Norconsulting – €15,000 Fine (Spain, 2023)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Spanish Data Protection Authority fined Norconsulting EUR 15,000 for not properly handling a person's request to access and delete their data. The company failed to comply with GDPR rules about data access and erasure. This case highlights the importance of respecting individuals' rights to control their personal information.
What happened
Norconsulting did not fulfill a person's request to access and delete their personal data as required by GDPR.
Who was affected
A person in Germany who received targeted job offer emails from Norconsulting.
What the authority found
The Spanish DPA found that Norconsulting failed to properly handle the person's requests for data access and erasure, violating GDPR rules.
Why this matters
This case emphasizes that companies must take requests for data access and deletion seriously under GDPR. Businesses should ensure they have clear processes for handling such requests to avoid fines.
GDPR Articles Cited
On 15 January 2020, Norconsulting (the controller), a human resources company established in Spain with contractual relations with various ad platform such as Linkedin, Infojobs or Xing AAA , sent an email to A.A.A., a data subject established in Germany (the data subject). The purpose of this email was to advertise targeted job offers to the data subject. On the same day, the data subject wrote back to the controller and requested: (i) access to the information under (Article 15(1)), (ii) deletion of the data (Article 17); (iii) communication to the recipients of these data (Article 19); and (iv) deletion of these data from the sites where they have been published (Article 17(2)). On 4 February 2020, the controller responded to the data subject, explaining that it had obtained the data subject’s contact through ad platforms to which the data subject was or had been, registered. The controller stated that it would delete the data subject’s email from its files. The data subject contacted the controller by email on 4 February, 15 March and 31 March 2020, stating that the response was not valid under the GDPR. On 31 March 2020, the data subject filed a complaint to the German DPA of Berlin on the matter. In accordance with Article 56(1) GDPR and in application of the procedural rules applicable to cross-border cases, the Berlin DPA transferred the case to the Spanish DPA, as lead supervisory authority. In the course of the proceedings, the controller claimed that it had obtained the data subject’s email address from contractual partners to which the data subject had agreed to share its data. The controller also stated that it deleted the data subject’s email address after their request. The Spanish DPA underlined that the focus of the legal proceedings was the exercise of the right of access and the right of erasure of the data subject, rather than the lawfulness of the processing carried out by the controller. Right of access The Spanish DPA found that the contr
Related Enforcement Actions (0)
No other enforcement actions found for Norconsulting in ES
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
28 February 2023
Authority
Agencia Española de Protección de Datos
Fine Amount
€15,000
GDPRhub ID
gdprhub-5752About this data
Cite as: Cookie Fines. Norconsulting - Spain (2023). Retrieved from cookiefines.eu
Last updated: