Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Banco Bilbao Vizcaya Argentaria S.A.: Insufficient legal basis for data processing
How it connects
Related across sources
Case Law Deutsche Wohnen SE v Staatsanwaltschaft Berlin News Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Guidance Guidelines 07/2020 on the concepts of controller and processor in the GDPR Guidance Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Literature GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection Literature GDPR Implementation Series ∙ Spain: Preparations for a New Law on Data Protection to Implement the GDPR
Full text
The Spanish DPA (AEPD) has imposed a fine on Banco Bilbao Vizcaya Argentaria S.A.. A data subject filed a complaint with the DPA due to the fact that the controller repeatedly sent him SMS messages about non-payments, although he had no contractual relationship with the controller. The controller stated that the unsolicited SMS messages were sent due to human error on part of its employees. The original fine of EUR 100,000 was reduced to EUR 60,000 due to voluntary payment and admission of guilt.
Industry: Finance, Insurance and Consulting
Original document at the source www.aepd.es