The Spanish authority sanctions CONECTA5 TELECINCO for non-compliance with prior consent for cookies on the www.mitele.es website

The Spanish Data Protection Agency sanctions a website publisher for placing cookies before any consent and for conditioning refusal on subscribing to a paid subscription.

Facts and context

The Spanish Data Protection Agency (AEPD) has today published a sanction decision against CONECTA5 TELECINCO, S.A.U. (including the imposition of a €5,000 fine) for breaches related to the use of cookies on its website.

The case originated from a complaint filed on 11 February 2025, alleging that the website mitele.es installed tracking and advertising cookies without obtaining the user's prior consent.

Reasons for the decision

The authority found a breach of the obligation to obtain prior consent for the placement and reading of data storage and retrieval devices.

  • Obligation to obtain consent before placing or reading cookies (Article 22.2 of Law 34/2002 on information society services and electronic commerce): During a technical inspection carried out on 13 January 2026, the AEPD found that from the first access to the site, and before any user interaction, several non-essential cookies were installed. These included analytics cookies (AMCV_, AMCVS_, s_cc), personalization (__Secure-BUCKET, __Secure-STRP), and advertising (NID). The authority rejected the entity's argument that the technical evidence was insufficient, stating that the use of standard browser inspection tools is a valid verification method and that the observed facts benefit from a presumption of truthfulness. The AEPD also specified that the responsibility to block third-party cookies before consent lies with the site publisher, even if these cookies come from third-party domains (such as google.com) for which the user may have given consent elsewhere. The mere existence of internal controls or periodic audits is not sufficient to exempt the publisher if, in practice, the non-consensual placement occurred. Finally, the authority noted that the cookie refusal option redirected to a page requiring subscription to a paid service, which is a relevant factual element in analyzing the consent mechanism.

Authority's decision

Consequently, the authority imposed a €5,000 fine on CONECTA5 TELECINCO, S.A.U..

Lessons learned

This decision confirms / specifies / recalls that:

  • The responsibility to prevent the placement or reading of non-essential cookies before consent lies with the site publisher, including for third-party cookies. Consent obtained by a third party on another platform is not valid for the visited site.
  • Supervisory authorities can establish proof of a cookie-related breach using standard inspection tools integrated into browsers. The burden of proof to the contrary, with probative technical evidence, lies with the entity concerned.
  • A cookie with multiple purposes, some of which are not strictly necessary for the service's operation, is entirely subject to the obligation to obtain prior consent.
  • The implementation of internal control procedures, although a good practice, does not constitute a mitigating circumstance or a valid defense if the material infringement, namely the placement of cookies without consent, is proven.
  • Liability for this type of infringement is objective: lack of intent does not exempt the publisher from responsibility once the result prohibited by law has occurred.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire