Spain Spain

I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U.

3,500,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2024-02-05.

Rank · Sector
#14
of 165 in Transportation and Energy
Rank · Spain
#11
of 1,071
Rank · All fines
#90
of 3,042

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2024-02-05
Controller / Processor
I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U.
Sector
Transportation and Energy
Quoted Articles
Art. 5 (1) f) GDPR, Art. 32 GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The Spanish DPA has imposed a fine of EUR 3.5 million on I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U. The controller had suffered a cyber attack on its GEA web application resulting in the compromise of personal data of millions of customers. During its investigation, the DPA found that Iberdrola had not taken sufficient security measures to prevent the attack.

Open original source Links to the regulator's original publication or another source.

Related fines