[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fM5FXQ5hvUh2WHYWqAcT7mv2SuTUVIKooVOrN21JiSJc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"d4c55010-03e3-4c8e-ada3-c8b3797fd953","spanish-utility-fined-220k-for-unlawful-data-processing-and-marketing","53167f99-af09-4b90-92b2-9adfccc11589","Spanish Utility Fined €220K for Unlawful Data Processing and Marketing","GERSTERNOVA S.A. violated GDPR by processing customer personal data for direct marketing without valid legal basis or consent, resulting in a substantial fine from Spain's data protection authority. The company failed to obtain proper authorization before conducting marketing calls and sending contracts containing sensitive personal information including ID numbers and banking details. Additionally, they violated transparency requirements by not providing mandatory information disclosures during the marketing call and failed to ensure their data processor's compliance with privacy regulations.","**Immediate actions:**\n- Conduct comprehensive audit of all current data processing activities and their legal bases\n- Suspend any direct marketing campaigns until valid consent or legal basis is established\n- Review and update all data processor agreements to ensure GDPR compliance requirements\n\n**Legal compliance measures:**\n- Implement consent management systems to properly capture and document customer permissions\n- Develop mandatory privacy disclosure scripts for all customer-facing communications\n- Establish regular compliance monitoring of third-party processors handling personal data\n\n**Long-term improvements:**\n- Train all marketing and customer service staff on GDPR requirements and lawful processing principles\n- Implement data minimization practices to limit collection to necessary information only\n- Create automated systems to track and manage consent status across all marketing channels",[12,13,14,15,16],"GDPR Article 6","GDPR Article 13","GDPR Article 28","ISO 27001 A.18.1.4","NIST Privacy Framework PR.AC-1","published","2026-03-31T12:08:46.979098+00:00","2026-03-31T12:08:46.896+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_EXP202307472&diff=51189&oldid=0","aepd-spain-exp202307472","AEPD (Spain) - EXP202307472",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":32,"name":33,"slug":34,"description":35,"color":36},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]