AEPD (Spain) - PS/00249/2025
Spain's AEPD fines solar company €10,000 for unsolicited marketing calls.
Summary
The Spanish Data Protection Agency (AEPD) has fined MÁS SOL ENERGÍA 15, S.L. €10,000 for making unsolicited marketing calls without valid consent and failing to provide required GDPR information. The company obtained data from external providers and could not prove the data subject had consented or that the data source was legitimate, despite claims of online form acceptance.
Full text
Help AEPD (Spain) - PS/00249/2025: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 09:56, 7 August 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators245 edits Tag: Decisions [1.0] (No difference) Latest revision as of 09:56, 7 August 2026 AEPD - PS/00249/2025 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 4(11) GDPR Article 5(2) GDPR Article 7 GDPR Article 14 GDPR Article 23(4) LOPDGDDArticle 66 Spanish Telecommunications Law (11/2022) Type: Complaint Outcome: Upheld Started: 04.02.2026 Decided: Published: 31.07.2026 Fine: 10000.0 EUR Parties: MÁS SOL ENERGÍA 15, S.L. National Case Number/Name: PS/00249/2025 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Spanish; Castilian Original Source: AEPD (in ES) Initial Contributor: bms The DPA fined a solar energy company €10,000 for making an unsolicited marketing call without proving valid consent and for failing to provide Article 14 GDPR information. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts MÁS SOL ENERGÍA 15, S.L., the controller, is a company that carries out customer acquisition through telephone calls to offer solar panel installation services. On 18 November 2024, the data subject received a marketing call from an agent acting on behalf of the controller. The agent addressed the data subject by name and asked questions about the type of residence in which he lived. When the data subject asked whether the controller had checked the Robinson List, the agent stated that this was unnecessary because the call was based on a “database”. When the data subject subsequently asked about the source of his personal data, the call ended. The data subject later contacted the controller’s customer service to enquire about the source of his data and was told that the data had been obtained by its sales department and might originate from his acceptance of cookies. The data subject disputed this, stating that he had never visited the controller’s website. At the time of the call, his telephone number had been registered with the Robinson List since March 2024. The controller explained that it obtained databases from external marketing providers which guaranteed that the personal data had been lawfully collected. It claimed that the data subject had consented in June 2020 through an online form to the processing of his data, the receipt of marketing communications and the disclosure of his data to third parties. As evidence, the controller provided a record containing the data subject’s details, an IP address, a timestamp and consent indicators, as well as a generic version of the relevant online form. However, the form was blank and did not contain any information specifically identifying the data subject. The controller also acknowledged that it did not independently verify the validity of the consent provided by its external supplier. Holding The DPA held that the controller violated Article 66(1)(b) LGTel and Article 14 GDPR. First, regarding the commercial call, the DPA considered that the controller had not demonstrated that the data subject had given valid consent within the meaning of Article 4(11) GDPR. The documentation provided did not establish that the data subject personally completed the registration, entered the telephone number or could be linked to the IP address contained in the record. Moreover, the controller did not provide the privacy policy applicable when the alleged consent was obtained, meaning that it could not establish the purposes or third parties covered by that consent. The DPA recalled that, pursuant to Articles 5(2) and 7 GDPR, it is for the controller to demonstrate that valid consent was obtained. This responsibility could not be transferred to the external data provider through contractual guarantees. The controller remained responsible for establishing a valid legal basis for using the purchased data for its own marketing campaign. This was particularly relevant because the data subject's telephone number was registered with the Robinson List. In the absence of sufficiently demonstrated specific consent allowing the controller to contact the data subject notwithstanding that registration, the controller could not rely on the exception under Article 23(4) LOPDGDD. Consequently, the DPA found that the unsolicited call lacked a valid legal basis and violated Article 66(1)(b) LGTel. Second, the DPA found a violation of Article 14 GDPR. Since the controller had obtained the personal data from a third party, it was required to provide the information listed in Article 14 GDPR. During the call, the agent merely referred to an unspecified “database” and did not adequately inform the data subject about the source of the data, the controller's identity, the legal basis for the processing or his data protection rights. The duration or termination of the call did not relieve the controller of this obligation, and the controller had not demonstrated that the required information was provided through another channel. The DPA imposed a fine of €5,000 for the violation of Article 66(1)(b) LGTel and a further €5,000 for the violation of Article 14 GDPR, resulting in a total fine of €10,000. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Spanish; Castilian original. Please refer to the Spanish; Castilian original for more details. Case No.: EXP202416818 (PS/00249/2025) DECISION IN THE ENFORCEMENT PROCEEDING Based on the proceedings conducted by the Spanish Data Protection Agency (hereinafter hereinafter, “AEPD”) and based on the following, BACKGROUND FIRST: On November 21, 2024, A.A.A. (hereinafter, the complainant) filed a complaint with the AEPD. The complaint is directed against the entity MÁS SOL ENERGÍA 15, S.L., with Tax ID No. B90346370 (hereinafter “MÁS SOL” or the “respondent”) for the alleged violation of Law 11/2022 of June 28, the General Telecommunications Law (hereinafter “LGTel”), and Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data (hereinafter the “GDPR”), and Organic Law 3/2018, of December 5, on Data Protection Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD). The complainant states in his complaint that on November 18, 2024, he received a sales call from the number ***PHONE.1, in which an agent identified as “B.B.B.” stated that she was calling on behalf of “Mas Sol,” an enterprise specializing in the installation of solar panels, and that she addressed him by name and asked whether he lived in an apartment or a single-family home. He notes that, when the data subject asked whether the company had previously checked the Robinson List, the caller responded that they were under no obligation to do so because they relied on a “database.” He adds that, when he tried to ask about the source of his personal data, the call was unilaterally disconnected. Subsequently, he contacted the enterprise’s customer service to find out the source of his personal data, and was told that this information was handled by the sales department and that it presumably stemmed from his acceptance of cookies—a claim he considers untrue, as he had ever visited the company’s website or given consent. The following documentation, among others, is submitted along with the complaint letter: - Screenshot of the call history from the complainant’s mobile device, showing an incoming call from the number ***PHONE.1, received on Monday, November 18, 2024, at 1:24 p.m., lasting 46 seconds, along with an audio recording of the call. - Ce