AEPD (Spain) - EXP202406239
Spain's AEPD upholds €1M GDPR fine against an energy company for inadequate call center identity verification.
Summary
Spain's Data Protection Agency (AEPD) has rejected an energy company's appeal and confirmed a €1,000,000 fine for inadequate identity verification protocols. The AEPD found that the call center's method, relying on static and easily accessible customer data without multi-factor authentication, violated GDPR Article 32. The agency also noted the lack of audit trails for verification processes as a failure to demonstrate compliance.
Full text
Help AEPD (Spain) - EXP202406239: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 11:12, 8 July 2026 view sourceNata (talk | contribs)4 editsTag: submission [1.0]← Older edit Latest revision as of 07:29, 16 September 2026 view source Sfl (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators567 editsm Tag: Visual edit Line 83: Line 83: }}}} The DPA rejected an energy company's internal appeal and upheld a €1,000,000 fine under [[Article 32 GDPR|Article 32 GDPR]], holding that a call centre identity verification protocol based on static, easily accessible customer data was inadequate.The DPA rejected an energy company's internal appeal and upheld a €1,000,000 fine under [[Article 32 GDPR]], holding that a call centre identity verification protocol based on static, easily accessible customer data was inadequate. == English Summary ==== English Summary == Line 99: Line 99: The DPA rejected all grounds of appeal and confirmed the fine of €1,000,000 and the corrective order.The DPA rejected all grounds of appeal and confirmed the fine of €1,000,000 and the corrective order. First, on the alleged violation of the right to be heard, the DPA held that no submissions to the proposed resolution had ever been received, neither around the date claimed by the controller (14 November 2025) nor under the registry number it cited, and that the controller had not even attached the alleged proof of filing to its appeal. Since the controller had been able to make submissions at every stage of the procedure, no violation of its right of defence had occurred. The DPA also recalled, under [[Article 118 GDPR]] Article 118 LPACAP, that facts and documents which a party could have submitted during the hearing phase but did not cannot be taken into account when deciding an appeal.First, on the alleged violation of the right to be heard, the DPA held that no submissions to the proposed resolution had ever been received, neither around the date claimed by the controller (14 November 2025) nor under the registry number it cited, and that the controller had not even attached the alleged proof of filing to its appeal. Since the controller had been able to make submissions at every stage of the procedure, no violation of its right of defence had occurred. The DPA also recalled, under Article 118 LPACAP, that facts and documents which a party could have submitted during the hearing phase but did not cannot be taken into account when deciding an appeal. Second, on the presumption of innocence, the DPA held that the sanctioning resolution had established, on the basis of the documents in the file, that the verification protocol did not meet the requirements of [[Article 32 GDPR]]. The guide listed nine categories of data but did not specify which four an agent had to request in each case or according to which criteria. The data used were static and, in many cases, easily accessible to third parties, and allowing verification with any 4 of 9 categories widened the combinations an unauthorised third party could know or deduce. The DPA held that this did not amount to multi-factor verification, since the system combined only personal data of the holder without any additional authentication factor such as passwords or one-time codes. It also held that the guide itself allowed agents to update a customer's telephone number or e-mail address when these appeared spontaneously during a conversation, without asking for the customer's confirmation, which could compromise future authentication and the accuracy of the database. Finally, the lack of any record of which data were requested and provided during verification made it impossible to reconstruct the process in case of an incident or audit, contrary to [[Article 32 GDPR#1b|Article 32(1)(b) GDPR]] and the accountability duty in [[Article 24 GDPR]].Second, on the presumption of innocence, the DPA held that the sanctioning resolution had established, on the basis of the documents in the file, that the verification protocol did not meet the requirements of [[Article 32 GDPR]]. The guide listed nine categories of data but did not specify which four an agent had to request in each case or according to which criteria. The data used were static and, in many cases, easily accessible to third parties, and allowing verification with any 4 of 9 categories widened the combinations an unauthorised third party could know or deduce. The DPA held that this did not amount to multi-factor verification, since the system combined only personal data of the holder without any additional authentication factor such as passwords or one-time codes. It also held that the guide itself allowed agents to update a customer's telephone number or e-mail address when these appeared spontaneously during a conversation, without asking for the customer's confirmation, which could compromise future authentication and the accuracy of the database. Finally, the lack of any record of which data were requested and provided during verification made it impossible to reconstruct the process in case of an incident or audit, contrary to [[Article 32 GDPR#1b|Article 32(1)(b) GDPR]] and the accountability duty in [[Article 24 GDPR]]. Third, on strict liability, the DPA held that the infringement had been committed at least negligently. Citing the CJEU judgment of 5 December 2023, C‑807/21 (Deutsche Wohnen), and Spanish case law, it noted that a controller can be fined under [[Article 83 GDPR]] when it could not have been unaware of the infringing nature of its conduct. Although [[Article 32 GDPR|Article 32 GDPR]] imposes an obligation of means rather than of result, an entity of the controller's size could not be considered to have adopted measures adequate to the risk when its verification, traceability and database update procedures showed clear deficiencies.Third, on strict liability, the DPA held that the infringement had been committed at least negligently. Citing the CJEU judgment of 5 December 2023, C‑807/21 (Deutsche Wohnen), and Spanish case law, it noted that a controller can be fined under [[Article 83 GDPR]] when it could not have been unaware of the infringing nature of its conduct. Although [[Article 32 GDPR]] imposes an obligation of means rather than of result, an entity of the controller's size could not be considered to have adopted measures adequate to the risk when its verification, traceability and database update procedures showed clear deficiencies. Fourth, on proportionality, the DPA held that the fine was calculated under the GDPR's own system, which applies as lex specialis over the general rules of administrative law. Starting from a turnover of €11,353,755,000, the maximum fine under [[Article 83 GDPR#4|Article 83(4) GDPR]] was €227,075,100. To set the level of seriousness under [[Article 83 GDPR#2|Article 83(2) GDPR]] and the EDPB Guidelines 04/2022 on the calculation of administrative fines, the DPA considered that all of the controller's customers were potentially affected (contextualised with the figure of 7,146,778 supply points), that the infringement lasted more than 18 months, and that the data at stake, including DNI and bank account numbers, qualified as sensitive within the meaning of the Guidelines even though they were not special categories under [[Article 9 GDPR]]. Negligence was assessed as neutral. As aggravating factors, the DPA applied [[Article 83 GDPR#2e|Article 83(2)(e) GDPR]], given a previous infringement in PS/00398/2021, and Article 76(2)(b) LOPDGDD in relation to [[Article 83 GDPR#2k|Article 83(2)(k) GDPR]]. It rejected the comparison with the €500,000 fine in EXP202500113, since that bank had a turnover more than ten times lower, an infringement lasting less than six months and no prior sanctions.Fourth, on proportionality, the DPA held that the fine was calculated under the GDPR's own system, which applies as lex specialis over the