Spain Spain

Equifax Iberica S.L.

1,000,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2021-04-23.

Rank · Sector
#28
of 322 in Finance, Insurance and Consulting
Rank · Spain
#30
of 1,071
Rank · All fines
#164
of 3,042

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2021-04-23
Controller / Processor
Equifax Iberica S.L.
Sector
Finance, Insurance and Consulting
Quoted Articles
Art. 5 (1) a), b), c), d) GDPR, Art. 6 (1) GDPR, Art. 14 GDPR
Type of violation
Insufficient legal basis for data processing

Summary

The Spanish DPA (AEPD) has imposed a fine of EUR 1,000,000 on Equifax Ibérica, SL. A total of 96 complaints were filed with the DPA against the controller because it had included personal data of individuals associated with alleged debts in the Judicial Claims and Public Entities File ("FIJ") without their consent. In some cases, these data were not even correct. According to the DPA, the processing of the data subjects' personal data involving the FIJ file had been unlawful and violated several data protection principles of data processing (lawfulness and transparency, purpose limitation, data minimization, and accuracy). In addition, the controller had not properly informed the data subjects about the processing of their data, thus violating its duty to inform them.

Open original source Links to the regulator's original publication or another source.

Related fines