OCI CINE, S.L. – €18,000 Fine (Spain, 2025)

€18,000Agencia Española de Protección de Datos2 June 2025Spain
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

OCI CINE, S.L. received a fine after a technical error allowed users to see each other's personal information when buying movie tickets. This is important because it shows that businesses must protect customer data and ensure their systems work correctly.

What happened

A system failure at OCI CINE allowed eight users to access personal data of other customers during ticket purchases.

Who was affected

Eight users of OCI CINE's app who inadvertently viewed personal information of other customers.

What the authority found

The Spanish data protection authority ruled that OCI CINE did not maintain accurate personal data and failed to implement necessary security measures.

Why this matters

This ruling emphasizes the need for companies to have robust data protection measures. Businesses should regularly check their systems to prevent similar data breaches.

GDPR Articles Cited

AI-verified

Art. 32(GDPR)
Art. 5(1)(d) GDPR
Art. 83(2)(a) GDPR
Art. 83(2)(b) GDPR
Art. 83(4)(a) GDPR
Art. 83(5)(a) GDPR
View original scraped data
Art. 5(1)(d) GDPR
Art. 32(GDPR)
Art. 83(2)(a) GDPR
Art. 83(2)(b) GDPR
Art. 83(4)(a) GDPR
Art. 83(5)(a) GDPR

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Article 71 LOPDGDD
Article 76(2)(b)
Article 85(3) Law 39/2015

Entities Involved

OCI CINE, S.L.
A.A.A.
Source verified 13 March 2026
articles corrected
national law identified
amount discrepancy
date discrepancy
Full Legal Summary
Detailed

On 5 June 2024, a data subject filed a complaint with the DPA against OCI CINE, S.L. (a cinema, the controller), regarding the automatic inclusion of another customer's personal data when purchasing movie tickets through the controller’s app.   Between 7 April 2024 and 6 August 2024, eight users of the controller's app (data subjects) experienced a failure in its systems that caused a coincidence of identifiers among customers. Data subjects were still linked to the standard user ID initially assigned during account registration on their first login on the controller's app, instead of receiving a personal user ID on their second login. Therefore, upon their next login, data subjects could view personal data of customers assigned to the initially standard user ID, such as name, surname, email address, telephone number, and Fidelity card number. The controller argued that it had measures in place to ensure compliance with data protection laws. Among those measures, the controller had requested and later accepted the recommendation of a consultancy company on the failure in its systems. Furthermore, the controller had used a toolAsesora Brecha, https://www.aepd.es/en/guides-and-tools/tools/asesora-brecha in order to determine whether it had the obligation to notify the DPA about the issue on its app. The tool exempted the controller from the notification. On 5 September 2024, the complaint was allowed to proceed. The DPA found a breach of the data accuracy principle (Article 5(1)(d) GDPR). The DPA held that the controller did not maintain accurate personal data of eight users and did not implement any technical or organizational measures to ensure accuracy or mitigate inaccurate factors. This was also a violation of Article 32 GDPR. The DPA fined the controller €30,000 in total; €4,000 for the violation of Article 5(1)(d) GDPR, and €26,000 for the violation of Article 32 GDPR. Pursuant to Law 39/2015, a Spanish law concerning administrative proceedings, the DPA

Details

Fine Date

2 June 2025

Authority

Agencia Española de Protección de Datos

Fine Amount

€18,000

GDPRhub ID

gdprhub-9458

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. OCI CINE, S.L. - Spain (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: