Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
GSMA LTD.: Insufficient technical and organisational measures to ensure information security
The Spanish DPA has imposed a fine of EUR 200,000 against GSMA LTD..
Full text
The Spanish DPA has imposed a fine of EUR 200,000 against GSMA LTD.. An individual had filed a complaint with the DPA because they had to transfer special categories of personal data (e.g., ID card data) to the controller in order to register for an event. In the course of its investigation, the DPA found that the controller had failed to conduct a data protection impact assessment for these processing operations.
Industry: Not assigned
How it connects
References
Related across sources
15625/2026 Cass.Civ. - 15625/2026 Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its… Supreme Court May 21, 2026 Privacy by Design & Default Privacy by Design DPIA
Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Oct 20, 2020 Privacy by Design & Default Privacy by Default Privacy by Design
Opinion 01/2025 EDPB- EDPS Joint Opinion 01/2025 on the Proposal for a Regulation on simplification measures for SMEs and SMCs, in particular the record-keeping obligation under Art. 30(5) GDPR De EDPB en EDPS steunen het doel om de administratieve lasten voor SMCs en MKB te verminderen, mits dit de bescherming van fundamentele rechten niet verlaagt. Ze benadrukken de… Opinion Jul 9, 2025 Accountability Criminal Data Processing
VwGH Ro 2025/04/0007-7 VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural The controller was an address publisher and direct advertising company that operated a data application to provide advertisers with personal data for targeted marketing measures.… Jun 24, 2026 Controllers Accountability Personal Data
Opinion 15/2025 certification criteria of BDO Consulting GmbH ·Opinion ·EDPB Jul 14, 2025 Certification Supervision Supervisory Authorities
Opinion 34/2025 C.E.C.L certification criteria ·Opinion ·EDPB Dec 2, 2025 Certification Supervision Supervisory Authorities