All About Water SL – €3,000 Fine (Spain, 2025)

€3,000Agencia Española de Protección de Datos8 April 2025Spain
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The data subject purchased a product through a website, All About Water S.L. (controller). The data subject later made a complaint to the controller about the product via email. The initial complaint was closed and joined with a second complaint, submitted by another individual. The data subject received a thread of emails relating to the 3rd party’s complaint, revealing their name, surname and contact number. The third party also erroneously received an email thread revealing the name, surname, address and telephone number of the data subject. On 15th July 2022, the data subject filed a complaint with the AEPD. During the course of the investigation, it was revealed that the process for merging complaints is performed manually and the incident giving rise to the complaint occurred as a result of human error. The controller did not supply, as requested, details of technical and organisational measures taken to ensure the confidentiality of personal data that employees are given access to. The DPA rejected the controller’s claim that no infringement of the GDPR occurred as the incident was explicable due to simple human error. The DPA was critical of the lack of technical and organisational measures adopted to ensure the confidentiality of personal data being handled by the employees, noting that issues such as that which arose could have been avoided if suitable measures had have been in place. The DPA found that the controller had infringed Article 5(1)(f) GDPR in failing to process personal data in a manner which ensures its appropriate security. The DPA considered the infringement serious in nature as an irretrievable loss of control occurred over the personal data, and the taking of online orders is the core business of the controller. The DPA fined the controller €3000 and ordered it to adopt appropriate technical and organisational security measures within one month.

GDPR Articles Cited

Art. 5(1)(f) GDPR
Full Legal Summary

The data subject purchased a product through a website, All About Water S.L. (controller). The data subject later made a complaint to the controller about the product via email. The initial complaint was closed and joined with a second complaint, submitted by another individual. The data subject received a thread of emails relating to the 3rd party’s complaint, revealing their name, surname and contact number. The third party also erroneously received an email thread revealing the name, surname, address and telephone number of the data subject. On 15th July 2022, the data subject filed a complaint with the AEPD. During the course of the investigation, it was revealed that the process for merging complaints is performed manually and the incident giving rise to the complaint occurred as a result of human error. The controller did not supply, as requested, details of technical and organisational measures taken to ensure the confidentiality of personal data that employees are given access to. The DPA rejected the controller’s claim that no infringement of the GDPR occurred as the incident was explicable due to simple human error. The DPA was critical of the lack of technical and organisational measures adopted to ensure the confidentiality of personal data being handled by the employees, noting that issues such as that which arose could have been avoided if suitable measures had have been in place. The DPA found that the controller had infringed Article 5(1)(f) GDPR in failing to process personal data in a manner which ensures its appropriate security. The DPA considered the infringement serious in nature as an irretrievable loss of control occurred over the personal data, and the taking of online orders is the core business of the controller. The DPA fined the controller €3000 and ordered it to adopt appropriate technical and organisational security measures within one month.

Related Enforcement Actions (0)

No other enforcement actions found for All About Water SL in ES

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

8 April 2025

Authority

Agencia Española de Protección de Datos

Fine Amount

€3,000

GDPRhub ID

gdprhub-9132

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. All About Water SL - Spain (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: