Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
BANCO CETELEM, S.A.: Insufficient legal basis for data processing
How it connects
Related across sources
Case Law Deutsche Wohnen SE v Staatsanwaltschaft Berlin News Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Guidance Guidelines 07/2020 on the concepts of controller and processor in the GDPR Guidance Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Literature GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection Literature GDPR Implementation Series ∙ Spain: Preparations for a New Law on Data Protection to Implement the GDPR
Full text
The Spanish DPA has imposed a fine on BANCO CETELEM, S.A.. A person had filed a complaint against the controller with the DPA due to the fact that debits had been made from their account by the controller to a third party without there even being a contractual relationship between the data subject and the controller. The DPA also found that further debits were made despite complaints and requests for the data to be deleted. The original fine of EUR 250,000 was reduced to EUR 150,000 due to the voluntary payment and the acknowledgement of responsibility.
Industry: Finance, Insurance and Consulting
Original document at the source www.aepd.es