The Spanish authority sanctions NH HOTEL GROUP S.A. for using cookies without prior consent with a fine of 10,000 euros
The Spanish authority sanctions a hotel group for placing non-essential cookies before any consent, and for the ineffectiveness of its management panel which did not respect the user's refusal.
Facts and context
The Spanish Data Protection Authority (AEPD) has today published a sanction decision against NH HOTEL GROUP S.A. (including the imposition of a fine of €10,000) for breaches related to the use of cookies.
The case originated from an ex officio inspection conducted by the authority on the company's website, revealing the installation of cookies before any user action.
Reasons for the decision
- Obligation to obtain consent before placing non-essential cookies (Article 22, paragraph 2, of Law 34/2002 on Information Society Services and Electronic Commerce): The authority found, during two separate inspections, that many non-technical cookies (performance, functionality, Google analytics, as well as other first-party and third-party cookies without identified purpose) were installed on the user's device upon arrival on the site, before the user could make any choice. Furthermore, the consent management mechanism was defective: although the options for non-necessary cookies were disabled by default in the configuration panel, clicking the "Yes, I accept" button without activating them still led to their installation, thus ignoring the user's implicit refusal. The authority also dismissed the company's argument that Google Analytics cookies were exempt from consent because they were linked to the reCAPTCHA function, recalling that Google's own terms of service require clear user information and obtaining their agreement.
Authority's decision
Consequently, the authority imposed a fine of €10,000 on NH HOTEL GROUP S.A.
However, the company benefited from a 20% reduction by making a voluntary payment of €8,000, which led to the closure of the procedure and waiver of any appeal.
Lessons learned
This decision reminds that:
- Compliance of a consent management panel is not limited to its appearance (sliders disabled by default), but requires effective technical implementation that ensures the user's refusal is respected.
- Invoking a consent exemption for cookies, such as those related to third-party services like Google reCAPTCHA, must be rigorously justified and can be dismissed by the authority if their main purpose is not deemed essential to the service.
- A compliance audit of cookies must include thorough technical checks to ensure that no non-essential cookie is placed before consent is obtained and that choices expressed via the management panel are technically honored.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire