Spain Spain

REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS, S.L.

1,380,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2025-05-26.

Rank · Sector
#27
of 167 in Transportation and Energy
Rank · Spain
#26
of 1,075
Rank · All fines
#149
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2025-05-26
Controller / Processor
REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS, S.L.
Sector
Transportation and Energy
Quoted Articles
Art. 5 (1) d) GDPR, Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Spanish DPA imposed a fine of EUR 1,380,000 on REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS, S.L. The controller used outdated technical and organisational measures to manage customer contracts. This resulted in an individual receiving energy bills, without having a contract with the controller. The size of the controller, a multinational company, and the large amount of personal data being processed, were seen as aggravating factors.

Open original source Links to the regulator's original publication or another source.

Related fines