Spain Spain

EDP Comercializadora, S.A.U.

1,500,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2021-05-04.

Rank · Sector
#25
of 167 in Transportation and Energy
Rank · Spain
#23
of 1,075
Rank · All fines
#136
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2021-05-04
Controller / Processor
EDP Comercializadora, S.A.U.
Sector
Transportation and Energy
Quoted Articles
Art. 13 GDPR, Art. 25 GDPR
Type of violation
Insufficient fulfilment of information obligations

Summary

The Spanish DPA (AEPD) has imposed a fine of EUR 1,500,000 on EDP Comercializadora, S.A.U.. The decision follows, in particular, several complaints received for processing personal data without consent. As the DPA found, the controller had failed to inform data subjects in accordance with Art. 13 GDPR when collecting their data. This involved data subjects not being informed of their rights under Art. 15 GDPR - Art. 22 GDPR, and the contact details of the controller (e.g. its address) being incomplete. Besides, the company's business practice allowed it to conclude contracts with customer representatives instead of with the customers directly. In these cases, however, the data controller did not check whether there was actually an authorization to represent the data subjects. The DPA finds that the controller failed to implement a procedure to verify the authorization of the alleged representatives.The fine is composed proportionately of EUR 1,000,000 for a breach of Art. 13 GDPR and EUR 500,000 for a breach of Art. 25 GDPR.

Open original source Links to the regulator's original publication or another source.

Related fines