[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fguo8WTwTRJcate00xqeYptbfvWgwr2t1s-VKB038UYs":3},{"article":4,"iocs":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":28,"category":29,"article_tags":33},"28b687e8-8d03-4af4-94aa-036bc26120a5","AN - SAN 3154\u002F2026","an-san-3154-2026-0561c7","← Older revision Revision as of 06:46, 3 August 2026 Line 129: Line 129: During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business. During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business. The DPA found that the information provided on the website was excessively generic and did not comply with [[Article 13 GDPR|Article 13 GDPR]]. It imposed a €5,000 fine and ordered the controller to bring its website into compliance. The DPA found that the information provided on the website was excessively generic and did not comply with [[Article 13 GDPR]]. It imposed a €5,000 fine and ordered the controller to bring its website into compliance. The DPA also concluded that the controller’s processing activities required the appointment of a DPO under [[Article 37 GDPR|Article 37(1)(b) GDPR]]. It imposed a further €20,000 fine and ordered the controller to appoint a DPO. The DPA also concluded that the controller’s processing activities required the appointment of a DPO under [[Article 37 GDPR|Article 37(1)(b) GDPR]]. It imposed a further €20,000 fine and ordered the controller to appoint a DPO. The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented the corrective measures. The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented the corrective measures. === Holding === === Holding === The High Court dismissed the appeal and upheld the total fine of €25,000. The High Court dismissed the appeal and upheld the total fine of €25,000. Regarding [[Article 13 GDPR|Article 13 GDPR]], the Court found that the controller’s privacy information was excessively generic and did not clearly explain the purposes, legal bases and relevant circumstances of the processing. It also held that the DPA was not limited to investigating only the exact issues identified in the initial complaint. The €5,000 fine was proportionate despite the controller’s subsequent corrective action. Regarding [[Article 13 GDPR]], the Court found that the controller’s privacy information was excessively generic and did not clearly explain the purposes, legal bases and relevant circumstances of the processing. It also held that the DPA was not limited to investigating only the exact issues identified in the initial complaint. The €5,000 fine was proportionate despite the controller’s subsequent corrective action. Regarding [[Article 37 GDPR|Article 37(1)(b) GDPR]], the Court held that the controller was required to appoint a DPO. Although its primary business was the provision of restaurant services, the processing of customer data was inseparable from its online ordering, marketing, loyalty and customer-management activities. Regarding [[Article 37 GDPR|Article 37(1)(b) GDPR]], the Court held that the controller was required to appoint a DPO. Although its primary business was the provision of restaurant services, the processing of customer data was inseparable from its online ordering, marketing, loyalty and customer-management activities. The processing also involved regular and systematic monitoring, as the controller continuously collected data such as customer preferences, browsing history, IP addresses, cookies and geolocation for commercial and operational purposes. Considering the number of data subjects, the volume and variety of data, the duration of the processing and its nationwide scope, the Court concluded that the processing was carried out on a large scale. The processing also involved regular and systematic monitoring, as the controller continuously collected data such as customer preferences, browsing history, IP addresses, cookies and geolocation for commercial and operational purposes. Considering the number of data subjects, the volume and variety of data, the duration of the processing and its nationwide scope, the Court concluded that the processing was carried out on a large scale. == Comment == == Comment == ''Share your comments here!'' ''Share your comments here!''","A data controller operating a restaurant business has been fined a total of €25,000 for violating GDPR. The DPA found that the website's privacy information was too generic and did not comply with Article 13 GDPR, leading to a €5,000 fine. Additionally, the controller was fined €20,000 for failing to appoint a Data Protection Officer (DPO) as required by Article 37(1)(b) GDPR, due to large-scale processing of customer data for online ordering, marketing, and loyalty programs. The High Court upheld the fines and the requirement to appoint a DPO.","A restaurant controller was fined €25,000 for GDPR violations related to privacy information and DPO appointment.","Help AN - SAN 3154\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 14:03, 31 July 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators236 edits Tag: Decisions [1.0] Revision as of 06:46, 3 August 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators236 editsTag: Visual editNewer edit → Line 129: Line 129: During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business.During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business. The DPA found that the information provided on the website was excessively generic and did not comply with [[Article 13 GDPR|Article 13 GDPR]]. It imposed a €5,000 fine and ordered the controller to bring its website into compliance.The DPA found that the information provided on the website was excessively generic and did not comply with [[Article 13 GDPR]]. It imposed a €5,000 fine and ordered the controller to bring its website into compliance. The DPA also concluded that the controller’s processing activities required the appointment of a DPO under [[Article 37 GDPR|Article 37(1)(b) GDPR]]. It imposed a further €20,000 fine and ordered the controller to appoint a DPO.The DPA also concluded that the controller’s processing activities required the appointment of a DPO under [[Article 37 GDPR|Article 37(1)(b) GDPR]]. It imposed a further €20,000 fine and ordered the controller to appoint a DPO. The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented the corrective measures.The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented the corrective measures. === Holding ====== Holding === The High Court dismissed the appeal and upheld the total fine of €25,000.The High Court dismissed the appeal and upheld the total fine of €25,000. Regarding [[Article 13 GDPR|Article 13 GDPR]], the Court found that the controller’s privacy information was excessively generic and did not clearly explain the purposes, legal bases and relevant circumstances of the processing. It also held that the DPA was not limited to investigating only the exact issues identified in the initial complaint. The €5,000 fine was proportionate despite the controller’s subsequent corrective action.Regarding [[Article 13 GDPR]], the Court found that the controller’s privacy information was excessively generic and did not clearly explain the purposes, legal bases and relevant circumstances of the processing. It also held that the DPA was not limited to investigating only the exact issues identified in the initial complaint. The €5,000 fine was proportionate despite the controller’s subsequent corrective action. Regarding [[Article 37 GDPR|Article 37(1)(b) GDPR]], the Court held that the controller was required to appoint a DPO. Although its primary business was the provision of restaurant services, the processing of customer data was inseparable from its online ordering, marketing, loyalty and customer-management activities.Regarding [[Article 37 GDPR|Article 37(1)(b) GDPR]], the Court held that the controller was required to appoint a DPO. Although its primary business was the provision of restaurant services, the processing of customer data was inseparable from its online ordering, marketing, loyalty and customer-management activities. The processing also involved regular and systematic monitoring, as the controller continuously collected data such as customer preferences, browsing history, IP addresses, cookies and geolocation for commercial and operational purposes. Considering the number of data subjects, the volume and variety of data, the duration of the processing and its nationwide scope, the Court concluded that the processing was carried out on a large scale.The processing also involved regular and systematic monitoring, as the controller continuously collected data such as customer preferences, browsing history, IP addresses, cookies and geolocation for commercial and operational purposes. Considering the number of data subjects, the volume and variety of data, the duration of the processing and its nationwide scope, the Court concluded that the processing was carried out on a large scale. == Comment ==== Comment == ''Share your comments here!''''Share your comments here!'' Revision as of 06:46, 3 August 2026 AN - SAN 3154\u002F2026 Court: AN (Spain) Jurisdiction: Spain Relevant Law: Article 13 GDPR Article 37(1)(b) GDPR Article 58(2)(d) GDPR Article 83 GDPR Article 34 LOPDGDDArticle 73 LOPDGDDArticle 74 LOPDGDD Decided: 16.07.2026 Published: Parties: KFC Restaurants Spain, S.L.U. AEPD National Case Number\u002FName: SAN 3154\u002F2026 European Case Law Identifier: ECLI:ES:AN:2026:3154 Appeal from: Appeal to: Unknown Original Language(s): Spanish; Castilian Original Source: Cendoj (in Spanish; Castilian) Initial Contributor: bms The High Court upheld €25,000 in fines against KFC for providing insufficiently specific privacy information and failing to appoint a DPO despite carrying out large-scale, regular and systematic monitoring. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts In May 2021, a data subject lodged a complaint with the Spanish Data Protection Authority against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website. The data subject claimed that the privacy information applicable to users in the EEA was not easily accessible, as the main privacy link led to a global policy. The data subject also alleged that users could not create an account without apparently accepting promotional communications, that the registration form did not correctly link to the privacy policy and that the controller had not appointed a data protection officer. The complaint further identified deficiencies in the privacy information, including insufficient details about the identity of the controller, recipients, international transfers and retention periods. During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business. The DPA found that the information provided on the website was excessively generic and did not comply with Article 13 GDPR. It imposed a €5,000 fine and ordered the controller to bring its website into compliance. The DPA also concluded that the controller’s processing activities required the appointment of a DPO under Article 37(1)(b) GDPR. It imposed a f","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AN_-_SAN_3154\u002F2026&diff=52571&oldid=52566","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F4\u002F4c\u002FCourts_logo1.png","2026-08-03T06:46:25+00:00","2026-08-03T08:00:15.338826+00:00",7,[18,21,24,26],{"name":19,"type":20},"website","product",{"name":22,"type":23},"profiling","technology",{"name":25,"type":23},"cookies",{"name":27,"type":23},"IP addresses","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":28,"icon":30,"name":31,"slug":32},null,"Policy","policy",[34,39,44],{"category":35},{"id":36,"icon":30,"name":37,"slug":38},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":40},{"id":41,"icon":30,"name":42,"slug":43},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":45},{"id":46,"icon":30,"name":47,"slug":48},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]