The Spanish authority closes a case against THE WAY MEDIA MARKETING AND DIGITAL SERVICES for unsolicited commercial communication

The Spanish data protection authority closed a case initiated against a company for sending unsolicited emails, after the company demonstrated that the messages originated from a third party impersonating its identity as part of a phishing campaign.

Facts and context

The Spanish data protection authority (AEPD) today published a decision to close a case against THE WAY MEDIA MARKETING AND DIGITAL SERVICES, S.L., initially initiated for an alleged failure to obtain prior consent for commercial prospecting.

The case was initiated on 15 July 2025 following a complaint from an individual reporting the receipt of unsolicited commercial emails for personal loan services, without ever having consented or provided their data to the sender.

Reasons for the decision

The authority analyzed the imputability of the alleged infringement to the company concerned and concluded the absence of responsibility of the latter.

  • Absence of proof of imputability of the sending of communications (Article 21, paragraph 1 of Law 34/2002 on information society services and electronic commerce): The authority considered that the company based its defense by demonstrating that it was not the originator of the sends. Technical analysis revealed that the emails came from a domain name (***DOMINIO.1) over which the company had no control, distinct from its corporate domain (***DOMINIO.2). Furthermore, the links contained in the messages redirected to an external URL (zesxu.wgnx.org) classified as fraudulent and used for phishing attempts, with no connection to the company's infrastructure. The authority therefore concluded identity theft and the absence of sufficient causal link to impute responsibility for the sending to the entity targeted by the complaint.

Authority's decision

Consequently, the authority ordered the closure of the case and imposed no sanctions on THE WAY MEDIA MARKETING AND DIGITAL SERVICES, S.L.

Lessons learned

This decision confirms / specifies / recalls that:

  • The responsibility for sending unsolicited commercial communications cannot be imputed to an entity without proof of a direct causal link and its effective control over the dispatch.
  • Technical analysis of email headers, sending domain names, and links contained in messages is decisive to establish or exclude the responsibility of the alleged sender.
  • Demonstrating that communications are part of a phishing or spoofing campaign by a third party constitutes an effective defense for the entity whose name is abusively used.
  • It is the responsibility of the supervisory authority to provide evidence that the prosecuted entity is indeed the originator of the infringement; in the absence of sufficient evidence, the case must be closed.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire