Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
VALORA PREVENCIÓN, S.L.U.: Insufficient technical and organisational measures to ensure information security
The Spanish DPA has imposed a fine of EUR 32,000 on VALORA PREVENCIÓN, S.L.U.
Full text
The Spanish DPA has imposed a fine of EUR 32,000 on VALORA PREVENCIÓN, S.L.U. The controller, a company offering occupational health and safety services, failed to implement sufficient technical and organisational measures. This resulted in the health data of an employee being leaked to a coworker of the data subject. The original fine of EUR 40,000 was reduced to EUR 32,000 due to immediate payment by the controller.
Industry: Industry and Commerce
How it connects
Related across sources
C-362/14 Maximillian Schrems v Data Protection Commissioner C-362/14 (Schrems I) CJEU Oct 6, 2015 Privacy Shield Supervision IP Address
Guidelines 03/2020 processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak Guidelines ·EDPB Apr 21, 2020 Healthcare Health Data Personal Data
W292 2292202-1 The data subject is in the military The unit he is employed at (controller) and the data subject are involved in a multitude of legal disputes concerning his employment, disciplinary proceedings, data protection… BVwG - W292 2292202-1 ·Federal Administrative Court Jun 30, 2026 Health Data Legitimate Interest Healthcare
C-311/18 Data Protection Commissioner v Facebook Ireland and Maximillian Schrems C-311/18 (Schrems II) CJEU Jul 16, 2020 Privacy Shield Processing Agreement International Transfer
C-136/17 GC and Others v CNIL C-136/17 (GC and Others) CJEU Sep 24, 2019 Right to be Forgotten Legitimate Interest Criminal Data
Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Oct 20, 2020 Privacy by Design & Default Privacy by Default Privacy by Design