All About Water SL – €3,000 Fine (Spain, 2025)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
All About Water SL mistakenly shared a customer's personal information with a third party due to a human error in handling complaints. This breach of privacy occurred when email threads were merged incorrectly, revealing sensitive information. The case serves as a reminder for businesses to implement better security measures to protect customer data.
What happened
All About Water SL revealed a customer's personal information to a third party by merging complaint emails incorrectly.
Who was affected
The customer whose personal information was accidentally shared with another individual.
What the authority found
The authority found that All About Water SL violated Article 5(1)(f) GDPR by failing to ensure appropriate security for personal data.
Why this matters
This ruling stresses the importance of having strong technical and organizational measures in place to protect personal data. Companies should take steps to prevent human errors that can lead to data breaches.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The data subject purchased a product through a website, All About Water S.L. (controller). The data subject later made a complaint to the controller about the product via email. The initial complaint was closed and joined with a second complaint, submitted by another individual. The data subject received a thread of emails relating to the 3rd party’s complaint, revealing their name, surname and contact number. The third party also erroneously received an email thread revealing the name, surname, address and telephone number of the data subject. On 15th July 2022, the data subject filed a complaint with the AEPD. During the course of the investigation, it was revealed that the process for merging complaints is performed manually and the incident giving rise to the complaint occurred as a result of human error. The controller did not supply, as requested, details of technical and organisational measures taken to ensure the confidentiality of personal data that employees are given access to. The DPA rejected the controller’s claim that no infringement of the GDPR occurred as the incident was explicable due to simple human error. The DPA was critical of the lack of technical and organisational measures adopted to ensure the confidentiality of personal data being handled by the employees, noting that issues such as that which arose could have been avoided if suitable measures had have been in place. The DPA found that the controller had infringed Article 5(1)(f) GDPR in failing to process personal data in a manner which ensures its appropriate security. The DPA considered the infringement serious in nature as an irretrievable loss of control occurred over the personal data, and the taking of online orders is the core business of the controller. The DPA fined the controller €3000 and ordered it to adopt appropriate technical and organisational security measures within one month.
Related Enforcement Actions (0)
No other enforcement actions found for All About Water SL in ES
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
8 April 2025
Authority
Agencia Española de Protección de Datos
Fine Amount
€3,000
GDPRhub ID
gdprhub-9132About this data
Cite as: Cookie Fines. All About Water SL - Spain (2025). Retrieved from cookiefines.eu
Last updated: