Owner of a Law Firm – €600 Fine (Spain, 2025)

€600Agencia Española de Protección de Datos3 April 2025Spain
reduced
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Spanish data protection authority fined the owner of a law firm for sending personal information in an email without proper security measures. This matters because it shows that businesses must protect personal data to avoid penalties. The fine was reduced after the owner admitted responsibility and paid quickly.

What happened

The owner of a law firm disclosed personal information in an external email without implementing sufficient security measures.

Who was affected

Clients of the law firm whose personal information was improperly shared in an email.

What the authority found

The authority ruled that the law firm failed to take adequate technical and organizational measures to protect personal data, violating GDPR's requirements.

Why this matters

This case highlights the importance of data security for businesses. It serves as a reminder that even small firms can face fines for not protecting personal information properly.

GDPR Articles Cited

AI-verified

Art. 5(1)(f) GDPR
View original scraped data
Art. 5(1) f) GDPR

Original data from scraper before AI verification against source document.

Source verified 17 March 2026
national law identified
Full Legal Summary
Detailed

The Spanish DPA imposed a fine on the owner of a law firm. The controller disclosed personal information in an external email because they did not implement sufficient technical and organizational measures. The original fine of EUR 1,000 was reduced to EUR 600 due to immediate payment and admission of responsibility by the controller.

Related Enforcement Actions (0)

No other enforcement actions found for Owner of a Law Firm in ES

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

3 April 2025

Authority

Agencia Española de Protección de Datos

Fine Amount

€600

Enforcement Tracker ID

ETid-2628

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Owner of a Law Firm - Spain (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: