The Spanish authority fines FLEXICAR INTERNACIONAL, S.L. for GDPR breaches following a data breach

A data breach at a car dealership revealed underlying failures in security, transparency regarding the retention of prospect data, and respect for the right to erasure, resulting in a financial penalty and corrective measures.

Facts and context

The Spanish data protection authority (AEPD) today published a sanction decision against FLEXICAR INTERNACIONAL, S.L. (including the imposition of a €680,000 fine) for breaches related to data security, transparency on retention periods, and non-compliance with individuals' rights.

The case originated from three complaints, two of which concerned the failure to comply with data erasure requests, revealed when the complainants received a data breach notification from the company.

Grounds for the decision

  • Integrity and confidentiality obligation (Article 5(1)(f) of the GDPR): The authority found that a data breach led to the exfiltration of personal information, including sensitive data such as national identity card numbers, for a large number of individuals. The AEPD described the company's conduct as "serious negligence," highlighting that it had not implemented cybersecurity recommendations made in 2022. This failure to ensure appropriate data security justified a €400,000 fine.
  • Security of processing obligation (Article 32 of the GDPR): The authority considered that the company had not implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk, particularly regarding "blocked" data. The fact that the breach affected data of unqualified customers (prospects) and individuals who had consented to receive commercial communications demonstrated this failure. This breach was sanctioned with a €250,000 fine.
  • Transparency obligation on retention periods (Article 13 of the GDPR): The company's privacy policy was deemed too generic. It did not distinguish retention periods between actual customers and unqualified customers (prospects), nor did it inform the latter that their data would be retained for five years. The authority concluded that this lack of precision prevented data subjects from exercising effective control over their data, constituting a violation of the information obligation, sanctioned by a €30,000 fine.

Authority's decision

Consequently, the authority imposed a €680,000 fine on FLEXICAR INTERNACIONAL, S.L.

Furthermore, the authority ordered the company to bring its information policy into compliance with Article 13 of the GDPR within one month, particularly for unqualified customers, and to adopt security measures compliant with Article 32 of the GDPR within four months, especially concerning data blocking.

Lessons learned

This decision confirms / specifies / reminds that:

  • A data retention policy must define precise and distinct durations for each category of data subjects (e.g., actual customers and prospects), a mere mention of legal limitation periods being insufficient.
  • Failure to implement security recommendations from previous audits can be qualified as serious negligence and constitutes an aggravating factor in assessing a breach of Article 5(1)(f) of the GDPR.
  • The security obligation of Article 32 of the GDPR also applies to data that is simply "blocked" (e.g., pending deletion or for legal reasons), which must be subject to appropriate technical and organizational protection measures.
  • A data breach notification sent to a person who has previously exercised their right to erasure constitutes material evidence of non-compliance with that right by the controller.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire