Spain Spain

CENTROS COMERCIALES CARREFOUR, S.A.

3,200,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2025-03-14.

Rank · Sector
#15
of 597 in Industry and Commerce
Rank · Spain
#14
of 1,075
Rank · All fines
#98
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2025-03-14
Controller / Processor
CENTROS COMERCIALES CARREFOUR, S.A.
Sector
Industry and Commerce
Quoted Articles
Art. 5 (1) f) GDPR, Art. 32 GDPR, Art. 34 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Spanish DPA imposed a fine of EUR 3,200,000 on CENTROS COMERCIALES CARREFOUR, S.A. The controller suffered a cyberattack, resulting in the leak of a large amount of personal data. The controller failed to implement sufficient technical and organizational measures to ensure data security. Additionally, the notification of the data subjects in regards to the data breach was insufficient.

Open original source Links to the regulator's original publication or another source.

Related fines