AEPD (Spain) - PS/00421/2020
Spain's AEPD fines Banco de Sabadell €5,000 for sending unsolicited commercial communications.
Summary
The Spanish Data Protection Agency (AEPD) has fined Banco de Sabadell €5,000 for violating the e-Privacy Directive and the Spanish Information Society Services Act. The bank sent commercial communications to a client who had explicitly opted out of receiving such messages, arguing it was necessary for contract fulfillment. The AEPD rejected this, classifying the communication as marketing and a breach of privacy.
Full text
Help AEPD (Spain) - PS/00421/2020: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 14:37, 13 December 2023 view sourceAr (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators2,246 editsmTag: Visual edit← Older edit Latest revision as of 11:12, 24 July 2026 view source Sfl (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators501 editsm Tag: Visual edit Line 23: Line 23: |Currency=EUR|Currency=EUR |EU_Law_Name_1=e-Privacy Directive|EU_Law_Name_1=ePrivacy Directive 2002/58/EC |EU_Law_Link_1=https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32002L0058&from=EN|EU_Law_Link_1=https://eur-lex.europa.eu/eli/dir/2002/58/oj |National_Law_Name_1=Article 21(1) LSSI|National_Law_Name_1=Article 21(1) LSSI Latest revision as of 11:12, 24 July 2026 AEPD - PS/00421/2020 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: ePrivacy Directive 2002/58/ECArticle 21(1) LSSI Type: Complaint Outcome: Upheld Started: Decided: Published: 07.04.2021 Fine: 5000 EUR Parties: BANCO DE SABADELL, S.A. National Case Number/Name: PS/00421/2020 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Spanish Original Source: AEPD decision (in ES) Initial Contributor: Óscar Jacobo The Spanish DPA (AEPD) fined a financial institution €5,000 for breaching the Spanish Act implementing the e-Privacy Directive by sending direct commercial communications without consent. Contents 1 English Summary 1.1 Facts 1.2 Dispute 1.3 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The client of a financial institution lodged a complaint before the Spanish DPA (AEPD) due to the delivery of a mail for commercial purposes, even though he had expressly rejected the delivery of commercial communications and promotional offers. Dispute Are the electronic communication sent by a financial entity to its clients to be considered as necessary for contract fulfilment or do they have commercial purposes (and thus would breach the principle of Article 21(1) of the Spanish Information Society Services Act (LSSI) regarding the delivery of electronic commercial communications to data subjects without prior authorization)? Holding The DPA rejected the argument of transaction-based customer communication and held that the mail had marketing purposes because the Controller publicizes its services, although the data subject had expressly indicated his refusal to receive advertising content. As a result, the DPA considered that the financial entity violated Article 21(1) LSSI. Furthermore, the commercial communication did not inform the recipient about his right to object to the processing of its data for marketing purposes. As a consequence, the Spanish DPA imposed a fine of €5,000. Comment It may seem that the Spanish DPA did not in-depth analyze the arguments expressed by the financial entity regarding whether the content included in the communication could be considered as necessary for contract fulfilment, particularly in the case of communications focus on reporting the maintenance of essential banking services during the lockdown. Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details. 1/7 Procedure Nº: PS / 00421/2020 RESOLUTION OF SANCTIONING PROCEDURE Of the procedure instructed by the Spanish Agency for Data Protection and based on to the following BACKGROUND FIRST: A.A.A. (hereinafter, the claimant) dated June 25, 2020 filed a claim with the Spanish Data Protection Agency. The claim is directed against BANCO DE SABADELL, S.A. with NIF A08000143 (in ahead, the claimed one). The reasons on which the claim is based are that said financial entity with which the claimant has contracted several financial products, on 06/17/20 he sent a commercial email, despite the fact that in your online account you have marked clearly you do not agree to receive advertising. Together with the claim, it provides a screenshot where it is seen marked in the COMMERCIAL INFORMATION AND PROMOTIONS section: "I do NOT want to enjoy offers that are 100% adapted to my profile." SECOND: In accordance with article 65.4 of Organic Law 3/2018, of 5 December, Protection of Personal Data and guarantee of digital rights (in hereinafter LOPDGDD), with reference number E / 06046/2020, a transfer of said claim to the defendant, on July 17, 2020, to proceed with its analysis and inform this Agency within a month, of the actions taken carried out to adapt to the requirements provided in the data protection regulations, To date there is no reply in this regard. THIRD: On November 30, 2020, the Director of the Spanish Agency of Data Protection agreed to initiate a sanctioning procedure to the claimed, by the alleged violation of article 21 of the LSSI, typified in article 38.4.d) of the LSSI, which may be sanctioned with a fine of up to € 5,000, in accordance with article 39.1 c) of the LSSI. FOURTH: Once the aforementioned Initiation Agreement was notified, the defendant presented allegations in which indicated that on August 10, 2020, it responded to the request received on August 17, 2020. July, stating that the communication sent to the claimant was not commercial but operational. Likewise, the claimed entity states that given the situation and the social scenario and sanitary in which we found ourselves during the State of Alarm, novel and exceptional, sent operational and contractual communications to its clients in the reporting on new channels and new operational and communication options C / Jorge Juan, 6 www.aepd.es 28001 - Madrid sedeagpd.gob.es 2/7 due to the need to accompany our clients in the contractual execution maintained with the Bank. In no way attending to the emails sent does it appear that there was a campaign or commercial communication for the purpose of offering, promoting or selling products or services, but information on operational solutions to your efforts banks that it had, motivated by the State of Alarm situation and the closure or limitation of face-to-face operations at branches motivated by the pandemic, as well as by the limitation of movements itself. Consequently and in accordance with the foregoing and the content of the communications sent, the respondent considers that the article has not been infringed 21 of the LSSI, as no advertising communications or promotional. Likewise, it considers that article 38.4 of the same text has not been infringed either. legal, section d) that typifies the alleged infringement, as it is not a commercial communication as required by the precept. For this reason, it considers that no responsibility can be attributed to it since the only purpose of the emails sent are to accompany our clients in an exceptional situation, during the Alarm State that did not end until June 21, 2020, without prejudice to subsequent restrictive regulations of the mobility, informing them about new channels and operational options and communication related to the maintenance of the contractual relationship, but in no case for the offer or sale of products or services. FIFTH: On February 2, 2021, the instructor of the procedure agreed to the opening of a period of practical tests, taking as incorporated the preliminary investigation actions, E / 06046/2020. SIXTH: On February 7, 2021, a resolution proposal was formulated, proposing that the Director of the Spanish Data Protection Agency dictate sanctioning resolution against BANCO DE SABADELL, S.A. with NIF A08000143, with a fine of € 5,000 (five thousand euros) for the violation of article 21 of the LSSI, typified in article 38.4.d) of the LSSI. SEVENTH: On February 19, 2021, allegations were presented against the motion for a resolution stating the following: “T