KFC Restaurants Spain, S.L.U. – Court Ruling (Spain, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
KFC Restaurants Spain was found to have inadequate privacy information on its website, leading to a complaint from a user. The decision shows that businesses must provide clear and accessible privacy details to their customers.
What happened
A user complained that KFC's website did not provide easily accessible privacy information and required consent for promotional communications without clear links to the privacy policy.
Who was affected
Website users in the European Economic Area (EEA) who interacted with KFC's website.
What the authority found
The DPA ruled that KFC's privacy information was too generic and did not meet GDPR requirements for clarity and accessibility.
Why this matters
This ruling highlights the necessity for businesses to ensure their privacy policies are clear and easy to find. Companies should review their privacy practices to avoid similar complaints.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
In May 2021, a data subject lodged a complaint with the DPA against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website. The data subject claimed that the privacy information applicable to users in the EEA was not easily accessible, as the main privacy link led to a global policy. The data subject also alleged that users could not create an account without apparently accepting promotional communications, that the registration form did not correctly link to the privacy policy and that the controller had not appointed a data protection officer. The complaint further identified deficiencies in the privacy information, including insufficient details about the identity of the controller, recipients, international transfers and retention periods. During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business. The DPA found that the information provided on the website was excessively generic and did not comply with Article 13 GDPR. It imposed a €5,000 fine and ordered the controller to bring its website into compliance. The DPA also concluded that the controller’s processing activities required the appointment of a DPO under Article 37(1)(b) GDPR. It imposed a further €20,000 fine and ordered the controller to appoint a DPO. The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented corrective measures. The Court dismissed the appeal and upheld the total fine of €25,000. Regarding Article 13 GDPR, th
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (0)
No other cases found for KFC Restaurants Spain, S.L.U. in ES
This is the only recorded case for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. KFC Restaurants Spain, S.L.U. - Spain (2026). Retrieved from cookiefines.eu
Last updated: