The Spanish authority imposes a sanction on HOLALUZ following a data breach: 675,000 euros fine

The Spanish authority imposed a sanction of €675,000 on an energy provider for serious security failures, notably for allowing the use of a shared account by 120 employees of a subcontractor and for misconfiguration of access rights that exposed the data of its entire customer base.

Facts and context

The Spanish Data Protection Authority (AEPD) today published a sanction decision against HOLALUZ-CLIDOM, S.A. (including the imposition of a €675,000 fine) for breaches related to processing security and the confidentiality principle.

The case originated from a data breach notification by the company on October 26 and 27, 2022, followed by two complaints from data subjects regarding a leak of their personal data.

Grounds for the decision

  • Obligation to ensure integrity and confidentiality (Article 5(1)(f) of the GDPR): The authority found that the confidentiality of personal data of approximately 31,000 individuals had been compromised. The company's fault was established due to a misconfiguration of access rights granted to its subcontractor, ***EMPRESA.2. The user account provided had roles allowing access to the entire HOLALUZ customer base, not only the portfolio of clients it managed. The authority considers this defective implementation of organizational measures, described as a human and isolated error by the company, to be the direct cause of the confidentiality breach, recalling that merely designing security measures is insufficient without their diligent implementation and use.
  • Obligation to ensure the security of processing (Article 32 of the GDPR): The authority noted several security failures. On one hand, the applications concerned were publicly accessible on the internet without IP address access restrictions, allowing connection from a country where the company has no activity. On the other hand, and considered particularly serious, the company allowed and was aware of the use of a single account shared by about 120 employees of its subcontractor. This practice, described as a "serious omission," makes any action traceability impossible and significantly increases data security risks. Finally, the absence of a password expiration policy was also noted as a missing security measure.

Authority's decision

Consequently, the authority imposed a fine of €675,000 on HOLALUZ-CLIDOM, S.A., broken down into €400,000 for the violation of Article 5(1)(f) of the GDPR and €275,000 for the violation of Article 32 of the GDPR.

Furthermore, the authority ordered the company to adopt, within three months, appropriate technical and organizational measures to ensure the security of the personal data it processes.

Lessons learned

This decision reminds that:

  • The use of a single user account shared by many employees, especially those of a subcontractor, constitutes a serious security failure that prevents any traceability of access and engages the responsibility of the controller.
  • The configuration of a subcontractor's access rights must be strictly limited to the principle of least privilege; granting access rights to the entire customer database beyond its scope of intervention constitutes a breach of the confidentiality principle.
  • The existence of a criminal procedure against the perpetrator of a cyberattack does not suspend the administrative sanction procedure against the controller, as the subject (the attacker versus the controller) and the legal basis (criminal versus administrative) are not identical.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire