The Spanish authority fines EDREAMS €20,000 for breaches of Articles 15 and 21 of the GDPR
The Spanish authority sanctions a company for failing to process a request to exercise rights sent in response to a commercial email, ruling that the controller must anticipate this communication channel even if it has designated others as preferred.
Facts and context
The Spanish Data Protection Authority (AEPD) has today published a sanction decision against VACACIONES EDREAMS S.L. (including the imposition of a €20,000 fine) for breaches related to the handling of requests to exercise rights.
The case originated from a complaint submitted by the Baden-Württemberg authority concerning the failure to respond to a request for access and objection sent by a customer on 23 August 2022.
Reasons for the decision
- Obligation to respond to an access request (Article 15 of the GDPR): The authority found that the data subject exercised their right of access by replying to a promotional email sent by the company. The request was only fulfilled in October 2023, more than a year later, and only following the authority's intervention. The company argued that it had not received the request because it used an external platform that automatically deleted replies to commercial communications, and that the person should have used dedicated channels (privacy form). The authority rejected this argument, considering it foreseeable that a recipient would reply directly to an email. Referring to Recital (59) of the GDPR, it recalled that the controller must facilitate the exercise of rights and is responsible for implementing the technical and organizational measures to process requests, regardless of the channel used by the person, as long as it is a contact point initiated by the controller itself.
- Obligation to process an objection request (Article 21 of the GDPR): For the same factual and legal reasons, the authority concluded a violation of the right to object. The objection to the processing of data for direct marketing purposes, made in the same email of 23 August 2022, was ignored for more than a year. The company's argument, based on the use of an unplanned channel and a technical tool that did not allow receipt of replies, was dismissed. The authority emphasized the proactive responsibility of the controller, who cannot hide behind their technical choices to justify non-compliance with data subjects' rights. The late response, after the investigation was opened, does not erase the initial breach.
Authority's decision
Consequently, the authority imposed a fine of €20,000 on VACACIONES EDREAMS, S.L., split into €10,000 for the violation of Article 15 of the GDPR and €10,000 for that of Article 21 of the GDPR.
Lessons learned
This decision reminds that:
- Providing dedicated channels for exercising rights (form, specific email address) does not relieve the controller of the obligation to process requests received by other means, including in response to commercial communications.
- It is the controller's responsibility to anticipate the communication channels that data subjects are likely to use to exercise their rights and to implement the technical and organizational processes to manage them.
- The choice of a tool or technical platform that prevents the receipt or processing of requests to exercise rights (for example, a "no-reply" system that deletes responses) is not a valid excuse and engages the controller's responsibility.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire