Spain Spain

BASER COMERCIALIZADORA DE REFERENCIA, S.A.

150,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2022-04-11.

Rank · Sector
#53
of 167 in Transportation and Energy
Rank · Spain
#83
of 1,075
Rank · All fines
#407
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2022-04-11
Controller / Processor
BASER COMERCIALIZADORA DE REFERENCIA, S.A.
Sector
Transportation and Energy
Quoted Articles
Art. 6 GDPR, Art. 32 GDPR
Type of violation
Insufficient legal basis for data processing

Summary

The Spanish DPA has fined BASER COMERCIALIZADORA DE REFERENCIA, S.A., EUR 150,000. A customer of the company had filed a complaint with the DPA since their electricity supply contract was modified without their consent. This resulted in an increase in the electricity supply. In the course of its investigations, the DPA found that a fraudster had pretended to be the data subject by providing the name and ID number of the data subject. In this way, they were able to modify the data subject's contract.

According to the DPA, the controller had not properly verified the identity of the fraudster before modifying the contract and, due to a lack of sufficient security measures, had not made sure that the inquirer was actually the data subject.

Open original source Links to the regulator's original publication or another source.

Related fines