AEPD: Ramona Films failed to comply with Article 58(2) order to provide processor
RAMONA FILMS, S.L., the controller, operated websites offering audiovisual content through subscriptions.
Original title: AEPD (Spain) - PS-00008-2025
Holding
The DPA found that the controller had infringed Article 58(2) GDPR by failing to comply with the corrective order issued in the previous proceedings. The DPA held that the controller had neither concluded the processor agreement required by the previous decision nor demonstrated that its relationship with the processor had instead been validly established as joint controllership under Article 26 GDPR. In particular, the purported joint controller agreement was unsigned and undated, and the controller ultimately acknowledged that it had never been concluded. The DPA also rejected the controller's arguments that the relationship with the processor and the subscription service had been terminated. It considered that the controller had provided contradictory information throughout the investigation and had failed to substantiate these claims. Consequently, the DPA found that the corrective measure imposed under Article 58(2)(d) GDPR remained unfulfilled. When determining the fine, the DPA considered, inter alia, the duration and intentional nature of the infringement, the fact that the processing involved identification and payment data, the close connection between the controller's activity and personal data processing, and the fact that the previous €40,000 fine for the Article 28(3) GDPR infringement had not achieved sufficient deterrent effect. The DPA therefore imposed a €60,000 fine for the infringement of Article 58(2) GDPR, pursuant to Article 83(6) GDPR.
From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓
In November 2023, the DPA fined the controller in proceedings PS-00308-2023 for several GDPR infringements, including a breach of Article 28(3) GDPR concerning the absence of a data processing agreement with a payment service provider, the processor. The DPA also ordered the controller, pursuant to Article 58(2)(d) GDPR, to provide within one month the processor agreement concluded with the processor. In December 2023, instead of providing the requested agreement, the controller informed the DPA that the two companies should be considered joint controllers. Following an investigation, the controller provided an unsigned and undated purported joint controller agreement. It subsequently acknowledged that this agreement had never been signed. The controller also stated that it had terminated its relationship with the processor and discontinued its subscription service. However, it was unable to provide evidence of the termination and the DPA found that subscriptions continued to be available through the website and redirected users to the processor's payment service. The controller argued that it had complied with the measures imposed and requested the closure of the proceedings.
Full text 79 findings
Machine translation of the decision, via GDPRhub — not the official text. Read the original
Case No.: EXP202404290 DECISION ON DISCIPLINARY PROCEEDINGS TABLE OF CONTENTS TABLE OF CONTENTS...........................................................................................................................1 BACKGROUND..........................................................................................................2 FIRST:.................................................................................................................2 SECOND:................................................................................................................4 THIRD PARTY:...............................................................................................................11 FOURTH:.................................................................................................................11 FIFTH:..................................................................................................................13 SIXTH:....................................................................................................................13 PROVEN FACTS................................................................................................13 FIRST:...............................................................................................................13 SECOND:..............................................................................................................13 THIRD:...............................................................................................................14 FOURTH:.................................................................................................................15 FIFTH:..................................................................................................................16 SIXTH:....................................................................................................................16 SEVENTH:................................................................................................................16 EIGHTH:..................................................................................................................17 LEGAL BASIS.................................................................................................17 I Jurisdiction.........................................................................................................17 II Preliminary Issues................................................................................................18 III Response to the Allegations in the Proposal to Initiate Proceedings......................................19 IV Breach of Obligation.
Article 58 of the GDPR, Corrective Powers of the Supervisory Authority.................................................................................................................................22 V Classification of the violation of Article 58(2) of the GDPR and determination for the purposes of the statute of limitations..............................................................................................................28 VI Penalty................................................................................................................29 RESOLVES:.................................................................................................................33 FIRST:...............................................................................................................33 C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 2/33 SECOND:..............................................................................................................33 THIRD:...............................................................................................................33 Regarding the proceedings conducted by the Spanish Data Protection Agency and based on the following BACKGROUND FIRST: The Spanish Data Protection Agency (hereinafter “AEPD”) has become aware of certain facts that could constitute a violation attributable to RAMONA FILMS, S.L., with Tax ID No. B87763405 (hereinafter “RAMONA” or the party under investigation).
On March 20, 2024, the Director of the AEPD decided to initiate investigative proceedings under the following terms: “On November 17, 2023, the Director of the Spanish Data Protection Agency Data Protection issued a decision in disciplinary proceeding number PS/00308/2023, brought against RAMONA FILMS, S.L. In that decision, in addition to imposing fines for violations of Articles 6.1.a), 13, 28.3, 32, 37, and 38.6 of the GDPR and Article 22.2 of the LSSI, it ordered RAMONA FILMS, S.L. to implement, within one month, the necessary corrective measures to bring its practices into compliance with personal data protection regulations, as well as to inform this Agency within the same timeframe of the measures adopted. Among the aforementioned measures was the requirement to enter into a processor agreement with the enterprise ***ENTERPRISE.1 in accordance with the provisions of data protection regulations.
On December 26, 2023, the respondent filed a brief reporting on compliance with the measures imposed in the decision of the sanctioning proceeding, simply stating the following regarding the execution of a processor agreement with the enterprise ENTERPRISE.1: ‘As can be seen in the privacy policy privacy policy of the enterprise ***ENTERPRISE.1, which is accessible during the step prior to registration as a subscriber of Ramona Films S.L., the User registers as a customer of the enterprise ***ENTERPRISE.1. With regard to data processing, and due to the specific nature of such processing, both enterprises are considered joint controllers. A step prior to registration has been included in which it is explained in detail to the data subject who will be the controller and that the data are processed by both companies. In this way, the data subject has complete information before entering any personal data .’
C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 3/33 Therefore, it is appropriate to open an investigation to determine whether RAMONA FILMS and ***ENTERPRISE.1 could be joint controllers of personal data processing, since, as it appears in relation to the data received by the payment platform ***PLATFORM.1, when a customer subscribes to the service, the enterprise ***ENTERPRISE.1, headquartered in Malta, provides RAMONA FILMS SL with the online payment service for subscribers.” That decision to open an investigation referred to the Resolution of the Director of the AEPD, dated November 17, 2023, which concluded disciplinary proceeding number PS/00308/2023 (case file no. EXP202207932). As it is relevant to this proceeding, it is worth noting that the background information for that Resolution included the following: “Regarding the submission of the processor agreement with ***ENTERPRISE.1 (the enterprise that provides the subscription form for the services of the portal ***URL.1), they state that: - The service agreement with the enterprise ***ENTERPRISE.1 dates back to 2004. - This provider was selected after verifying that it complies with current data protection regulations. - After the GDPR took effect, the data controller, RAMONA, sent the corresponding contract to ***ENTERPRISE.1 for signature, but ***ENTERPRISE.1 itself replied by referring RAMONA to its privacy policy, claiming it was unable to manage such contracts due to its large number of clients.
RAMONA analyzed the risk of non-compliance and deemed it low, so it decided to continue working with the enterprise ***ENTERPRISE.1.” (…) “It has been confirmed that RAMONA FILMS SL uses the enterprise ***ENTERPRISE.1, headquartered in Malta, to manage User subscriptions and act as a payment gateway for content viewing services; it has also been confirmed that there is no data processing agreement with this third party. RAMONA FILMS SL states that after the GDPR took effect, they contacted this enterprise to attempt to sign a data processing agreement, and that this enterprise replied by referring them to its privacy policy and stating that it could not sign this type of contract; they assert that RAMONA analyzed the risk of non-compliance and deemed it low, so it decided to continue working with this provider.” As a result, in the aforementioned Resolution dated November 17, 2023, RAMONA, among other violations, for breaching Article 28.3 of the GDPR, as defined in Article 83.4 of that regulation, due to the absence of a processor agreement with ***ENTERPRISE.1, with an administrative fine of 40,000.00 euros.
Likewise, it was ordered that, pursuant to Article 58.2.d) of the GDPR, it report, within one month, on the processor agreement entered into with the enterprise ENTERPRISE.1 (hereinafter, ***ENTERPRISE.1), in accordance with the provisions of data protection regulations. 6 Jorge Juan St., www.aepd.es 28001 – Madrid sedeaepd.gob.es 4/33 SECOND: The Subdirectorate General for Data Inspection conducted preliminary investigative proceedings to clarify the facts in question, pursuant to the functions assigned to supervisory authorities under Article 57.1 and the powers granted under Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VIII of the LOPDGDD. As a result of the actions taken, the following facts have come to light: This Agency has documented the following evidence relevant to the proceedings, regarding the content of RAMONA’s web pages: - On April 2, 2024, the website “***URL.1” was accessed by simulating a subscription to its services, and it was confirmed that, prior to being redirected to the website of the enterprise ***EMPRESA.1, an informational screen appears with the following text: “You are about to access the payment gateway to subscribe to the services of Ramona Films S.L. To ensure greater User security, Ramona Films S.L. delegates the management of this task to ***PLATFORM.1, a leading enterprise in its sector.
Therefore, in order to complete the subscription, you must register as a User (at no additional cost) with the enterprise ***COMPANY.1. To register as a customer of ***COMPANY.1, you must fill out the following form with some basic information, as well as your payment details. It is important that you understand, before proceeding with registration, that your data will be processed both by Ramona Films (to manage your registration as a subscriber and provide the contracted service) and by ***ENTERPRISE.1 (for managing payment for the current service and for future services provided by both Ramona Films and other enterprises that have outsourced this service to ***ENTERPRISE.1). It is therefore essential that, before filling out and submitting the form, you review the privacy policies of both Ramona Films S.L. and the enterprise ***ENTERPRISE.1.” Following the text above is RAMONA’s privacy policy, which states the following: “Ramona Films S.L. Privacy Policy Data Controller Identity: RAMONA FILMS S.L.U B87763405 Address: SAN ROMUALDO 26, 5th FLOOR – DOOR B2 28037 MADRID MADRID Email: ***EMAIL.1 C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 5/33 Purpose: Registration as a subscriber.
Provision of the service contracted by the data subject.” - Also dated April 2, 2024, a document was created setting forth the Terms of Service and Privacy Policy that ***ENTERPRISE.1 includes in the form that collects data from Users who wish to subscribe to the services of RAMONA. The following text stands out from its content: “2. Description of the services ***ENTERPRISE.1 will provide a User ID to access the website and its content for which the membership is purchased; or ***ENTERPRISE.1 will process as a separate order any transaction for tangible items purchased through this . ***ENTERPRISE.1 assumes no liability for the merchandise ordered through this website. All customer service regarding tangible items is the responsibility of the seller, and it is hereby noted that any inquiries must be directed directly to the customer service contacts listed on the website. ***ENTERPRISE.1 does not provide any type of warranty, including, but not limited to, any statement, complaint, or description made by the seller regarding the tangible items. ***ENTERPRISE.1 is not liable for lost shipments or damaged or defective items.” - On 07/30/2024, the page “***URL.1” was accessed again and it was verified that during the subscription process, users are redirected to ***ENTERPRISE.1 and that RAMONA is listed as the controller, under the same terms as those listed on April 2, 2024.
Various requests were also made to RAMONA, yielding the responses detailed below: On April 2, 2024, a copy of the contract or binding agreement with the enterprise ***ENTERPRISE.1 was requested to establish joint controllers for data processing. On April 24, 2024, a response was received from RAMONA, containing two statements: “Regarding the agreement with the enterprise ***ENTERPRISE.1 to establish joint responsibility for data processing, as well as the analysis conducted by Ramona Films on the same. Attached as Annex 1 is the joint controller agreement submitted to ***ENTERPRISE.1, and as Annex 2 is the internal analysis conducted, which concludes that ***ENTERPRISE.1 is not a processor but a joint controller.” (…) “The Spanish Data Protection Agency is hereby informed that, due to the continuous obstacles posed by ***ENTERPRISE.1 regarding the documentation of the relationship between the parties within the framework of data protection, Ramona Films proceeded to terminate the contract binding it to said company.
At the C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 6/33 , Ramona Films S.L. does not currently offer any subscription services to its customers.” The aforementioned document provided as Annex 1 (submitted as a joint controller agreement) contains neither a date nor a signature from either party. Its content includes the following text: “Ramona Films offers its customers audiovisual material through a subscription to the service. ***ENTERPRISE.1 offers its customers a secure means of payment for third-party services previously verified by ***ENTERPRISE.1 itself. The payment for services contracted from Ramona Films S.L. through the platform of ***ENTERPRISE.1 requires the joint processing of personal data.” “The joint processing of customers’ personal data is intended to enable a secure channel for their subscription to the services offered by Ramona Films S.L. The purpose and means of processing are determined jointly by the Parties (hereinafter, the “Parties” shall refer to the two companies jointly).
Therefore, data protection legislation stipulates joint responsibility for such processing in this context, pursuant to Art. 26 of the GDPR.” “The Parties are authorized to freely process the personal data obtained within the framework of joint responsibility for their own purposes, to the extent that such activities are permitted by applicable Regulations regarding data protection and the Party in question informs the data subjects about of these activities.” “Both parties shall disclose in their privacy policy, pursuant to Art. 13 of the GDPR, the specific purpose for which the data is processed, as well as the legal basis for such processing. The Parties shall make this Agreement available to customers who so request.” “The parties shall be liable to the data subjects in accordance with applicable law. With regard to the internal relationship, the liability of the parties is determined in accordance with their respective scope of responsibility , without prejudice to the provisions of this agreement or any other agreements allocating responsibilities between the parties.”
The document in Annex 2, presented as an internal analysis of the position of joint liability with ***ENTERPRISE.1, is neither dated nor signed. Nor is ENTERPRISE.1’s involvement in the document substantiated. It contains the following relevant text: “***ENTERPRISE.1 is an enterprise that enables its customers to make secure online payments. Payments can only be made to enterprises that have previously registered on the ***ENTERPRISE.1 platform. The enterprise registration process involves a thorough review of the enterprise that allows ***ENTERPRISE.1 to assure its customers that online payments are secure. Para make payments through ***ENTERPRISE.1, the customer must C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 7/33 register on the platform. Once the registration process is complete, the customer will be able to make secure online payments to any enterprise previously verified by ***COMPANY.1.”
“Ramona Films SL offers its customers audiovisual products that require a prior subscription. When a customer wishes to subscribe to the enterprise’s services, they are directed to the ***ENTERPRISE.1 platform for make the payment, since Ramona Films currently only accepts subscriptions from customers registered on the ***ENTERPRISE.1 platform. Once subscribed, the customer can log in to the website and access the audiovisual material for the duration of the subscription.” “Based on an analysis of the data processing carried out by the parties, it can be concluded that neither company can be designated as a processor. ***ENTERPRISE.1 processes its customers’ data independently of Ramona Films, since the data collected from its customers is used for different business purposes. Ramona Films offers its own services to its customers, and it is possible to offer them through platforms other than ***ENTERPRISE.1 (although at this time, for business reasons, only payments made through the ***ENTERPRISE.1 platform are accepted).”
“The European Commission, via the website https://commission.europa.eu/law/law-opic/dataprotection/reform/rules- business-and-organisations/obligations/controllerprocessor/whatdata-controller- or-data-processor_es, provides a clear explanation of the roles under discussion. Regarding the joint controllers, it states that this role applies ‘when, together with one or more organizations, it jointly determines “why” and “how” personal data should be processed.’ This definition and the subsequent examples only serve to reinforce the relationship between ***ENTERPRISE.1 and Ramona Films S.L. as joint controllers.” “Therefore, since both entities decide on the purposes and means of personal data processing belonging to their shared customers, it can only be concluded that the relationship between the companies is one of joint controllers.” On June 21, 2024, a new request was issued asking for the submission of the signed and dated joint controller agreement, proof of the obstacles raised by ***ENTERPRISE.1 to the formalization of the agreement, and provide evidence of the termination of the agreement with ***ENTERPRISE.1, all in accordance with the statements made by RAMONA in its response to the previous request.
On July 18, 2024, a response was received from RAMONA to that request, in which she states the following: “Regarding the joint liability agreement with the enterprise ***ENTERPRISE.1, it was never signed by the parties. As a result of the disciplinary proceeding EXP202207932 initiated by this agency against our company, and given the refusal by ENTERPRISE.1 to sign a processor agreement (Appendix 1), we proceeded to analyze the possibility of structuring the C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 8/33 relationship within a joint controller agreement. After conducting the corresponding analysis, it was concluded that this was appropriate, and discussions were held with ***ENTERPRISE.1 in this regard. Seeing that the process was being delayed due to the other party’s reluctance and the high risk of receiving a new penalty from the Spanish Data Protection Agency, it was decided to suspend the service and, therefore, terminate the contract de facto.”
“Regarding the cancellation of the contract with ***ENTERPRISE.1, we do not have any documentation to substantiate it. The service does not entail a cost per se, since it is based on a percentage of subscriptions. Upon canceling the subscription service (which is no longer offered to our customers), the relationship with ***ENTERPRISE.1 ceases. It can be verified that this enterprise has not received any revenue from ***ENTERPRISE.1 since the first quarter of 2024. This decision, combined with the lack of real alternatives in the market, has left the company with no realistic options for business viability.” “Regarding the analysis of data processing, there is no documentation related to this matter other than that provided. The analysis presented took into account three aspects: a) The service offered by ***ENTERPRISE.1—online payment—and its design (requiring customers to register in order to subscribe to third-party platforms), which are considered controllers (as shown in Annex 1).
The entire process can be viewed on PLATFORM.1. b) The service offered by Ramona Films to its customers, which required as a subscriber. This service has been discontinued (as reported in our initial response), and no subscription service is currently offered through this company. c) Data protection regulations and texts from the European Commission. All of these are referenced in the analysis conducted.” Attached is a screenshot of an email sent from the address ***EMAIL.2 (recipient not visible) on September 26, 2023, with the subject line “Spanish Data Protection Authority Request to Ramona Films S.L.” and the following content “(…)” Unofficial translation: “(…)”. On July 30, 2024, upon this Agency’s learning of a change in the policy of the websites under investigation, a new request was sent to RAMONA requesting confirmation of the effective date of the change in ownership of the controller and proof of the change in the controller.
On August 23, 2024, a response was received from RAMONA to the request, in which it stated the following: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 9/33 “Regarding the effective date of the change in ownership of the controller, both the domain and the business associated with it were sold to the company Clams & Turnips Enterprise Korlatolt Felelossegu Tartasa on March 1, 2024.” “Proof of receipt for the first three payments toward the total amount under the aforementioned contract is provided, with the first of these payments dated the same day the contract was signed. This is provided for the purpose of verifying the change in ownership as well as to identify the purchasing party. This Agency is hereby informed that a notification has been sent to the data subjects informing them of the change in ownership of the website.” RAMONA attaches three files containing copies of transaction statements for March 1, 2024, April 12, 2024, and May 8, 2024, with the following descriptions: - “Funds added by CLAMS TURNIPS ENTERPRISE KFT • PAYMENT FOR PURCHASE OF REVOESM2 DOMAINS” - “Funds added by CLAMS TURNIPS ENTERPRISE KFT • 2nd PAYMENT REVOESM2 SALE” - “Funds added by CLAMS TURNIPS ENTERPRISE KFT • 3rd PAYMENT FOR THE PURCHASE OF REVOESM2 DOMAINS” On December 4, 2024, a new request for information was sent to RAMONA, asking for a copy of the contract for the sale of the domain names to the new owner, CLAMS & TURNIPS ENTERPRISE KORLATOLT FELELOSSEGU TARTASA (hereinafter, CLAMS & TURNIPS), confirmation of the domains affected by the change in ownership, and proof that the change in ownership was communicated to the affected individuals whose personal data was being processed, including the number of individuals notified and the content of the notification.
On 12/27/2024, a response was received from RAMONA to the aforementioned request, which included a copy of the requested contract, signed on 03/01/2024. The contract is signed by a single person, A.A.A., acting in the representation of both the seller and the buyer. The company RAMONA, of which he acts as sole administrator, is listed as the selling party, and the Hungarian company CLAMS & TURNIPS ENTERPRISE KORLÁTOLT FELELOSSÉGU TÁRSASÁG, of which he acts as a joint administrator, is listed as the buyer. The contract includes the following relevant paragraphs: - (…) Regarding notification of the change in ownership, RAMONA states that it was communicated in stages, via regular mail, to 1,147 data subjects. However, no proof of such notification was provided; instead, an appendix was submitted containing a template of the notification sent, which includes the following text: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 10/33 “Dear actor/actress: In keeping with the policy of transparency that characterizes RAMONA FILMS S.L.U., we would like to inform you that we have reached an agreement to sell all of our websites and platforms, with the exception of ramonafilms.es, to the Hungarian company CLAMS & TURNIPS ENTERPRISE KORLÁTOLT FELELOSSÉGU, with Tax Number 32465408-2-42 and registered office at Erzse bet kira lyne ú tja 96/B (1142, Budapest.
The contract you signed when you became part of our great family expressly included a clause transferring the recorded images both to our company and to “all those third parties, whether individuals or legal entities to whom the photographer may assign the rights to exploit the audiovisual content.” The agreement between the companies will take effect as of March 1 of this year. Regarding the processing of your personal data, both the controller (RAMONA FILMS SLU) and the purpose and legal basis for such processing remain unchanged. However, pursuant to the contract you signed with us, the rights to exploit the recorded footage will be transferred to CLAMS & TURNIPS ENTERPRISE KORLÁTOLT FELELOSSÉGU under the same conditions and on the same platforms as RAMONA FILMS SLU had been doing. Please remember that current data protection regulations grant you the right to request access to your personal data held by our possession, the right to request its rectification or erasure, the right to request the restriction of its processing, the right to object to the processing, the right not to be subject to automated individual decision-making, and the right to data portability.
You can find more information about these rights on the website of the Spanish Data Protection Agency (https://www.aepd.es/derechos-y-deberes/ejerce-tus-derechos). To exercise any of the rights described above, as well as to raise any questions regarding this matter in connection with this operation, you may contact our data protection officer at ***EMAIL.3. Of course, if you do not have an email address, you can contact us at the following address: SAN ROMUALDO 26, 5th FLOOR – DOOR B2 – 28037 MADRID (MADRID). If you believe that your rights regarding data protection are not being properly addressed, you may file a complaint with the Spanish Data Protection Agency (www.agpd.es). Any other questions may be directed to our email address ***EMAIL.4, where we will address it with the utmost diligence. THIRD: On August 11, 2025, the Presidency of the Spanish Data Protection Agency agreed to initiate disciplinary proceedings against the respondent, in accordance with the provisions of Articles 63 and 64 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), for the alleged violation of Article 58(2) of the GDPR, as defined in Article 83(6) of the GDPR, Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR).
FOURTH: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 11/33 On September 11, 2025, RAMONA filed a brief of arguments in which it states the following: First, it includes the following summary of the facts at issue in the proceeding: “FIRST.—As indicated in the letter from the Spanish Data Protection Agency itself, on December 26, 2023, a response was provided to the requests for information set forth in the decision regarding disciplinary proceeding EXP202207932. SECOND.- In said response, under the section titled “Third-Party Report,” the Spanish Data Protection Agency is informed that, after analyzing the relationship between the enterprise ***COMPANY.1 and Ramona Films S.L., it is understood that both enterprises are joint controllers of the personal data under review. THIRD.—Since we do not have a signed joint controller agreement and in light of previous experience with the signing of the processor agreement, it has been decided to terminate the relationship with ***ENTERPRISE.1, as continuing the relationship could result in a new sanction by the Spanish Data Protection Agency.
FOURTH.— Ramona Films does not receive any payment from ***ENTERPRISE.1 for subscriptions initiated after 2023. The last payment received by Ramona Films dates from February 2024 and corresponds to transactions from November and December 2023. FIFTH.—This decision, as reported in the response to the new request for information related to EXP202404290 dated July 17, 2024, leaves the company with no option for business viability. SIXTH.—Given the new circumstances, Ramona Films decided to sell its domains on March 1, 2024, to a third-party company, as previously documented to the Spanish Data Protection Agency in a letter dated December 26, 2024. Therefore, the simulated purchases made on April 2, 2024, and July 30, 2024, cannot apply, since on those dates the domain was not owned by Ramona Films but by the company CLAMS & TURNIPS ENTERPRISE KORLÁTOLT FELELOSSÉGU TÁRSASÁG.” Based on the facts described, the company states that “it has acted responsibly throughout the process of adapting to the data protection regulations regarding the deficiencies penalized in EXP202207932.
Indeed, the decisions made to ensure compliance have rendered the enterprise commercially unviable.” It adds that there is no contradiction in the account of the facts presented to this Agency. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 12/33 Regarding the evidence gathered by this Agency during the website registration process, it states the following: “The simulated purchases presented as proof that data processing had not ceased are dated after the sale of the domain to the company CLAMS & TURNIPS ENTERPRISE KORLÁTOLT FELELOSSÉGU TÁRSASÁG; therefore, they should not be taken into consideration. The fact that the old text appeared during the registration process listing Ramona Films as the controller can only be attributed to the new owner of the domain, never to our company.” Regarding the joint liability agreement and the continuation of its relationship with ENTERPRISE.1, we state the following: “Although it is true that ultimately no joint liability agreement was signed with the enterprise ***ENTERPRISE.1, and that all terms were disclosed during the subscription process itself, said process has not been effective following our letter of December 26, 2023, as the risk of a new penalty has taken precedence over the viability of the company itself.”
It concludes that the facts demonstrate the absence of a violation and requests the closure of the sanctioning proceeding “having demonstrated that all measures requested by this Agency have been taken.” FIFTH: On March 2, 2026, a proposed resolution was issued, recommending that the Presidency of the Spanish Data Protection Agency impose a sanction on RAMONA FILMS, S.L., with Tax ID B87763405, for a violation of Article 58(2) of the GDPR, as defined in Article 83(6) of the GDPR, with a fine of SIXTY THOUSAND EUROS (60,000.00 euros). This proposal was served electronically via the Single Authorized Electronic Address (DEHÚ) service, with access to its content by RAMONA on the same day, March 2, 2026, and no objections to said proposed resolution have been received. SIXTH: According to the report generated by the AXESOR tool, the entity RAMONA had a turnover of 392,393 euros in 2022. Based on the proceedings conducted in this case and the documentation on file, the following facts have been established: ESTABLISHED FACTS C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 13/33 FIRST: On November 17, 2023, this Agency issued a decision in disciplinary proceedings against RAMONA under case number PS/00308/2023.
That decision provided, among other things, for the following measure: “TO ORDER RAMONA FILMS, S.L., with Tax ID No. B87763405, that, pursuant to Article 58.2.d) of the GDPR, within one month, report on: (…) - The processor agreement entered into with the enterprise ***ENTERPRISE.1 in accordance with the provisions of data protection regulations.” SECOND: On December 26, 2023, RAMONA submitted a written statement to this Agency reporting compliance with the previously ordered measure, stating the following: “Regarding the content of the contract with the enterprise ***ENTERPRISE.1. As can be seen in the privacy policy of the enterprise ***ENTERPRISE.1, accessible during the pre-registration step to become a subscriber of Ramona Films S.L., the user registers as a customer of the enterprise ***ENTERPRISE.1. In the data processing, and due to its specific nature, both companies are considered joint controllers.
A step prior to registration has been included that explains in detail to the data subject who will be the controller and that the data is processed by both companies. In this way, the data subject has all the necessary information before entering any personal data.” This letter is not accompanied by any documentary evidence to support these claims. THIRD: On April 2, 2024, the website “***URL.1” featured a subscription section that redirected users to the website of the enterprise ***ENTERPRISE.1 for payment. Prior to this redirection, an informational screen appeared with the following text: “You are about to access the payment gateway para subscribe to the services of Ramona Films S.L. To ensure greater user security, Ramona Films S.L. delegates the management of this task to ***PLATFORM.1, a leading enterprise in its sector. Therefore, to complete the subscription, you must register as User (at no additional cost) of the enterprise ***COMPANY.1.
To register as a customer of ***COMPANY.1, you must fill out the following form with some basic information, as well as your payment details. It is important that you understand, before proceeding with registration, that your information will be processed both by Ramona Films (to manage your registration as a subscriber and provide the contracted service) and by ***ENTERPRISE.1 (to process payment for the current service and future services provided by both Ramona Films and other enterprises that have outsourced their services to ***ENTERPRISE.1). C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 14/33 It is therefore essential that, before filling out and submitting the form, you review the privacy policies of both Ramona Films S.L. and the enterprise ***ENTERPRISE.1.” Following the text above was RAMONA’s privacy policy, which stated the following: “Ramona Films S.L. Privacy Policy” Data Controller Identity: RAMONA FILMS S.L.U.
B87763405 Address: SAN ROMUALDO 26, 5th FLOOR - DOOR B2 28037 MADRID MADRID Email: ***EMAIL.1 Purpose: Subscriber registration. Provision of the service contracted by the data subject.” On July 30, 2024, the page “***URL.1” indicated that during the subscription process redirects to ***ENTERPRISE.1 and that RAMONA is listed as the controller, under the same terms as those listed on 04/02/2024. FOURTH: On 12/27/2024, RAMONA provided a copy of a contract dated 03/01/2024. The contract is signed by a single person, A.A.A., acting on the name and representation of both the seller and the buyer. The company RAMONA, of which he acts as sole administrator, is listed as the seller, and the Hungarian company CLAMS & TURNIPS ENTERPRISE KORLÁTOLT FELELOSSÉGU TÁRSASÁG, of which he acts as a joint administrator, is listed as the buyer. The contract includes the following relevant paragraphs: - (…) FIFTH : On April 24, 2024, RAMONA sent a letter to this Agency in response to a request to submit the joint responsibility agreement signed with ENTERPRISE.1, in which she stated the following: “Regarding the agreement with the enterprise ***ENTERPRISE.1 to establish joint responsibility for data processing, as well as the analysis conducted by Ramona Films regarding the same.
Attached as Annex 1 is the joint controller agreement submitted to ***ENTERPRISE.1, and as Annex 2 is the internal analysis conducted, which concludes that ***ENTERPRISE.1 is not a processor but a joint controller.” (…) C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 15/33 “The Spanish Data Protection Agency is hereby informed that, due to the continuous obstacles raised by ***ENTERPRISE.1 regarding the documentation of the relationship between the parties within the framework of data protection, Ramona Films has terminated the contract with said company. At present, Ramona Films S.L. does not offer any subscription services to its customers.” SIXTH: On July 18, 2024, RAMONA sent a letter to this Agency in response to a request to provide the joint liability agreement with ***ENTERPRISE.1 , which included the following text: “Regarding the joint liability agreement with the enterprise ***ENTERPRISE.1, this agreement was never signed by the parties (…) Regarding the cancellation of the contract with ***ENTERPRISE.1, we do not have any documentation to substantiate it.
The service does not entail a cost per se, as it is based on percentages of subscriptions. Upon cancellation of the subscription service (which is not offered to our customers), the relationship with ***ENTERPRISE.1 ceases.” SEVENTH: On June 21, 2024, in response to a request from this Agency regarding the obstacles raised by the enterprise ***ENTERPRISE.1 regarding the formalization of the contract and to verify the termination of the contract with ***ENTERPRISE.1—all in accordance with the statements made by RAMONA in its response to the previous request— RAMONA submitted the following response dated July 18, 2024: “Regarding the joint liability agreement with the enterprise ***ENTERPRISE.1, it was never signed by the parties. As a result of the disciplinary proceeding EXP202207932 initiated by this agency against our company, and in light of ***ENTERPRISE.1’s refusal to sign a processor agreement (Appendix 1), we proceeded to analyze the possibility of framing the relationship within a joint data controller agreement.
After conducting the corresponding analysis, it was concluded that this was appropriate, and discussions were held with ***ENTERPRISE.1 in this regard. Seeing that the process was being delayed due to the other party’s reluctance and the high risk of receiving a new penalty from the Spanish Data Protection Agency, it was decided to suspend the service and, therefore, terminate the contract de facto.” “Regarding the cancellation of the contract with ***ENTERPRISE.1, we do not have any documentation to substantiate it. The service does not entail a cost per se, as it is based on a percentage of subscriptions. Upon canceling the subscription service (which is no longer offered to our customers), the relationship with ENTERPRISE.1 ceases. It is verifiable that this enterprise has not received any revenue from ***ENTERPRISE.1 since the first quarter of 2024. This decision, combined with the lack of viable alternatives in the market, has left the company with no realistic options for business viability.”
C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 16/33 “Regarding the analysis of data processing, there is no additional documentation beyond what has been provided. The analysis presented took into account three aspects: a) The service offered by ***ENTERPRISE.1—online payment—and its design service itself (requiring customers to register in order to subscribe to third-party platforms), which are considered controllers (as shown in Annex 1). The entire process can be viewed at PLATFORM.1. b) The service offered by Ramona Films to its customers, which required registering as a subscriber. This service has been discontinued (as reported in our initial response), and no subscription service is currently offered through this company. c) Data protection regulations and European Commission documents. All of these are referenced in the analysis conducted.” EIGHTH: On September 11, 2025, RAMONA submitted a written statement of arguments regarding the decision to initiate this proceeding, in which it acknowledges that there is no joint liability agreement, in the following terms: “Although it is true that ultimately no joint liability agreement was signed with the enterprise ***EMPRESA.1, and that all terms were disclosed during the signing process itself, said process has not been effective subsequent to our letter dated December 26, 2023, since the risk of a new penalty has taken precedence over the viability of the company itself.”
LEGAL GROUNDS I Jurisdiction In accordance with the powers granted by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR) grants to each supervisory authority, and as established in Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), the Presidency of the Spanish Data Protection Agency has jurisdiction to initiate and resolve these proceedings. II Preliminary Issues Article 4(1) of the GDPR defines “personal data” as: “any information relating to an identified or identifiable natural person (‘the data subject’); an identifiable natural person is one whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 17/33 various elements specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.”
Article 4(2) of the GDPR defines “processing” as: “any operation or set of operations performed on personal data or on sets of personal data, whether whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.” Article 4(7) of the GDPR defines the “controller” or “data controller” as: “the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing; if Union law Union or of the Member States determines the purposes and means of the processing, the controller or the specific criteria for its designation may be established by Union law or the laws of the Member States.”
In turn, Article 4(8) of the GDPR defines the “processor” as the natural or legal person, public authority, agency, or other body that performs personal data processing on behalf of the controller. In the present case, in accordance with the provisions of Articles 4(1) and 4(2) of the GDPR, it is evident that personal data processing is taking place, since RAMONA carries out, among other processing activities, the collection, storage, and disclosure of personal data of natural persons, including identifying information, for the purpose of managing subscription sign-ups for the services offered through its websites. RAMONA carries out this activity in its capacity as the controller, given that it is the entity that determines the purposes and means of such activity, pursuant to Article 4.7 of the GDPR. In accordance with the Resolution of the Director of the Spanish Data Protection Agency Data of November 17, 2023, RAMONA was ordered, among other corrective measures, to inform this Agency, within one month, of the execution of a contract for processor services with the enterprise ***ENTERPRISE.1 in accordance with the provisions of data protection regulations, as a result of the existence of a violation of Article 28.3 of the GDPR.
III Response to the Objections to the Proposal to Initiate Proceedings In response to the arguments presented, the following should be noted: Regarding the absence of contradictions, the account of the facts that RAMONA includes in its submission—which has been transcribed in the background section—does not correspond to the evidence on file in this proceeding. Specifically, for the following reasons: RAMONA asserts that C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 18/33 “after analyzing the relationship between the enterprise ***ENTITY.1 and Ramona Films S.L., it is understood that both enterprises are joint controllers” and that “since we do not have a signed joint controller agreement and given the previous experience with the signing of the processor agreement, it has been decided to terminate the relationship with ***ENTERPRISE.1, as continuing the relationship could result in a new sanction by the Spanish Data Protection Agency.”
However, it omits the following relevant facts: - that it was RAMONA who, on December 26, 2023, in order to comply with the measure ordered in the resolution of November 17, 2023, which determined that RAMONA was required to report the execution of a processor contract with the enterprise ***ENTERPRISE.1 in accordance with the provisions of data protection regulations, informed this Agency that there was a joint controller agreement with ***ENTERPRISE.1, - that, upon being requested to provide said contract, it sent on April 24, 2024, an unsigned contract from ***ENTERPRISE.1, - and that, upon being asked for the signed contract, it replied on 06/21/24 that said contract was never actually signed “due to the continuous obstacles posed by ***ENTERPRISE.1 regarding the documentation of the relationship,” - that, when asked to provide documentation of these obstacles from ***ENTERPRISE.1, it submitted a single email response from ***ENTERPRISE.1, dated September 26, 23.
This email predates even the conclusion of disciplinary proceeding PS/00308/2023; failure to comply with the measures imposed in that proceeding gives rise to the present proceeding. Furthermore, that email is a response from ***ENTERPRISE.1 to a previous email that RAMONA does not provide, in which ***ENTERPRISE.1 states that in its dealings with its customers, it acts as the controller and not as a processor. In short, the facts cited by RAMONA do not correspond to the documentation it has provided, and its responses to this Agency’s requests are mutually contradictory. Regarding the termination of its relationship with ***ENTERPRISE.1, RAMONA asserts that “it receives no payments from ***ENTERPRISE.1 for subscriptions initiated after 2023. The last payment from Ramona Films dates from February 2024 and corresponds to transactions from November and December 2023.” However, it omits that RAMONA informed this Agency, in its letter dated April 24, 2024, that “it proceeded to terminate the contract binding it to said company.”
However, when asked to provide said contract, it claims it does not have the documentation, even though in the previous disciplinary proceeding, PS/00308/2023, RAMONA stated that it had a service contract with ***ENTERPRISE.1 dating back to 2004. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 19/33 RAMONA also fails to mention that, regardless of the enterprise’s ownership, it has been shown that as of April 2, 2024, it was possible to subscribe to the services of the “***URL.1” website and that, for such a subscription, users were redirected to ***ENTERPRISE.1. RAMONA states that the decision to terminate the relationship with ***ENTERPRISE.1 “is detailed in the response to the new request for information related to EXP202404290 dated July 17, 2024.” However, it should be noted that said letter, as mentioned above, is a result of several prior requests to which RAMONA responded by stating that there was a contract that it did not provide, which it subsequently provided without a signature, and which it finally acknowledged was not signed.
Regarding the decision to sell its domains to another enterprise (albeit with the same manager, who signs said contract as the owner of both the selling enterprise and the purchasing company), RAMONA asserts that said sale took place on March 1, 2024, and therefore “the simulated purchases made on April 2, 2024, and July 30, 2024, cannot apply, since on those dates the domain was not owned by Ramona Films but rather by the company CLAMS & TURNIPS ENTERPRISE KORLÁTOLT FELELOSSÉGU TÁRSASÁG.” In this regard, it should be noted that, despite asserting that this change occurred on March 1, 2024, RAMONA did not report it in its three written responses to this Agency—which were in response to a request for information as part of the preliminary investigative proceedings—and it was not until July 30, 2024, when this Agency inquired due to a change in the website’s privacy policy, that RAMONA replied, dated August 23, 2024, that the domain had been sold.
Furthermore, it is relevant (and this is the fact giving rise to the present enforcement proceeding) that on December 26, 2023, RAMONA submitted a letter to this Agency reporting compliance with the measure ordered in enforcement proceeding PS/00308/2023. In that submission, RAMONA states the following: “Regarding the content of the contract with the enterprise ***ENTERPRISE.1. As can be seen in the privacy policy of ***ENTERPRISE.1 accessible during the registration process to become a subscriber of Ramona Films S.L., the User registers as a customer of the enterprise ***EMPRESA.1. With regard to data processing, and given its specific nature, both companies are considered joint controllers. A step prior to registration has been included that explains in detail to the data subject who will be the controller and that the data is processed by both companies. In this way, the data subject has the complete information before entering any personal data.”
In other words, as of November 26, 2023, RAMONA reported that the processing was ongoing, although RAMONA and ***ENTERPRISE.1 were considered joint controllers rather than a controller and a processor, without providing any documentation to support their assertions. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 20/33 Under these circumstances, given that documentation regarding this relationship was requested and having received the responses from RAMONA analyzed above, regardless of the sale of the domain in March 2024, RAMONA had not complied with the measure imposed in the Resolution of proceeding PS/00308/2023, and the data processing and its relationship with ***ENTERPRISE.1 remained undocumented. In short, RAMONA’s claim that “there is no contradiction in the account of the facts presented to this Agency” must be rejected. Regarding its description of the facts transcribed above, RAMONA states that “it has acted responsibly throughout the process of bringing the sanctioned deficiencies in EXP202207932 into compliance with data protection regulations.
So much so that the decisions made to ensure compliance have rendered the enterprise commercially unviable.” In this regard, it should be noted that this claim is not accepted. First, because RAMONA responded to this Agency that it had complied with the measure, when in reality the joint-responsibility relationship it claimed to have with ***ENTERPRISE.1 had not been formalized. And second, because there is no record in any of the documentation provided by RAMONA of any actual initiative to regularize that relationship, which was what it was ordered to do in the Decision of the penalty proceeding PS/00308/2023. RAMONA further argues that the evidence regarding the registration process dates from after the sale of the domain and that the fact that “the old text appeared in the registration process, which listed Ramona Films as the party responsible for processing can only be attributed to the new owner of the domain, never to our company.”
The fact that RAMONA continues to appear as the controller for processing after the sale of the domain (as well as the option to subscribe with payment to ***ENTERPRISE.1) had been highlighted in the initial decision as one of the contradictions between the information provided by RAMONA in its submissions. This contradiction regarding the termination of the subscription service was in addition to those relating to the existence of a liability agreement, the discontinuation of the subscription service, and the alleged obstacles raised by ***ENTERPRISE.1 to regularize its relationship. In short, the claim that the entity responsible for the information appearing on the domain is the new responsible party—that is, the enterprise CLAMS & TURNIPS ENTERPRISE KORLÁTOLT FELELOSSÉGU TÁRSASÁG—does not preclude the conclusion that, contrary to what RAMONA asserted in its letter dated December 26, 2023, its relationship with ***ENTERPRISE.1 had not been formalized.
As for its assertion that “although it is true that ultimately there was no signed joint liability agreement with the enterprise ***ENTERPRISE.1, and that all terms were disclosed during the subscription process itself, said process has not been carried out since our letter of December 26, C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 21/33 2023,” the fact is that RAMONA informed this Agency that said relationship had been formalized and updated the information on its website; however, according to the information provided subsequently and the evidence gathered, this was not the case. Furthermore, after December 26, 2023, RAMONA sent four responses to this Agency’s requests, containing contradictory information, in which it did not mention that, after December 26, 2023, the subscription process was no longer active. This claim, which RAMONA is now adding, appears to contradict the fact that the enterprise sold the web domain three months later, based on a purchase agreement in which the person listed as the administrator of both enterprises is the same, and that through this agreement, users can continue to access the subscription service, furthermore, being redirected to the same enterprise for payment: ***ENTERPRISE.1.
RAMONA concludes its statement of defense by pointing out that the facts demonstrate the absence of a violation and by requesting that the proceedings be dismissed “since it has been proven that all measures requested by this Agency have been taken.” This argument is rejected, as it has not been substantiated in any way. Thus, the measure ordered by this Agency in the Resolution of disciplinary proceeding PS/00308/2023 consisted of “ORDERING RAMONA FILMS, S.L., with Tax ID No. B87763405, pursuant to Article 58.2.d) of the GDPR, to report within one month on: (…) - Processor Agreement entered into with the enterprise ***ENTERPRISE.1 in accordance with the provisions of the data protection regulations.” However, on December 26, 2023, RAMONA reported that it had complied with said requirement, having concluded that its relationship with ***ENTERPRISE.1 was one of joint controllers, documenting this and updating the information on its website, whereas it has since become evident that this assertion does not correspond to reality.
In short, it has not entered into the data processing agreement with ***ENTERPRISE.1 as ordered; despite this, it initially reported that it had entered into said agreement and ultimately acknowledges that said agreement never existed. IV Breach of obligation. Article 58 of the GDPR, Corrective powers of the supervisory authority The second paragraph of Article 58 of the GDPR provides as follows: “2. Each supervisory authority shall have all of the following correction powers listed below: (…) d) to order the controller or processor to ensure that processing operations comply with the provisions of this Regulation, where appropriate, in a specific manner and within a specified time limit” C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 22/33 In the present case, on November 17, 2023, the Director of the AEPD issued a decision in the enforcement proceeding regarding case no. EXP202207932.
In that decision, RAMONA was sanctioned for various breaches of the GDPR and was ordered, pursuant to Article 58(2)(d) of the GDPR, to report on the adoption of several measures relating to said breaches. Among these measures, RAMONA was ordered, within one month, to report on the “Processor Agreement entered into with the enterprise ENTERPRISE.1 in accordance with the provisions of data protection regulations.” As described in the facts, on December 26, 2023, RAMONA submitted a written statement reporting on compliance with the ordered measure. Thus, regarding the data processing agreement it was required to provide with ***ENTERPRISE.1, instead of submitting the aforementioned agreement, it stated that it considered itself jointly responsible with ***ENTERPRISE.1 for the processing of personal data, which was why it did not submit the requested data processing agreement. As a result of the foregoing, on March 20, 2024, the Director of the AEPD to open an investigation to “determine whether RAMONA FILMS and ***ENTERPRISE.1 might be joint controllers for the processing of personal data.”
As part of these investigative proceedings, several responses have been received from RAMONA, transcribed in the “Facts” section, which are contradictory among themselves and contradictory to the evidence gathered by this Agency, for the reasons analyzed below. This response would indicate that there is neither a data processing agreement nor a liability agreement in place between RAMONA and ENTERPRISE.1, for the reasons analyzed below. The responses from RAMONA contain contradictions on at least four points: - the existence of a joint liability agreement, - the termination of RAMONA’s relationship with ***ENTERPRISE.1 - the discontinuation of the subscription service, and - the obstacles imposed by ***ENTERPRISE.1 to regularize its relationship. First, regarding the existence of a joint liability agreement, when RAMONA was asked to provide said joint liability agreement with ENTERPRISE.1, in accordance with what the enterprise itself had stated, on on April 24, 2024, RAMONA submitted as the contract a document without a date or signature (from either enterprise) that she claims is the joint liability agreement governing the legal relationship between the two enterprises regarding the processing of personal data.
Furthermore, it states that “due to the continuous obstacles posed by ***ENTERPRISE.1 regarding the documentation of the relationship between the parties within the framework of data protection, Ramona Films proceeded to terminate the contract binding it to said enterprise. Currently, Ramona Films S.L. does not offer any subscription service to its customers” C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 23/33 However, when RAMONA is asked to provide the signed joint liability agreement, proof of the termination of the contract with ***ENTERPRISE.1, and evidence of the alleged obstacles raised by ***ENTERPRISE.1, RAMONA confirms, as of July 18, 2024, that the joint responsibility agreement was never signed. This makes it clear that the alleged joint responsibility agreement that RAMONA sent to the AEPD for the purpose of having the corrective measures imposed deemed to have been fulfilled, never existed, despite RAMONA’s assertion to the contrary before the AEPD.
Specifically, in its letter dated 12/26/2023, RAMONA reported on compliance with the measure issued by this Agency pursuant to Article 58(2)(d) of the GDPR, stating that “In the processing of data, and due to the specific nature of such processing, both companies are considered joint controllers. A step has been included prior to registration that explains in detail to the data subject who will be the controller and that the data are processed by both companies.” (emphasis added) If both companies were considered joint controllers, as RAMONA asserted, there would need to be an agreement in which both parties determine their responsibilities regarding compliance with the obligations, in accordance with the provisions of Article 26 of the GDPR. In fact, both the alleged joint control agreement and the assessment document regarding it should have been signed by both enterprises, so that in this way ***ENTERPRISE.1 would endorse the statements made by RAMONA before the AEPD.
In summary, RAMONA had been ordered to provide evidence of the formalization of its relationship with ***ENTERPRISE.1 as a data processor. RAMONA initially reported that, in fact, the relationship is one of joint responsibility. When this Agency requested that it provide evidence of said relationship of shared responsibility, RAMONA submitted a contract that was neither dated nor signed. And when asked to provide a signed and dated copy, it acknowledged that such a contract had never existed. Second, regarding her relationship with ***ENTERPRISE.1, RAMONA stated in her letter dated April 24, 2024, that said relationship no longer existed, asserting that “Ramona Films proceeded to terminate the contract binding it to that enterprise.” However, when asked to provide proof of the termination of the service contract with ***ENTERPRISE.1, RAMONA states that “Regarding the cancellation of the contract with ***ENTERPRISE.1, we do not have any documentation to substantiate it.
The service does not entail a cost per se, as it is based on percentages of subscriptions. Upon canceling the subscription service (which is no longer offered to our customers), the relationship with ***ENTERPRISE.1 ceases. It is verifiable that this enterprise has not received any revenue from ***ENTERPRISE.1 since the first quarter of 2024.” Thus, they have not provided evidence of the termination of any contract either. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 24/33 On the other hand, the explanation provided by RAMONA would contradict other previous statements regarding its relationship with ***ENTERPRISE.1. It claims it cannot verify the cancellation because “we do not have documentation to prove it. The service does not entail a cost per se, as it is based on percentages of the subscriptions.” However, on previous occasions, she stated that the relationship with ENTERPRISE.1 was indeed documented in a contract (for the provision of services).
Thus, in the aforementioned previous disciplinary proceeding (PS/00308/2023, resolved by the Director of the AEPD on 11/17/2023), RAMONA claimed to have a service contract with ***ENTERPRISE.1 dating back to 2004. On the other hand, in its response dated April 20, 2024, it states that “Ramona Films proceeded to terminate the contract binding it to said company.” It is therefore unclear why RAMONA has not provided documentary evidence of said termination. As an alternative to providing documentary evidence of this termination, RAMONA asserts that it is verifiable that she has not received any income from ***ENTERPRISE.1 since the first quarter of 2024, but she does not provide any evidence to that effect. However, as previously stated, evidence has been gathered showing that as of April 2, 2024, it was possible to subscribe to the services of the website “***URL.1” and that for such a subscription, users were redirected to ***ENTERPRISE.1.
Therefore, there appears to be evidence that, contrary to what RAMONA claims, the relationship with the enterprise ***ENTERPRISE.1 did in fact continue. In short, RAMONA claims that its relationship with ***ENTERPRISE.1 no longer exists, but it does not substantiate this, and the explanations it provides contradict other statements made by RAMONA itself. Third, regarding the subscription service, RAMONA indicated in her letter dated April 24, 2024, that this service no longer existed. This statement also contradicts the evidence gathered by this Agency. As detailed above in the Facts, on both April 2, 2024, and subsequently on July 30, 2024 (a date subsequent to the letter in which RAMONA states that the subscription service was no longer offered subscription service was no longer offered), evidence was gathered showing that it was possible to subscribe to RAMONA’s services on the website “***URL.1”.
Upon accessing the subscription section, users are redirected to ***ENTERPRISE.1, and in the information provided, RAMONA continues to appear as the data controller. Fourth, RAMONA alleges obstacles posed by ***ENTERPRISE.1, which would have prevented the formalization of a data processor or joint controller agreement and compliance with the measure adopted by this Agency. Specifically, in its response dated July 18, 2024, to the request from this Agency’s inspector, RAMONA provides an email dated September 26, 2023, which reads as follows: (…) However, this email cannot be considered as evidence of the alleged obstacles raised by ***ENTERPRISE.1 to formalize the correspondent relationship, for several reasons. This email is a response to an earlier communication from RAMONA that the enterprise does not provide, and it rejects the signing of a document that RAMONA allegedly sent to ENTERPRISE.1—which RAMONA also fails to provide.
Therefore, it is not possible to know what was discussed or C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 25/33 proposed to ***ENTERPRISE.1, nor what the content was of the document that RAMONA sent to ***ENTERPRISE.1 and which the latter allegedly rejected. Furthermore, in the body of the email, ***ENTERPRISE.1 states that it acts as the controller and not as a processor in its dealings with its clients. Based on the foregoing, what RAMONA would be demonstrating with that email is, at most case, that ***ENTERPRISE.1 rejected a relationship in which ***ENTERPRISE.1 would serve as a processor. However, it does not prove that RAMONA initiated the procedures to document their relationship as joint controllers, in accordance with Article 26 of the GDPR, nor that ***ENTERPRISE.1 rejected this possibility. Furthermore, it should be noted that the date of the email from ***ENTERPRISE.1 (September 26, 2023) and the subject line listed therein (“Spanish Data Protection Authority Request to Ramona Films S.L.”).
Therefore, it can be inferred that this was ***ENTERPRISE.1’s response to a communication from RAMONA prior to the resolution of the previous enforcement proceeding. Thus, if on 11/17/2023 this Agency ordered RAMONA to report within one month regarding its relationship with ***ENTERPRISE.1, it would be unacceptable that on 12/27/2023 it informed the Agency that both entities were jointly responsible without having agreed upon their respective responsibilities in accordance with Article 26 of the GDPR. Nor would it be acceptable for it to subsequently claim that joint liability could not be documented due to obstacles raised by ***ENTERPRISE.1, based on an email from ***ENTERPRISE.1 that predates even this Agency’s Agency in the context of PS/00308/2023, whose failure to comply with the measures ordered has given rise to this new sanctioning proceeding. Aside from the four contradictions highlighted regarding the relationship between RAMONA and ***ENTERPRISE.1, subsequently, as this Agency has become aware of a change in ownership of RAMONA’s websites, it is requested that RAMONA provide information on the date of the change and the new owner.
On August 23, 2024, RAMONA reported that the change took effect on March 1, 2024, and that the websites and domains were sold to the Hungarian enterprise CLAMS & TURNIPS ENTERPRISE. It did not provide a sales contract, but it did, para substantiate the change in ownership, submit three documents that it claims correspond to the first three installment payments. When asked to provide the sales contract for the websites, on December 27, 2024, RAMONA submitted a contract dated March 1, 2024, bearing the signature of a single person, A.A.A., who allegedly acted in the representation of both the seller and the buyer. This response also contradicted the information that appeared on the website “***URL.1” as of April 2, 2024, and as of July 30, 2024, in which, although one section of the website listed CLAMS & TURNIPS as the controller for processing, RAMONA continued to be listed as the controller for processing in the section regarding subscriber registration section of the page and when redirecting to ***ENTERPRISE.1 for payment of the subscription, as documented in the investigative proceedings and transcribed above in the facts.
C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 26/33 Of all the above, the numerous contradictions detected in RAMONA’s statements regarding its relationship with ***ENTERPRISE.1 stand out. In this regard, it should be noted that the obligations imposed by the GDPR in the relationships between the data controller and the processor or between joint controllers, as set forth in Articles 28 and 26, are not a mere formality, but rather a means of guaranteeing the rights of data subjects affected by the processing. Guidelines 07/2020 on the concepts of “controller” and “processor” in the GDPR, adopted on July 7, 2021, by the European Data Protection Board (hereinafter, EDPB), state the following in paragraphs 2, 14, 48, and 165: “2. The concept of ‘controller’ and its interaction with the concept of ‘processor’ are of fundamental importance in the application of the GDPR, since they determine who is responsible for compliance with the various data protection rules and how data subjects can exercise their rights in practice.
The GDPR expressly introduces the principle of proactive accountability, under which the controller is responsible for compliance with the principles governing the processing of personal data set forth in Article 5 and must be able to demonstrate such compliance. (…) 14. Since the ultimate objective of assigning the role of controller for processing is to ensure proactive accountability and effective and comprehensive data protection for personal data, the concept of “controller” should be interpreted broadly enough to promote, to the greatest extent possible, effective and comprehensive protection of data subjects,⁷ for the purpose of ensuring the full effectiveness of Union law on data protection, avoiding loopholes, and preventing any circumvention of the regulations, without this implying any reduction in the powers of the processor. (…) 48. As detailed in Section 2 of Part II, classification as joint controllers has implications for the allocation of obligations with a view to complying with data protection regulations, in particular those related to the rights of natural persons.
(…) 165. It is clear from this provision that joint controllers must define who, in each case, will be responsible for responding to requests from data subjects when they exercise the rights granted to them by the GDPR, and for providing them with information, as required by Articles 13 and 14 of the GDPR; that is, they must define in their internal agreement which requests from the data subject each party is responsible for responding to.” In short, determining who is the controller or whether there are joint controllers or processors, as the case may be, serves as a safeguard for the data subject rights of those affected by the processing, who will be able to exercise their rights regarding their personal data to the extent that these roles and the obligations associated with them are clearly defined. 6 Jorge Juan St.www.aepd.es 28001 – Madrid sedeaepd.gob.es 27/33 In this case, since there was no agreement setting forth the relationship between RAMONA and ***ENTERPRISE.1 (neither as joint controllers nor as a controller and processor), the data subjects (the subscribers to its websites) did not They had clear information regarding the responsibilities that RAMONA assumed or delegated in the context of the processing of their personal data.
In summary, it can be concluded that, in accordance with the Resolution of the Director of the AEPD dated November 17, 2023, RAMONA was obligated to provide information regarding a processor agreement with the enterprise ***ENTERPRISE.1, in accordance with what had been revealed during the sanctioning proceedings. RAMONA stated on December 26, 2023, that both entities considered themselves joint controllers, as indicated on its website. However, the investigation revealed that no joint controller agreement existed, nor has RAMONA provided evidence of any contact or initiative to enter into one. Furthermore, there is evidence that, contrary to RAMONA’s claims, ENTERPRISE.1 continued to handle matters related to the payment of website subscriptions on the dates when RAMONA claims their relationship had ended. Finally, there are contradictions regarding the change in ownership of the websites “***URL.1” and “***URL.2,” which RAMONA claims to have carried out on March 1, 2024, despite which it continued to be listed as the responsible party as of April 2, 2024, and also as of July 30, 2024.
Based on the foregoing, there appears to be evidence in the proceedings that the measure ordered by the Director of this Agency on November 17, 2023, consisting of reporting on the execution of a processor agreement with the enterprise ***ENTERPRISE.1 in accordance with the provisions of data protection regulations. Therefore, there has been a breach of Article 58.2(d) of the GDPR. V Classification of the violation of Article 58.2 of the GDPR and determination for purposes of the statute of limitations Article 83(6) of the GDPR classifies a violation of the following article as an administrative violation, which shall be penalized in accordance with paragraph 2 of this article with administrative fines of up to 20,000,000 EUR or, in the case of an enterprise, an amount equivalent to up to 4% of the total annual global turnover for the previous fiscal year, whichever is amount: “failure to comply with the decisions of the supervisory authority pursuant to Article 58(2).”
For its part, Article 71 of the LOPDGDD, “Infractions,” states that: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 28/33 “The acts and conduct referred to in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this organic law, constitute violations.” For the sole purpose of the statute of limitations, Article 72 of the LOPDGDD establishes the following: 1. In accordance with the provisions of Article 83(5) of Regulation (EU) 2016/679, the following are considered very serious and shall be subject to a three-year statute of limitations: infractions that constitute a substantial violation of the articles mentioned therein, and, in particular, the following: (…) 2. Infractions referred to in Article 83(6) of Regulation (EU) 2016/679 shall be considered equally serious and shall also be subject to a three-year statute of limitations.
VI Penalty In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR must be observed, which state: “1. Each supervisory authority shall ensure that the imposition of Administrative fines pursuant to this article for infringements of this Regulation referred to in paragraphs 4, 9, and 6 are, in each individual case, effective, proportionate, and dissuasive. 2. Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or in lieu of the measures set forth in Article 58(2)(a) through (h) and (j). When deciding on the imposition of an administrative fine and its amount in each individual case, due account shall be taken of: a) the nature, gravity, and duration of the violation, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the extent of the harm they have suffered; (b) whether the infringement was intentional or due to negligence; (c) any measures taken by the controller or processor to mitigate the damage suffered by the data subjects; d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures they have implemented pursuant to Articles 25 and 32; e) any previous infringements committed by the controller or processor; f) the extent of cooperation with the supervisory authority for the purpose of remedying the breach and mitigating its potential adverse effects; g) the categories of data affected by the breach; h) how the supervisory authority became aware of the breach, in particular whether the controller or processor reported the breach and, if so, to what extent; C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 29/33 i) where the measures referred to in Article 58(2) have been previously ordered against the controller or processor in question in connection with the same matter, compliance with those measures; j) adherence to codes of conduct pursuant to Article 40 or to certification mechanisms approved in accordance with Article 42, and k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, as a result of the violation.”
For its part, article 76, “Sanctions and Corrective Measures,” of the LOPDGDD provides: “1. The penalties provided for in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the criteria for proportionality set forth in paragraph 2 of that article. 2. In accordance with the provisions of Article 83(2)(k) of Regulation (EU) 2016/679, the following may also be taken into account: a) The ongoing nature of the violation. b) The connection between the infringer’s activities and the processing of personal data. c) The profits obtained as a result of the commission of the violation. d) The possibility that the data subject’s conduct may have contributed to the commission of the violation. e) The existence of a merger by absorption occurring after the commission of the violation, which cannot be attributed to the absorbing entity. f) The impact on the rights of minors. g) Having a data protection officer, when not required by law. h) The submission by the controller or processor, on a voluntary basis, to alternative dispute resolution mechanisms, in those cases where disputes exist between them and any data subject.”
In the present case, with regard to the seriousness of the possible violation, with particular attention to the consequences its commission has on those affected, a fine should be imposed, in addition to the adoption of measures, if appropriate. The fine imposed must be, in each individual case, effective, proportionate, and deterrent, in accordance with the provisions of Article 83(1) of the GDPR. To ensure these principles, the turnover of RAMONA: 392,393 euros in 2022. For the purposes of deciding on the imposition of an administrative fine and its amount, based on the established facts, it is considered appropriate to determine the penalty imposed in accordance with the following circumstances, as set forth in the provisions cited above. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 30/33 First, for the purpose of determining the level of severity of the violation, it is considered that the following circumstances apply: • The nature, severity, and duration of the violation, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the extent of the damages they have suffered (Article 83(2)(a) of the GDPR).
In the present case, it is worth noting, with regard to the duration of the violation, that it has extended not only from the beginning of the relationship between RAMONA and ***ENTERPRISE.1—for which it was already the subject of a sanction in a previous enforcement proceeding—but also that, once a fine was imposed and despite that, the violation has continued. RAMONA has never submitted either a data processing agreement or a valid joint controller agreement with ***ENTERPRISE.1. However, for the order to comply with the measure ordered by the AEPD arising from PS/00308/2023, it submitted a mere document (undated and unsigned by both entities) that it claimed was the joint liability agreement entered into with ENTERPRISE.1, only to later acknowledge, following the AEPD’s requests on this matter, that such an agreement never existed. Furthermore, it should be noted that the email from ***ENTERPRISE.1—which is the only document RAMONA provided to support its claim regarding the “obstacles” faced by that enterprise in documenting their relationship, is dated September 26, 2023.
In other words, by the time the resolution ordering the measure subject to these proceedings (November 17, 2023), RAMONA would already have had the response from ***ENTERPRISE.1; despite this, it would have maintained the relationship without any agreement in place (neither as a data controller and data processor nor as joint controllers). Regarding the duration of the violation, it is ultimately noteworthy that the noncompliance would have continued after the sanctioning resolution was issued and would have persisted even after RAMONA reported on its alleged compliance with the measure (December 26, 2023). All of this occurred without any evidence of any genuine effort by RAMONA to bring the relationship into compliance. • Intent or negligence in the infringement (Article 83(2)(b) of the GDPR). As analyzed above, in the present case, RAMONA’s intent in committing the violation is evident for the following reasons: - First, RAMONA informed this Agency of the existence of a joint liability relationship with the enterprise ***EMPRESA.1 to demonstrate compliance with a measure ordered by the AEPD (as a result of the proven noncompliance in PS/00308/2023), but failed to provide evidence of an agreement regarding that alleged joint responsibility when requested to do so.
It submitted as valid a joint liability agreement that was undated and unsigned by both enterprises; later, in response to requests from the AEPD, it had to acknowledge that said joint liability agreement was never signed by ***ENTERPRISE.1. - It subsequently reported that there was no longer a relationship with ***ENTERPRISE.1, citing the termination of the contract and the discontinuation of the system at C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 31/33 subscription system. However, when asked to provide proof of that termination, not only was no supporting documentation provided, but this Agency also found evidence that the subscription system remained on the website and that users were redirected to ***ENTERPRISE.1 through it. For these reasons, it is considered that there was manifest intent in the conduct that constitutes the violation, insofar as RAMONA not only failed to demonstrate compliance with the measures ordered by the Resolution of the Director of the AEPD dated November 17, 2023, but also reported, in order to justify them, certain facts that did not exist, providing for that purpose unsigned and undated documents prepared ad hoc. • Categories of data affected by the violation (Article 83(2)(g) of the GDPR).
In the present case, the violation affects the personal data of all individuals who use the payment gateway with ***ENTERPRISE.1, which includes, in addition to identifying data, the bank details necessary to complete the payment. Likewise, the following aggravating factors are considered: • The connection between the infringer’s activity and the processing of personal data (Article 76.2(b) of the LOPDGDD). In the present case, RAMONA’s activity consists of offering online services to its customers through subscriptions, for which an essential element would be the processing of data from Users of its websites. Given the circumstances listed above, it is also worth noting that Article 83.1 of the GDPR establishes that the supervisory authority shall ensure that the fines imposed “are, in each individual case, effective, proportionate, and dissuasive.” In this regard, the ordered measure—which was allegedly breached—was imposed as part of a sanctioning proceeding in which fines were imposed for seven violations of the GDPR.
One of these violations was for non-compliance with Article 28.3 regarding the relationship between RAMONA and ENTERPRISE.1, with a fine of 40,000 euros. Despite these sanctions, it was alleged that not only was there non-compliance with the ordered measure at issue in these proceedings (to provide information on the data processor agreement with ***ENTERPRISE.1), but also contradictions in the information provided by RAMONA to justify compliance with that measure while the non-compliance persisted. In this regard, it can be concluded that the fines previously imposed, in particular the one imposed for the violation of Article 28.3 regarding the contract between RAMONA and ENTERPRISE.1, have not had the deterrent effect required by Article 83(1) of the GDPR. In this regard, Guidelines 04/2022 on the calculation of fines under the GDPR, adopted on May 24, 2023, by the EDPB, state in paragraph 144 that: “Supervisory authorities may consider increasing the fine if they do not consider the amount to be sufficiently deterrent.
In certain C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 32/33 circumstances, the application of a deterrent multiplier may be justified. This multiplier may be set at the discretion of the supervisory authority, in order to reflect the deterrence objectives described above.” A balancing of the circumstances set forth in Article 83(2) of the GDPR and Article 76(2) of the LOPDGDD, with respect to the violation committed by breaching the provisions of Article 58(2) of the GDPR, as well as the need to ensure the deterrent effect of the fine provided for in Article 83(1) of the GDPR, allows for the imposition of an administrative fine of 60,000.00 euros. Therefore, in accordance with applicable law and after evaluating the criteria for determining the severity of sanctions, the existence of which has been established, the Presidency of the Spanish Data Protection Agency RESOLVES: FIRST: TO IMPOSE on RAMONA FILMS, S.L., with Tax ID No. B87763405, for a violation of Article 58(2) of the GDPR, as defined in Article 83(6) of the GDPR, a fine of 60,000.00 euros (SIXTY THOUSAND euros).
SECOND: TO NOTIFY RAMONA FILMS, S.L. of this decision. THIRD: This decision shall become enforceable once the deadline for filing the optional appeal for reconsideration (one month from the day following notification of this decision) has expired without the data subject having exercised this right. The party subject to the penalty is hereby notified that they must pay the imposed penalty once this decision becomes enforceable, in accordance with the provisions of Art. 98.1.b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), within the voluntary payment period established in Art. 68 of the General Collection Regulation, approved by Royal Decree 939/2005, of July 29, in conjunction with Art. 62 of Law 58/2003, of December 17, by making a payment indicating the taxpayer identification number (NIF) of the party subject to the penalty and the procedure number appearing at the top of this document, into the restricted account No. IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX), opened in the name of the Spanish Data Protection Agency at the bank CAIXABANK, S.A. Otherwise, the amount will be collected through enforcement proceedings.
Upon receipt of the notice and once it becomes enforceable, if the date of enforceability falls between the 1st and 15th of each month, inclusive, the deadline for making a voluntary payment will be the 20th of the following month or the next business day thereafter; and if it falls between the 16th and the last day of each month, inclusive, the payment deadline will be until the 5th of the second following month or the next business day thereafter. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 33/33 In accordance with the provisions of Article 50 of the LOPDGDD, this Decision shall be made public. Publication shall take place once it has been notified to the data subjects. Against this resolution, which concludes the administrative proceedings pursuant to Article 48.6 of the LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, the data subjects may, at their discretion, file an appeal for reconsideration with the Presidency of the Spanish Data Protection Agency within one month from the day following notification of this resolution, or directly file an administrative-litigious appeal before the Administrative-Litigious Chamber of the National Court, in accordance with the provisions of Article 25 and paragraph 5 of the Fourth Additional Provision of Law 29/1998, of July 13, regulating the Administrative Jurisdiction, within two months from the day following notification of this decision, as provided for in Article 46.1 of the aforementioned Law.
Finally, it is noted that, in accordance with the provisions of Article 90.3(a) of the LPACAP, the final administrative decision may be provisionally suspended if the data subject expresses their intention to file an administrative appeal. If this is the case, the data subject must formally notify the Spanish Data Protection Agency of this fact by submitting a written notice to the Spanish Data Protection Agency through the Agency’s Electronic Registry web/, or through any of the other registries provided for in Art. 16.4 of the aforementioned Law 39/2015, of October 1. The data subject must also submit to the Agency the documentation proving that the contentious- administrative appeal has been effectively filed. If the Agency is not made aware of the filing of the contentious-administrative appeal within two months from the day following the notification of this decision, it will consider the precautionary suspension to have ended. 938-090326 Lorenzo Cotino Hueso President of the Spanish Data Protection Agency C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es