The Spanish authority closes the case against Reclamaciones Judiciales Letrados Asociados following a criminal conviction
Facts and context
The Spanish Data Protection Authority (AEPD) has today published a decision to dismiss a procedure against the company RECLAMACIONES JUDICIALES LETRADOS ASOCIADOS, S.L., initially prosecuted for breaches related to its obligations as a processor.
The case originated from the discovery, during other procedures, of forged postal delivery slips, which led to the opening of an investigation into the processor, RECLAMACIONES JUDICIALES LETRADOS ASOCIADOS, S.L. (RJLA), which was responsible for these mailings on behalf of the controller, DTS DISTRIBUIDORA DE TELEVISIÓN DIGITAL, S.A.
Reasons for the decision
The investigation revealed that RJLA, acting as a processor for debt collection, had produced false delivery slips and postal dispatch certificates to simulate the sending of formal notices prior to registering debtors in creditworthiness files. The national postal service confirmed that the documents in question were forged. In light of these elements, the controller, DTS, terminated the contract with RJLA and filed a criminal complaint.
- Failure to act on the controller's instructions (Article 28(10) of the GDPR): The procedure was opened against the processor on the grounds that by falsifying documents essential to the assigned task, it had potentially determined the purposes and means of the processing itself, thus acting outside the controller's instructions. However, the authority did not rule on the substance of this breach, as a parallel criminal procedure concerning the same material facts of document forgery resulted in a final conviction of the manager of the processor company for the offence of forgery. The authority therefore considered that the unlawfulness of the facts had already received a criminal judicial response.
Authority's decision
Consequently, the authority ordered the dismissal of the procedure against RECLAMACIONES JUDICIALES LETRADOS ASOCIADOS, S.L.
Lessons
This decision recalls that:
- A final criminal conviction for material facts identical to those examined in an administrative sanction procedure may lead the supervisory authority to dismiss its own procedure, applying the principle that no one can be prosecuted or punished criminally twice for the same facts.
- Forgery by a processor of documents intended to prove compliance with a legal obligation (such as prior notification before registration in a bad debtor file) constitutes a serious offence liable to criminal sanctions, beyond the administrative sanctions provided for by the GDPR.
- The controller must exercise particular vigilance over the compliance evidence provided by its processors, as its responsibility may be engaged primarily due to the fraudulent actions of the latter.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire