Spain Spain

CAJA DE SEGUROS REUNIDOS, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.

24,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2022-10-09.

Rank · Sector
#153
of 322 in Finance, Insurance and Consulting
Rank · Spain
#327
of 1,075
Rank · All fines
#992
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2022-10-09
Controller / Processor
CAJA DE SEGUROS REUNIDOS, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.
Sector
Finance, Insurance and Consulting
Quoted Articles
Art. 6 (1) GDPR
Type of violation
Insufficient legal basis for data processing

Summary

The Spanish DPA has imposed a fine on CAJA DE SEGUROS REUNIDOS, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.. A data subject filed a complaint with the DPA. The data subject had taken out an insurance policy with the controller, the beneficiary of which was his ex-life partner at the time. After the separation, the ex-life partner asked the controller to change the debit entry for the premium from the data subject's account to her account. The controller carried out this change without the consent of the data subject. The DPA considered this to be an unlawful change to the personal data of the data subject. The original fine of EUR 40,000 was reduced to EUR 24,000 due to voluntary payment and admission of responsibility.

Open original source Links to the regulator's original publication or another source.

Related fines