BASER COMERCIALIZADORA DE REFERENCIA, S.A.

€150,000

Insufficient legal basis for data processing

Datum odločitve

11. april 2022

Organ

Spanish Data Protection Authority (aepd)

ES

Sektor

Transportation and Energy

Država

ES

Zakon

GDPR

Status

FINAL

Opis

The Spanish DPA has fined BASER COMERCIALIZADORA DE REFERENCIA, S.A., EUR 150,000. A customer of the company had filed a complaint with the DPA since their electricity supply contract was modified without their consent. This resulted in an increase in the electricity supply. In the course of its investigations, the DPA found that a fraudster had pretended to be the data subject by providing the name and ID number of the data subject. In this way, they were able to modify the data subject's contract. According to the DPA, the controller had not properly verified the identity of the fraudster before modifying the contract and, due to a lack of sufficient security measures, had not made sure that the inquirer was actually the data subject.

Pravne navedbe

Art. 6Art. 32

Vprašanja in kršitve

Insufficient legal basis for data processing

Spremljajte novice o uveljavljanju zasebnosti

Spoštujemo vašo zasebnost. Eno e-poštno sporočilo na mesec, brez neželene pošte, odjava kadar koli.