The Spanish authority sanctions RETSINNAL GROUP for unlawful processing of data in a creditworthiness file
Facts and context
The Spanish data protection authority (AEPD) has today published a sanction decision against RETSINNAL GROUP, S.L.U. (including the imposition of a fine of €16,000) for breaches related to the unlawful registration of data in a creditworthiness file.
The case originates from a complaint filed on 15 September 2024, concerning the registration of the complainant's data in a credit information system for a disputed debt.
Grounds for the decision
- Obligation of lawfulness of processing (Article 6(1) of the GDPR): The authority found that the company had communicated the complainant's personal data to a credit information system (ASNEF) for a debt of €2,040. However, this debt was disputed, notably through a criminal complaint and an arbitration procedure. The authority recalls that, to be lawful, registration in such a file requires, under Article 20 of the Spanish Organic Law 3/2018, that the debt be certain, due, and payable, which was not the case here. The communication of data, which constitutes processing in itself, therefore lacked a legal basis. The company's argument that the registration was not effective or consulted by third parties was dismissed, the infringement being constituted as soon as the data were unlawfully communicated.
Decision of the authority
Consequently, the authority imposed a fine of €16,000 on RETSINNAL GROUP, S.L.U.
Lessons learned
This decision reminds that:
- The mere communication of data to a third party, such as a creditworthiness file, constitutes data processing subject to the GDPR, regardless of the validation, publication, or subsequent consultation of this data.
- The registration of a debt in a creditworthiness file is lawful only if the claim is certain, due, and payable; a debt subject to administrative or judicial dispute does not meet these conditions.
- Corrective measures taken after the finding of unlawful processing, such as debt cancellation or data removal, may constitute a mitigating circumstance but do not erase liability for the initial infringement.
- It is the responsibility of the data controller to verify and document that all legal conditions are met before communicating data to a credit information system.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire