# AEPD (Spain) - PS/00249/2025

- Type: Enforcement
- Source: AEPD (Spain)
- Date: 2026-08-12
- Original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00249/2025
- Canonical: https://overview.legal/posts/187487
- Topics: IP Address, Cookies, Direct Marketing, Personal Data, Legitimate Interest, Lawful Basis, Consent, Controllers, Processing, Marketing

## Summary

Facts — MÁS SOL ENERGÍA 15, S.L., the controller, is a company that carries out customer acquisition through telephone calls to offer solar panel installation services. On 18 November 2024, the data subject received a marketing call from an agent acting on behalf of the controller. The agent addressed the data subject by name and asked questions about the type of residence in which he lived. When the data subject asked whether the controller had checked the Robinson List, the agent stated that this was unnecessary because the call was based on a “database”. When the data subject subsequently asked about the source of his personal data, the call ended. The data subject later contacted the controller’s customer service to enquire about the source of his data and was told that the data had been obtained by its sales department and might originate from his acceptance of cookies. The data subject disputed this, stating that he had never visited the controller’s website. At the time of the call, his telephone number had been registered with the Robinson List since March 2024. The controller explained that it obtained databases from external marketing providers which guaranteed that the personal data had been lawfully collected. It claimed that the data subject had consented in June 2020 through an online form to the processing of his data, the receipt of marketing communications and the disclosure of his data to third parties. As evidence, the controller provided a record containing the data subject’s details, an IP address, a timestamp and consent indicators, as well as a generic version of the relevant online form. However, the form was blank and did not contain any information specifically identifying the data subject. The controller also acknowledged that it did not independently verify the validity of the consent provided by its external supplier. Holding — The DPA held that the controller violated Article 66(1)(b) LGTel and Article 14 GDPR. First, regarding the commercial call, the DPA considered that the controller had not demonstrated that the data subject had given valid consent within the meaning of Article 4(11) GDPR. The documentation provided did not establish that the data subject personally completed the registration, entered the telephone number or could be linked to the IP address contained in the record. Moreover, the controller did not provide the privacy policy applicable when the alleged consent was obtained, meaning that it could not establish the purposes or third parties covered by that consent. The DPA recalled that, pursuant to Articles 5(2) and 7 GDPR, it is for the controller to demonstrate that valid consent was obtained. This responsibility could not be transferred to the external data provider through contractual guarantees. The controller remained responsible for establishing a valid legal basis for using the purchased data for its own marketing campaign. This was particularly relevant because the data subject's telephone number was registered with the Robinson List. Although the registration, and as specific consent was not sufficiently demonstrated, the controller could not rely on the exception under Article 23(4) LOPDGDD. Consequently, the DPA found that the unsolicited call lacked a valid legal basis and violated Article 66(1)(b) LGTel. Second, the DPA found a violation of Article 14 GDPR. Since the controller had obtained the personal data from a third party, it was required to provide the information listed in Article 14 GDPR. During the call, the agent merely referred to an unspecified “database” and did not adequately inform the data subject about the source of the data, the controller's identity, the legal basis for the processing or his data protection rights. The duration or termination of the call did not relieve the controller of this obligation, and the controller had not demonstrated that the required information was provided through another channel. The DPA imposed a fine of €5,000 for the violation of Article 66(1)(b) LGTel and a further €5,000 for the violation of Article 14 GDPR, resulting in a total fine of €10,000.

## Full text

Case No.: EXP202416818 (PS/00249/2025) DECISION IN THE ENFORCEMENT PROCEEDING Based on the proceedings conducted by the Spanish Data Protection Agency (hereinafter hereinafter, “AEPD”) and based on the following, BACKGROUND FIRST: On November 21, 2024, A.A.A. (hereinafter, the complainant) filed a complaint with the AEPD. The complaint is directed against the entity MÁS SOL ENERGÍA 15, S.L., with Tax ID No. B90346370 (hereinafter “MÁS SOL” or the “respondent”) for the alleged violation of Law 11/2022 of June 28, the General Telecommunications Law (hereinafter “LGTel”), and Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data (hereinafter the “GDPR”), and Organic Law 3/2018, of December 5, on Data Protection Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD). The complainant states in his complaint that on November 18, 2024, he received a sales call from the number ***PHONE.1, in which an agent identified as “B.B.B.” stated that she was calling on behalf of “Mas Sol,” an enterprise specializing in the installation of solar panels, and that she addressed him by name and asked whether he lived in an apartment or a single-family home. He notes that, when the data subject asked whether the company had previously checked the Robinson List, the caller responded that they were under no obligation to do so because they relied on a “database.” He adds that, when he tried to ask about the source of his personal data, the call was unilaterally disconnected. Subsequently, he contacted the enterprise’s customer service to find out the source of his personal data, and was told that this information was handled by the sales department and that it presumably stemmed from his acceptance of cookies—a claim he considers untrue, as he had ever visited the company’s website or given consent. The following documentation, among others, is submitted along with the complaint letter: - Screenshot of the call history from the complainant’s mobile device, showing an incoming call from the number ***PHONE.1, received on Monday, November 18, 2024, at 1:24 p.m., lasting 46 seconds, along with an audio recording of the call. - Certificate from the Robinson List Service, issued in the claimant’s name, which states that their registration has been active since March 9, 2024. It indicates that the following numbers are registered on the telephone channel: ***PHONE.2 (since March 9, 2024) and ***PHONE.3 (since August 29, 2024). C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 2/23 SECOND: On November 29, 2024, in accordance with the provisions of Article 65.4 of the LOPDGDD, this Agency forwarded said complaint to the respondent so that it could analyze it and respond, within one-month period, regarding the matters set forth in the complaint. THIRD: On December 24, 2024, the respondent submitted a written response in which it stated, in summary, that it conducts telemarketing campaigns using databases contractually acquired from specialized third-party enterprises, specifically ***ENTERPRISE.1 or ***ENTERPRISE.2, which guarantee that the data has been obtained with the informed consent of the data subjects and in accordance with the regulations. With regard to the complainant, the respondent indicates that consent was granted on June 30, 2020, at 9:17 p.m. via the website ***WEB.1, providing the IP address and the supporting document with the consent boxes checked for the processing of data and the sending of commercial communications, including by third parties. It also states that calls are managed through the automated platform PLATAFORMA.1, based on encrypted lists provided by the supplier, without any manual intervention in dialing or modifying the data, with operators to making notes, and the system has protocols for registering numbers such as “DO NOT CALL” or “OPT-OUT.” Finally, it notes that it has control mechanisms in place to prevent errors, based on system automation and the monitoring of these records, with no incidents having been detected to date; in any case, records marked as “OPT-OUT” take precedence in the event of a discrepancy. The following documentation is attached to the letter: - A generic subscription form for a commercial newsletter, which collects personal data such as first name, last name, email address, gender, date of birth, ZIP code, and cell phone number. It includes three checkboxes with the following text: (i) I have read and accept the terms and conditions of the site and the Privacy Policy, and I authorize the processing of my Personal Data for the services offered by the site; (ii) I consent to the processing of my Personal Data for the purpose of sending advertising communications and for commercial purposes set forth in Article 2 of the Privacy Policy; and (iii) I consent to my personal data being disclosed to third parties on our list of sponsors, as specified in Article 2 of the Privacy Policy. The form also reminds the data subject that they may object at any time to processing for marketing purposes or commercial profiling. The document is completely blank; it contains no data entered by any person, so there is no reference whatsoever to the complainant or their personal data. - CFR from ***ENTERPRISE.3 stating that the data contained in its database corresponds to a registration made through the website: ***WEB.1. It includes C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 3/23 a table with personal data: First Name: A.A.A. Last Name: (...) IP Address: (...) Date/time of registration: 06/30/2020 – 9:17 p.m. Mobile phone number: ***PHONE.2 ZIP code: (...). Consent indicators “dd,” “dm,” “dmt” (0=NO, 1=YES), with a value of 1 for all three indicators, and that, on the “registration for a contest or similar” form, the data subject had checked the consent boxes for marketing, third-party marketing, and data processing. FOURTH: On February 21, 2025, in accordance with Article 65 of the LOPDGDD, the complaint filed by the complainant was accepted for processing. FIFTH: On February 4, 2026, the Presidency of the Spanish Data Data Protection agreed to initiate disciplinary proceedings against the respondent pursuant to the provisions of Articles 63 and 64 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter the LPACAP), for the alleged violation of Article 66.1.b) of the LGTel, as defined in Article 107.30 of the aforementioned law, with an initial penalty of 5,000 euros (five thousand euros) and for the alleged violation of Article 14 of the GDPR, as defined in Article 83.5.b of the aforementioned regulation, with an initial penalty of 5,000 euros (five thousand euros). SIXTH: On February 13, 2026, the respondent filed a brief of arguments in which it reiterates that the complainant’s consent was validly obtained and verified through technical records (IP address, date and time, and URL), stating that on June 30, 2020, at 9:17 p.m., such consent was given via the website ***WEB.1 and that this type of evidence has previously been deemed sufficient by the AEPD, citing case EXP202400904, which was resolved on April 24, 2024, with the proceedings closed. Furthermore, it argues that requiring an unequivocal link between said technical record and the user’s physical identity constitutes a reversal of the burden of proof and a disproportionate requirement not provided for in the regulations. Regarding due diligence, the enterprise states that it has acted with a high standard of care by contracting with specialized providers (***ENTERPRISE.2 / ***ENTERPRISE.3), with whom it maintains a contract that guarantees the lawfulness of the data and in which the provider assumes responsibility for data collection, also providing certifications of privacy policies that disclose the transfer of data to third parties for marketing purposes. It maintains that, should there be a defect in the data collection, responsibility would lie with the supplier and not with the entity, as it acted under the principle of legitimate expectations and without any indication of irregularity. Regarding the duty to provide information, it states that the phone call lasted 46 seconds and ended abruptly, which materially prevented it from providing the required information. It points out that it has information protocols whose application was thwarted by the interruption of the call and adds that it was not was not required to prove this point at an earlier stage, which would have left it defenseless. Along with the written statement of arguments, the following documentation is submitted: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 4/23 - Document 1.—Decision issued by the Director of the Spanish Data Protection Agency in case EXP202400904, initiated by a complaint filed on January 10, 2024, regarding the receipt of from a specific phone line, which includes the background of the case, the referral to the entity against which the complaint was filed, that entity’s statements regarding the origin of the personal data, the existence of a contract with a database provider, and the submission of a certificate confirming the obtaining of consent via a web form; it was ultimately agreed to close the complaint and notify the parties. - Document 2.—Dated December 2, 2024, a notice issued by ***ENTERPRISE.3 detailing the personal data contained in its database associated with a specific record, including first and last names, IP address, date and time of registration, cell phone number, zip code, and consent checkboxes for data processing, direct marketing, and third-party marketing, indicating that the data comes from a registration made through the website pocketcoupons.net via an online form, that information was provided during the process in accordance with Article 13 of the GDPR, and that the data has been erased from the database. - Document 3.—Contractual document corresponding to the General Terms and Conditions of Sale of ***ENTERPRISE.2., version 1/2024, which describes the enterprise’s identity and activities and sets forth the conditions applicable to the provision of digital marketing services and the supply of databases, including the definition of terms, the types of advertising campaigns, the collection and delivery of leads, Tracking systems, the obligations of the parties, the processing of personal data, the , the duration of the contract, and the rules governing property rights. SEVENTH: On March 3, 2026, a proposed resolution was issued stating that the Presidency of the Spanish Data Protection Agency should impose a fine on the entity MÁS SOL for violating Article 66.1.b) of the LGTel, as defined in Article 107.30 of the aforementioned law, with a fine of 5,000 euros (five thousand euros) and for the violation of Article 14 of the GDPR, as defined in Article 83.5.b) of the aforementioned Regulation, with a fine of 5,000 euros (five thousand euros). Notice of this proposed resolution was duly served on the respondent on March 9, 2026, via the Single Authorized Electronic Address (DEHÚ) service, and the respondent was granted a period of time to file a response. There is no record of any response from the respondent to said notification. EIGHTH: MÁS SOL ENERGÍA 15, S.L., with Tax ID No.: B90346370, is an enterprise with a turnover of 41 million euros. Based on the proceedings conducted in this case and the documentation on file, the following PROVEN FACTS C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 5/23 First. – MÁS SOL ENERGÍA 15, S.L., with Tax ID No. B90346370, is a commercial entity that engages in activities related to customer acquisition through telephone calls to offer solar panel installation services . Second. – There is a screenshot of the call history from a , showing an incoming call to the number ***PHONE.2 from the number ***PHONE.1, received on November 18, 2024, at 1:24 , lasting 46 seconds. Third. – An audio file corresponding to the call received from the number ***PHONE.1 on the indicated date and time is included, the content of which reflects a telephone conversation initiated by a person who identifies himself as an agent and who states that they are calling on behalf of “MÁS SOL,” inquiring about the type of housing occupied by the recipient of the call. Fourth. – The record shows that MÁS SOL, in its response filed on dated 12/24/2024 and in its brief of arguments dated 02/13/2026, states that it conducts commercial prospecting campaigns via telephone calls, that such campaigns are carried out through an automated dialing system called ***PLATAFORMA.1, and that the personal data used in these campaigns comes from the import of lists provided by external enterprises specializing in advertising and marketing services, ***EMPRESA.1 or ***EMPRESA.2. Furthermore, in these documents, the entity indicates that, regarding the call made on 11/18/2024, the personal data used corresponds to a record associated with the phone number ***PHONE.2. Fifth. – There is a certificate from the Robinson List Service, issued in the name of A.A.A., which indicates that his registration has been active since March 9, 2024. This certificate lists the telephone number TELÉFONO.2 is listed on the telephone channel, with a registration date of 03/09/2024. Sixth. – Documentation has been provided consisting of a CFR issued by ENTERPRISE.3, dated 12/02/2024, which indicates that its database contains a record associated with the following personal data: first name A.A.A., last names (...), mobile phone number ***PHONE.2, ZIP code (...), IP address (...), and registration date and time 06/30/2020 – 9:17 p.m. The aforementioned documentation includes a table with indicators regarding consent for data processing, marketing, and third-party marketing, identified as “dd,” “dm,” and “dmt” (0=NO, 1= YES), with the value 1 appearing in all three indicators. Seventh. – There is a generic form for subscribing to a commercial newsletter, which contains fields for entering personal data and three checkboxes for consent regarding data processing, the sending of advertising communications, and the transfer of data to third parties. This form is blank, with no data filled in and no identifying reference to any specific person. In particular, the following information is provided next to the checkboxes: (i) I have read and accept the site’s terms and conditions and Privacy Policy, and I authorize the processing of my personal data for the services offered by the site; (ii) I accept C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 6/23 the processing of my personal data for the purpose of sending advertising communications and for the commercial purposes set forth in Article 2 of the Privacy Policy; and (iii) I consent to the disclosure of my personal data to third parties on our list of sponsors, as specified in Article 2 of the Privacy Policy. LEGAL BASIS I Jurisdiction In accordance with the powers granted to each supervisory authority by Article 58.2 of the GDPR and in accordance with the provisions of Article 114.1.b) of the LGTel, and as provisions of Articles 47, 48.1, 64.2, and 68.1 of the LOPDGDD, the Presidency of the AEPD has jurisdiction to resolve this proceeding. Likewise, Article 63.2 of the LOPDGDD provides that: “Proceedings handled by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, this Organic Law, the adopted to implement it, and, to the extent they do not contradict them, on a subsidiary basis, by the general rules on administrative procedures.” Finally, Transitional Provision 4, “Procedures Regarding the Powers Granted to the Spanish Data Protection Agency by Other Laws,” establishes that: “The provisions of Title VIII and its implementing regulations shall apply to the proceedings that the Spanish Data Protection Agency may have to conduct in the exercise of the powers conferred upon it by other laws.” II Summary of the Facts In the present case, the complainant states that on November 18, 2024, at 1:24 p.m., he received a telemarketing call from the number ***PHONE.1, made by an agent identified as “B.B.B.” on behalf of “Mas Sol,” who addressed him by name and began asking questions about his type of residence. He notes that, when he asked whether they had checked the Robinson List beforehand, the caller responded that they were under no obligation to perform such a check since the call was based on a “database,” and adds that, when he asked about the source of his personal data, the call was unilaterally terminated. He explains that, after contacting the enterprise’s customer service to find out the source of his data, he was told that the data had been obtained was the responsibility of the sales department and that the reason might be the acceptance of cookies—a claim he considers incorrect since he had never accessed the website. Along with his written statement, he provides documentation consisting of a screenshot of the calls from the complainant’s mobile device, which shows an incoming call on November 18, 2024, at 1:24 p.m. lasting 46 seconds, as well as an official certificate from the Robinson List confirming his active registration since March 9, March 2024 para the telephone numbers ***TELÉFONO.2 and ***TELÉFONO.3. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 7/23 For its part, the respondent submitted a written response to the notification of proceedings in which it states, in summary, that it makes sales calls and that the data used in its campaigns originate from the contractual acquisition of a database from an external enterprise specializing in advertising and marketing services for enterprises, identified as ***ENTERPRISE.1 or ***ENTERPRISE.2, which guarantees that the databases are legally compliant, that the data was collected in accordance with applicable regulations, and that there is proof of the data subject’s consent to the processing, transfer, and sending of marketing communications. It states that, after requesting proof of consent from the provider, the provider submitted information indicating that the complainant had filled out a form on June 30, 2020, at 9:17 p.m. on the website ***WEB.1, from the IP address (...), having checked boxes regarding data processing, direct marketing, and third-party marketing. It notes that it does not conduct any additional verification of the validity of the consent, but merely accepts the information provided by the provider. It also attaches documentation consisting of a generic form for subscribing to a commercial newsletter—with no data filled in and no reference to the complainant—and a letter from ***ENTERPRISE.3 that includes a table with data attributed to the complainant and which asserts that the complainant had given consent on the aforementioned website for marketing purposes and for the transfer of data to third parties for marketing. III Response to the Allegations in the Order to Proceed First. – Regarding the proof of consent and the evidentiary validity of the certificate The complaint invokes the dismissal order issued in case EXP202400904 as a decisive precedent, arguing that the assessment made in that case regarding the evidentiary sufficiency of the data collection certificate would preclude a different assessment in the present proceedings, pursuant to the principles of legal certainty, legitimate expectations, and the doctrine of estoppel. Furthermore, it argues that the requirement to unequivocally link the technical record submitted to the claimant’s identity as a natural person would amount to a reversal of the burden of proof and the imposition of a verification not required by the regulations. This argument cannot be upheld. This is because the application of the principles of equality, legal certainty, and legitimate expectations requires the existence of a substantial identity between the cases being compared, which is not limited to subjective or objective identity, but necessarily extends to factual and evidentiary identity. The doctrine of one’s own acts does not support the claim to obtain an identical result in proceedings in which different bodies of evidence are at issue, nor does it limit the Administration’s authority to assess, in each specific case, the facts that have actually been established, in particular C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 8/23 when previous decisions are adopted within the framework of prior proceedings and on the basis of a preliminary assessment. In this regard, Article 65 of the LOPDGDD governs the acceptance for processing of complaints and preliminary investigative proceedings, establishing that, prior to the initiation of disciplinary proceedings, the Spanish Data Protection Agency Data Protection Agency may conduct investigations to determine whether there are grounds justifying the initiation of disciplinary proceedings, and may decide, in light of such investigations, either to dismiss the case or to accept the complaint and continue the proceedings. In particular, the decision to dismiss the case issued in file EXP202400904 expressly states that it is not appropriate to initiate disciplinary proceedings since the complaint has been addressed and that the processing of the complaint in accordance with the provisions of Article 65.4 of the LOPDGDD has led to the resolution of the issues raised. Now, the aforementioned Article 65.4 provides that “If, as a result of such referral proceedings, the controller or processor demonstrates that it has taken measures to comply with applicable regulations, the Spanish Data Protection Agency may refuse to process the complaint,” which is considered applicable in the aforementioned case, albeit with the caveat that all of this “is without prejudice to the Agency’s ability, by exercising the investigative and corrective powers it holds, may carry out actions relating to the data processing referred to in the complaint.” From this perspective, the argument that the submission of a certificate of traceability for the lead—which was taken into consideration in deciding to close the proceedings in a previous case—would automatically preclude the existence of reasonable grounds in the present case, is not consistent with the meaning and scope of Article 65 of the LOPDGDD. The provision does not attribute to the submission of a specific document an automatic effect of precluding the initiation of disciplinary proceedings, nor does it prevent the Agency from assessing the need to determine administrative liability within the framework of disciplinary proceedings. Furthermore, the fact that the call was made has been substantiated by a record of the mobile device’s call history and an audio recording, in which the caller identifies himself as an agent acting on behalf of the entity against which the complaint was filed. It is also established that the entity MÁS SOL conducts marketing campaigns via telephone calls and that it obtains the personal data used in such campaigns through an external provider. Liability for the processing of personal data is not shifted by the fact that the data was obtained by a third party; it is incumbent upon the respondent entity, in its capacity as the controller, to demonstrate the existence of a valid legal basis that legitimizes the processing carried out. With regard to the consent invoked, the respondent entity provides documentation submitted by its external provider consisting of an alleged record made on June 30, 2020, on the website ***WEB.1, indicating an IP address, a specific date and time, and a reference to certain consent checkboxes that were allegedly checked. However, this documentation does not C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 9/23 proves that the complainant provided valid, free, informed, and unambiguous consent to receive commercial communications. There is no evidence that the complainant personally completed the registration or that the personal data was entered by him, nor is there any technical evidence that unequivocally links the indicated IP address to the complainant. Nor is there any evidence demonstrating that the complainant’s phone number was entered by him when filling out the form. The generic form provided is blank, and the respondent has not provided the privacy policy in effect at the time the registration allegedly took place, which makes it impossible to objectively determine the specific purposes for which and the third parties to whom the data would have been disclosed. This conclusion does not stem from requiring the respondent to adopt enhanced or disproportionate verification mechanisms not provided for in the applicable regulations, but rather from the finding that the evidence provided does not meet the minimum threshold necessary to demonstrate that consent was in fact given by the data subject. In accordance with the principle of proactive accountability established in Article 5(2) of the GDPR, the burden of proving the existence of valid consent rests entirely with the controller, and the obligation to demonstrate the absence of the alleged consent. This is expressly set forth in Article 7 of the GDPR, , which requires the controller to have adequate safeguards in place to demonstrate the existence of consent, by stipulating that “Where processing is based on the data subject’s consent, the controller must be able to demonstrate that the data subject consented to the processing of their personal data.” It should also be noted that the defendant itself acknowledges that it does not verify the validity of the consent provided by its external vendor and that it merely accepts the files received—a course of action incompatible with the data controller’s processing to demonstrate the existence of a valid legal basis, in compliance with the requirements of Article 66.1.b) of the LGTel. In summary, the argument put forward by the respondent regarding proof consent and the alleged existence of a binding precedent must be entirely dismissed, as the existence of valid consent in accordance with the requirements of Article 4.11 of the GDPR has not been established... Second. – Joint response to points II) and III) of the allegations: regarding due diligence in the selection of the provider and the alleged exclusive attribution of liability to the provider for data collection. The respondent maintains, in essence, that it has acted with due diligence in the selection of its data providers (***ENTERPRISE.2 / ***ENTERPRISE.3), relying on the existence of a contract containing warranty clauses and on certifications regarding privacy policies; and, accordingly, asserts that any potential irregularity in data collection should be attributed exclusively to the supplier, as the latter holds technical control over the form and the verification mechanisms, invoking an alleged legitimate expectation regarding the traceability provided. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 10/23 These arguments cannot be upheld. Pursuant to Article 4.7 of the GDPR, the controller is the legal entity that determines the purposes and means of the processing. In the present case, the entity is the controller, as it decided on the specific purpose of the processing—the conduct of commercial call campaigns to promote its own products or services—and determined the essential means for its execution, including the integration of the data into its system and the use of an automated dialing platform. The fact that the data comes from an external provider does not alter this conclusion: the provider merely supplies contacts, while the decision to use that data in a specific campaign, at a specific time, and for its own benefit rests exclusively with the respondent, which assumes the legal status of data controller vis-à-vis the data subjects and the supervisory authority. In this context, the existence of a commercial contract with warranty clauses and the provision of certifications regarding privacy policies are not sufficient to exclude the liability of the controller, who must verify that the procedure used to obtain consent complies with the GDPR. Article 5(2) of the GDPR expressly states that the controller shall be responsible for compliance with the principles of processing and must be able to demonstrate such compliance (accountability), which constitutes a specific and direct obligation that cannot be transferred to a third party merely by entering into a contract. This conclusion is reinforced by the provisions of Guidelines 5/2020 on consent, whose points 105 through 108 emphasize that, when processing is based on consent, the controller must be able to demonstrate that the data subject for the processing operation (Recital 42), and may choose methods of verification tailored to its operations, while retaining the obligation to provide sufficient evidence of how and when consent was obtained, as well as the information provided to the data subject at that time. The Guidelines further specify that the obligation to demonstrate consent does not necessarily imply excessive additional data processing, but it does require having sufficient evidence to link the consent to the processing and to the specific data subject. Applying these requirements to the present case, the due diligence required of the data controller is not limited to incorporating generic safeguard clauses or accepting documentation issued by the provider as exclusive proof of lawfulness, but rather requires that, in each specific case, the data controller be able to demonstrate that the data used to make the call were obtained on a valid legal basis and that the consent invoked meets the conditions of Article 4.11 of the GDPR. However, in the present case, the documentation provided by the respondent—which originated from the provider—does not sufficiently demonstrate that the complainant provided valid consent, nor that the complainant was effectively informed at the time of the alleged collection of consent to obtain specific and informed consent, nor, in general, that the workflow used met the relevant criteria for valid consent under the terms set forth. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 11/23 In particular, the respondent bases its standing on an alleged registration on pocketcoupons.net dated 06/30/2020, referencing an IP address and checkboxes that were supposedly checked. However, this documentation does not prove that the complainant personally carried out said registration or that the data was entered by him, nor does it provide technical evidence that unequivocally links the IP address to him. Furthermore, the respondent has not provided the privacy policy in effect at the time of the data was collected, limiting itself to providing the policy effective as of December 18, 2025, which cannot serve to substantiate the specific information that, if any, was provided to the data subject, much less that specific consent had been granted. The respondent has also stated that it does not verify the validity of the consent submitted by the provider and that it merely accepts the filing systems received, which is incompatible with the data controller’s obligation to demonstrate, in a specific case, that the data subject did in fact grant consent and that he or she was informed at the time the data was collected, in accordance with paragraphs 105 through 108 of Guidelines 5/2020. Furthermore, the attempt to shift liability “to the source” on the grounds that the supplier exercises technical control over the form cannot succeed either. The administrative charge is not based on a hypothetical “hidden defect” on the part of the provider, but rather on the respondent entity’s use of personal data to make a marketing call without having established a valid legal basis for that specific processing. The provider’s potential liability for its own activity does not exclude the liability of the entity against which the complaint is filed for the processing it chooses to carry out, in its capacity as the controller. Finally, the argument regarding legitimate expectations or the appearance of lawfulness derived from the provider’s documentation does not undermine the foregoing. Accountability requires that the data controller be able to demonstrate the legal basis and valid consent in each specific case, and this requirement becomes particularly relevant when, as in the present case, there is a prior, express objection documented by the registration of the affected number in the Robinson List Service, which required the utmost diligence in verifying that, despite such objection, there was specific consent that exempted the data controller from consulting that database pursuant to Art. 23.4. LOPDGDD, a circumstance that does not exist here. Consequently, the arguments set forth in points II) and III) must be dismissed, as the respondent has failed to demonstrate the existence of consent from the data subject for the processing carried out, and the mere existence of contractual safeguards or the actions of the provider do not allow the defendant to shift its responsibility for the processing consisting of making the sales call. Third. – Regarding the alleged absence of a breach of the duty to provide information set forth in Article 14 of the GDPR The respondent contends that it was unable to comply with the duty to provide information set forth in Article 14 of the GDPR as a result of the interruption of the telephone call, C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 12/23 arguing that attributing such a violation would violate the principle of presumption of innocence and would amount to imposing an impossible obligation of result on it. This argument cannot be upheld. The duty to provide information set forth in Article 14 of the GDPR constitutes an autonomous, positive, and enforceable legal obligation on the part of the controller when personal data has not been obtained directly from the data subject. Compliance with this obligation is not optional nor is it contingent upon the data subject’s initiative; it is the responsibility of the controller to ensure and demonstrate that such information has been effectively provided, in accordance with the principle of accountability enshrined in Article 5(2) of the GDPR. In the present case, a review of the telephone call recording reveals that the caller initially identifies themselves by stating: “I’m calling from Mas Sol, the solar panel enterprise.” Next, in response to the complainant’s explicit question regarding prior verification of his inclusion on the Robinson List, the caller responds verbatim: “I don’t have to check any of that, sir; I work from a database.” Subsequently, when the complainant requests clarification regarding the origin of said database, the response is limited to a generic and imprecise reference, without identifying its source or providing any relevant additional information. From the verbatim content of the recording, it is clear that the respondent entity omitted the legally required information regarding the specific origin of the data subject’s personal data, limiting itself to an unspecified reference to the existence of “a database.” Such a reference is manifestly insufficient to fulfill the duty to provide information imposed by Article 14 of the GDPR, as it does not allow the data subject to know the source of their data or the context in which it was collected. Furthermore, during the call, no information was provided regarding the full identity of the controller, the legal basis justifying the use of the personal data, or the rights to which the data subject is entitled under data protection regulations. This omission deprives the complainant of the real and effective opportunity to exercise his rights and constitutes a substantive nullification of the right to information, amounting to a full and independent violation of Article 14 of the GDPR. Contrary to the respondent’s complaints, the recording does not show any interruption that would have made it materially impossible to fulfill the duty to provide information. On the contrary, it is on record that there was sufficient dialogue during which the complainant directly raised questions regarding the origin and legitimacy of the processing of his data, without the respondent entity providing the minimum required information or offering an immediate alternative channel to access it. The duration of the call or its subsequent termination does not exempt the controller from complying with this obligation, nor does it allow the lack of information to be attributed to the data subject’s conduct. The duty to provide information should have been fulfilled during the course of the initial communication itself, at least in its essential elements, but this did not occur. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 13/23 Nor has the existence of alternative or complementary mechanisms been proven that would have allowed the complainant to subsequently access the information required by Article 14 of the GDPR. The subsequent submission of informative guidelines or internal protocols does not prove that these were actually used in the specific call in question that is the subject of this case, nor that the legally required information was provided by other means within the time frame established by the regulation. The respondent also argues that the allegation of this violation would infringe upon its right to a fair hearing, as this issue was not expressly raised during the preliminary proceedings phase. This argument cannot be accepted either. The subject matter of the proceedings—the making of a telemarketing call and the lawfulness of the processing of the personal data used—was fully known to the respondent from the outset of the proceedings. The duty to provide information set forth in Article 14 of the GDPR is directly linked to the lawfulness of the processing when the data has not been obtained from the data subject, and therefore any failure to comply with this duty does not constitute a surprise element nor is it outside the scope of the investigation. The referral proceedings governed by Article 65 of the LOPDGDD are intended to determine the existence of grounds justifying the initiation of disciplinary proceedings, without any obligation to specify at this preliminary stage all possible legal violations that may be identified in light of the body of evidence included in the case file. In this context, the absence of a specific requirement relating to Article 14 of the GDPR does not give rise to any substantive lack of defense, especially since the respondent entity has had access to the complaint and an effective opportunity to present its arguments and submit the documentation it deemed relevant in the disciplinary proceedings. In short, in light of the literal content of the call recording and the body of evidence in the case file, it must be concluded that the respondent failed to comply with the duty to provide information imposed by Article 14 of the GDPR, without any violation of its right of defense or any grounds that would exclude or mitigate its liability. For all the foregoing reasons, the arguments raised by the respondent must be dismissed in their entirety, and the disciplinary proceedings must continue, as the existence of valid consent for making the marketing call has not been established, nor has compliance with the obligations required by Article 66.1.b) of the LGTel, nor of the duty to provide information imposed by Article 14 of the GDPR, which applies when personal data has not been obtained directly from the data subject. III Breach of Article 66 of the LGTel C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 14/23 Making unsolicited calls for commercial communication purposes, without prior consent or without another legal basis for doing so, may constitute a violation of the provisions of Article 66 of the LGTel, regarding the “Right to data protection and privacy in relation to unsolicited communications, traffic and location data, and subscriber directories,” as paragraph 1.b) provides as follows: “1. With regard to data protection and privacy in relation to unsolicited communications, end users of publicly available interpersonal communications services based on numbering shall have the following rights: (…) b) not to receive unsolicited calls for commercial communication purposes, unless the User has given prior consent to receive this type of commercial communications, or unless the communication is based on another legal basis provided for in Article 6(1) of Regulation (EU) 2016/679 on the processing of personal data.” Furthermore, Article 66 concludes by stipulating the following in its fifth paragraph: “5. The provisions of this article are without prejudice to the application of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, April 2016, and Organic Law 3/2018 of December 5 on Data Protection and the Guarantee of Digital Rights, and, in particular, the application of the concept of consent set forth therein.” Article 66.1.b) of the LGTel regulates the protection of users against unsolicited communications, establishing as an essential requirement the existence of a valid legal basis, such as the prior consent of the data subject, or any other basis set forth in Article 6.1 of the GDPR. Its purpose is to protect users from intrusive commercial practices that do not respect their privacy and control over commercial communications. By requiring prior consent or a valid legal basis, this provision ensures that enterprises respect users’ rights, thereby preventing unsolicited commercial communications. In this way, it reinforces the protection framework established by the GDPR, ensuring a balance between legitimate commercial activities and the fundamental rights of Users. The defendant bases the lawfulness of the commercial call on the consent of the complainant. However, Article 4.11 of the GDPR defines the consent of the data subject as: any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she, either by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her. Furthermore, Guidelines 5/2020 on consent within the meaning of the GDPR, provide, in paragraphs 105 through 108, as follows: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 15/23 “105. Recital 42 states that: ‘Where processing is carried out with the consent of the data subject, the controller must be able to demonstrate that the data subject has given his or her consent to the processing operation.’ 106. Controllers are free to develop methods that enable compliance with this provision, tailored to their daily operations. At the same time, the obligation to demonstrate that a controller has obtained valid consent must not, in and of itself, result in excessive additional data processing. This means that data controllers should have sufficient data to demonstrate a link to the processing (to show that consent was obtained), but should not collect more information than is necessary. 107. It is up to the data controller to demonstrate that it obtained valid consent from the data subject. The GDPR does not prescribe exactly how this should be done. However, the controller must be able to demonstrate that, in a specific case, a data subject has given consent. The obligation to demonstrate consent will exist for as long as the processing activity involving the data in question continues. Once that activity has ended, evidence of consent must not be stored beyond what is strictly necessary to comply with a legal obligation or for the establishment, exercise, or defense of complaints, in accordance with Article 17(3)(b) and (e). 108. For example, the data controller must maintain a record of the consent statements received, so that it can demonstrate how consent was obtained and when such consent was obtained, and must also demonstrate what information was provided to the data subject at the time. The controller must also be able to demonstrate that the data subject was informed and that the controller’s workflow met all the relevant criteria for valid consent.” In the present case, it has been established that the entity MÁS SOL conducts marketing campaigns for its products and services via telephone calls and receives and uses the information provided by an external vendor. MÁS SOL’s liability is not negated by the fact that the data used by MÁS SOL was obtained by a third party. In this case, MÁS SOL obtained the complainant’s data from its external provider and made a marketing call to him on November 18, 2024. Regarding the complainant’s consent, the respondent provides various documents submitted by the aforementioned third-party provider, consisting of an alleged registration on the website pocketcoupons.net dated June 30, 2020, via an IP address IP address, a time, and a reference to consent checkboxes that were allegedly checked. However, this documentation does not establish that the complainant provided valid, free, informed, and unambiguous consent to receive communications C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 16/23 , in accordance with Article 4.11 of the GDPR and Guidelines 5/2020 on consent, which require that the data controller be able to demonstrate, in each specific case, that the declaration of consent was given by the data subject. Consequently, the controller of commercial communications—in this case, MÁS SOL—must be able to demonstrate that it has obtained the authorization or consent of the data subject to make commercial calls and must also show the mechanisms used to obtain it. The regulation does not establish a specific mechanism for proving that consent has been obtained, but it does require that the data controller be able to demonstrate that the User has requested or expressly authorized the commercial calls, and is therefore free to implement the method and record-keeping system that best suits the organization’s processes; however, it does require that the party responsible demonstrate who, when, how, and for what purpose the sales calls were authorized, as well as the information provided to the User at the time consent was obtained. In the present case, it has not been proven that the complainant personally made the registration, nor that the data was entered by him. There is no evidence that unequivocally links the IP address to the complainant. No technical evidence has been provided to demonstrate that the complainant’s phone number (which appears on the Robinson List) was entered by him when filling out the form. The form that the claimant allegedly filled out contains checkboxes stating (i) I have read and accept the site’s terms and conditions and the Privacy Policy, and I authorize the processing of my personal data for the services offered by the site (ii) I consent to the processing of my personal data for the sending of advertising and for the commercial purposes set forth in Article 2 of the Privacy Policy; and (iii) I consent to my personal data being disclosed to third parties on our list of sponsors, as specified in Article 2 of the Privacy Policy. However, the entity against which the complaint was filed does not provide the Privacy Policy in effect at the time the complainant allegedly entered the data; therefore, it is not even known what specific purposes the complainant would have consented to or to which third parties the complainant would have authorized the disclosure of their data. Furthermore, the respondent acknowledges that it does not verify the validity of the consent submitted by the Provider and that it merely accepts the files received, which is incompatible with the data controller’s obligation to demonstrate consent, in accordance with points 105 through 108 of Guidelines 5/2020. Consequently, it is considered that the respondent made an unsolicited commercial call without a valid legal basis, thereby violating Article 66.1.b) of the LGTel, which recognizes Users’ right not to receive unsolicited calls for commercial communication purposes, unless there is prior consent or the legal bases set forth in Article 6.1 of the GDPR apply. IV Classification of the violation of Article 66 of the LGTel and characterization of the violation for purposes of the statute of limitations C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 17/23 The conduct described in the preceding points—making a commercial call without the data subject’s consent or another legal basis that would permit it— constitutes a violation of Article 66.1.b) of the LGTel, classified as “serious” pursuant to Article 107.30 of the aforementioned law: “30. The violation of the rights of consumers and end users, as established in Title III and its implementing regulations, including the rights to number storage, roaming within the European Union, and international roaming, regarding regulated intra-Community communications and open access to the Internet.” For its part, article 113 of the LGTel states that: “Very serious violations shall be subject to a three-year statute of limitations, serious violations to a two-year statute of limitations, and minor violations to a one-year statute of limitations. The statute of limitations for violations shall begin to run from the day on which they were committed. The statute of limitations shall be interrupted by the initiation, with the knowledge of the data subject, of the disciplinary proceedings. The statute of limitations period shall resume if the disciplinary proceedings are suspended for more than one month for reasons not attributable to the alleged offender. (…)” V Penalty for violation of Article 66 of the LGTEL. In accordance with the provisions of Article 109.1.c) of the LGTEl, this violation may be punishable by a fine of up to 2 million euros. Meanwhile, Article 110.1 of the aforementioned law establishes the criteria for determining the amount of the penalty: “a) the severity of previous violations committed by the party being penalized; b) the damage caused, such as the creation of interference to authorized third parties , and its remediation; c) voluntary compliance with any precautionary measures that may be imposed during the penalty proceedings; d) refusal or obstruction of access to facilities or of providing the required information or documentation; e) cessation of the infringing activity, either prior to or during the processing of the penalty proceedings; f) the impact on protected legal interests relating to the use of the public radio spectrum, public order, public safety, and national security, or Users’ rights; g) active and effective cooperation with the competent authority in detecting or proving the infringing activity.” C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 18/23 In accordance with these criteria, it is deemed appropriate to impose on the respondent entity an administrative penalty of 5,000 euros (five thousand euros) for the violation of Article 66.1.b) of the LGTel, as defined in Article 107.30 of the aforementioned law. VI Failure to comply with Article 14 of the GDPR Article 14 of the GDPR, regarding “Information to be provided where personal data have not been obtained from the data subject,” states that: “1. Where personal data have not been obtained from the data subject, the controller shall provide the data subject with the following information: a) the identity and contact details of the controller and, where applicable, of its representative; b) the contact details of the data protection officer, where applicable; c) the purposes of the processing for which the personal data are intended, as well as the legal basis for the processing; d) the categories of data being processed; e) the recipients or categories of recipients of the personal data, where applicable; f) where applicable, the controller’s intention to transfer personal data to a recipient in a third country or to an international organisation, and the existence or absence of an adequacy decision by the Commission, or, in the case of transfers referred to in Articles 46 or 47 or Article 49(1), second paragraph, a reference to the appropriate or suitable safeguards and the means para obtain a copy of them or the location where they have been made available. 2. In addition to the information referred to in paragraph 1, the controller shall provide the data subject with the following information necessary to ensure fair and transparent processing with respect to the data subject: a) the period for which the personal data will be stored or, where that not possible, the criteria used to determine that period; b) where the processing is based on Article 6(1)(f), the legitimate interests of the controller or of a third party; c) the existence of the right to request from the controller access to personal data concerning the data subject, and to have such data rectified or erased, or to impose a restriction on its processing, and to object to the processing, as well as to data portability; d) where the processing is based on Article 6(1)(a) or Article 9(2)(a), the existence of the right to withdraw consent at any time, without affecting the lawfulness of the processing based on consent prior to its withdrawal; e) the right to lodge a complaint with a supervisory authority; f) the source from which the personal data are derived and, where applicable, whether they are derived from publicly available sources; g) the existence of automated decision-making, including profiling, as referred to in Article 22(1) and (4), and, at least in such C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 19/23 cases, meaningful information regarding the logic applied, as well as the significance and the anticipated consequences of such processing for the data subject.” 3. The controller shall provide the information specified in paragraphs 1 and 2: a) within a reasonable period of time after the personal data are collected, and no later than one month, taking into account the specific circumstances in which such data are processed; b) if the personal data are to be used for communication with the data subject, no later than the time of the first communication to said data subject, or c) if the personal data is intended to be disclosed to another recipient, no later than the time the personal data is first disclosed (…)”. Article 14 of the GDPR stipulates that when the data subject’s personal data has not been collected directly from the data subject, the controller must provide certain essential information to ensure transparency. This includes the identity and contact information of the controller, the purpose of the processing, the legal basis, the categories of data processed, the source of the data, and the data subject rights, among other aspects. This article requires that this information be provided within a reasonable timeframe, no later than one month and upon first contact with the data subject, or before the data is disclosed to a third party. Its primary objective is to ensure that data subjects receive the necessary information when their personal data is obtained from third parties. This requirement aims to prevent data subjects from being placed in a vulnerable position due to a lack of knowledge regarding how, by whom, and for what purpose their data is being used. Article 14 ensures that the data subject rights are not undermined by a lack of information, establishing that the controller must act proactively to provide all relevant information in a timely and appropriate manner. In the present case, the respondent obtained the complainant’s data from ENTERPRISE.1 / ***ENTERPRISE.2 without complying with the provisions of Article 14 of the GDPR, as it failed to provide the complainant with the information required by that article. The absence of this information not only constitutes a formal violation but also substantially affects the complainant’s rights by preventing them from exercising their rights regarding personal data protection with full knowledge of the facts. Therefore, by failing to provide the information required by Article 14 of the GDPR within the established time limit, and by failing to ensure that the data subject was aware of the details of the processing of their personal data, the respondent has breached the obligations imposed by that article. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 20/23 Based on the evidence currently available at the time of the resolution of the sanctioning proceeding, it is considered that the facts set forth violate the provisions of Article 14 of the GDPR VII Classification of the violation of Article 14 of the GDPR and assessment for purposes of the statute of limitations Article 83(5)(b) provides as follows: “5. Infringements of the following provisions shall be subject, in accordance with paragraph 2, to administrative fines of up to 20,000,000 EUR or, in the case of an enterprise, an amount equivalent to 4% of the total annual global turnover for the preceding fiscal year, whichever is higher: (…) b) the data subject rights under Articles 12 through 22;” In this regard, article 71 of the LOPDGDD establishes that “The following constitute infractions: the acts and conduct referred to in paragraphs 4, 5, and 6 of Article 83 of the GDPR, as well as those that are contrary to this Organic Law.” For the purposes of the statute of limitations, Article 72.1.h) of the LOPDGDD states: “Article 72. Infractions considered very serious. 1. Pursuant to Article 83(5) of Regulation (EU) 2016/679, the following are considered very serious and shall be subject to a three-year statute of limitations: infractions that constitute a substantial violation of the articles mentioned therein and, in particular, the following: (…) h) Failure to fulfill the duty to inform the data subject about the processing of their personal data in accordance with the provisions of Articles 13 and 14 of Regulation (EU) 2016/679 and Article 12 of this Organic Law.” VIII Penalty for Violation of Article 14 of the GDPR. In order to determine the administrative fine to be imposed, the provisions of Articles 83(1) and 83(2) of the GDPR must be observed, which state: “1. Each supervisory authority shall ensure that the imposition of under this article for infringements of this Regulation referred to in paragraphs 4, 9, and 6 are, in each individual case, effective, proportionate, and dissuasive. 2. Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or in lieu of the measures set forth in Article 58(2)(a) through (h) and (j). When deciding on the C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 21/23 imposition of an administrative fine and its amount in each individual case, the following shall be duly taken into account: a) the nature, gravity, and duration of the violation, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the extent of the damages they have suffered; b) whether the infringement was intentional or due to negligence; c) any measures taken by the controller or processor to mitigate the damages suffered by the data subjects; d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures they have implemented pursuant to Articles 25 and 32; e) any previous infringements committed by the controller or processor; data controller; f) the degree of cooperation with the supervisory authority to remedy the breach and mitigate its potential adverse effects; g) the categories of data affected by the breach; (h) the manner in which the supervisory authority became aware of the breach, in particular whether the controller or processor notified the supervisory authority of the breach and, if so, to what extent; (i) where measures referred to in Article 58(2) have been previously ordered against the controller or processor in question in relation to the same matter, compliance with those measures; j) adherence to codes of conduct pursuant to Article 40 or to certification mechanisms approved pursuant to Article 42; and k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial gains obtained or losses avoided, directly or indirectly, through the violation.” For its part, article 76, “Penalties and Corrective Measures,” of the LOPDGDD provides: “1. The penalties provided for in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the criteria for proportionality set forth in paragraph 2 of that article. 2. In accordance with the provisions of Article 83(2)(k) of Regulation (EU) 2016/679, the following may also be taken into account: a) The ongoing nature of the violation. b) The connection between the infringer’s activities and the processing of personal data. c) The profits obtained as a result of the commission of the violation. d) The possibility that the data subject’s conduct may have contributed to the commission of the violation. e) The existence of a merger by absorption occurring after the commission of the violation, which cannot be attributed to the absorbing entity. f) The impact on the rights of minors. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 22/23 g) Having a data protection officer, where not mandatory. h) The data controller or processor’s voluntary submission to alternative dispute resolution mechanisms in cases where disputes arise between them and the data subject.” In the present case, recital 1 states that the seriousness of the potential violations and the consequences their commission has on those affected warrant the imposition of a fine, in addition to the adoption of measures, if appropriate. The fine imposed must be, in each individual case, effective, proportionate, and dissuasive, in accordance with the provisions of Article 83(1) of the GDPR. A balancing of the circumstances set forth in Article 83(2) of the GDPR and Article 76(2) of the LOPDGDD, allows for the imposition of an administrative penalty of 5,000 euros (five thousand euros) for the violation committed by breaching the provisions of Article 14 of the GDPR, as defined in Article 83.5.b of said regulation. Therefore, in accordance with applicable law and having assessed the violations whose existence has been proven, the Presidency of the Spanish Data Protection Agency RESOLVES: FIRST: TO IMPOSE on the entity MÁS SOL ENERGÍA 15, S.L., with Tax ID No. B90346370, for the following violations, the fines indicated below: - Violation of Article 66.1.b) of the LGTel, as defined in Article 107.30 of the aforementioned regulation, a fine of 5,000 euros (five thousand euros). - Violation of Article 14 of the GDPR, as defined in Article 83(5)(b) of the aforementioned Regulation, a fine of 5,000 euros (five thousand euros). SECOND: NOTIFY MÁS SOL ENERGÍA 15, S.L. of this decision. THIRD: This decision shall become enforceable once the deadline for filing the optional appeal for reconsideration has expired (one month from the day following the notification of this decision) without the data subject having exercised this right. The party subject to the penalty is hereby notified that they must pay the imposed penalty once this decision becomes enforceable, in accordance with the provisions of Art. 98.1.b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), within the voluntary payment period set forth in Article 68 of the General Collection Regulation, approved by Royal Decree 939/2005, dated July 29, in conjunction with Art. 62 of Law 58/2003, dated December 17, by making a payment and indicating the taxpayer identification number (NIF) of the party subject to the penalty and the procedure number appearing at the top of this document, into the restricted account No. IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX), opened in the name of the Spanish Data Protection Agency at the bank CAIXABANK, S.A.. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 23/23 Otherwise, collection will proceed through enforcement proceedings. Upon receipt of the notification and once it becomes enforceable, if the enforceability date falls between the 1st and 15th of each month, inclusive, the deadline for voluntary payment will be until the 20th of the following month or the next business day thereafter; and if it falls between the 16th and the last day of each month, both inclusive, the payment deadline will be until the 5th of the second following month or the next business day thereafter. In accordance with the provisions of Article 50 of the LOPDGDD, this Resolution shall be made public. Publication shall take place once it has been notified to the data subjects. Against this resolution, which concludes the administrative proceedings pursuant to Article 48.6 of the LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, the data subjects may, at their discretion, file an appeal for reconsideration with the Presidency of the Spanish Data Protection Agency within one month from the day following notification of this resolution, or directly file an administrative appeal with the Administrative Chamber of the National Court, in accordance with the provisions of Article 25 and paragraph 5 of the fourth additional provision of Law 29/1998, of July 13, regulating the Administrative Jurisdiction, within two months from the day following notification of this decision, pursuant to Article 46.1 of the aforementioned Law. Finally, it is noted that, in accordance with the provisions of Article 90.3(a) of the LPACAP, the final administrative decision may be suspended as a precautionary measure if the data subject expresses their intention to file a contentious-administrative appeal. If this is the case, the data subject must formally notify the Spanish Data Protection Agency of this fact by submitting a written notice to the Spanish Data Protection Agency through the Agency’s Electronic Registry , or through any of the other registries provided for in Art. 16.4 of the aforementioned Law 39/2015, of October 1. The data subject must also provide the Agency with the documentation proving that the administrative appeal has been effectively filed. If the Agency is not notified of the filing of the contentious- administrative appeal within two months from the day following notification of this decision, it will consider the precautionary suspension to have ended. Lorenzo Cotino Hueso President of the Spanish Data Protection Agency C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es

---
Generated by overview.legal · https://overview.legal/posts/187487 · 2026-08-22
