# IBERDROLA, S.A.: Non-compliance with general data processing principles

- Type: Enforcement
- Source: Spanish Data Protection Authority (aepd)
- Date: 2024-02-07
- Original: https://www.enforcementtracker.com/ETid-2557
- Canonical: https://overview.legal/posts/48672
- Topics: Security, IP Address, Law Enforcement, Processing Agreement, Supervisory Authorities, Processing

## Summary

The Spanish DPA has fined IBERDROLA, S.A. EUR 3 million following a cyberattack on I-DE Redes, which led to the compromise of customer data from millions of individuals. Although the cyberattack targeted the GEA web application of I-DE Redes, Iberdrola, as the entity responsible for managing the group's IT systems and security infrastructure, was found to have failed in implementing sufficient security measures to prevent the incident.

## Full text

The Spanish DPA has fined IBERDROLA, S.A. EUR 3 million following a cyberattack on I-DE Redes, which led to the compromise of customer data from millions of individuals. Although the cyberattack targeted the GEA web application of I-DE Redes, Iberdrola, as the entity responsible for managing the group's IT systems and security infrastructure, was found to have failed in implementing sufficient security measures to prevent the incident.

GDPR Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR
Industry: Transportation and Energy

---
Generated by overview.legal · https://overview.legal/posts/48672 · 2026-08-22
