Equifax Iberica S.L.

€1,000,000

Insufficient legal basis for data processing

Decision Date

April 23, 2021

Authority

Spanish Data Protection Authority (aepd)

ES

Sector

Finance, Insurance and Consulting

Country

ES

Law

GDPR

Status

FINAL

Description

The Spanish DPA (AEPD) has imposed a fine of EUR 1,000,000 on Equifax Ibérica, SL. A total of 96 complaints were filed with the DPA against the controller because it had included personal data of individuals associated with alleged debts in the Judicial Claims and Public Entities File ('FIJ') without their consent. In some cases, these data were not even correct. According to the DPA, the processing of the data subjects' personal data involving the FIJ file had been unlawful and violated several data protection principles of data processing (lawfulness and transparency, purpose limitation, data minimization, and accuracy). In addition, the controller had not properly informed the data subjects about the processing of their data, thus violating its duty to inform them.

Legal Citations

Art. 5 (1)Art. 6 (1)Art. 14

Issues & Violations

Insufficient legal basis for data processing

Stay Updated on Privacy Enforcement

We respect your privacy. One email per month, no spam, unsubscribe anytime.