National Court · AN - SAN 3154/2026
In May 2021, a data subject lodged a complaint with the DPA against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website.
The data subject claimed that the privacy information applicable to users in the EEA was not easily accessible, as the main privacy link led to a global policy. The data subject also alleged that users could not create an account without apparently accepting promotional communications, that the registration form did not correctly link to the privacy policy and that the controller had not appointed a data protection officer. The complaint further identified deficiencies in the privacy information, including insufficient details about the identity of the controller, recipients, international transfers and retention periods. During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business. The DPA found that the information provided on the website was excessively generic and did not comply with Article 13 GDPR. It imposed a €5,000 fine and ordered the controller to bring its website into compliance. The DPA also concluded that the controller’s processing activities required the appointment of a DPO under Article 37(1)(b) GDPR. It imposed a further €20,000 fine and ordered the controller to appoint a DPO. The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented corrective measures. Holding — The Court dismissed the appeal and upheld the total fine of €25,000. Regarding Article 13 GDPR, the Court found that the controller’s privacy information was excessively generic and did not clearly explain the purposes, legal bases and relevant circumstances of the processing. It also held that the DPA was not limited to investigating only the exact issues identified in the initial complaint. The €5,000 fine was proportionate despite the controller’s subsequent corrective action. Regarding Article 37(1)(b) GDPR, the Court held that the controller was required to appoint a DPO. Although its primary business was the provision of restaurant services, the processing of customer data was inseparable from its online ordering, marketing, loyalty and customer-management activities. The processing also involved regular and systematic monitoring, as the controller continuously collected data such as customer preferences, browsing history, IP addresses, cookies and geolocation for commercial and operational purposes. Considering the number of data subjects, the volume and variety of data, the duration of the processing and its nationwide scope, the Court concluded that the processing was carried out on a large scale.
How it connects
References
- Art. 13
- Art. 83(5)(b)
- Art. 74(1)(a)
- Art. 37
- Art. 73
- Art. 83
- Art. 74
- Art. 13(1)(e)
- Art. 34
- Art. 6
- Art. 29
- Art. 6(1)(f)
- Art. 49(1)
- Art. 6(1)(a)
- Art. 9(2)(a)
- Art. 22(1)
- Art. 58(2)
- Art. 37(1)(b)
- Art. 35(4)
- Art. 83(4)(a)
- Art. 83(2)
- Art. 76
- Art. 58(2)(d)
- Art. 9(2)
- Art. 57(1)(f)
- Art. 77(1)
- Art. 25
- Art. 58(1)
- Art. 39
- Art. 3
- Art. 97
- Art. 89(2)
- Art. 28
- HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)
- CJEU - C-311/18 - Facebook Ireland and Schrems
- Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems
- Data Protection Commissioner v. Schrems and Facebook
Related across sources
Full text 66 paragraphs
: SAN 3154/2026 - ECLI:ES:AN:2026:3154 Cendoj ID: 28079230012026100385 Court: National Court. es COMMON PROCESSING SERVICE Team/User: RMG Form: N40000 JUDGMENT FREE TEXT ART. L. /Ms. IGNACIO LOPEZ CHOCARRO Against: THE SPANISH AGENCY FOR INSTITUTIONAL DATA PROTECTION STATE LAWYER JUDGMENT HONORABLE PRESIDING JUDGE FERNANDO LUIS RUIZ PIÑEIRO HONORABLE JUSTICES AMALIA BASANTA RODRÍGUEZ LUIS HELMUTH MOYA MEYER RICARDO FERNÁNDEZ CARBALLO-CALERO PRESIDING JUDGE: MS. AMALIA BASANTA RODRÍGUEZ 1 CASE LAW Madrid, July 16, 2026. Having examined the administrative appeal filed with this Administrative Chamber of the National Court, filed by Court Attorney Mr. ,” against the Decision dated February 13, 2023 by the Director of the Spanish Data Protection Agency, dismissing the appeal for reconsideration filed against another decision dated June 8, 2022, which imposed on said entity a fine of 5,000 E for a violation of Article 13 of the GDPR in relation to Article 83(5)(b), classified as minor under Article 74(1)(a) of the LOPDPGDD, and a second fine of 20,000 E for a violation of Article 37 of the GDPR, classified as serious under Article 73 of the LOPDPGDD (PS/00140/2022).
And against the decision of the Director of the Spanish Data Protection Agency, dated June 23, 2023 —Case No. L. es to the provisions of Article 13 of the GDPR, as well as the appointment of a data protection officer. The defendant was the General State Administration, assisted and represented by the STATE LAWYER. The amount in dispute was set at 25,000 euros. The presiding judge of this Section was Ms. Amalia Basanta Rodríguez, who expresses the opinion of the Chamber. 5(b), classified as minor under Article 74. 1(a) of the LOPDPGDD, and a second fine of 20,000 E for a violation of Article 37 of the GDPR, classified as serious under Article 73 of the LOPDPGDD (PS/00140/2022). L. es to the provisions of Article 13 of the GDPR, as well as the appointment of a data protection officer. 1(b) of the GDPR, taking into account the absence and misapplication of the aggravating factors that the AEPD considers in the decision challenged by this complaint.
-With regard to the penalty of FIVE THOUSAND EUROS (5,000 euros), that the proceedings be returned to the investigative phase so that the AEPD may initiate a warning procedure, in accordance Organic Law 3/2018, given that a warning is no longer considered a sanction but rather an autonomous procedure intended for situations such as the one set forth in the present case. In a letter dated July 14, 2023, the appellant expanded the appeal to include the AEPD’s request of June 23, 2023: “… so that, within TEN BUSINESS DAYS from the day following notification of this letter, the appellant may demonstrate to this Agency that it has adopted the appropriate corrective measures, in accordance with the provisions of the aforementioned resolution” (NUM000). —Once the complaint was filed, it was forwarded to the Lawyer, along with the administrative file, so that he could file a response; and, after said response was formalized on August 2, 2023, he requested in his pleading that the appellant’s claims be dismissed and that costs be awarded.
—After the complaint was answered, the case proceeded to the evidentiary phase; the proposed evidence was presented and admitted on the plaintiff’s instance, with the result on record; once the proceedings were concluded, the case file was 2 CASE LAW were ready for judgement, and a date was set for deliberation and ruling on July 7 of this year, on which date, indeed, deliberation took place and a judgement was issued. 5(b), classified as minor under Article 74. 1(a) of the LOPDPGDD, and a second penalty of 20,000 E for a violation of Article 37 of the GDPR, classified as serious under Article 73 of the LOPDPGDD (PS/00140/2022). L. es to the provisions of Art 13 of the GDPR, as well as the appointment of a data protection officer. The aforementioned AEPD Resolution of February 13, 2023, stated: “BACKGROUND FIRST: On May 28, 2021, this Agency received a complaint filed by Mr. Valeriano ...
es. S. es/privacidad). es/cuenta/registro), registration is not possible without checking the box “I accept the terms and conditions of use to receive special offers and promotions from KFC and its franchisees”—in other words, you are required to receive special offers and promotions. At no point is the privacy policy mentioned or linked to, nor is its acceptance required at the time of registration; the only reference is to “terms and conditions of use,” which leads to a legal notice. - The respondent is an entity that engages in advertising and commercial prospecting activities, and it carries out data processing based on the preferences of data subjects or performs activities that involve profiling of data subjects in accordance with its cookie policy and privacy policy; therefore, it is required to have a data protection officer, but does not. - In the privacy policy: (a) the recipients of personal information are not specified; (b) the details of the data controller (company name, tax ID number, registered office) are not provided; (c) the possibility of international data transfers is mentioned, but the data subject is not informed of the existence of adequacy decisions, safeguards, binding corporate rules, or specific situations that apply.
Only generic phrases such as “adequate safeguards” are used. Nor is the procedure explained for obtaining a copy of this information or of the data that was provided; (d) the data storage period is not specified; generic phrases such as “for as long as necessary” are used..... , in which, among other things, it stated: “a. es/privacy and includes information on the processing of personal data carried out by the company’s various brands, detailing, among other things, the following: a) The type of information processed; b) The purposes of the processing; c) The automated processing that may be carried out; d) The categories of data recipients; e) Options and control over the information; f) How the data is stored and protected; g) A link to the privacy policy for the European Economic Area and the United Kingdom; h) Information regarding the privacy of minors; i) Contact information. es/multimarcas and provides details—supplementing the information in the first layer, the remaining information required by Article 13 of the GDPR: a.
Legal basis for processing; b. Data storage and transfer; c. Information on the rights of data subjects and how to exercise them; d. Contact information; e. Appendices detailing the categories of data processed, the purposes of the processing, and the legal bases for such processing. es/multimarcas containing specific information for residents of the EEA and the United Kingdom and includes the remaining information required by Article 13 of the GDPR. Similarly, the Privacy Policy must include the following statement at the top to direct users to the specific jurisdictional disclosures: “Please see our global Privacy Policy below, which applies to your jurisdiction. ” The absence of this statement constitutes an omission with respect to our global privacy policies, which we will correct along with the other changes and improvements to be made as a result of this complaint. Implementation date: these changes will be implemented by September 30, 2021.
- Inability to create an account without agreeing to receive special offers and promotions: The website account creation page is designed to allow users to create accounts without having to agree to receive special offers and promotions. However, due to an error or glitch in the form’s configuration, the text for both acceptance checkboxes includes authorization to receive special offers and promotions. The text of the first checkbox is correct; this corresponds to the User’s express consent to receive offers and promotions from KFC and is optional to check. es,” and it is required to be checked. Although the text of the checkbox indicates that the authorization refers to receiving offers and promotions, the internal processing of the authorization is limited to consent for the creation of the User account. Once the error is detected, KFC will correct and modify it so that the text in the checkboxes corresponds to the authorizations.
Implementation date: these changes have already been applied. —Appendix II. —The form does not provide a link to the privacy policies, since these must be accepted in order to create an account. The link on the web account creation form is designed to provide access to the terms and conditions of use and the privacy policy. However, due to an error or glitch in the hyperlink configuration, it points to the Legal Notice instead of the correct documents. Once the error is detected, KFC will correct and modify it so that the hyperlink points to the terms and conditions of use. Implementation date: these changes have already been implemented. - No Data Protection Officer has been appointed, given that the entity engages in advertising and commercial prospecting activities and performs data processing based on the preferences of the data subjects or carries out activities that involve profiling them.
1 of the GDPR.... - In the privacy policies: The recipients of personal data are not specified. es/privacidad includes, in Section 4, information regarding how User information is shared, and in Section 7, the 4 CASE LAW regarding the disclosure of data to public authorities based on the User’s state or country of residence. Section 4 of the privacy policy describes up to 10 different categories of data recipients. In this regard, Article 13(1)(e) of the GDPR states that the controller must inform the recipients or categories of recipients of personal data, where applicable. ” In this case, given that this is a general privacy policy that applies to all brands and across different territories, the recipients are not predetermined; therefore, only information is provided regarding the categories of recipients to whom the data may be disclosed, including the purpose or reason for such disclosure.
1(e) of the GDPR regarding the provision of information concerning the categories of recipients. Regarding the Absence of Details on the Data Protection Officer. es—the general policy applicable to all jurisdictions and the specific policy for residents of the EEA, the UK, and Switzerland—the identification of the controller can be found in the Legal Notice. We acknowledge this omission and will implement this improvement to provide greater clarity and transparency to the information provided in the privacy policies, by redirecting Users to the Legal Notice within the privacy policy to identify the controller in each territory, including Spain. These changes will be implemented by the end of September 2021. The possibility of international data transfers is detailed, but the data subject is not informed of the existence of adequacy decisions, safeguards, binding corporate rules, or specific situations that apply.
The privacy notice specific to the EEA and the United Kingdom informs users of the possibility of international transfers and includes a statement that, if such transfers occur, KFC will ensure that: a) personal information is transferred to countries recognized as offering an equivalent level of protection; or b) the transfer is carried out in accordance with appropriate safeguards, such as the standard data protection clauses adopted by the European Commission. Notwithstanding these measures, the country and jurisdiction to which the data is transferred may provide a lower level of data protection than that provided for in EEA or UK law. Although this information may seem too general, we take note of this and will make improvements to provide greater clarity and transparency in the information provided in the privacy policy, redirecting users to the contact information for each data controller in each territory so they can request additional information regarding any international transfers that may take place and the appropriate safeguards used to ensure an adequate level of security for such transfers.
A screenshot of the information provided regarding international transfers is attached as Appendix III. Implementation date: these changes will be implemented by September 30, 2021. d. The data storage period is not specified. es/privacidad includes information regarding the data retention period. 1(a) of the GDPR states that the controller must provide information on the period during which personal data will be stored or, where this is not possible, the criteria used to determine that period. ” 5 CASE LAW Information regarding the data retention period is attached as Annex IV. 1 (a) of the GDPR regarding the provision of information concerning data storage periods or the criteria for establishing such periods. However, while this information may seem too generic, we take note and will make an improvement to provide greater clarity and transparency to the information provided in the privacy policy; we will include more specific storage criteria or storage periods in the privacy notice specific to the EEA and the UK.
Implementation date: these changes will be implemented by September 30, 2021..... FIFTH: On November 30, 2021, and February 9, 2022, ... - For each activity, the following must be provided: the number of customer records processed, the range of data elements for each customer that are subject to processing, the duration for which each customer’s data is processed, and details regarding how long such data is retained in its information systems; the geographic or territorial scope of the processing, specifying whether its systems process data relating to customers from a specific territorial area or from the entire national territory; and c) a summary of the analyses conducted by the entity to assess the need to appoint a DPO, indicating whether a DPO has been appointed and, if so, whether this appointment has been communicated and published. SIXTH: On March 1, 2022, and March 10, 2022, the respondent entity sent ...
two separate response letters... in which, among other things, it reported on the following aspects: “An extract from the Record of Processing Activities (RAT) is provided, which reflects all the processing activities carried out by KFC in connection with advertising activities involving customers, specifying the number of customers whose data is processed and the type of data processed for each activity, as well as the duration for which such data is processed. In this regard, KFC has a data storage schedule and an internal protocol for storage and erasure of personal data once it is no longer necessary. It should be noted that KFC does not, under any circumstances, perform profiling; processing activities related to the sending of commercial information are carried out based on the User’s consent (opt-in system) and without user segmentation. Processing activities related to advertising are always carried out with the User’s prior consent, unlike processing activities related to fulfilling user orders, which are carried out on the basis of the performance of a contract.
The geographic scope of the processing activities is Spain, with data management centralized for the entire national territory. Regarding the analyses conducted by your organization to assess the need to appoint a DPO, please indicate whether you have appointed one and, if so, whether this has been communicated and published: In this regard, KFC has determined that there is no obligation to appoint a DPO, since the processing activities carried out do not fall within the scope of Article 37 of the GDPR, nor is the entity among those required to do so under Article 34 of the LOPDGDD. Similarly, data protection compliance management has been handled by in-house staff specializing in data protection—specifically, from the UK, through Samantha Sayers, Global Privacy Lead Counsel—and by external expert consultants in each of the countries where the company operates. However, as previously indicated, we will periodically evaluate internally the need to designate such a role, based on potential operational changes as well as the launch of new business lines that may involve the incorporation of new processing activities, in order to provide greater assurances of compliance to our clients and Users regarding activities and procedures in the processing of personal data, particularly if processing activities for profiling were to be initiated....
— Pursuant to the aforementioned request, the required documentation is hereby submitted to this Agency as follows: A copy of an excerpt from the Register of Processing Activities related to customers and for advertising purposes, as Annex I; and a copy of the Internal Analysis conducted to assess the need to appoint a DPO as Annex II. - Regarding the obtaining of Users’ consent for the processing of their personal data: 1. es/cuenta/registro, where the User can register on the website and is asked to provide their first name, last name, phone number, email address, and credit card number. To submit the form, the User must click the option: _ I accept the >. There is also the option to voluntarily sign up to receive special offers and promotions by clicking the option _ I want to sign up to receive special offers, sweepstakes, and promotions from KFC and/or its franchisees. For more information, visit our >.
>. 2. By clicking the link: >, located at the top of the home page, the website redirects to a new page where you can select your order and choose whether to have it delivered to your home or pick it up at the restaurant. es/checkout, where the User must enter their personal data: first name, last name, phone number, email address, and credit card number. To submit the form, the User must click the option: _ I accept the >. Users also have the option to voluntarily sign up to receive special offers and promotions by clicking the option _ I want to sign up to receive special offers, sweepstakes, and promotions from KFC and/or its franchisees. For more information, visit our >. > 3. es/nosotros/trabaja-en-kfc where the User can sign up or register to receive job offers via the link: Once the user has entered their personal data—first name, last name, email address, and ID number—they must check the following boxes: I am not a robot.
I have read, understand, and accept the > There is also a banner with the following information: Basic Data Protection Information: Data Controller: KFC IBERIA; Purposes: To include in the enterprise’s candidate database the information from the resume you provide when creating your account with us to use it in future recruitment processes for which your profile may be a good fit; Legal Basis: Consent of the data subject; Recipients: We will not disclose your data to third parties except where legally required and to the enterprises listed in the additional information. 4. es/subscripcion, where the User must provide their first name, last name, and email address. ” For more information, visit our >. - Regarding the "Privacy Policy": 1. , an enterprise registered in Spain, with its registered office at Serrano Galvache 56, Edificio Madroño, 3rd Floor, KFC, Madrid, 28033. Tax ID (CIF): B86281599.
Para contact us, please call +34 917 68 07 30. Registration: Data Protection: We will collect, store, and process your personal data in accordance with our privacy Policy. Please read our > to ensure that you are satisfied with and understand its contents before creating an account. Terms and Conditions for Orders Placed via Mobile: Data Protection: We will collect, store, and process your personal data in accordance with our >. Please read our privacy policy to ensure that you are satisfied with and understand its contents before creating an account. ). 2. )”. 3. , with Tax ID B86281599 and registered address at Calle Serrano Galvache (Pq. Empresarial Pq. Norte), 56 - Edif. Olmo, 5th Floor, Madrid, Madrid. es. Phone: 91 904 18 81. Regarding the legal basis for data processing . Based on the consent provided and the right to withdraw your consent at any time, where consent has been given.
Regarding the storage and data transfers within the EEA and the United Kingdom. Regarding the individual rights of EEA residents and how to exercise them, and the right to file a complaint with your local authority. How to contact the website controller. In addition to the information provided in the “Privacy Policy” and the “Privacy Notice,” two appendices are attached containing the following information: - Appendix 1 details the categories of personal information collected, as well as the legal basis for processing personal information and the recipients of such personal information. - Appendix 2 lists the categories of personal information collected and how that information is used. The table also lists the legal basis for processing personal information and the recipients of such personal information.... PROVEN FACTS. es, Users can enter their personal data through various procedures: a) to create a user account; b) to register as a job seeker with the company; c) to place an online order for its products; and d) to receive promotional offers.
Before submitting a form for any of these procedures containing personal data, you must first provide consent for the processing of such data; you may access the website’s “Privacy Policy” via the link: “Terms of Use”—“Privacy Policy (General)”—“Privacy Notice” (Exclusive to the EEA and the United Kingdom). The four forms mentioned above also offer the option to voluntarily sign up to receive periodic promotional offers from the brand. The “Privacy Policy” for the website in question is divided into three documents: a) Website Terms of Use; b) A generic privacy policy for all countries; and c) A specific privacy policy for the countries of the European Economic Area (EEA), the United Kingdom, and Switzerland. ) Data protection: We will collect, store, and process your personal data in accordance with our Privacy Policy. )". es/privacidad, ? "generic policy for all countries," the following introduction appears: "KFC® ("KFC," "we," "our," or "us") is committed to protecting your privacy.
This KFC Privacy Policy (this “Policy”) applies to our websites, online experiences, and mobile Apps for mobile devices running Apple iOS, Windows, or Android that link to the Policy (collectively, our “Sites”), and describes how we collect, use, and disclose your personal information when you visit our Sites or our in-store restaurants and kiosks, or otherwise interact with us (collectively, our “Service”). By accessing or using our Service, you indicate that you have read, understood, and agree to our collection, storage, use, and disclosure of your personal information as described in this Policy and in our Terms of Use, available on our site. For more information about the privacy practices of other enterprises within Yum Brands, Inc. (“Yum Brands”) (the “Brands”), visit: Yum Brands Privacy Policy. PIZZA HUT® Privacy Policy. TACO BELL® Privacy Policy. THE HABIT® Privacy Policy. ) 2.
) We may also use your information to personalize your experience with us and promote our rewards or loyalty programs. ). 4. HOW WE SHARE YOUR INFORMATION We may share, sell, or disclose your information in the instances described below. ” 9 JURISDICTION Other Brands: We may share personal information with our parent enterprise, Yum Brands, and other Yum Brands enterprises and our affiliates, which may use your information in a manner similar to that described in this Policy. ) Promotional Partners: We may share limited information with third parties with whom we partner to provide contests and sweepstakes, or other joint promotional activities. Typically, these partners will be clearly identified in the contest rules or promotional materials. Selected Strategic Business and Marketing Partners: We may share limited data with our preferred strategic business and marketing partners so that they can provide you with information and marketing messages about products or services that may interest you.
These parties may use your information in accordance with their own privacy policies. Online advertising partners: We may share information with third-party online advertising partners or allow these partners to collect information from you directly on our Sites to facilitate online advertising. For more information, please see our Cookies and Ads Policy, available on our Site. ) Other instances in which we may share your personal information: Service providers and consultants: Personal information may be shared with third-party vendors and other service providers who provide services to us or on our behalf. This may include vendors and distributors involved in marketing or advertising activities or that provide mail or email services, tax and accounting services, product compliance, delivery services, payment processing, data enrichment services, fraud prevention, web hosting, or analytics services.
es/multimarcas, you can read the following regarding the purposes for which the personal data collected will be used and the legal basis for such processing: "This Privacy Notice for the EEA and the United Kingdom supplements the information contained in our Privacy Policy and applies solely to individuals residing in the European Economic Area ("you") and to the Sites and Services available in the EEA, as well as in the United Kingdom, that link to this Privacy Notice). Unless expressly stated otherwise, all terms have the same meaning as defined in our Privacy Policy or as otherwise defined in the EU General Data Protection Regulation 2016/679 of the European Parliament and of the Council (“GDPR”). Appendix 1 details the categories of personal information we collect about you and how we use that information when you use the Service, as well as the legal basis on which we rely to process personal information and the recipients of such information.
In addition, the table in Annex 2 details the categories of personal information that we collect about you automatically and how we use that information. The table also lists the legal basis on which we rely to process personal information and the recipients of such personal information. - Profile information such as your name, phone number, date of birth, and profile photo. 1. We may use this information to set up and authenticate your account on the Service: The processing is necessary to fulfill a contract with you and to take steps prior to entering into a contract with you. 2. We may use this information to communicate with you, including sending communications related to the Service: The processing is necessary to fulfill a contract with you. 3. We may use this information to send you marketing communications in accordance with your preferences: We will only use your personal information in this way to the extent that you have given us your consent to do so.
4. We may use this information to handle inquiries and complaints made by you or about you in connection with the Service: The processing is necessary for our legitimate interests, specifically to administer the Service and communicate with you effectively to respond to your inquiries or complaints. ) Information about payments and transactions, including payment information (such as your credit or debit card details or bank account information), and the time, date, and amount of the transactions. — We use this information to facilitate transactions and provide you with the Service: The processing is necessary to fulfill a contract with you. — We use this information for customer service: The processing is necessary to fulfill a contract with you. —We use this information to detect and prevent fraud: Processing is necessary for our legitimate interests, specifically the detection and prevention of fraud.
1. We use GPS technology to determine your current location in order to provide you with relevant content and show where that content was created: Processing is necessary for our legitimate interests, specifically to administer the Service. We will only use your personal information in this way to the extent that you have given us your consent to do so. 1. , by email, phone, mail, or through an online form or online chat), we may record your comments and feedback: Processing is necessary for our legitimate interests, specifically to respond to your question or comment, to evaluate and improve our products and services, and to inform our marketing and advertising. - Information received from third parties, such as social media platforms. If you interact with the Service through a social media platform, we may receive information from that platform, such as your name, profile information, and any other information that you allow the platform to share with third parties.
The data we receive depends on your privacy settings on the social media platform. — We may use this information to authenticate you and grant you access to the Service: Processing is necessary to fulfill a contract with you. - We may use this information to customize how the Service is displayed to you (such as the language in which it is presented): The processing is necessary for our legitimate interests, specifically to tailor the Service so that it is more relevant to our Users. ) Usage information, such as the amount of time you spend using our products, your results when using our products, any issues you encounter while using our products, and any other information generated by the products regarding how you use our products. - We may use this information to analyze how the Service works, troubleshoot issues with the Service, improve the Service, and develop new products and services: The processing is necessary for our legitimate interests, specifically to improve our products and services, address any errors in our products and services, and develop new products and services.
— We may use this information to develop new products and features available through the Service or to improve the Service in any way: The processing is necessary for our legitimate interest, specifically to develop and improve the Service. )—All personal information listed above. —We may use all the personal information we collect to operate, maintain, and provide you with the features and functionality of the Service, communicate with you, monitor and improve the Service and the business, and develop new products and services: The processing is necessary for our legitimate interests, specifically to manage and improve the Service. - Information about how you access and use the Service. For example, how often you access the Service, the time at which you access the Service and how long you use it, the approximate location from which you access the Service, whether you access the Service from multiple devices, and other actions you take on the Service.
— We may use information about how you use and connect to the Service to present the Service on your device: The processing is necessary for our legitimate interests, specifically to tailor the Service to the User. — We may use this information to identify products and Services that may be of interest to you for marketing purposes: The processing is necessary for our legitimate interests, specifically to provide information about our direct marketing. - We may use this information to monitor and improve the Service and our business, troubleshoot issues, and provide updates on the development of new products and services: The processing is necessary for our legitimate interests, specifically to monitor and troubleshoot issues with the Service and improve the Service overall. - Log files and information about your device. We also collect information about the tablet, smartphone, or other electronic device you use to connect to the Service.
This information may include details about the device type, the device’s unique identification numbers, operating systems, browsers, and applications connected to the Service via the device, your mobile network, IP address, and your device’s phone number (if applicable). — We may use information about how you use and connect to the Service to present the Service on your device: The processing is necessary for our legitimate interests, specifically to tailor the Service to the User. - We may use this information to identify products and Services that may be of interest to you for marketing purposes: The processing is necessary for our legitimate interests, specifically to provide information about our direct marketing. - We may use this information to monitor and improve the Service and our business, prevent and detect fraud, troubleshoot issues, and provide information on the development of new products and services: The processing is necessary for our legitimate interests, specifically to monitor and troubleshoot issues with the Service and to improve the Service in general.
es/ multimarcas. All of these are accessible from the various forms (listed in the previous section) and through the links at the bottom of the home page. ) Data protection: We will collect, store, and process your personal data in accordance with our Privacy Policy. Please read our Privacy Policy to ensure that you are satisfied with and understand its contents before creating an account. - In the “Privacy Policy” document ( ), you can find the following information regarding the processing of the personal data collected: 1. what type of information they collect 2. how they use the personal information they collect 3. what information they collect automatically 4. how they share the information collected. 5. Options and control regarding the information collected. 6. How the information is stored and protected. 7. Jurisdictional disclosures. 8. Children’s privacy. 9. Links to other websites and services.
10. How to contact the controller. L. The legal basis for processing in the EEA and the United Kingdom is stated as: 12 JURISDICTION The table in Annex 1 sets forth the categories of personal information they collect, as well as the legal basis and the recipients of such personal information. The table in Annex 2 sets forth the categories of personal information they collect automatically. The table also lists the legal basis on which they process personal data and the recipients of such personal data. Information is provided regarding data storage and transfers. Information is provided regarding the individual rights of EEA residents: Right to object. Right of access. Right to rectification. Right to erasure. You also have the right to file a complaint with your Data Protection Authority. Information regarding the storage of personal data is provided: For individuals residing in the EEA we store personal data for no longer than is necessary to fulfill the purposes for which we collect the data, such as delivering your order, maintaining our service, complying with our legal obligations, and resolving disputes.
We will store your personal data in accordance with applicable statutory limitation periods, as required by the tax and accounting regulations of each EEA country. es describes the purposes of personal data processing and specifies the legal basis for each one, the processing of data for these purposes would not constitute further processing. es/multimarcas. All of these are accessible from the various forms (listed in the previous section) and via the links at the bottom of the homepage. ) Data protection: We will collect, store, and process your personal data in accordance with our Privacy Policy. Please read our Privacy Policy to ensure that you are satisfied with and understand its contents before creating an account. - In the "Privacy Policy" document ( ), we can find the following information regarding the processing of the personal data collected: 1. what type of information they collect 2.
how they use the personal information they collect 3. what information they collect automatically 4. how they share the information collected. 5. Options and control regarding the information collected. 6. How they store and protect the information 7. Jurisdictional disclosures 8. Children’s privacy 9. Links to other websites and services 10. How to contact the controller. L. Regarding the legal basis for processing in the EEA and the United Kingdom, the following is stated: The table in Annex 1 sets forth the categories of personal information they collect, as well as the legal basis and the recipients of such personal information. The table in Annex 2 sets out the categories of personal information they collect automatically. The table also lists the legal basis on which they rely to process personal information and the recipients of such personal information. Information is provided regarding data storage and transfer.
Information is provided regarding the individual rights of EEA residents: Right to object. Right of access. Right to rectification. Right to erasure. You also have the right to file a complaint with your Data Protection Authority. Information regarding the storage of personal data is provided: For individuals residing in the EEA, we store personal data for as long as necessary to fulfill the purposes for which we collect the data, such as delivering your order, maintaining our service, complying with our legal obligations, and resolving disputes. We will store your personal data in accordance with the applicable statutory limitation periods, as well as the tax and accounting regulations of each EEA country. Upon the expiration of these periods, or upon your request, the data will be erased or anonymized so that it can no longer be used to identify you, unless we are legally authorized or required to perform storage of the personal data for a longer period.
es does not provide precise information regarding the purposes of data processing, as it uses such as “we may use…,” without the respondent having substantiated the reason why such language was necessary, as required by the Transparency Guidelines pursuant to Regulation (EU) 2016/679 of the Article 29 Working Party, last revised and adopted on April 11, 2018, which stipulate the following: “13. The use of terms such as ‘may,’ ‘could,’ ‘some,’ ‘frequently,’ and ‘possible’ should be avoided. When controllers choose to use vague language, they must be able to demonstrate, in accordance with the principle of proactive accountability, why the use of such language could not be avoided and why it does not undermine the fairness of the processing. - Classification and characterization of the violation Regarding the information that the controller must provide to the data subject when data is collected from them.
Recital 60 of the GDPR states: “The principles of fair and transparent processing require that the data subject be informed of the existence of the processing operation and its purpose. The controller must provide the data subject with any additional information necessary to ensure fair and transparent processing, taking into account the specific circumstances and context in which the personal data are processed. The data subject must also be informed of the existence of profiling and the consequences of such profiling. If personal data are obtained from the data subjects, they must also be informed as to whether they are required to provide such data and of the consequences of failing to do so. Such information may be provided in combination with standardized icons that offer, in an easily visible, intelligible, and clearly 14 CASE LAW legible manner, an adequate overview of the intended processing.
” Recital 61 of the GDPR states the following: “Information regarding the processing of their personal data must be provided to data subjects at the time it is collected from them or, if collected from another source, within a reasonable period of time, depending on the circumstances of the case. If personal data may be lawfully disclosed to another recipient, the data subject must be informed at the time the data is first disclosed to that recipient. The controller who intends to perform processing on the data for a purpose other than that for which it was collected must provide the data subject, prior to such further processing, with information regarding that other purpose and any other necessary information. When the source of the personal data cannot be provided to the data subject because multiple sources were used, general information must be provided. For its part, Article 13 of the GDPR details the information that must be provided to the data subject when their personal data is collected directly from them, establishing the following: “1.
When personal data relating to a data subject are obtained from the data subject, the controller shall, at the time the data are obtained, provide the data subject with: a) the identity and contact details of the controller and, where applicable, of the controller’s representative; b) the contact details of the data protection officer, if any; c) the purposes of the processing for which the personal data are intended and the legal basis for the processing; d) where the processing is based on Article 6(1)(f), the legitimate interests of the controller or of a third party; e) the recipients or categories of recipients of the personal data, where applicable; f) where case, the controller’s intention to transfer personal data to a third country or an international organisation and the existence or absence of a Commission adequacy decision, or, in the case of transfers referred to in Articles 46 or 47 or the second paragraph of Article 49(1), a reference to the adequate or appropriate safeguards and the means of obtaining a copy of them or the fact that they have been provided.
2. 1(c) of the GDPR, users must be informed of the purposes of the processing to which their personal data will be put and the applicable legal basis for such processing (Art. 6 GDPR), avoiding practices such as including overly generic or unspecific purposes that could lead to further processing that exceeds the data subject’s reasonable expectations. ) share, sell, or disclose your information with: Other Brands: We may share personal information with our parent enterprise: Yum Brands and other Yum Brands enterprises and our subsidiaries, which may use your information in a manner similar to that described in this Policy. Or, for example, when the entity states that it may share the personal data collected with its third-party service providers. ). Based on the legal grounds set forth above, the facts indicated in the previous section constitute a violation of Article 13 of the GDPR. - Penalty Imposed.
This violation may be penalized with a fine of up to €20,000,000, or, in the case of an enterprise, an amount equivalent to a maximum of 4% of the total of the preceding financial year, whichever is higher, in accordance with Article 83(5)(b) of the GDPR. ” Taking into account the circumstances of the case, with respect to the violation committed by breaching the provisions of Article 13 of the GDPR, an initial fine of 5,000 euros (five thousand euros) is hereby imposed. es) into compliance with current regulations, bringing it into line with the provisions of Article 13 of the GDPR.... - Regarding the absence of a data protection officer.... - Classification and characterization of the violation Regarding whether or not it is necessary to appoint a data protection officer, Article 37 of the GDPR stipulates the following: “1. The controller and the processor shall designate a data protection officer whenever ...
”. ” ‘Core activities’ may be considered the key operations necessary to achieve the objectives of the controller or processor. However, ‘core activities’ should not be interpreted as exclusive when data processing is an inseparable part of the activity of the controller or processor. For example, the main activity of a hospital is to provide health care. However, a hospital could not provide healthcare safely and effectively without processing data concerning health, such as patients’ medical records. Therefore, the processing of such data must be considered one of the core activities of any hospital, and hospitals must, consequently, appoint a DPO. Another example would be a private security enterprise that conducts surveillance of a number of private shopping centers and public spaces. Surveillance is the core activity, which in turn is inextricably linked 16 CASE LAW inextricably linked to the processing of personal data.
Therefore, this enterprise must also appoint a DPO. Furthermore, all enterprises carry out certain activities, such as paying their employees or performing routine IT support tasks. Such activities are examples of support functions necessary for the organization’s main activity or business. ” The Art 29 Working Party interprets “habitual” to have one or more of the following meanings: a) continuous or occurring at specific intervals over a specific period; b) recurring or repeated at predetermined times or taking place constantly or periodically. The Working Party interprets “systematic” to mean one or more of the following: a) occurring in accordance with a system; b) preestablished, organized, or methodical; c) taking place as part of an overall data collection plan; d) carried out as part of a strategy. As an example, it cites data-driven marketing activities, such as location tracking—for example, through mobile apps, loyalty programs, or behavioral advertising.
Thus, in the case under review, it meets the criterion of being routine and in accordance with a data collection plan to obtain customer data and expand its business reach. One need only glance at its privacy policy, which shows that it collects all kinds of data, including the IP address (a key point of location), browsing history, and User preferences, as well as data derived from cookies—including Tracking cookies—geolocation data, and billing data, among others. And they collect this data on a regular basis, as they need it to provide their services and improve the performance of their business. Among other things, the privacy policy states that the data is used for statistical and service-related purposes. Third, it must be determined whether the processing is on a large scale; regarding this, WP 243 establishes certain criteria, “recommending that the following factors, in particular, be taken into account when determining whether the processing is carried out on a large scale: a) the number of data subjects affected, either as a specific figure or as a proportion of the relevant population; b) the volume of data or the variety of data elements being processed; c) the duration or permanence of the data processing activity; d).
the geographic scope of the processing activity. ” The EDPB does not define what constitutes “large scale” in any specific terms, but rather adheres to the criteria referenced. ’ In the WP29 guidelines on the Data Protection Officer (WP243) and on the DPIA (WP248), both endorsed by Board, it has recommended taking several specific factors into account when determining whether processing is carried out on a large scale. The Board is of the opinion that these factors are sufficient to assess whether the processing of personal data is undertaken on a large scale. ". Large-scale processing involves processing a considerable amount of personal data (all of which are listed in its privacy policy) within a specific territorial scope (in this case, at the national level); affecting multiple data subjects (this is a widely used app with a large number of data subjects); and may also entail a high risk (one of the data points used is geolocation).
Having examined the parameters outlined in this specific case, it is clear that this constitutes large-scale data processing. ” In response to the allegations raised in the complaint regarding the quantitative criteria that may be used other supervisory authorities to determine when processing is on a large scale, we must point out that the AEPD is an independent supervisory authority that, in the performance of its duties, determines in each specific case whether or not the processing is on a large scale, taking into account the relevant circumstances. On another note, we would point out that the mandatory appointment of a DPO in the case provided for in Article 37(1)(b) of the GDPR is linked solely to compliance with the conditions set forth therein and not to other factors cited by the plaintiff, such as the type of data or processing operations. The fact that the principal activities of the controller or processor consist of processing operations which, due to their nature, scope, and/or purposes, require regular and systematic monitoring of data subjects on a large scale already necessitates the appointment of a DPO, given the risks involved, especially if such processing is carried out via the internet or an app, as in the case under review.
The role of the DPO as a qualified advisor to the controller or processor is an essential safeguard in the cases provided for in the GDPR and the LOPDGDD to guarantee citizens’ fundamental rights and prevent the materialization of risks that a given activity may entail. Consider, for example, identity theft (Art. 2 of the LOPDGDD). The notion that the risk is trivial is therefore ruled out. In any case, failing to appoint a DPO when it is mandatory poses a risk to the protection of personal data. 1 and 3, regarding the appointment of a data protection officer: 1. 1 of Regulation (EU) 2016/679 3. ” Based on the legal grounds set forth above, the facts indicated in the previous section constitute a violation of Article 37 of the GDPR. - Penalty This violation may be penalized with a fine of up to €10,000,000 or, in the case of an enterprise, an amount equivalent to up to 2% of the total annual global turnover for the , whichever is higher, in accordance with Article 83(4)(a) of the GDPR.
” In accordance with the aforementioned provisions, for the purpose of determining the amount of the penalty to be imposed in this case, it is considered appropriate to adjust the penalty in accordance with the following aggravating factors established in Article 83(2) of the GDPR: - The intentional nature of the violation on the part of KFC (subsection b), given that it is an entity whose business involves the continuous processing of customers’ personal data; it is considered of particular importance to recall at this point the Supreme Court ruling of October 17, 2007 (Case No. 63/2006), which states that: “…the Supreme Court has held that negligence exists whenever a legal duty of care is disregarded, that is, when the offender does not act with the required diligence. 2 of the LOPDGDD: - The connection between the offender’s activity and the processing of personal data (subsection b), considering the extent to which KFC is embedded in the country’s economy, involving the personal data of thousands of customers who access its services daily.
1 of the GDPR, allows for the imposition of a penalty of 20,000 euros (twenty thousand euros). — Measures. " SECOND. — The plaintiff argues in support of its appeal that the minor violation attributed to it (failure to comply with the principle of transparency in its privacy policy) is unrelated to the initial complaint; and that, if anything, a warning sanction would be appropriate. Regarding the serious violation of the provisions of Article 37 of the GDPR (appointment of a data protection officer), she contends that it does not apply, since, given her primary activity, she is not required to do so. For his part, the State Lawyer maintains that the contested decisions are in accordance with the law. THIRD. — Article 13 of the GDPR provides: “1. Where personal data relating to a data subject are obtained from the data subject, the controller shall, at the time of collection, provide the data subject with all the information set forth below: a) the identity and contact details of the controller and, where applicable, of its representative; 19 CASE LAW b) the contact details of the data protection officer, if any; c) the purposes of the processing for which the personal data are intended and the legal basis for the processing; d) where the processing is based on Article 6(1)(f), the legitimate interests of the controller or of a third party; e) the recipients or categories of recipients of the personal data, if applicable; f) where applicable, the controller’s intention to transfer personal data to a third country or international organisation and the existence or absence of a Commission adequacy decision, or, in the case of transfers referred to in Articles 46 or 47 or the second paragraph of Article 49(1), a reference to the appropriate or suitable safeguards and the means to obtain a copy of them or to the fact that they have been provided.
2. The controller must provide the data subject with any additional information necessary to ensure fair and transparent processing, taking into account the specific circumstances and context in which the personal data are processed. The data subject must also be informed of the existence of profiling and the consequences of such profiling. Such information may be provided in combination with standardized icons that offer, in an easily visible, intelligible, and clearly legible manner, an adequate overview of the intended processing. " And Recital 61 of the GDPR states: "Data subjects should be provided with information regarding the processing of their personal data at the time it is collected from them or, if collected from another source, within a reasonable period of time, depending on the circumstances of the case. The controller who intends to process the data for a purpose other than that for which it was collected must provide the data subject, prior to such further processing, with information regarding that other purpose and any other necessary information.
” With regard to our case, despite the plaintiff’s assertions, the complainant alleged to the AEPD that facts detected on the KFC website could constitute breaches of obligations related to privacy policies. ” In summary, these violations are as follows: - lack of direct access to the privacy policies for Users in the European Economic Area; - inability to create an account without agreeing to receive special offers and promotions; 20 CASE LAW - the registration form does not provide a link to the privacy policies, even though these must be accepted in order to create an account. If we refer to the administrative record and, specifically, to the statement of defense filed by the respondent—now plaintiff—submitted to the AEPD on August 20, 2021, it expressly acknowledges these violations and, furthermore, as the appealed decision highlights, the appellant’s website contained only very generic references regarding the purposes for which personal data would be used.
” Other non-compliant practices were also identified, noted, and addressed (We have taken note of this shortcoming and will implement this improvement to provide greater clarity and transparency to the information provided in the privacy policies, by redirecting Users to the Legal Notice in the privacy policy to identify the controller in each jurisdiction, including Spain. These changes will be implemented by the end of September 2021; regarding the lack of detail on data storage periods, although this information may seem too generic, we take note and will make an improvement to provide greater clarity and transparency to the information provided in the privacy policy; we will include more specific storage criteria or storage periods in the privacy notice specific to the EEA and the UK. ) As we have already indicated, data protection regulations require, in this regard, that information that is too generic or unspecific—which could conceal processing activities that exceed the User’s reasonable expectations—be avoided; therefore, the information provided by the appellant to Users regarding the privacy policy is inadequate, constituting a clear violation of Article 13 of the GDPR, which requires that, at the time personal data is collected, the data subject be provided with all information regarding—among other things—the purposes of the processing of their personal data and the legal basis for such processing.
Returning to the alleged “disconnect” between the initial complaint and the facts investigated by the AEPD, it must be be noted that even if this were the case—which it is not—it is neither relevant nor does it have the nullifying consequences that the plaintiff claims, since a data subject’s complaint may be nothing more than a means of bringing a possible violation of data protection regulations to the attention of the supervisory authority. What cannot be concluded—nor is it required by any provision—is that the supervisory authority’s actions were limited to the scope of the specific and concrete complaint filed by the data subjects, as this would entail an absurd limitation on the AEPD’s supervisory powers. As the State Lawyer points out, the CJEU takes a broad view of the powers of supervisory authorities to impose sanctions for violations of the GDPR, regardless of whether such sanctions may stem directly from a complaint (Judgments of the CJEU of July 16, 2020, C-311/18, Data Protection Commissioner Schrems 2, and of October 6, 2015, C-362/14, Schrems).
According to the first of these judgments: “109 Furthermore, pursuant to Article 57(1)(f) of the GDPR, it is incumbent upon each supervisory authority, within its territory, to handle complaints that any person, in accordance with Article 77(1) of the aforementioned Regulation, may lodge if they consider that the processing of personal data concerning them infringes that Regulation, and to examine the substance of such complaints to the extent necessary. The supervisory authority must handle such complaints with all due diligence (see, by analogy, with respect to Article 25(6) of Directive 95/46, the judgement of October 6, 2015, Schrems, C-362/14, EU:C:2015:650, paragraph 63). 111 To enable them to handle the complaints lodged, Article 58(1) of the GDPR confers on each supervisory authority significant investigative powers. ) is required, pursuant to Union law, Union law, to take appropriate action to remedy the identified deficiency, regardless of the origin or nature of that deficiency.
” Consequently, the claim raised by the plaintiff alleging a disconnect between the initial complaint and the investigation and sanctioning proceedings conducted by the AEPD must be dismissed. FOURTH. —With regard to the alleged lack of proportionality of the sanction imposed, specifically the warning, the response must likewise be negative. 21 CASE LAW As this Chamber has consistently held, citing the Supreme Court rulings of the Third Chamber dated December 3, 2008 (Case No. 6602/2004) and April 12, April 2012 (Case No. 3 of Law 40/2015 on the Legal Regime for the Public Sector. This is because every sanction must be determined in accordance with the nature of the infraction committed and based on a criterion of proportionality in relation to the circumstances of the act. This principle, as noted in the aforementioned Supreme Court ruling of April 12, 2012, cannot be exempt from judicial review.
5(b), carries a fine of up to 20,000 E or, in the case of an enterprise, an amount equivalent to 4% of its annual turnover; this is classified as a minor violation under Art. 74(a) of the LOPDGDD. The fine of 5,000 E imposed is not considered disproportionate, given that numerous breaches of the privacy policy were observed, even though the enterprise reacted immediately by adopting corrective measures. —Regarding the second of the violations attributed to the plaintiff—failure to appoint a data protection officer—Art 37(1)(b) of the GDPR provides: “1. ” .... 5. The data protection officer shall be appointed on the basis of his or her professional qualities and, in particular, his or her expert knowledge of data protection law and practice and his or her ability to perform the duties set forth in Article 39. 6. The data protection officer may be a member of the staff of the controller or processor or may perform his or her duties under a service contract.
7. 1 and Article 3 on “Appointment of a data protection officer,” provides as follows: “1. 1 of Regulation (EU) 2016/679. 3. The level of specialized knowledge required must be determined, in particular, based on the data processing operations carried out and the level of protection required for the personal data processed by the controller or processor. ” The plaintiff considers that it is not required to appoint a data protection officer because, as it asserts, its main activity is the restaurant business, which is conducted primarily in person at its 22 CASE LAW establishments and restaurants, and that activity is not related to the processing of such customers’ personal data as an ancillary activity. ” However, in light of these arguments, we must concur with the interpretation put forward by the AEPD in the contested Resolution, drawing upon the “Guidelines on Data Protection Officers” (16/ WP243 rev.
01) drawn up by the Article 29 Data Protection Working Party (adopted on December 13, 2016, and revised and adopted on April 5, 2017). ” A core activity is an operation necessary to achieve the objectives of the controller, but this does not preclude the possibility that data processing may be an inseparable part of the controller’s activity. In our case, data processing is not the plaintiff’s core activity, but neither can it be separated from it. We need only refer to the list of ESTABLISHED FACTS, which shows that the plaintiff collects personal data from Users through various procedures: a) to create a user account; b) to register as a job seeker with the network; c) to place an online order for its products; and d) to receive promotional offers. It is also evident that the entity engages in advertising and commercial prospecting activities, carrying out processing based on customer preferences and, consequently, performs activities that involve profiling, interacts with social media platforms, and uses profile information and any other data permitted by the social media platform that is shared with third parties..
) share, sell, or disclose your information with: Other Brands: We may share personal information with our parent enterprise, Yum Brands, and other Yum Brands enterprises and our affiliates, which may use your information in a manner similar to that described in this Policy. The entity also states that it may share the personal data collected with its external service providers. In accordance with the requirements of Article 37(1)(b) of the GDPR, the AEPD Resolution notes that the Art 29 Working Party interprets the term “habitual” to have one or more of the following meanings: a) continuous or occurring at specific intervals over a specific period; b) recurring or repeated at predetermined times; c) taking place on a constant or periodic basis. It interprets “systematic” to mean one or more of the following: a) occurring in accordance with a system; b) preestablished, organized, or methodical; c) taking place as part of an overall data collection plan; d) carried out as part of a strategy.
As an example, it cites data-driven marketing activities, such as location tracking—for example, through mobile apps, loyalty programs, or behavioral advertising. ); and it does so on a regular basis to provide its services and to improve the performance of its business. Finally, it is also indisputable that the data processing is carried out on a large scale, given the criteria established by WP 243, which “recommends” that the following factors be taken into account: a) the number of data subjects affected, either as a specific figure or as a proportion of the relevant population; b) the volume of data or the variety of data elements being processed; c) the duration or permanence of the data processing activity; d) the geographic scope of the processing activity. We have presented sufficient evidence to support the concurrence of these factors; therefore, the plaintiff’s claim should be dismissed, and, for the same reasons set forth in Legal Ground 4, there is no disproportion in the penalty imposed.
—Regarding the challenge to the AEPD’s Resolution of June 23, 2023—Case No. L. was required, within TEN BUSINESS DAYS, to demonstrate that it had adopted the appropriate corrective measures—this constitutes an act implementing the Resolution of February 13, 2023, in exercise of the powers granted under Art 58. 2 of the GDPR, the validity of which was not only not challenged by the plaintiff, but—in its brief of arguments—it expressed its agreement with the measures established by the AEPD regarding the privacy policy and the appointment of a data protection officer—even though it set forth the reasons for its disagreement—it did not object either. In these proceedings, the plaintiff has not actually raised any challenge in this regard; therefore, no ruling on this matter is warranted. —Pursuant to Art. 1 of the Law Governing this Jurisdiction, costs are to be imposed on the plaintiff, whose claims have been dismissed in their entirety.
—To dismiss the present appeal No. 420/2023 filed by Court Attorney Mr. 1(a) of the LOPDPGDD, and a second penalty of 20,000 E for a violation of Article 37 of the GDPR, classified as serious under Art 73 of the LOPDPGDD (PS/00140/2022). And against the decision of the Director of the Spanish Data Protection Agency, dated June 23, 2023— Case No. L. es to the provisions of Article 13 of the GDPR, as well as the appointment of a data protection officer. —To order the plaintiff to pay the costs of the appeal. This judgement is subject to an appeal to the Court of Cassation, which must be filed with this Chamber within 30 days from the day following its notification; the brief preparing the appeal must demonstrate compliance with the requirements set forth in Article 89(2) of the Jurisdiction Act, justifying the objective interest in appealing to the Supreme Court. Thus, by this judgement of ours, a certified copy of which shall be forwarded together with the administrative record to its office of origin for enforcement, we hereby render, order, and sign this judgement.
The dissemination of the text of this decision to data subjects not involved in the proceedings in which it was rendered may only take place after the personal data contained therein has been anonymized and with full respect for the right to privacy, the rights of data subjects requiring special protection, protection, or the guarantee of anonymity for victims or those who have suffered harm, where applicable. The personal data included in this ruling may not be transferred or disclosed for purposes contrary to the law.