The Royal Clinic by Doctor Marin – €2,400 Fine (Spain, 2020)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Royal Clinic by Doctor Marin was fined for not having a clear cookie policy on its website. This matters because it shows the importance of being transparent about how user data is collected. Small business owners should ensure they inform visitors about cookies to avoid penalties.
What happened
The clinic's website lacked a cookie policy, violating transparency requirements.
Who was affected
Website visitors who accessed The Royal Clinic's site without being informed about cookie usage.
What the authority found
The Spanish data protection authority found that the clinic failed to provide clear information about cookies, violating GDPR's transparency rules.
Why this matters
This case highlights the need for clear cookie policies on websites. Businesses should review their cookie disclosures to comply with data protection laws.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
A data subject sent a complaint to the AEPD against a plastic surgery clinic because he had received unwanted publicity on his phone number. The data subject tried to find in the website of the clinic information about who to address his complaint to but he couldn't find it due to lack of a privacy policy in the website. The AEPD sent a request for information to the clinic and they replied that they provide adequate information to their clients upon collection of their data when the clients go for the first time to the clinic. The clinic argued that in the data sheet where the personal data is collected, the data subjects are informed that their data will be used also for sending them publicity (such as discounts, offers, etc.). The AEPD checked the website of the clinic (three months after the answer from the clinic was received) and they found that both the privacy policy and the cookies policy were missing. Does the lack of a privacy and cookie policy on a website infringe Article 13 GDPR and Article 22(2) LSSI? The AEPD decided to impose a fine to the clinic: € 2000 for the lack of the privacy policy and € 2000 for the lack of cookies policy on the website. The absence of a privacy policy infringed Article 13 GDPR and the absence of a cookie policy infringed Article 22(2) of the Spanish law on the Information Society and Electronic Commerce Services (LSSI). However, the fine got reduced due to: 1. prompt payment; 2. acknowledgement of responsibility (that includes the commitment of the company not to pursue any further appeal against the decision).
Violations (2)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
The cookie banner or cookie policy provides vague, incomplete, or unclear information about what cookies are used and why.
Art. 12, 13 GDPR
Related Enforcement Actions (0)
No other enforcement actions found for The Royal Clinic by Doctor Marin in ES
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
11 November 2020
Authority
Agencia Española de Protección de Datos
Fine Amount
€2,400
GDPRhub ID
gdprhub-2960About this data
Cite as: Cookie Fines. The Royal Clinic by Doctor Marin - Spain (2020). Retrieved from cookiefines.eu
Last updated: