Marbella Resorts S.L. – €4,200 Fine (Spain, 2021)
Marbella Resorts S.L. was fined for mishandling a guest's personal data, which ended up being shared inappropriately. This incident emphasizes the need for businesses to handle customer information carefully. Companies must train their staff to protect personal data properly.
What happened
Marbella Resorts S.L. improperly shared a guest's personal data by allowing an unauthorized concierge to copy it.
Who was affected
A hotel guest whose personal data was mishandled by Marbella Resorts S.L.
What the authority found
The Spanish Data Protection Authority found that Marbella Resorts violated GDPR rules by not adequately protecting customer data.
Why this matters
This ruling serves as a reminder for businesses to train employees on data protection and ensure that only authorized personnel handle personal information.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The Spanish DPA (AEPD) has imposed a fine of EUR 7,000 on Marbella Resorts S.L.. In the case at hand, the data subject had booked a room in the hotel complex of the controller. On the day of the data subject's arrival, a concierge made copies of the data subject's data. However, the concierge was not authorized to do so. He was solely authorized to verify the reservation and then to give the guests the keys to their room. After providing the controller with his personal data, the data subject discovered that his personal data had been published on a page with online content for adults. In this regard, the DPA found a lack of diligence on the part of the controller in managing the personal data of its customers and thus a violation of Article 28 (3) GDPR. The fine is composed proportionally of EUR 2,000 for a breach of Art. 22(2) LSSI and 5,000 EIR for a breach of Art. 28(3) GDPR. However, the original fine of EUR 7,000 was reduced to EUR 4,200 due to the immediate payment and admission of guilt.
Violations (1)
The cookie banner uses misleading language to trick or pressure users into accepting cookies (dark patterns).
Art. 7 GDPR
Related Enforcement Actions (0)
No other enforcement actions found for Marbella Resorts S.L. in ES
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
6 July 2021
Authority
Agencia Española de Protección de Datos
Fine Amount
€4,200
Enforcement Tracker ID
ETid-762
About this data
Cite as: Cookie Fines. Marbella Resorts S.L. - Spain (2021). Retrieved from cookiefines.eu
Last updated: