Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274.: Non-compliance with general data processing principles
The Spanish DPA has imposed a fine on IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274.
Full text
The Spanish DPA has imposed a fine on IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274. Due to a technical error in its online platform, personal data, including health information, of 3,395 individuals was unlawfully transferred to 354 recipients. The DPA found that the controller had failed to implement appropriate technical and organisational measures to protect personal data that could have prevented such an incident. The original fine of EUR 1 million was reduced to EUR 600,000 due to voluntary payment and admission of responsibility.
Industry: Individuals and Private Associations
How it connects
Related across sources
C-311/18 Data Protection Commissioner v Facebook Ireland and Maximillian Schrems C-311/18 (Schrems II) CJEU Jul 16, 2020 Privacy Shield Processing Agreement International Transfer
C-362/14 Maximillian Schrems v Data Protection Commissioner C-362/14 (Schrems I) CJEU Oct 6, 2015 Privacy Shield Supervision IP Address
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) CJEU Jan 12, 2023 Supervisory Authorities IP Address Supervision
C-136/17 GC and Others v CNIL C-136/17 (GC and Others) CJEU Sep 24, 2019 Right to be Forgotten Legitimate Interest Criminal Data
C-507/17 Google LLC v CNIL C-507/17 (Google Territorial Scope) CJEU Sep 24, 2019 Territorial scope (GDPR) Right to be Forgotten Direct Marketing