REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS, S.L.

€1,380,000

Insufficient technical and organisational measures to ensure information security

Date de décision

26 mai 2025

Autorité

Spanish Data Protection Authority (aepd)

ES

Secteur

Transportation and Energy

Pays

ES

Droit

GDPR

Statut

FINAL

Description

The Spanish DPA imposed a fine of EUR 1,380,000 on REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS, S.L. The controller used outdated technical and organisational measures to manage customer contracts. This resulted in an individual receiving energy bills, without having a contract with the controller. The size of the controller, a multinational company, and the large amount of personal data being processed, were seen as aggravating factors.

Citations légales

Art. 5 (1)Art. 32

Questions et violations

Insufficient technical and organisational measures to ensure information security

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.