The Spanish authority declares the expiration of a procedure against AUDINFOR SYSTEM for GDPR infringements
Facts and context
The Spanish data protection authority (AEPD) has today published a decision to close the sanction procedure initiated against the company AUDINFOR SYSTEM, S.L., concerning alleged breaches related to the absence of legal basis and data protection by design.
The case originated from a complaint by the National Commission on Markets and Competition (CNMC) regarding possible fraudulent uses of the supply points information system.
Reasons for the decision
The authority had opened a sanction procedure on 20 September 2024 for several alleged infringements. However, the final decision notes that the legal twelve-month period granted to conclude the procedure has expired, resulting in its expiration without a substantive examination of the breaches having taken place. The initially notified charges were as follows:
- Absence of legal basis (Article 6(1) of the GDPR): The authority had opened a sanction procedure due to two alleged infringements of this provision. The facts concerned possible fraudulent uses of the supply points information system, suggesting processing of personal data without an appropriate legal basis. The closure decision does not examine the substance of these allegations.
- Failure to implement data protection by design (Article 25 of the GDPR): An infringement of this principle was also attributed to the company. The authority suspected that the technical and organizational measures implemented were not designed to effectively guarantee data protection principles. As with the first breach, the substance of this accusation was not analyzed.
Authority's decision
Consequently, the authority declared the expiration of the sanction procedure and ordered the archiving of the file.
Lessons learned
This decision reminds that:
- Compliance with procedural deadlines provided by national law is imperative for a supervisory authority, their expiration potentially leading to the closure of a case without substantive examination of the alleged breaches.
- Access to and use of shared sectoral databases, such as the supply points information system in the energy sector, constitute a major point of vigilance for authorities.
- Reports from other regulatory authorities, such as those in charge of competition, can trigger in-depth investigations in data protection matters.
- An alleged unlawful data processing may lead an authority to simultaneously examine the absence of legal basis and the failure to implement data protection by design.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire