Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
PRESTAMER, S.L.: Insufficient technical and organisational measures to ensure information security
The Spanish DPA has imposed a fine on PRESTAMER, S.L..
Full text
The Spanish DPA has imposed a fine on PRESTAMER, S.L.. The controller had sent an e-mail without using the blind copy option, revealing the email addresses of all recipients to the other recipients. The original fine of EUR 3,000 was reduced to EUR 1,800 due to voluntary payment and acknowledgement of responsibility.
Industry: Finance, Insurance and Consulting
How it connects
Related across sources
1 As 183/2023-62 Health insurer must disclose aggregated patient treatment data under Free Access to OAKS Consulting s.r.o. (the company) provided consulting services concerning market access conditions for medicinal products and medical devices. Pursuant to the Czech Act on Free… Supreme Administrative Court Aug 4, 2026 Pseudonymization Anonymization Personal Data
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address
BA-6S/221/2019 Court upholds €50,000 fine on Sociálna poisťovňa for sending sensitive data by ordinary Sociálna poisťovňa, the social insurance agency (the controller), processes applications for foreign invalidity pensions and forwards related documents to the social insurance… Jun 25, 2025 Integrity and Confidentiality Principle Personal Data Data Breaches
C-807/21 Deutsche Wohnen SE v Staatsanwaltschaft Berlin C-807/21 (Deutsche Wohnen) CJEU Dec 5, 2023 Fines Public Authority Processors
Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Oct 20, 2020 Privacy by Design & Default Privacy by Default Privacy by Design
2026 EWCA Civ 1130 EWCA (UK) - 2026 EWCA Civ 1130 Three persons who had brought personal injury claims arising from road traffic accidents and whose personal and health data were included in a spreadsheet prepared for use in… Court of Appeal (Civil Division) Sep 2, 2026 Retention Period Pseudonymization Anonymization