BASER COMERCIALIZADORA DE REFERENCIA, S.A.

€150,000

Insufficient legal basis for data processing

Decision Date

11 de abril de 2022

Authority

Spanish Data Protection Authority (aepd)

ES

Sector

Transportation and Energy

Country

ES

Law

GDPR

Status

FINAL

Description

The Spanish DPA has fined BASER COMERCIALIZADORA DE REFERENCIA, S.A., EUR 150,000. A customer of the company had filed a complaint with the DPA since their electricity supply contract was modified without their consent. This resulted in an increase in the electricity supply. In the course of its investigations, the DPA found that a fraudster had pretended to be the data subject by providing the name and ID number of the data subject. In this way, they were able to modify the data subject's contract. According to the DPA, the controller had not properly verified the identity of the fraudster before modifying the contract and, due to a lack of sufficient security measures, had not made sure that the inquirer was actually the data subject.

Legal Citations

Art. 6Art. 32

Issues & Violations

Insufficient legal basis for data processing

Stay Updated on Privacy Enforcement

We respect your privacy. One email per month, no spam, unsubscribe anytime.