BASER COMERCIALIZADORA DE REFERENCIA, S.A.

€150,000

Insufficient legal basis for data processing

Date de décision

11 avril 2022

Autorité

Spanish Data Protection Authority (aepd)

ES

Secteur

Transportation and Energy

Pays

ES

Droit

GDPR

Statut

FINAL

Description

The Spanish DPA has fined BASER COMERCIALIZADORA DE REFERENCIA, S.A., EUR 150,000. A customer of the company had filed a complaint with the DPA since their electricity supply contract was modified without their consent. This resulted in an increase in the electricity supply. In the course of its investigations, the DPA found that a fraudster had pretended to be the data subject by providing the name and ID number of the data subject. In this way, they were able to modify the data subject's contract. According to the DPA, the controller had not properly verified the identity of the fraudster before modifying the contract and, due to a lack of sufficient security measures, had not made sure that the inquirer was actually the data subject.

Citations légales

Art. 6Art. 32

Questions et violations

Insufficient legal basis for data processing

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.