The Spanish authority sanctions AXESOR for unlawful processing of self-employed entrepreneurs' data and marketing without legal basis
The Spanish Data Protection Agency sanctions a data broker for the commercial reuse of self-employed workers' data from the public census, without a valid legal basis and without prior information to the data subjects.
Facts and context
The Spanish Data Protection Agency (AEPD) today published a sanction decision against the company AXESOR, including the imposition of a fine of €128,000, for breaches related to the lawfulness of processing and the obligation to inform the data subjects.
The case originated from a complaint dated 27 December 2022, denouncing the marketing for commercial prospecting purposes of personal data of self-employed workers, initially collected by the Spanish tax administration (AEAT).
Grounds for the decision
- Obligation of lawfulness of processing (Article 6(1) of the GDPR): The authority found that AXESOR processed and marketed the data of 1,665,049 self-employed workers, obtained indirectly via the company CAMERDATA, which itself received them from the Spanish Chamber of Commerce. However, the Chamber of Commerce receives these data from the tax administration only on the basis of a legal obligation (Law 4/2014) and for the exclusive purpose of preparing the Public Census of Companies. The AEPD considered that the reuse of these data by AXESOR for commercial purposes constituted a purpose limitation breach. The legitimate interest invoked by AXESOR was dismissed, the authority considering that the usage restrictions imposed by the sectoral law prevail and that no impact assessment demonstrating the predominance of its interests over the rights and freedoms of the data subjects, whose professional address may be their private address, had been carried out.
- Obligation to inform the data subjects (Article 14 of the GDPR): AXESOR obtained the personal data indirectly, never individually informing the self-employed workers concerned. The AEPD emphasized that this total lack of information deprived the data subjects of knowledge about the processing of their data and, consequently, of the possibility to exercise their rights, notably the right to object. The authority considered that AXESOR had not demonstrated that providing this information was impossible or would require a disproportionate effort, thus violating the transparency principle.
Decision of the authority
Consequently, the authority imposed a fine of €160,000 on AXESOR, reduced to €128,000 following a voluntary payment.
Furthermore, the authority ordered AXESOR to cease processing the data concerned and to delete them within three months.
Lessons learned
This decision reminds that:
- Data collected by a public authority based on a legal obligation for a specific public interest purpose cannot be reused by third parties for commercial purposes without a distinct and valid legal basis.
- The invocation of legitimate interest for processing data obtained indirectly requires a rigorous impact assessment and the implementation of sufficient safeguards, notably clear information enabling data subjects to effectively exercise their right to object.
- The information obligation provided for in Article 14 of the GDPR is an essential prerequisite for the exercise of data subjects' rights; its non-compliance vitiates the lawfulness of processing, especially when based on legitimate interest.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire