AEPD (Spain) - PS/00249/2025
Spain's AEPD fines solar company €10,000 for unsolicited marketing calls.
Summary
Spain's data protection authority (AEPD) has fined a solar energy company €10,000 for making unsolicited marketing calls without valid consent and failing to provide GDPR Article 14 information. The company could not prove the data subject had given consent, nor did it provide the applicable privacy policy at the time of consent.
Full text
Help AEPD (Spain) - PS/00249/2025: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 09:56, 7 August 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators246 edits Tag: Decisions [1.0] Latest revision as of 10:18, 7 August 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators246 editsTag: Visual edit Line 104: Line 104: }}}} The DPA fined a solar energy company €10,000 for making an unsolicited marketing call without proving valid consent and for failing to provide [[Article 14 GDPR|Article 14 GDPR]] information.The DPA fined a solar energy company €10,000 for making an unsolicited marketing call without proving valid consent and for failing to provide [[Article 14 GDPR]] information. == English Summary ==== English Summary == Line 118: Line 118: As evidence, the controller provided a record containing the data subject’s details, an IP address, a timestamp and consent indicators, as well as a generic version of the relevant online form. However, the form was blank and did not contain any information specifically identifying the data subject. The controller also acknowledged that it did not independently verify the validity of the consent provided by its external supplier.As evidence, the controller provided a record containing the data subject’s details, an IP address, a timestamp and consent indicators, as well as a generic version of the relevant online form. However, the form was blank and did not contain any information specifically identifying the data subject. The controller also acknowledged that it did not independently verify the validity of the consent provided by its external supplier. === Holding ====== Holding === The DPA held that the controller violated Article 66(1)(b) LGTel and [[Article 14 GDPR|Article 14 GDPR]].The DPA held that the controller violated [https://www.boe.es/buscar/act.php?id=BOE-A-2022-10757 Article 66(1)(b) LGTel] and [[Article 14 GDPR]]. First, regarding the commercial call, the DPA considered that the controller had not demonstrated that the data subject had given valid consent within the meaning of [[Article 4 GDPR|Article 4(11) GDPR]]. The documentation provided did not establish that the data subject personally completed the registration, entered the telephone number or could be linked to the IP address contained in the record. Moreover, the controller did not provide the privacy policy applicable when the alleged consent was obtained, meaning that it could not establish the purposes or third parties covered by that consent.First, regarding the commercial call, the DPA considered that the controller had not demonstrated that the data subject had given valid consent within the meaning of [[Article 4 GDPR|Article 4(11) GDPR]]. The documentation provided did not establish that the data subject personally completed the registration, entered the telephone number or could be linked to the IP address contained in the record. Moreover, the controller did not provide the privacy policy applicable when the alleged consent was obtained, meaning that it could not establish the purposes or third parties covered by that consent. The DPA recalled that, pursuant to Articles 5(2) and 7 GDPR, it is for the controller to demonstrate that valid consent was obtained. This responsibility could not be transferred to the external data provider through contractual guarantees. The controller remained responsible for establishing a valid legal basis for using the purchased data for its own marketing campaign. The DPA recalled that, pursuant to [[Article 5 GDPR|Articles 5(2)]] and [[Article 7 GDPR|7 GDPR]], it is for the controller to demonstrate that valid consent was obtained. This responsibility could not be transferred to the external data provider through contractual guarantees. The controller remained responsible for establishing a valid legal basis for using the purchased data for its own marketing campaign. This was particularly relevant because the data subject's telephone number was registered with the Robinson List. In the absence of sufficiently demonstrated specific consent allowing the controller to contact the data subject notwithstanding that registration, the controller could not rely on the exception under Article 23(4) LOPDGDD. Consequently, the DPA found that the unsolicited call lacked a valid legal basis and violated Article 66(1)(b) LGTel.This was particularly relevant because the data subject's telephone number was registered with the Robinson List. In the absence of sufficiently demonstrated specific consent allowing the controller to contact the data subject notwithstanding that registration, the controller could not rely on the exception under [https://www.boe.es/buscar/act.php?id=BOE-A-2018-16673 Article 23(4) LOPDGDD]. Consequently, the DPA found that the unsolicited call lacked a valid legal basis and violated [https://www.boe.es/buscar/act.php?id=BOE-A-2022-10757 Article 66(1)(b) LGTel]. Second, the DPA found a violation of [[Article 14 GDPR|Article 14 GDPR]]. Since the controller had obtained the personal data from a third party, it was required to provide the information listed in [[Article 14 GDPR|Article 14 GDPR]]. During the call, the agent merely referred to an unspecified “database” and did not adequately inform the data subject about the source of the data, the controller's identity, the legal basis for the processing or his data protection rights. The duration or termination of the call did not relieve the controller of this obligation, and the controller had not demonstrated that the required information was provided through another channel. Second, the DPA found a violation of [[Article 14 GDPR]]. Since the controller had obtained the personal data from a third party, it was required to provide the information listed in [[Article 14 GDPR]]. During the call, the agent merely referred to an unspecified “database” and did not adequately inform the data subject about the source of the data, the controller's identity, the legal basis for the processing or his data protection rights. The duration or termination of the call did not relieve the controller of this obligation, and the controller had not demonstrated that the required information was provided through another channel. The DPA imposed a fine of €5,000 for the violation of Article 66(1)(b) LGTel and a further €5,000 for the violation of [[Article 14 GDPR|Article 14 GDPR]], resulting in a total fine of €10,000.The DPA imposed a fine of €5,000 for the violation of [https://www.boe.es/buscar/act.php?id=BOE-A-2022-10757 Article 66(1)(b) LGTel] and a further €5,000 for the violation of [[Article 14 GDPR]], resulting in a total fine of €10,000. == Comment ==== Comment == Latest revision as of 10:18, 7 August 2026 AEPD - PS/00249/2025 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 4(11) GDPR Article 5(2) GDPR Article 7 GDPR Article 14 GDPR Article 23(4) LOPDGDDArticle 66 Spanish Telecommunications Law (11/2022) Type: Complaint Outcome: Upheld Started: 04.02.2026 Decided: Published: 31.07.2026 Fine: 10000.0 EUR Parties: MÁS SOL ENERGÍA 15, S.L. National Case Number/Name: PS/00249/2025 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Spanish; Castilian Original Source: AEPD (in ES) Initial Contributor: bms The DPA fined a solar energy company €10,000 for making an unsolicited marketing call without proving valid consent and for failing to provide Article 14 GDPR information. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts MÁS SOL ENERGÍA 15, S.L., the controller, is a company that carries out customer acquisition through telephone calls to offer solar panel installation services. On 18 November 2024, the data subject received a marketing call from