The Spanish authority sanctions KAFFA KOFFEE ORGANISATION for non-cooperation

The Spanish authority sanctions a company not for the initial data breach, but for its failure to comply with a previous decision ordering it to implement corrective measures.

Facts and context


The Spanish Data Protection Authority (AEPD) published on 19 June 2026 a sanction decision against KAFFA KOFFEE ORGANISATION, S.L., including the imposition of a fine of €900, for failing to comply with an injunction issued in a previous decision.


This case follows a previous decision dated 7 November 2024, in which the authority ordered the company to stop sending emails revealing recipients' addresses to each other and to prove the implementation of corrective measures.



Grounds for the decision


The authority found a breach by the company:



  • Obligation to comply with the injunctions of the supervisory authority (Article 58(2) of the GDPR): The authority notes that its initial decision of 7 November 2024, which became final and enforceable, was duly notified to the company, as were subsequent reminders. Despite a first notification received on 13 February 2025 and a second rejected on 12 April 2025, the company never provided the required evidence of compliance. The authority considers this inaction a direct breach of the obligation to cooperate and submit to its corrective powers. This breach is qualified as an infringement under Article 83(6) of the GDPR.



Decision of the authority


Consequently, the authority imposed a fine of €900 on KAFFA KOFFEE ORGANISATION, S.L.


Furthermore, the authority ordered the company to prove, within one month from the finality of this decision, that it has implemented the measures imposed in the initial decision of 7 November 2024.



Lessons learned


This decision reminds that:



  • Failure to comply with an injunction issued by a supervisory authority constitutes a separate and punishable infringement in itself, regardless of the initial violation.

  • Deliberate disregard of the corrective powers of an authority, as provided in Article 58 of the GDPR, is a serious infringement that may lead to very high administrative fines, pursuant to Article 83(6) of the GDPR.

  • Supervisory authorities ensure the proper execution of their decisions and may initiate new sanction procedures in case of absence of proof of compliance within the deadlines.

  • The size and financial situation of a company, such as its status as a microenterprise and its low turnover, are criteria taken into account to modulate the amount of the fine, but do not exempt it from its obligation to comply with decisions.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire