chain for statistical purposes by a controller
specializing in the provision of these services; the processing of customer data in the normal course of
business by an insurance company or a bank.”
The EDPB does not define what constitutes “large scale” in any specific terms, but rather adheres to the criteria referenced.
This is made clear in other documents: “The GDPR does not precisely define what constitutes ‘large-
scale.’ In the WP29 guidelines on the Data Protection Officer (WP243) and on the DPIA (WP248), both endorsed by
Board, it has recommended taking several specific factors into account when determining whether processing
is carried out on a large scale. The Board is of the opinion that these factors are sufficient to assess whether
the processing of personal data is undertaken on a large scale. Therefore, the Board requests the Supervisory
Authority of the Czech Republic to amend its list accordingly, by deleting the explicit figures in its list, and
referring to the aforementioned definitions of “large scale,” Opinion 4/2018 on the draft list of
17
CASE LAW
the competent supervisory authority of the Czech Republic regarding the processing operations subject to the
requirement of a data protection impact assessment (Article 35(4) of the GDPR).”
We must supplement this with Recital 91 of the GDPR, which stipulates, with regard to data protection
impact assessments, that:
"This applies, in particular, to large-scale processing operations intended to process
a considerable amount of personal data at the regional, national, or supranational level and which could affect
a large number of data subjects and are likely to result in a high risk, for example, due to the sensitivity of the data,
where, depending on the level of technical expertise achieved, new technology has been used on a large
scale, and to other processing operations that pose a high risk to the rights and freedoms of
data subjects, in particular where such operations make it more difficult for data subjects to exercise their
rights...". 
Large-scale processing involves processing a considerable amount of personal data (all of which are listed
in its privacy policy) within a specific territorial scope (in this case, at the national level); affecting
multiple data subjects (this is a widely used app with a large number of data subjects);
and may also entail a high risk (one of the data points used is geolocation).
Having examined the parameters outlined in this specific case, it is clear that this constitutes large-scale data processing.
The Confederation of European Data Protection Organizations (CEDPO) also establishes a series of common
interpretive criteria (which are neither binding nor a regulatory provision) and indicates, insofar as it may
be relevant to us, that:
“Core activities” must be construed in accordance with the description of the organization’s corporate purpose
and its P&L revenues; “Large scale” should be understood according to a risk-based approach
(rather than relying solely on criteria such as the number of employees or the “volume” of personal data processed within a certain
period of time); “Monitoring of behavior” shall exclude the IT monitoring activities that any organization
must carry out today for the purposes of (i) (cyber)security; (ii) protecting the organization’s systems and
assets (including intellectual property and confidential information, as well as the personal data stored or otherwise processed by
the organization); and (iii) complying with laws and regulatory guidance (e.g., data protection obligations, anti-fraud
and anti-money laundering activities).”
In response to the allegations raised in the complaint regarding the quantitative criteria that may be used
other supervisory authorities to determine when processing is on a large scale, we
must point out that the AEPD is an independent supervisory authority that, in the performance of its duties,
determines in each specific case whether or not the processing is on a large scale, taking into account the
relevant circumstances.
On another note, we would point out that the mandatory appointment of a DPO in the case provided for in
Article 37(1)(b) of the GDPR is linked solely to compliance with the conditions set forth therein and
not to other factors cited by the plaintiff, such as the type of data or processing operations. The fact
that the principal activities of the controller or processor consist of processing operations
which, due to their nature, scope, and/or purposes, require regular and systematic monitoring of data subjects
on a large scale already necessitates the appointment of a DPO, given the risks involved, especially if such
processing is carried out via the internet or an app, as in the case under review.
The role of the DPO as a qualified advisor to the controller or processor is an essential safeguard
in the cases provided for in the GDPR and the LOPDGDD to guarantee citizens’ fundamental rights
and prevent the materialization of risks that a given activity may entail.
Consider, for example, identity theft (Art. 28.2 of the LOPDGDD).
The notion that the risk is trivial is therefore ruled out.
In any case, failing to appoint a DPO when it is mandatory poses a risk to the protection of personal data.
In this regard, the LOPDGDD stipulates the following in Articles 34.1 and 3, regarding the appointment of a
data protection officer:
1. “Controllers and processors must appoint a data protection officer in
the cases provided for in Article 37.1 of Regulation (EU) 2016/679
3. Controllers and processors shall notify the Spanish Data Protection Authority
or, where applicable, the regional data protection authorities, within ten days, of the appointments,
18
CASE LAW
appointments and dismissals of data protection officers, both in cases where they are
required to appoint one and in cases where the appointment is voluntary.”
Based on the legal grounds set forth above, the facts indicated in the previous section
constitute a violation of Article 37 of the GDPR.
IV.-
c.- Penalty
This violation may be penalized with a fine of up to €10,000,000 or, in the case of an enterprise,
an amount equivalent to up to 2% of the total annual global turnover for the
, whichever is higher, in accordance with Article 83(4)(a) of the GDPR.
In this regard, Article 73 of the LOPDGDD considers the following to be a serious violation, for the purposes of the statute of limitations: “v) Failure to comply with
the obligation to designate a data protection officer
when such appointment is required in accordance with Article 37 of Regulation (EU) 2016/679 and Article
34 of this Organic Law.”
In accordance with the aforementioned provisions, for the purpose of determining the amount of the penalty to be imposed in this
case, it is considered appropriate to adjust the penalty in accordance with the following
aggravating factors established in Article 83(2) of the GDPR:
- The intentional nature of the violation on the part of KFC (subsection b), given that it is an entity
whose business involves the continuous processing of customers’ personal data; it is considered of
particular importance to recall at this point the Supreme Court ruling of October 17, 2007 (Case No. 63/2006), which states
that: “…the Supreme Court has held that negligence exists whenever a legal duty
of care is disregarded, that is, when the offender does not act with the required diligence. And in assessing
the degree of diligence, special consideration must be given to whether or not the individual is a professional, and there is no doubt
that, in the case now under review, given that the appellant’s activity involves the constant and extensive handling of
personal data, particular emphasis must be placed on rigor and the utmost care in complying with the
relevant legal provisions.”
It is further considered that the penalty to be imposed should be determined in accordance with the following
aggravating factors, as established in Article 76.2 of the LOPDGDD:
- The connection between the offender’s activity and the processing of personal data (subsection
b), considering the extent to which KFC is embedded in the country’s economy, involving
the personal
data of thousands of customers who access its services daily.
A balance of the circumstances set forth in Article 83.2 of the GDPR and Article 76.2 of the LOPDGDD, with respect to
the violation committed by breaching the provisions of Article 37.1 of the GDPR, allows for the imposition of a penalty of 20,000
euros (twenty thousand euros).
IV.—
Measures.
This Agency agrees to require the data controller to adopt appropriate measures to bring its actions
into compliance with the regulations mentioned in this decision, in accordance with the provisions of the aforementioned Article 58(2)(d) of the GDPR;
the corrective measure to be imposed on the website owner consists of appointing a Data Protection Officer
Data Protection Officer, as stipulated in Article 37 of the GDPR..."
SECOND. — The plaintiff argues in support of its appeal that the minor violation attributed to it
(failure to comply with the principle of transparency in its privacy policy) is unrelated to the initial complaint;
and that, if anything, a warning sanction would be appropriate.
Regarding the serious violation of the provisions of Article 37 of the GDPR (appointment of a data protection officer),
she contends that it does not apply, since, given her primary activity, she is not required to do so.
For his part, the State Lawyer maintains that the contested decisions are in accordance with the law.
THIRD. — Article 13 of the GDPR provides:
“1. Where personal data relating to a data subject are obtained from the data subject, the controller shall, at the
time of collection, provide the data subject with all the information set forth below:
a) the identity and contact details of the controller and, where applicable, of its representative;
19
CASE LAW
b) the contact details of the data protection officer, if any;
c) the purposes of the processing for which the personal data are intended and the legal basis for the processing;
d) where the processing is based on Article 6(1)(f), the legitimate interests of the controller or
of a third party;
e) the recipients or categories of recipients of the personal data, if applicable;
f) where applicable, the controller’s intention to transfer personal data to a third country or international organisation
and the existence or absence of a Commission adequacy decision, or, in the case of
transfers referred to in Articles 46 or 47 or the second paragraph of Article 49(1), a reference to
the appropriate or suitable safeguards and the means to obtain a copy of them or to the fact that they
have been provided.
2. In addition to the information referred to in paragraph 1, the controller shall provide the data subject,
at the time the personal data are collected, with the following information necessary to ensure
fair and transparent processing: (a) the period for which the personal data will be stored or,
where this is not possible, the criteria used to determine that period; b) the existence of the right to request
from the controller access to personal data concerning the data subject, and its rectification or
erasure, or the restriction of its processing, or to object to the processing, as well as the right to data
portability; c) where the processing is based on Article 6(1)(a) or Article 9(2)(
a), the existence of the right to withdraw consent at any time, without this affecting the lawfulness
of the processing based on consent prior to its withdrawal; d) the right to lodge a complaint with
a supervisory authority; e) whether the provision of personal data is a legal or contractual requirement, or a
necessary requirement for entering into a contract, and whether the data subject is obliged to provide the personal data
and is informed of the possible consequences of failing to provide such data; f) the existence of automated decision-making,
including profiling, as referred to in Article 22(1) and (4), and, at least in such
cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences
of such processing for the data subject.”
Recital 60 of the GDPR states:
“The principles of fair and transparent processing require that the data subject be informed of the existence of
the processing operation and its purpose.The controller must provide the data subject with any
additional information necessary to ensure fair and transparent processing, taking into account
the specific circumstances and context in which the personal data are processed. The data subject must also be informed
of the existence of profiling and the consequences of such profiling. If
personal data are obtained from the data subjects, they must also be informed as to whether they are required to
provide such data and of the consequences of failing to do so.Such information may be provided in
combination with standardized icons that offer, in an easily visible, intelligible, and clearly
legible manner, an adequate overview of the intended processing. Icons presented in electronic
format must be machine-readable." 
And Recital 61 of the GDPR states:
"Data subjects should be provided with information regarding the processing of their personal data at the time
it is collected from them or, if collected from another source, within a reasonable period of time, depending on the
circumstances of the case. If personal data may be lawfully disclosed to another recipient, the
data subject must be informed at the time the data is first disclosed to that recipient.The controller
who intends to process the data for a purpose other than that for which it was collected must
provide the data subject, prior to such further processing, with information regarding that other purpose and any other
necessary information. When the source of the personal data cannot be disclosed to the data subject because it was obtained from
from multiple sources, general information must be provided.”
With regard to our case, despite the plaintiff’s assertions, the complainant alleged to the AEPD that facts
detected on the KFC website could constitute breaches of obligations related to privacy
policies.
He listed potential violations of the GDPR regarding the aforementioned privacy policy, detailing a number of
violations that the complainant believed he had identified, adding, “I am sure there are more.”
In summary, these violations are as follows:
- lack of direct access to the privacy policies for Users in the European Economic Area;
- inability to create an account without agreeing to receive special offers and promotions;
20
CASE LAW
- the registration form does not provide a link to the privacy policies, even though these must
be accepted in order to create an account.
If we refer to the administrative record and, specifically, to the statement of defense filed by the respondent—now
plaintiff—submitted to the AEPD on August 20, 2021, it expressly acknowledges these violations and,
furthermore, as the appealed decision highlights, the appellant’s website contained only very generic references
regarding the purposes for which personal data would be used.
These references were along the lines of “personalizing your experience with us and promoting our
rewards and loyalty programs,” “… To share with third-party providers..." or "(...) share, sell, or disclose
your information with: Other Brands: We may share personal information with our parent enterprise: Yum
Brands and other Yum Brands enterprises and our subsidiaries, which may use your information in a manner similar
to that described in this Policy.”
Other non-compliant practices were also identified, noted, and addressed (We have taken
note of this shortcoming and will implement this improvement to provide greater clarity and transparency to the information
provided in the privacy policies, by redirecting Users to the Legal Notice in the privacy policy
to identify the controller in each jurisdiction, including Spain. These changes will be
implemented by the end of September 2021; regarding the lack of detail on data storage periods, although
this information may seem too generic, we take note and will make an improvement to provide
greater clarity and transparency to the information provided in the privacy policy; we will include
more specific storage criteria or storage periods in the privacy notice specific to the EEA and the UK.
Implementation date: These changes will be implemented by September 30, 2021....)
As we have already indicated, data protection regulations require, in this regard, that
information that is too generic or unspecific—which could conceal processing activities that exceed
the User’s reasonable expectations—be avoided; therefore, the information provided by the appellant to Users
regarding the privacy policy is inadequate, constituting a clear violation of Article 13 of the GDPR, which requires that, at
the time personal data is collected, the data subject be provided with all information regarding—among
other things—the purposes of the processing of their personal data and the legal basis for such processing.
Returning to the alleged “disconnect” between the initial complaint and the facts investigated by the AEPD, it must be
be noted that even if this were the case—which it is not—it is neither relevant nor does it have the nullifying consequences
that the plaintiff claims, since a data subject’s complaint may be nothing more than a means of bringing
a possible violation of data protection regulations to the attention of the supervisory authority.
What cannot be concluded—nor is it required by any provision—is that the supervisory authority’s actions were
limited to the scope of the specific and concrete complaint filed by the data subjects, as this would entail an
absurd limitation on the AEPD’s supervisory powers.
As the State Lawyer points out, the CJEU takes a broad view of the powers of
supervisory authorities to impose sanctions for violations of the GDPR, regardless of whether such sanctions may
stem directly from a complaint (Judgments of the CJEU of July 16, 2020, C-311/18, Data Protection
Commissioner Schrems 2, and of October 6, 2015, C-362/14, Schrems).
According to the first of these judgments:
“109 Furthermore, pursuant to Article 57(1)(f) of the GDPR, it is incumbent upon each supervisory authority, within
its territory, to handle complaints that any person, in accordance with Article 77(1) of the
aforementioned Regulation, may lodge if they consider that the processing of personal data concerning them
infringes that Regulation, and to examine the substance of such complaints to the extent necessary. The supervisory authority
must handle such complaints with all due diligence (see, by analogy, with
respect to Article 25(6) of Directive 95/46, the judgement of October 6, 2015, Schrems,
C-362/14, EU:C:2015:650, paragraph 63).
111 To enable them to handle the complaints lodged, Article 58(1) of the GDPR confers on each
supervisory authority significant investigative powers. (...) is required, pursuant to Union law,
Union law, to take appropriate action to remedy the identified deficiency, regardless
of the origin or nature of that deficiency. For the purpose, article 58(2) of that Regulation
lists the various corrective powers available to the supervisory authority.”
Consequently, the claim raised by the plaintiff alleging a disconnect between
the initial complaint and the investigation and sanctioning proceedings conducted by the AEPD must be dismissed.
FOURTH. —With regard to the alleged lack of proportionality of the sanction imposed, specifically the
warning, the response must likewise be negative.
21
CASE LAW
As this Chamber has consistently held, citing the Supreme Court rulings of the Third Chamber dated December 3, 2008 (Case No. 6602/2004) and April 12,
April 2012 (Case No. 5149/2009), the principle of proportionality of sanctions—which is the fundamental
principle that underlies and governs the process of determining the severity of sanctions—implies, in legal terms, “their adequacy to the
severity of the act constituting the violation,” as provided for in Article 29.3 of Law 40/2015 on the
Legal Regime for the Public Sector. This is because every sanction must be determined in accordance with the nature of the
infraction committed and based on a criterion of proportionality in relation to the circumstances of the act.
This principle, as noted in the aforementioned Supreme Court ruling of April 12, 2012, cannot be exempt from judicial review.
The appellant, as previously stated, has committed a violation of Article 13 of the GDPR, for which, pursuant to Article
83.5(b), carries a fine of up to 20,000 E or, in the case of an enterprise, an amount
equivalent to 4% of its annual turnover; this is classified as a minor violation under Art. 74(a) of the LOPDGDD.
The fine of 5,000 E imposed is not considered disproportionate, given that numerous
breaches of the privacy policy were observed, even though the enterprise reacted immediately by adopting
corrective measures.
FIFTH.—Regarding the second of the violations attributed to the plaintiff—failure to appoint a
data protection officer—Art 37(1)(b) of the GDPR provides:
“1. The controller and the processor shall designate a data protection officer whenever:
b) the core activities of the controller or the processor consist of processing operations which, by
reason of their nature, scope, and/or purpose, require regular and systematic monitoring of data subjects
on a large scale.”
....
5. The data protection officer shall be appointed on the basis of his or her professional qualities and, in
particular, his or her expert knowledge of data protection law and practice and
his or her ability to perform the duties set forth in Article 39.
6. The data protection officer may be a member of the staff of the controller or processor
or may perform his or her duties under a service contract.
7. The controller or processor shall publish the contact details of the data protection officer
and shall communicate them to the supervisory authority.”
Organic Law 3/2018, in Article 34.1 and Article 3 on “Appointment of a data protection officer,” provides as follows:
“1. Controllers and processors must designate a data protection officer in
the cases provided for in Article 37.1 of Regulation (EU) 2016/679.
3. Controllers and processors shall notify the Spanish
Data Protection Authority or, where applicable, the regional data protection authorities, within ten days, of the designations,
appointments, and dismissals of data protection officers, both in cases where they are
required to designate a data protection officer as well as in cases where the designation is voluntary.”
As provided in Article 97 of the GDPR:
“When monitoring internal compliance with this Regulation, the controller or processor
must be assisted by a person with specialized knowledge of the law and practice in
the field of data protection—if the processing is carried out by a public authority, with the exception of courts
or other independent judicial authorities in the exercise of their judicial functions; if the processing is carried out
in the private sector by a controller whose core activities consist of large-scale processing operations
requiring regular and systematic Tracking of data subjects; or if the
main activities of the controller or processor consist of the large-scale processing of special categories
of personal data and data relating to criminal convictions and offenses.In the private sector, the
main activities of a data controller are related to its core business and are not related to the
processing of personal data as ancillary activities.The level of specialized knowledge required
must be determined, in particular, based on the data processing operations carried out and
the level of protection required for the personal data processed by the controller or processor. Such data protection officers, whether or not they are employees of the controller, must be in a position to
perform their duties and tasks independently.” 
The plaintiff considers that it is not required to appoint a data protection officer because, as
it asserts, its main activity is the restaurant business, which is conducted primarily in person at its
22
CASE LAW
establishments and restaurants, and that activity is not related to the processing of such
customers’ personal data as an ancillary activity.
Furthermore, she argues that the processing of her customers’ personal data is neither routine nor systematic, much less
“on a large scale.”
However, in light of these arguments, we must concur with the interpretation put forward by the
AEPD in the contested Resolution, drawing upon the “Guidelines on Data Protection Officers” (16/
WP243 rev. 01) drawn up by the Article 29 Data Protection Working Party (adopted on December 13,
2016, and revised and adopted on April 5, 2017).
First, as indicated in the Resolution, “the ‘main activities’ may be considered the key operations
necessary to achieve the objectives of the controller or processor,” although
“‘core activities’ should not be interpreted as exclusive when data processing is
an inseparable part of the activity of the controller or processor.”
A core activity is an operation necessary to achieve the objectives of the controller,
but this does not preclude the possibility that data processing may be an inseparable part of the
controller’s activity.
In our case, data processing is not the plaintiff’s core activity, but neither can it be separated
from it.
We need only refer to the list of ESTABLISHED FACTS, which shows that the plaintiff collects personal data
from Users through various procedures:
a) to create a user account;
b) to register as a job seeker with the network;
c) to place an online order for its products; and
d) to receive promotional offers.
It is also evident that the entity engages in advertising and commercial prospecting activities, carrying
out processing based on customer preferences and, consequently, performs activities that
involve profiling, interacts with social media platforms, and uses profile information and any other
data permitted by the social media platform that is shared with third parties..
Furthermore, on its website, the company refers to the purposes for which the personal data collected will be used,
including, among others, the following:
“(...) to personalize your experience with us and promote our rewards or loyalty programs
(...)",
"(...) share, sell, or disclose your information with: Other Brands: We may share personal information
with our parent enterprise, Yum Brands, and other Yum Brands enterprises and our affiliates, which may
use your information in a manner similar to that described in this Policy.
The entity also states that it may share the personal data collected with its external
service providers.
In accordance with the requirements of Article 37(1)(b) of the GDPR, the AEPD Resolution notes that the Art 29 Working Party
interprets the term “habitual” to have one or more of the following meanings:
a) continuous or occurring at specific intervals over a specific period;
b) recurring or repeated at predetermined times;
c) taking place on a constant or periodic basis.
It interprets “systematic” to mean one or more of the following:
a) occurring in accordance with a system;
b) preestablished, organized, or methodical;
c) taking place as part of an overall data collection plan;
d) carried out as part of a strategy.
As an example, it cites data-driven marketing activities, such as location tracking—for example, through mobile apps, loyalty programs, or behavioral advertising.
23
CASE LAW
It is clear that the plaintiff follows a plan to collect customer data in order to expand its
business (e.g., including the IP address, which is key to location tracking, browsing history, and
User preferences, data derived from cookies—including Tracking cookies—and
geolocation data...); and it does so on a regular basis to provide its services and to improve the performance
of its business.
Finally, it is also indisputable that the data processing is carried out on a large scale, given the criteria
established by WP 243, which “recommends” that the following factors be taken into account:
a) the number of data subjects affected, either as a specific figure or as a proportion of the
relevant population;
b) the volume of data or the variety of data elements being processed;
c) the duration or permanence of the data processing activity;
d) the geographic scope of the processing activity.
We have presented sufficient evidence to support the concurrence of these factors; therefore,
the plaintiff’s claim should be dismissed, and, for the same reasons set forth in Legal Ground 4,
there is no disproportion in the penalty imposed.
SIXTH.—Regarding the challenge to the AEPD’s Resolution of June 23, 2023—Case No. NUM000—by
which KFC RESTAURANTS SPAIN, S.L. was required, within TEN BUSINESS DAYS, to demonstrate
that it had adopted the appropriate corrective measures—this constitutes an act implementing the Resolution of February 13,
2023, in exercise of the powers granted under Art 58. 2 of the GDPR, the validity of which was not only not
challenged by the plaintiff, but—in its brief of arguments—it expressed its agreement with the measures
established by the AEPD regarding the privacy policy and the appointment of a
data protection officer—even though it set forth the reasons for its disagreement—it did not
object either.
In these proceedings, the plaintiff has not actually raised any challenge in this regard; therefore, no
ruling on this matter is warranted.
SEVENTH.—Pursuant to Art. 139.1 of the Law Governing this Jurisdiction, costs are to be imposed on the
plaintiff, whose claims have been dismissed in their entirety.
WE HEREBY RULED
FIRST.—To dismiss the present appeal No. 420/2023 filed by Court Attorney
Mr. IGNACIO LOPEZ CHOCARRO, on behalf of and with representation for the entity “KFC RESTAURANTS SPAIN,
S.L.U.,” against the Decision of February 13, 2023, issued by the Director of the Spanish Data Protection Agency
which dismisses the appeal filed against another decision dated June 8, 2022, which imposed on said
entity a fine of 5,000 E for a violation of Article 13 of the GDPR in relation to Article 83.5(b), classified as
minor under Article 74.1(a) of the LOPDPGDD, and a second penalty of 20,000 E for a violation of Article 37 of the
GDPR, classified as serious under Art 73 of the LOPDPGDD (PS/00140/2022).
And against the decision of the Director of the Spanish Data Protection Agency, dated June 23, 2023—
Case No. NUM000—requiring KFC RESTAURANTS SPAIN, S.L. to demonstrate, within TEN
BUSINESS DAYS, demonstrate that it had adopted the appropriate corrective measures consisting of bringing
the website www.kfc.es <WWW.kfc.es/> to the provisions of Article 13 of the GDPR, as well as the appointment
of a data protection officer.
SECOND.—To order the plaintiff to pay the costs of the appeal.
This judgement is subject to an appeal to the Court of Cassation, which must be filed with this Chamber within
30 days from the day following its notification; the brief preparing the appeal must
demonstrate compliance with the requirements set forth in Article 89(2) of the Jurisdiction Act,
justifying the objective interest in appealing to the Supreme Court.
Thus, by this judgement of ours, a certified copy of which shall be forwarded together with the administrative record to its
office of origin for enforcement, we hereby render, order, and sign this judgement.
The dissemination of the text of this decision to data subjects not involved in the proceedings in which it was rendered may only
take place after the personal data contained therein has been anonymized and with
full respect for the right to privacy, the rights of data subjects requiring special protection,
protection, or the guarantee of anonymity for victims or those who have suffered harm, where applicable.
The personal data included in this ruling may not be transferred or disclosed for purposes contrary
to the law.