[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fEr6G6eQ-go6s4gVCrTdVd6fz3cInGLefVokL-9tXpTQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":46},"c5708453-e5e5-4e34-a5dd-cd215a18cb1d","spanish-dpa-fines-film-company-60000-for-ignoring-gdpr-corrective-order","c9d1e53e-f533-495b-8d44-b3db2df1d060","Spanish DPA Fines Film Company €60,000 for Ignoring GDPR Corrective Order","RAMONA FILMS was fined €60,000 not merely for an initial GDPR violation, but for failing to comply with a corrective order issued by Spain's AEPD — a compounding failure that significantly increased their liability. The core issue was the absence of a lawful Data Processing Agreement (DPA) with a payment provider, a fundamental GDPR Article 28 requirement governing controller-processor relationships. Submitting an unsigned, undated document and mischaracterizing the relationship as joint controllership demonstrated both legal misunderstanding and a lack of internal compliance governance. This case illustrates that regulatory non-compliance does not simply go away — regulators escalate enforcement when organizations fail to remediate identified gaps. The reputational and financial consequences of ignoring corrective orders far outweigh the cost of proper compliance.","**Immediate actions:**\n- Audit all third-party vendor relationships to identify any missing or unsigned Data Processing Agreements (DPAs) as required by GDPR Article 28.\n- Establish a dedicated regulatory response workflow to ensure corrective orders from supervisory authorities are tracked, assigned ownership, and actioned within required timeframes.\n\n**Long-term improvements:**\n- Maintain a centralized data processor register that records the legal basis, contract status, and controller\u002Fprocessor classification for every third-party data relationship.\n- Train legal, compliance, and procurement teams on the distinction between data controllers, processors, and joint controllers to prevent misclassification.\n- Implement a contract lifecycle management process that flags unsigned, undated, or expired data processing agreements before they become regulatory liabilities.\n\n**Governance & oversight measures:**\n- Appoint or engage a qualified Data Protection Officer (DPO) to oversee regulatory correspondence and ensure timely responses to supervisory authority orders.\n- Schedule periodic internal audits of GDPR compliance posture, specifically reviewing third-party data flows and associated contractual documentation.",[12,13,14,15,16,17,18,19],"GDPR Article 28 (Processor obligations and Data Processing Agreements)","GDPR Article 26 (Joint Controllers)","GDPR Article 58 (Powers of supervisory authorities)","GDPR Article 83 (Conditions for imposing administrative fines)","NIST Privacy Framework PR.P-P4 (Data processing policies, processes, and procedures)","CIS Control 15 (Service Provider Management)","ISO\u002FIEC 27001 Annex A.15 (Supplier relationships)","ITIL Service Design — Supplier Management Practice","published","2026-08-24T08:21:20.374802+00:00","2026-08-24T08:21:20.289+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_PS-00008-2025&diff=52761&oldid=52752","aepd-spain-ps-00008-2025-7144e0","AEPD (Spain) - PS-00008-2025",[28,34,40],{"id":29,"name":30,"slug":31,"description":32,"color":33},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":41,"name":42,"slug":43,"description":44,"color":45},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]