[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fJAi4FmZhx9KN4K_yg6Q7BtLHem3XzQJ1DrfyNGSxTa4":3},{"article":4,"iocs":39},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"38c84984-c37e-49f5-a0ba-6a3b6ef2b3d4","AEPD (Spain) - PS\u002F00259\u002F2020","aepd-spain-ps-00259-2020-4ec698","Standardized name and link ← Older revision Revision as of 11:14, 24 July 2026 Line 28: Line 28: |GDPR_Article_Link_2=Article 22 GDPR#1 |GDPR_Article_Link_2=Article 22 GDPR#1 |EU_Law_Name_1=Article 5(3) Directive 2002\u002F58\u002FEC |EU_Law_Name_1=Article 5(3) ePrivacy Directive 2002\u002F58\u002FEC |EU_Law_Link_1=https:\u002F\u002Feur-lex.europa.eu\u002FLexUriServ\u002FLexUriServ.do?uri=CONSLEG:2002L0058:20091219:EN:HTML |EU_Law_Link_1=https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2002\u002F58\u002Foj |National_Law_Name_1=Article 22(1) LSSI |National_Law_Name_1=Article 22(1) LSSI","The Spanish Data Protection Agency (AEPD) has fined Bankia €50,000 for sending a client a letter with a commercial message on the envelope, despite the client having previously objected to receiving such communications. The bank's defense that it was not a commercial communication and was based on legitimate interest was rejected by the AEPD, which cited violations of GDPR Article 6(1)(f) and the ePrivacy Directive.","Spain's AEPD fines Bankia €50,000 for sending commercial communications to a client who objected.","Help AEPD (Spain) - PS\u002F00259\u002F2020: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 13:56, 14 July 2021 view sourceCvl (talk | contribs)noContributionReport872 editsTag: Visual edit← Older edit Latest revision as of 11:14, 24 July 2026 view source Sfl (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators500 editsm Tag: Visual edit Line 28: Line 28: |GDPR_Article_Link_2=Article 22 GDPR#1|GDPR_Article_Link_2=Article 22 GDPR#1 |EU_Law_Name_1=Article 5(3) Directive 2002\u002F58\u002FEC|EU_Law_Name_1=Article 5(3) ePrivacy Directive 2002\u002F58\u002FEC |EU_Law_Link_1=https:\u002F\u002Feur-lex.europa.eu\u002FLexUriServ\u002FLexUriServ.do?uri=CONSLEG:2002L0058:20091219:EN:HTML|EU_Law_Link_1=https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2002\u002F58\u002Foj |National_Law_Name_1=Article 22(1) LSSI|National_Law_Name_1=Article 22(1) LSSI Latest revision as of 11:14, 24 July 2026 AEPD (Spain) - PS\u002F00259\u002F2020 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 6(1)(f) GDPR Article 22(1) GDPR Article 5(3) ePrivacy Directive 2002\u002F58\u002FECArticle 22(1) LSSI Type: Complaint Outcome: Upheld Started: Decided: 06.07.2021 Published: 09.07.2021 Fine: 50000 EUR Parties: BANKIA, S.A. National Case Number\u002FName: PS\u002F00259\u002F2020 European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Spanish Original Source: AEPD (in ES) Initial Contributor: n\u002Fa The Spanish DPA fined a bank €50,000 for sending commercial communications on the envelope of a letter to a client that had exercised their right to object. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A data subject exercised their right to object to receiving commercial communications against a bank (Bankia\u002FCaixabank), after what whose DPO confirmed that the right had been correctly exercised. However, two years after that, the data subject received a letter from the bank which envelope contained a commercial communication, promoting and informing about the bank's services. The data subject lodged a complaint with the Spanish DPA (AEPD). The bank alleged that it was not a commercial communication but a mere standard envelope like the banners and signs that they display at their offices, that include information about the bank's services, and that the letter inside was just information sent to the client regarding the services that they had contracted. The bank also stated that it was not a direct marketing action, as it did not include any profiling or made use of individual preferences, but was general information sent to their clients. They alleged that they were relying on a legitimate interest for this. The bank also alleged that they had not processed their client's data for marketing purposes, since the processing was done to send the letter, and the envelope containing the commercial message was just accidental to it, but the data was not processed for that purpose. Holding The Spanish DPA determined that the actions performed by the bank were nevertheless commercial communications with a marketing purpose, and that the controller did not have a legal basis for doing so, as the bank could not rely on a legitimate interest since the data subject had exercised their right to object, in accordance to Article 21 GDPR. The Spanish DPA also made reference to Recitals 69 and 70. The AEPD also noted that the privacy policy of the bank declared that commercial communications were based on consent, contrary to what the controller alleged during the procedure. Therefore, the AEPD concluded that there had been a violation of Article 6(1)(f) and fined the controller €50,000, compelling it to implement the necessary measures to prevent the sending of commercial communications to data subjects that have objected to them. The Spanish DPA took into account the lack of diligence, the scope of the infringing behaviour (even if in this case there was an only claimant, the lack of measures to prevent it may make it happen regarding other clients), the link between the controller's activity and the infringement, and the recidivism of the controller; and the fact that the entity was assimilated by another entity, so the infringement could be attributed to the latter entity, as a mitigating factor. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details. 1\u002F48  Procedure No.: PS \u002F 00259\u002F2020 RESOLUTION OF SANCTIONING PROCEDURE Of the procedure instructed by the Spanish Agency for Data Protection and with based on the following: BACKGROUND FIRST: D. A.A.A., with NIF *** NIF.1 (hereinafter, the claimant), files claim before the Spanish Data Protection Agency (AEPD) dated 04\u002F06\u002F2020. The claim is directed against BANKIA, S.A., with NIF A14010342 (as successive, the claimed). The reason on which you base your claim is the receipt of commercial advertising that the respondent sent via postal mail after that he had objected to the processing of his data for advertising purposes and that the claimed, of whom he is a client, responded that he was attending to his right and proceeded to adopt the necessary measures for its compliance. Provide these documents with your claim: to. The one that contains the commercial communication (annex 2), integrated in turn by two documents. In the first of them, in the lower right part, they appear the personal data of the claimant -name, two surnames and postal address full- and below a barcode. The position in which they are located in the document the personal data coincides with the one that occupies the a type of envelope commonly used in postal mail that allows see the recipient's information printed inside the envelope. In the upper right corner of the document is the anagram of the claimed with his name. In the lower right corner the indication “11.02.2020”. In the The body of the document has this legend: “It costs a lot to find the house of your dreams. Therefore, WE REMOVE THE COMMISSIONS FROM YOUR NEW MORTGAGE. Just for having your payroll domiciled and nothing else. We take away the commissions of: ”Next, in two parallel columns, figure: \"OPENING\"; \"EARLY AMORTIZATION\"; \"CANCELLATION IN ADVANCE ”; \"POST COSTS\". Immediately below it is indicated: “So that dreaming costs less. * Check conditions at Bankia branches or bankia.es ”. The second document that makes up Annex 2 of the claim is identical to the first with this particularity: the recipient's personal data do not match those of the claimant - the postal address is the same but not the name and surname, in this case B.B.B.- nor the date of shipment, in this case case on 02\u002F24\u002F2020. to. The letter, dated 11\u002F28\u002F2018, that the respondent sent to the claimant in which acknowledges receipt of your request not to receive information of a commercial nature or publicity of the entity and that your data were not communicated to other entities, affiliates of the Bankia group or collaborators with the commercial (Annex 1). In it, the respondent informs the claimant that she has responded to your request and has proceeded to adopt the necessary measures for your compliance. C \u002F Jorge Juan, 6 www.aepd.es 28001 - Madrid sedeagpd.gob.es 2\u002F48 The following excerpt from the letter sent to the claimant is reproduced in response to your request not to receive commercial information: “In relation to your request for which you [the claimant], with D.N.I. [the one of claimant], you inform us of your desire not to receive information of a commercial or advertising of this Entity, as well as that your data is not communicated to other entities or investees of the Bankia group or collaborators, we inform you that we have complied with your request and we have proceeded to adopt the necessary measures for its compliance. \" (The","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_PS\u002F00259\u002F2020&diff=52462&oldid=17262","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F5\u002F59\u002FLogoES.jpg","2026-07-24T11:14:15+00:00","2026-07-24T12:00:18.1669+00:00",7,[18],{"name":19,"type":20},"Bankia","vendor","d95477d7-eb04-4fad-a2dc-be1428040ce7",{"id":21,"icon":23,"name":24,"slug":25},null,"Privacy Fines","privacy-fines",[27,32,37],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":38},{"id":21,"icon":23,"name":24,"slug":25},[]]