Skip to content
Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

SERVICIOS FINANCIEROS CARREFOUR, E.F.C.: Insufficient technical and organisational measures to ensure information security

The Spanish DPA has imposed a fine of EUR 1,500,000 on SERVICIOS FINANCIEROS CARREFOUR, E.F.C.

€1,500,000 Fine
SERVICIOS FINANCIEROS CARREFOUR, E.F.C.
SPAIN
Art. 5 GDPR

Full text

The Spanish DPA has imposed a fine of EUR 1,500,000 on SERVICIOS FINANCIEROS CARREFOUR, E.F.C. The controller suffered a successfull cyberattack due to insufficient technical and organisational measures. The original fine of EUR 2,500,000 was reduced to EUR 1,500,000 due to immediate payment and admission of responsibility by the controller.

Industry: Finance, Insurance and Consulting

How it connects

S 5 SF 65/24 DS SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus… Social Court Nuremberg Jun 10, 2026 Processors Controllers Integrity and Confidentiality Principle
Guidelines 04/2021 Codes of Conduct as tools for transfers Guidelines on codes of conduct and monitoring bodies Guidelines ·EDPB Feb 22, 2022 International Transfer Processing Agreement Codes of Conduct