Back to Feed
PolicyJul 31, 2026

AN - SAN 3154/2026

Spanish court upholds €25,000 fine against KFC for GDPR violations.

Summary

The Spanish National Court has upheld a €25,000 fine against KFC Restaurants Spain for violating GDPR. The violations included providing insufficient privacy information and failing to appoint a Data Protection Officer (DPO) despite systematic monitoring of customer data. The court found KFC's privacy notices too generic and that data processing was integral to its online and customer management activities, necessitating a DPO.

Full text

Help AN - SAN 3154/2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 14:03, 31 July 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators231 edits Tag: Decisions [1.0] (No difference) Latest revision as of 14:03, 31 July 2026 AN - SAN 3154/2026 Court: AN (Spain) Jurisdiction: Spain Relevant Law: Article 13 GDPR Article 37(1)(b) GDPR Article 58(2)(d) GDPR Article 83 GDPR Article 34 LOPDGDDArticle 73 LOPDGDDArticle 74 LOPDGDD Decided: 16.07.2026 Published: Parties: KFC Restaurants Spain, S.L.U. AEPD National Case Number/Name: SAN 3154/2026 European Case Law Identifier: ECLI:ES:AN:2026:3154 Appeal from: Appeal to: Unknown Original Language(s): Spanish; Castilian Original Source: Cendoj (in Spanish; Castilian) Initial Contributor: bms The High Court upheld €25,000 in fines against KFC for providing insufficiently specific privacy information and failing to appoint a DPO despite carrying out large-scale, regular and systematic monitoring. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts In May 2021, a data subject lodged a complaint with the Spanish Data Protection Authority against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website. The data subject claimed that the privacy information applicable to users in the EEA was not easily accessible, as the main privacy link led to a global policy. The data subject also alleged that users could not create an account without apparently accepting promotional communications, that the registration form did not correctly link to the privacy policy and that the controller had not appointed a data protection officer. The complaint further identified deficiencies in the privacy information, including insufficient details about the identity of the controller, recipients, international transfers and retention periods. During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business. The DPA found that the information provided on the website was excessively generic and did not comply with Article 13 GDPR. It imposed a €5,000 fine and ordered the controller to bring its website into compliance. The DPA also concluded that the controller’s processing activities required the appointment of a DPO under Article 37(1)(b) GDPR. It imposed a further €20,000 fine and ordered the controller to appoint a DPO. The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented the corrective measures. Holding The High Court dismissed the appeal and upheld the total fine of €25,000. Regarding Article 13 GDPR, the Court found that the controller’s privacy information was excessively generic and did not clearly explain the purposes, legal bases and relevant circumstances of the processing. It also held that the DPA was not limited to investigating only the exact issues identified in the initial complaint. The €5,000 fine was proportionate despite the controller’s subsequent corrective action. Regarding Article 37(1)(b) GDPR, the Court held that the controller was required to appoint a DPO. Although its primary business was the provision of restaurant services, the processing of customer data was inseparable from its online ordering, marketing, loyalty and customer-management activities. The processing also involved regular and systematic monitoring, as the controller continuously collected data such as customer preferences, browsing history, IP addresses, cookies and geolocation for commercial and operational purposes. Considering the number of data subjects, the volume and variety of data, the duration of the processing and its nationwide scope, the Court concluded that the processing was carried out on a large scale. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Spanish; Castilian original. Please refer to the Spanish; Castilian original for more details. Case No.: SAN 3154/2026 - ECLI:ES:AN:2026:3154 Cendoj ID: 28079230012026100385 Court: National Court. Contentious-Administrative Chamber Location: Madrid Section: 1 Date: 07/16/2026 Appeal No.: 420/2023 Decision No.: 402/2026 Proceeding: Ordinary proceeding Presiding Judge: AMALIA BASANTA RODRIGUEZ Type of Decision: Judgement NATIONAL COURT ADMINISTRATIVE LITIGATION CHAMBER 1ST Section MADRID JUDGMENT: 00402 / 2026 PASEO DE LA CASTELLANA 14 Phone: 914007284 Emailelectrónico:audiencianacional.salacontencioso.s1@justicia.es COMMON PROCESSING SERVICE Team/User: RMG Form: N40000 JUDGMENT FREE TEXT ART. 206.1.3 LEC N.I.G.: 28079 23 3 2023 0005208 Procedure: PO ORDINARY PROCEDURE 0000420 / 2023 Re: THE DATA PROTECTION AGENCY From: KFC RESTAURANTS SPAIN, S.L. Lawyer SOLICITOR: Mr./Ms. IGNACIO LOPEZ CHOCARRO Against: THE SPANISH AGENCY FOR INSTITUTIONAL DATA PROTECTION STATE LAWYER JUDGMENT HONORABLE PRESIDING JUDGE FERNANDO LUIS RUIZ PIÑEIRO HONORABLE JUSTICES AMALIA BASANTA RODRÍGUEZ LUIS HELMUTH MOYA MEYER RICARDO FERNÁNDEZ CARBALLO-CALERO PRESIDING JUDGE: MS. AMALIA BASANTA RODRÍGUEZ 1 CASE LAW Madrid, July 16, 2026. Having examined the administrative appeal filed with this Administrative Chamber of the National Court, filed by Court Attorney Mr. IGNACIO LOPEZ CHOCARRO, on behalf of and with representation for the entity “KFC RESTAURANTS SPAIN, S.L.U.,” against the Decision dated February 13, 2023 by the Director of the Spanish Data Protection Agency, dismissing the appeal for reconsideration filed against another decision dated June 8, 2022, which imposed on said entity a fine of 5,000 E for a violation of Article 13 of the GDPR in relation to Article 83(5)(b), classified as minor under Article 74(1)(a) of the LOPDPGDD, and a second fine of 20,000 E for a violation of Article 37 of the GDPR, classified as serious under Article 73 of the LOPDPGDD (PS/00140/2022). And against the decision of the Director of the Spanish Data Protection Agency, dated June 23, 2023 —Case No. NUM000—, requiring KFC RESTAURANTS SPAIN, S.L. to demonstrate, within TEN BUSINESS DAYS , demonstrate that it had adopted the appropriate corrective measures consisting of bringing the website www.kfc.es <WWW.kfc.es/> to the provisions of Article 13 of the GDPR, as well as the appointment of a data protection officer. The defendant was the General State Administration, assisted and represented by the STATE LAWYER. The amount in dispute was set at 25,000 euros. The presiding judge of this Section was Ms. Amalia Basanta Rodríguez, who expresses the opinion of the Chamber. FACTS OF THE CASE FIRST.—The contested act is the Resolution of February 13, 2023, issued by the Director of the Spanish Data Protection Agency, dismissing the appeal filed against another resolution dated June 8, 2022, which imposed a fine of 5,000 E on said entity for a violation of Article 13 of the GDPR in relation to Article 83.5(b), classified as minor under Article 74. 1(a) of the LOPDPGDD, and a second fine of 20,000 E for a violation of Article 37 of the GDPR, classified as serious under Article 73 of the LOPDPGDD (PS/00140/2022). And against the decision of the Director of the Spanish Data Protection Agency, dated June 23, 2023— case file NUM000—requiring KFC RESTAURANTS SPAIN, S.L. to demonstrate, within TEN WORKING DAYS, demonstrate

Entities

KFC (vendor)KFC Restaurants Spain, S.L.U. (product)