The Spanish authority closes a case sanctioning A.A.A. for a GDPR infringement following a criminal conviction

The Spanish authority closes a procedure for data dissemination without legal basis, on the grounds that the facts have already been subject to a final criminal conviction, thus applying the principle *ne bis in idem*.

Facts and context

The Spanish Data Protection Agency (AEPD) published a decision to close proceedings against an individual for the live broadcast of a sexual assault, the facts having already been penalized.

The case began after the publication of a press article reporting the live broadcast of an assault on an online platform, leading the authority to open an ex officio investigation on 4 November 2022.

Reasons for the decision

The authority had initially opened a sanction procedure considering that the facts were likely to constitute the following infringement:

  • Lack of legal basis for processing (Article 6(1) of the GDPR): The person concerned was accused of having recorded and live broadcast on an online platform images of a victim who was intoxicated and unaware of the situation, without any legal basis justifying such processing of personal data. The evidence, including a video recording and screenshots, clearly showed the commission of the acts and the identification of the perpetrator.

However, the authority found that these same facts had been subject to criminal proceedings. A final sentence from the juvenile court ***JUZGADO.1 dated ***FECHA.6 convicted the perpetrator of sexual assault and the offence of discovery and disclosure of secrets. The conviction included two years of semi-open detention, one year of supervised release, and compensation of €3,000 for moral damage. The AEPD therefore considered that the facts had already been judged and sanctioned by the criminal court, which justified the closure of its own procedure.

Authority's decision

Consequently, the authority decided to close the procedure without further action.

Lessons learned

This decision reminds that:

  • The principle *ne bis in idem* can lead a data protection authority to close a procedure when the same facts have already resulted in a final criminal conviction, considering that the criminal sanction is sufficient.
  • The non-consensual dissemination of intimate images constitutes not only a violation of the GDPR (lack of legal basis) but can also be criminally qualified, notably under the offence of disclosure of secrets.
  • A supervisory authority can suspend a sanction procedure in data protection pending the outcome of a criminal procedure concerning the same facts.
  • Supervisory authorities can initiate investigations ex officio based on public information, such as press articles, without waiting for a formal complaint to be filed.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire