Private individual

€3,000

Non-compliance with general data processing principles

Decision Date

June 6, 2023

Authority

Spanish Data Protection Authority (aepd)

ES

Sector

Individuals and Private Associations

Country

ES

Law

GDPR

Status

FINAL

Description

The Spanish DPA has fined a private individual EUR 3,000. An individual had filed a complaint with the DPA against the controller due to the fact that the controller had provided them with a false receipt that contained another customer's data and not their own. During its investigation, the DPA found that the controller had failed to implement adequate technical and organizational measures to protect personal data.

Legal Citations

Art. 5 (1)Art. 32 (1)

Issues & Violations

Non-compliance with general data processing principles

Stay Updated on Privacy Enforcement

We respect your privacy. One email per month, no spam, unsubscribe anytime.