The Spanish authority sanctions CERRADA, S.L. for failure to protect passwords

Sending passwords in clear text by email, including in the welcome message, constitutes a violation of the security obligation under Article 32 of the GDPR, even if the passwords are encrypted in the data controller's information system.

Facts and context

The Spanish Data Protection Authority (AEPD) has today published a sanction decision against CERRADA, S.L. including the imposition of a fine of €5,000 for failures related to the security of customers' passwords.

The procedure was initiated following a complaint from a user who received, after the creation of their account on 11 October 2024, a welcome email containing their username and password in clear text.

Reasons for the decision

  • Obligation to ensure the security of processing (Article 32 of the GDPR): The authority found that sending the password in clear text in the welcome email constituted an inappropriate security measure given the risks. It recalled that the email protocol (SMTP) does not guarantee the confidentiality of transmitted data, exposing it to risks of interception and manipulation by malicious third parties, as highlighted in the "Good Practices Report" of the Spanish National Cryptologic Center. The authority considered that this practice created a significant vulnerability, regardless of whether passwords are encrypted in the company's internal systems or whether any actual damage was demonstrated.

Authority's decision

Consequently, the authority imposed a fine of €5,000 on CERRADA, S.L. The company benefited from a 20% reduction for voluntary payment, reducing the amount paid to €4,000.

Furthermore, the authority ordered the company to cease, within one month from the date the decision becomes final, the practice of sending passwords and user data by email, including in account creation messages.

Lessons learned

This decision reminds that:

  • The security of personal data must be ensured not only at rest in information systems but also during their transmission.
  • Sending passwords in clear text by email is considered an inadequate technical and organizational measure to ensure a level of security appropriate to the risk.
  • The violation of the security obligation is constituted by the existence of a vulnerability creating a risk for data subjects, without the need to prove the occurrence of actual damage.
  • The implementation of corrective measures after the detection of a failure does not cancel the initial violation, although it may be taken into account in determining the sanction.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire