Private individual
€5,000
Non-compliance with general data processing principles
Decision Date
March 16, 2023
Authority
Spanish Data Protection Authority (aepd)
ES
Sector
Individuals and Private Associations
Country
ES
Law
GDPRStatus
FINALDescription
The Spanish DPA has imposed a fine of EUR 5,000 on a private individual. The controller sent an e-mail with personal data to several recipients in an open distribution list. This made it possible for the recipients to view the e-mail addresses of all other recipients.
Legal Citations
Art. 5 (1)Art. 32 (1)
Issues & Violations
Non-compliance with general data processing principles