20 AÑOS DE MÚSICA A.I.E.
Non-compliance with general data processing principles
Decision Date
June 17, 2024
Authority
Spanish Data Protection Authority (aepd)
ES
Sector
Industry and Commerce
Country
ES
Law
GDPRStatus
FINALDescription
The Spanish DPA has imposed a fine on 20 AÑOS DE MÚSICA A.I.E.. A person had filed a complaint with the DPA due to the fact that in order for minors to attend concerts organized by the controller, powers of attorney from their legal guardians as well as copies of the identity documents of both the legal guardians and the minors were required. During its investigation, the DPA found that such extensive data collection would not have been necessary and violated the principle of data minimization. The DPA also found that the controller had not sufficiently informed the data subjects about the data processing. For example, the controller failed to provide precise information on the exercise of data subjects' rights. The original fine of EUR 5,000 was reduced to EUR 3,000 due to voluntary payment and admission of responsibility.