AFIANZA ASESORES, S.L. – €145,000 Fine (Spain, 2024)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
AFIANZA ASESORES, S.L. was fined EUR 145,000 after a USB stick containing sensitive personal data was stolen because it was not encrypted. This case is significant as it emphasizes the need for companies to protect personal data properly. Businesses should implement strong security measures to avoid costly penalties.
What happened
A USB stick with sensitive personal data was stolen from AFIANZA ASESORES, S.L. without encryption.
Who was affected
Individuals whose personal data was stored on the stolen USB stick were affected.
What the authority found
The Spanish data protection authority ruled that the company acted negligently by not encrypting the USB, violating GDPR's security requirements.
Why this matters
This case underscores the importance of data security measures, such as encryption. Companies must take appropriate steps to protect personal data to avoid significant fines.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
AFIANZA ASESORES, S.L. is a consultancy company engaged in, among other work, the provision of legal advice. A USB stick with a large amount of personal data, including data pertaining to a criminal proceeding, was stolen. The USB was not encrypted. The controller conducted an internal investigation. It informed the Spanish DPA (AEPD) of the incident 13 days after its occurrence. On 2 July 2021, the AEPD ordered the controller to communicate the breach to data subjects. On 24 June 2022, the AEPD initiated sanctioning proceedings against the controller and proposed a sanction of €160,000. The AEPD considered that the controller had suffered a breach resulting in the unauthorized disclosure of personal data. The AEPD noted that it considered the controller’s storage of personal data on a removable device without encryption negligent, resulting in an aggravating factor for the fine. The controller argued that there was no evidence that a third party had ever accessed the information contained in the USB. Instead, the infringing ‘disclosure’ or ‘breach’ was entirely hypothetical. Thus, the controller argued, it could not be proved that any third party ever improperly accessed the information contained in the USB and no breach of confidentiality could be demonstrated. The controller also argued that it protected its data diligently and had adequate security measures in place. For instance, all personnel with access to personal data were instructed of their obligations and responsibilities. It also conducted IT audits to verify appropriate measures and security standards in place. The controller emphasised that Article 32 GDPR does not regulate a closed list of security measures – instead, it requires the controller to apply appropriate measures. It thus challenged the focus of the sanctioning proceedings on the absence of encryption on the USB because it was not an obligatory security measure and this did not take account of the controller’s other security measures.
Related Enforcement Actions (0)
No other enforcement actions found for AFIANZA ASESORES, S.L. in ES
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
16 March 2024
Authority
Agencia Española de Protección de Datos
Fine Amount
€145,000
GDPRhub ID
gdprhub-8227About this data
Cite as: Cookie Fines. AFIANZA ASESORES, S.L. - Spain (2024). Retrieved from cookiefines.eu
Last updated: