The Spanish authority sanctions MÁS SOL ENERGÍA 15, S.L. for unsolicited commercial calls and failure to provide information
Facts and context
The Spanish Data Protection Authority (AEPD) has today published a sanction decision against MÁS SOL ENERGÍA 15, S.L. (including the imposition of a fine of €10,000) for breaches related to telemarketing and the information obligation.
The case originated from a complaint by an individual who received an unsolicited commercial call on 18 November 2024, while registered on the telephone marketing opt-out list.
Grounds for the decision
- Lack of legal basis for commercial prospecting (Article 6 of the GDPR and Article 66.1.b of the General Telecommunications Law): The authority found that the company could not demonstrate having obtained valid consent from the complainant to receive commercial calls. The evidence provided, such as a generic form and a technical recording without probative link to the data subject, was deemed insufficient to prove free, specific, informed and unambiguous consent. The AEPD emphasized that the burden of proof of consent lies with the controller, even when data are acquired from a third-party provider, and that merely accepting files from the latter without verification does not meet this requirement.
- Failure to comply with the information obligation (Article 14 of the GDPR): As the complainant's personal data were obtained through an external provider, the company was required to provide the information set out in Article 14 of the GDPR, including the source of the data. The authority noted that this information was not communicated to the complainant, neither within a reasonable time after obtaining the data nor at the first telephone contact, thus depriving them of the possibility to effectively exercise their rights.
Authority's decision
Consequently, the authority imposed a fine of €10,000 on MÁS SOL ENERGÍA 15, S.L., split into €5,000 for the violation of telecommunications legislation and €5,000 for the breach of Article 14 of the GDPR.
Lessons learned
This decision reminds that:
- The burden of proof of valid consent always lies with the controller, who must be able to actively demonstrate its validity.
- Acquiring databases from third-party providers does not exempt the controller from its obligation to verify the validity of the consent collected by that provider; it cannot simply accept files without its own due diligence.
- The mere provision of a technical recording (such as an IP address) and an unfilled generic form is insufficient to prove that a specific person has given unambiguous consent.
- When processing is based on data not collected directly from the data subject, the information obligation under Article 14 of the GDPR must be scrupulously respected, notably regarding the mention of the data source.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire