Spanish DPA Fines Film Company €60,000 for Ignoring GDPR Corrective Order
RAMONA FILMS was fined €60,000 not merely for an initial GDPR violation, but for failing to comply with a corrective order issued by Spain's AEPD — a compounding failure that significantly increased their liability. The core issue was the absence of a lawful Data Processing Agreement (DPA) with a payment provider, a fundamental GDPR Article 28 requirement governing controller-processor relationships. Submitting an unsigned, undated document and mischaracterizing the relationship as joint controllership demonstrated both legal misunderstanding and a lack of internal compliance governance. This case illustrates that regulatory non-compliance does not simply go away — regulators escalate enforcement when organizations fail to remediate identified gaps. The reputational and financial consequences of ignoring corrective orders far outweigh the cost of proper compliance.
Tactical Insight
Immediate actions
- Audit all third-party vendor relationships to identify any missing or unsigned Data Processing Agreements (DPAs) as required by GDPR Article 28.
- Establish a dedicated regulatory response workflow to ensure corrective orders from supervisory authorities are tracked, assigned ownership, and actioned within required timeframes.
Long-term improvements
- Maintain a centralized data processor register that records the legal basis, contract status, and controller/processor classification for every third-party data relationship.
- Train legal, compliance, and procurement teams on the distinction between data controllers, processors, and joint controllers to prevent misclassification.
- Implement a contract lifecycle management process that flags unsigned, undated, or expired data processing agreements before they become regulatory liabilities.
Governance & oversight measures
- Appoint or engage a qualified Data Protection Officer (DPO) to oversee regulatory correspondence and ensure timely responses to supervisory authority orders.
- Schedule periodic internal audits of GDPR compliance posture, specifically reviewing third-party data flows and associated contractual documentation.