Asociación Escuela Nacional de Equitación – €4,000 Fine (Spain, 2024)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Asociación Escuela Nacional de Equitación, a horse riding school in Spain, shared a customer's name in a public reply to negative reviews. This action violated privacy rules because they did not have the proper legal basis to disclose that information. The school was fined €4,000 and ordered to delete the customer's data.
What happened
The horse riding school shared a customer's name in replies to reviews on Google without proper legal grounds.
Who was affected
The customer whose name was mentioned in the school's public replies on Google.
What the authority found
The Spanish Data Protection Agency found that the school violated GDPR by not having a valid legal basis for sharing the customer's personal data.
Why this matters
This case highlights the importance of having a legal basis before sharing personal information online. Businesses should ensure they understand privacy laws to avoid similar penalties.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The controller, a horse riding school, has a profile on Google where customers can write reviews. Following some negative comments written by customers, the controller replied to them. Since the controller believed that these reviews were defaming its reputation, it referred to the possibility of suing the authors of the reviews in court, like it had already successfully done with the data subject. In doing so, the controller explicitly mentioned the name of the data subject. The data subject, having noticed that their name appeared in this replies, filed a complaint with the DPA. They argued that the judgement at hand was the result of a court proceeding initiated by another entity and that they had never sent the controller this judgement. First, the DPA held that the controller had shared the name of the data subject on its Google profile without the proper legal basis. Therefore, it found a violation of Article 6 GDPR. Secondly, the DPA noted that it is obvious that the controller has personal data of the data subject. Moreover, the controller has not proved that it had collected that data directly from the data subject. Therefore, the controller should have given the data subject the information set by Article 14 GDPR. Since it did not do so, the DPA found a violation of this provision. On these grounds, the DPA issued a fine of €4,000 and ordered the controller to delete the data subject’s data.
Related Enforcement Actions (0)
No other enforcement actions found for Asociación Escuela Nacional de Equitación in ES
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
8 July 2024
Authority
Agencia Española de Protección de Datos
Fine Amount
€4,000
GDPRhub ID
gdprhub-8246About this data
Cite as: Cookie Fines. Asociación Escuela Nacional de Equitación - Spain (2024). Retrieved from cookiefines.eu
Last updated: