Back to all lessons
Awareness Lessons
2 months ago

Spanish DPA Fines Film Company €60,000 for Ignoring GDPR Corrective Order

RAMONA FILMS was fined €60,000 not merely for an initial GDPR violation, but for failing to comply with a corrective order issued by Spain's AEPD — a compounding failure that significantly increased their liability. The core issue was the absence of a lawful Data Processing Agreement (DPA) with a payment provider, a fundamental GDPR Article 28 requirement governing controller-processor relationships. Submitting an unsigned, undated document and mischaracterizing the relationship as joint controllership demonstrated both legal misunderstanding and a lack of internal compliance governance. This case illustrates that regulatory non-compliance does not simply go away — regulators escalate enforcement when organizations fail to remediate identified gaps. The reputational and financial consequences of ignoring corrective orders far outweigh the cost of proper compliance.

Tactical Insight

Immediate actions

  • Audit all third-party vendor relationships to identify any missing or unsigned Data Processing Agreements (DPAs) as required by GDPR Article 28.
  • Establish a dedicated regulatory response workflow to ensure corrective orders from supervisory authorities are tracked, assigned ownership, and actioned within required timeframes.

Long-term improvements

  • Maintain a centralized data processor register that records the legal basis, contract status, and controller/processor classification for every third-party data relationship.
  • Train legal, compliance, and procurement teams on the distinction between data controllers, processors, and joint controllers to prevent misclassification.
  • Implement a contract lifecycle management process that flags unsigned, undated, or expired data processing agreements before they become regulatory liabilities.

Governance & oversight measures

  • Appoint or engage a qualified Data Protection Officer (DPO) to oversee regulatory correspondence and ensure timely responses to supervisory authority orders.
  • Schedule periodic internal audits of GDPR compliance posture, specifically reviewing third-party data flows and associated contractual documentation.