AEPD (Spain) - PS-00008-2025
Spain's AEPD fines Ramona Films for failing to comply with a previous GDPR order.
Summary
Spain's data protection authority (AEPD) has fined Ramona Films, S.L. for failing to comply with a corrective order issued in previous GDPR proceedings. The company was initially fined for lacking a data processing agreement with a payment service provider and was ordered to provide the agreement. Instead, Ramona Films claimed joint controllership, providing an unsigned and undated agreement, which it later admitted was never signed. The AEPD found this to be a violation of Article 58(2) GDPR.
Full text
Help AEPD (Spain) - PS-00008-2025: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 12:20, 21 August 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators269 edits Tag: Decisions [1.0] Latest revision as of 13:48, 21 August 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators269 editsTag: Visual edit Line 97: Line 97: === Facts ====== Facts === RAMONA FILMS, S.L., the controller, operated websites offering audiovisual content through subscriptions. In November 2023, the DPA fined the controller in proceedings PS-00308-2023 for several GDPR infringements, including a breach of [[Article 28 GDPR|Article 28(3) GDPR]] concerning the absence of a data processing agreement with a payment service provider, the processor. The DPA also ordered the controller, pursuant to [[Article 58 GDPR|Article 58(2)(d) GDPR]], to provide within one month the processor agreement concluded with the processor.RAMONA FILMS, S.L., the controller, operated websites offering audiovisual content through subscriptions. In November 2023, the DPA fined the controller in proceedings [https://www.aepd.es/documento/ps-00308-2023.pdf PS-00308-2023] for several GDPR infringements, including a breach of [[Article 28 GDPR|Article 28(3) GDPR]] concerning the absence of a data processing agreement with a payment service provider, the processor. The DPA also ordered the controller, pursuant to [[Article 58 GDPR|Article 58(2)(d) GDPR]], to provide within one month the processor agreement concluded with the processor. In December 2023, instead of providing the requested agreement, the controller informed the DPA that the two companies should be considered joint controllers. Following an investigation, the controller provided an unsigned and undated purported joint controller agreement. It subsequently acknowledged that this agreement had never been signed.In December 2023, instead of providing the requested agreement, the controller informed the DPA that the two companies should be considered joint controllers. Following an investigation, the controller provided an unsigned and undated purported joint controller agreement. It subsequently acknowledged that this agreement had never been signed. Line 104: Line 104: The controller argued that it had complied with the measures imposed and requested the closure of the proceedings.The controller argued that it had complied with the measures imposed and requested the closure of the proceedings. === Holding ====== Holding === The DPA found that the controller had infringed [[Article 58 GDPR|Article 58(2) GDPR]] by failing to comply with the corrective order issued in the previous proceedings.The DPA found that the controller had infringed [[Article 58 GDPR|Article 58(2) GDPR]] by failing to comply with the corrective order issued in the previous proceedings. The DPA held that the controller had neither concluded the processor agreement required by the previous decision nor demonstrated that its relationship with the processor had instead been validly established as joint controllership under [[Article 26 GDPR|Article 26 GDPR]]. In particular, the purported joint controller agreement was unsigned and undated, and the controller ultimately acknowledged that it had never been concluded.The DPA held that the controller had neither concluded the processor agreement required by the previous decision nor demonstrated that its relationship with the processor had instead been validly established as joint controllership under [[Article 26 GDPR]]. In particular, the purported joint controller agreement was unsigned and undated, and the controller ultimately acknowledged that it had never been concluded. The DPA also rejected the controller's arguments that the relationship with the processor and the subscription service had been terminated. It considered that the controller had provided contradictory information throughout the investigation and had failed to substantiate these claims. Consequently, the DPA found that the corrective measure imposed under [[Article 58 GDPR|Article 58(2)(d) GDPR]] remained unfulfilled.The DPA also rejected the controller's arguments that the relationship with the processor and the subscription service had been terminated. It considered that the controller had provided contradictory information throughout the investigation and had failed to substantiate these claims. Consequently, the DPA found that the corrective measure imposed under [[Article 58 GDPR|Article 58(2)(d) GDPR]] remained unfulfilled. Latest revision as of 13:48, 21 August 2026 AEPD - PS-00008-2025 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 28(3) GDPR Article 58(2) GDPR Article 76 LOPDGDD Type: Investigation Outcome: Violation Found Started: 11.08.2025 Decided: 09.03.2026 Published: 19.08.2026 Fine: 60000.0 EUR Parties: RAMONA FILMS, S.L. National Case Number/Name: PS-00008-2025 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Spanish Original Source: AEPD (in ES) Initial Contributor: bms he DPA fined a controller €60,000 for failing to comply with a corrective order requiring it to formalise and report its relationship with a processor. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts RAMONA FILMS, S.L., the controller, operated websites offering audiovisual content through subscriptions. In November 2023, the DPA fined the controller in proceedings PS-00308-2023 for several GDPR infringements, including a breach of Article 28(3) GDPR concerning the absence of a data processing agreement with a payment service provider, the processor. The DPA also ordered the controller, pursuant to Article 58(2)(d) GDPR, to provide within one month the processor agreement concluded with the processor. In December 2023, instead of providing the requested agreement, the controller informed the DPA that the two companies should be considered joint controllers. Following an investigation, the controller provided an unsigned and undated purported joint controller agreement. It subsequently acknowledged that this agreement had never been signed. The controller also stated that it had terminated its relationship with the processor and discontinued its subscription service. However, it was unable to provide evidence of the termination and the DPA found that subscriptions continued to be available through the website and redirected users to the processor's payment service. The controller argued that it had complied with the measures imposed and requested the closure of the proceedings. Holding The DPA found that the controller had infringed Article 58(2) GDPR by failing to comply with the corrective order issued in the previous proceedings. The DPA held that the controller had neither concluded the processor agreement required by the previous decision nor demonstrated that its relationship with the processor had instead been validly established as joint controllership under Article 26 GDPR. In particular, the purported joint controller agreement was unsigned and undated, and the controller ultimately acknowledged that it had never been concluded. The DPA also rejected the controller's arguments that the relationship with the processor and the subscription service had been terminated. It considered that the controller had provided contradictory information throughout the investigation and had failed to substantiate these claims. Consequently, the DPA found that the corrective measure imposed under Article 58(2)(d) GDPR remained unfulfilled. When determining the fine, the DPA considered, inter alia, the duration and intentional nature of the infringement, the fact that the processing involved identification and payment data, the close connection between the controller's activity and per
Indicators of Compromise
- url — https://www.aepd.es/documento/ps-00308-2023.pdf