[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fA8koNDk9-SSejOD7jsjw_sw42kB0TJ3KNG9aOe6jMuE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"77659a59-1b10-4447-b370-5dea008b8728","banco-de-sabadell-fined-for-ignoring-customer-marketing-opt-out","78297181-7c2d-433d-9aa8-0e7eddb93962","Banco de Sabadell Fined for Ignoring Customer Marketing Opt-Out","Banco de Sabadell sent commercial communications to a customer who had explicitly withdrawn consent, then incorrectly attempted to justify the contact as a contractual necessity. The AEPD rejected this argument, affirming that marketing communications require affirmative consent and cannot be reframed as operational necessity. This case highlights how organisations frequently misclassify marketing activities to circumvent consent obligations, exposing themselves to regulatory penalties. Proper consent lifecycle management — from collection through to honouring withdrawal — is a fundamental requirement under e-Privacy and GDPR frameworks.","**Immediate actions:**\n- Audit all active marketing lists to verify that opted-out customers are immediately and fully suppressed across every communication channel.\n- Establish a clear internal definition distinguishing 'marketing communications' from 'contractual\u002Foperational communications' to prevent misclassification.\n\n**Long-term improvements:**\n- Implement a centralised Consent Management Platform (CMP) that propagates opt-out signals in real time to all downstream marketing and CRM systems.\n- Train customer-facing and marketing staff on the legal boundaries between legitimate interest, contractual necessity, and consent-based processing.\n- Conduct periodic compliance audits to verify that consent records are accurate, up to date, and honoured across all business units.\n\n**Detection & monitoring measures:**\n- Deploy automated monitoring to flag and halt any outbound communications to customers with recorded opt-out status before dispatch.\n- Maintain detailed logs of consent status changes and communication events to provide an auditable trail in the event of a regulatory investigation.",[12,13,14,15,16,17,18,19,20],"GDPR Article 6 (Lawfulness of Processing)","GDPR Article 7 (Conditions for Consent)","GDPR Article 21 (Right to Object)","ePrivacy Directive 2002\u002F58\u002FEC Article 13 (Unsolicited Communications)","Spanish LSSI-CE (Information Society Services Act)","NIST SP 800-53 PT-4 (Consent)","NIST SP 800-53 IP-1 (Consent)","CIS Control 3 (Data Protection)","ISO\u002FIEC 27701:2019 (Privacy Information Management)","published","2026-07-24T12:22:09.334454+00:00","2026-07-24T12:22:09.015+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_PS\u002F00421\u002F2020&diff=52461&oldid=38441","aepd-spain-ps-00421-2020-5f4343","AEPD (Spain) - PS\u002F00421\u002F2020",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]