Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
CLUB GIMNASIA RÍTMICA SAN ANTONIO: Insufficient legal basis for data processing
The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on CLUB GIMNASIA RÍTMICA SAN ANTONIO.
Full text
The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on CLUB GIMNASIA RÍTMICA SAN ANTONIO. A person had filed a complaint against the controller with the AEPD based on the controller's posting of pictures and videos of her two underage daughters on Instagram. The complainant had previously told the controller that she did not want pictures of her daughters to be posted on social media as she refused to give permission for her daughters to be photographed and recorded.
Industry: Individuals and Private Associations
How it connects
References
Related across sources
C-645/19 Facebook Ireland Ltd and Others v Gegevensbeschermingsautoriteit In Case C-645/19, the Court of Justice of the European Union (Grand Chamber) addressed a preliminary ruling from the Brussels Court of Appeal concerning Facebook Ireland Ltd and… CJEU ·Grand Chamber Jun 15, 2021 Supervision Supervisory Authorities Controllers
C-40/17 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV C-40/17 (Fashion ID) CJEU Jul 29, 2019 Controllers Legitimate Interest Processors
C-210/16 Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein C-210/16 (Wirtschaftsakademie) CJEU Jun 5, 2018 IP Address Controllers Processors
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address
C-46/23 Budapest Főváros IV. Kerület Újpest Önkormányzat Polgármesteri Hivatala v Nemzeti Adatvédelmi és Információszabadság Hatóság In a preliminary ruling requested by the Budapest High Court, the Court of Justice interpreted whether Article 58(2)(d) and (g) of the GDPR permits a national supervisory… CJEU ·Fifth Chamber Mar 14, 2024 Right to be Forgotten Personal Data Right to Restriction
Guidelines 8/2020 targeting of social media users Guidelines ·EDPB Apr 13, 2021 Marketing IP Address Transparency