The Spanish authority closes a case against COFIDIS for sending information to an email address modified by the complainant himself
The Spanish data protection authority has archived a procedure initiated against a credit institution for an alleged breach of confidentiality, after the latter demonstrated that the sending of contractual information to an incorrect email address resulted from a modification made by the complainant himself in his client area.
Facts and context
The Spanish data protection authority (AEPD) published a decision to archive a procedure against COFIDIS S.A., SUCURSAL EN ESPAÑA, concerning an alleged breach of the principle of confidentiality of personal data.
The case originated from a complaint by an individual reproaching the credit institution for having sent, on February 24, 2024, contractual information to his mother's email address, with whom the institution had no contractual relationship.
Reasons for the decision
- Obligation to ensure the integrity and confidentiality of data (Article 5(1)(f) of the GDPR): The authority considered that no violation of this principle was established. Indeed, although contractual information was sent to a third-party email address, the institution proved, by producing computer logs and screenshots, that this address had been entered by the complainant himself in his personal space on December 19, 2023, replacing his former address. Applying the principles of presumption of innocence and *in dubio pro reo*, applicable in administrative sanction law, the authority concluded that it was not possible to hold the data controller responsible, as the case elements did not allow to establish with certainty that the address had not been provided by the complainant.
Authority's decision
Consequently, the authority decided to archive the sanction procedure initiated against COFIDIS S.A., SUCURSAL EN ESPAÑA.
Lessons learned
This decision reminds that:
- The traceability of actions performed by users in their personal spaces (such as modifying contact data) is essential evidence to defend against an accusation of confidentiality breach.
- In the context of a sanction procedure, the principle of presumption of innocence applies, and the burden of proof of the infringement lies with the supervisory authority.
- The implementation of automatic notifications informing the user of any modification of critical personal information, such as their email address, is a relevant security measure and probative element in case of dispute.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire