Thomas International Systems, S.A. – €40,000 Fine (Spain, 2023)

€40,000Agencia Española de Protección de Datos16 January 2023Spain
reduced
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Thomas International Systems, S.A. was fined for processing sensitive personal data like ethnicity and disability without consent. This matters because it highlights the importance of handling sensitive data carefully and ensuring consent is obtained. The Spanish authority reduced the fine from EUR 50,000 to EUR 40,000 due to voluntary payment.

What happened

Thomas International processed sensitive personal data without the necessary consent.

Who was affected

Participants of psychological tests conducted by Thomas International on behalf of Agroxarxa.

What the authority found

The Spanish DPA found that Thomas International violated GDPR by processing sensitive data without a valid legal basis.

Why this matters

This case underscores the need for companies to have a valid legal basis, such as consent, when processing sensitive data. It serves as a reminder for businesses conducting tests or surveys to ensure they comply with data protection laws.

GDPR Articles Cited

Art. 9 GDPR
Full Legal Summary
Detailed

The Spanish DPA has imposed a fine on Thomas International Systems, S.A.. Thomas International performs psychological tests on behalf of other companies. Thomas International had conducted such a test on behalf of the company Agroxarxa, S.L.. A participant of such a test had filed a complaint against the controller because they had to provide sensitive personal data (ethnicity, disability). However, Agroxarxa had indicated that the test did not request and process such sensitive data. During its investigation, the DPA found that Thomas International had nevertheless processed sensitive personal data without the consent of the data subject or the processing being necessary for the fulfillment of the contractually agreed purpose between Agroxarxa and Thomas International. The DPA considered this to be a violation of Art. 9 GDPR. The original fine of EUR 50,000 was reduced to EUR 40,000 due to voluntary payment.

Related Enforcement Actions (0)

No other enforcement actions found for Thomas International Systems, S.A. in ES

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

16 January 2023

Authority

Agencia Española de Protección de Datos

Fine Amount

€40,000

Enforcement Tracker ID

ETid-1576

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Thomas International Systems, S.A. - Spain (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: