Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
RCL CRUISES LTD: Non-compliance with general data processing principles
How it connects
Related across sources
Guidance Guidelines 07/2020 on the concepts of controller and processor in the GDPR Guidance Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidance Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 Guidance Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01) Guidance Guidelines 9/2022 on personal data breach notification under GDPR Guidance Guidelines 07/2022 on certification as a tool for transfers
Full text
The Spanish DPA has imposed a fine of EUR 15,000 on RCL CRUISES LTD. An individual had filed a complaint with the DPA. The individual, after requesting information about a cruise ship by e-mail, had received an e-mail from the controller containing personal data of another individual. The DPA found that the controller had failed to implement appropriate technical and organizational measures to protect personal data.
Industry: Accomodation and Hospitality
Original document at the source www.aepd.es