{"id":14330,"date":"2023-08-21T07:00:15","date_gmt":"2023-08-21T07:00:15","guid":{"rendered":"https:\/\/letslaw.es\/?p=14330"},"modified":"2023-12-04T16:35:41","modified_gmt":"2023-12-04T16:35:41","slug":"70-000-euros-fine-for-pelayo-insurance-company-for-the-non-consensual-transfer-of-personal-data","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/70-000-euros-fine-for-pelayo-insurance-company-for-the-non-consensual-transfer-of-personal-data\/","title":{"rendered":"70.000 euros fine for Pelayo Insurance company for the non-consensual transfer of personal data"},"content":{"rendered":"<p>The 70.000 euros fine for Pelayo Insurance Company is a consecuence for the non-consensual transfer of personal data. It has been fined by The Spanish Data Protection Agency (AEPD) as the tranfer of personal data was to a third party without the client&#8217;s consent.<\/p>\n<p>This act by Pelayo Mutua de Seguros y Reaseguros constitutes<strong> an infringement regulated by two articles<\/strong> of Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals regarding the processing of personal data and on the free movement of such data (GDPR).<\/p>\n<p>More specifically, it is based on <strong>articles 5.1.f)<\/strong> of the mentioned legislation, which states that the processing of data shall be carried out in a way that ensures security and protection, through integrity and confidentiality. For its part, and in relation to the precept, Article 32 indicates the security of the processing.<\/p>\n<h2>Lack of consent in the transfer of personal data<\/h2>\n<p>The claim against the insurer arose from a complaint filed by the client on 22 September 2021. In the complaint, she alleged that <strong>the insurer had transferred a large amount of her personal data<\/strong>, such as name, surname, ID card number, address, telephone number, information about the policy she had taken out, etc., to a third party without any consent.<\/p>\n<p>This third party, the recipient of the personal data, was a person with whom the customer had signed an earnest money contract for the subsequent sale and purchase of her car.<\/p>\n<p>In this context, she discovered that her personal data had been transferred when the car buyer sent her a copy of a document which contained her personal information and the insurance policy that she had taken out with Pelayo.<\/p>\n<p>At the time the customer filed the complaint, the insurer initially justified that the transfer had been carried out in a legitimate manner since the third party was already aware of the data due to the contractual relationship related to the sale and purchase it had been maintaining with the injured party.<\/p>\n<h2>Infringement of the GDPR and breach of security measures<\/h2>\n<p>The AEPD has stated that the insurer has committed a breach of the principle of integrity and confidentiality regulated in article 5.1.f) of the GDPR.<\/p>\n<p>According to this, personal data must be processed in a manner that ensures adequate security, including unauthorized processing by providing information to a third party without the data subject&#8217;s approval. This, as the AEPD pointed out, is <strong>due to a lack of diligence<\/strong> in complying with the principle of confidentiality.<\/p>\n<p>In addition, there was a breach of security measures, thus violating another precept of the regulations in force. It was found that Pelayo, as the responsible party, did not deploy the measures that should have been adopted in this type of situation <strong>to guarantee and ensure the security of the data<\/strong> by inserting technical and organizational security measures that guarantee a level of security proportional to the risk in order to comply with the provisions of article 32 RGPD.<\/p>\n<h2>Consequences of transfering personal data without previous consent<\/h2>\n<p>In view of this situation, the AEPD imposed a fine of <strong>50,000 euros<\/strong> for failing to comply with art. 5.1.f) and another of 20,000 euros for violating the provisions of article 32.<\/p>\n<p>However, despite the breach of security measures, the entity was able to benefit from reductions based on voluntary payment and acknowledgement of responsibility, thus deducting 20% of the amounts.<\/p>\n<p>Consequently, and with the application of both reductions, a total penalty of 42,000 euros has been imposed. Nevertheless, the judgement is not final, and the insurer has the possibility of appealing before the Litigation Chamber of the National High Court.<\/p>\n<p>At Letslaw our team have a wide experience on <a title=\"Digital Lawyers - Letslaw\" href=\"https:\/\/letslaw.es\/en\/digital-lawyers\/\">Digital Law<\/a> and <a title=\"Data Protection Lawyers - Letslaw\" href=\"https:\/\/letslaw.es\/en\/privacy-data-protection-lawyers\/\">Data Protection<\/a>, among other services. Do not hesitate to contact us.<\/p>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/14330#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>The Spanish Data Protection Agency (AEPD) has fined Pelayo Mutua de Seguros y Reaseguros a Prima Fija with a fine of 70,000 euros for the transfer of a client&#8217;s personal data to a third part without her consent.<\/p>\n","protected":false},"author":2,"featured_media":14326,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[243,258],"tags":[],"class_list":["post-14330","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection","category-digital-law"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/14330","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=14330"}],"version-history":[{"count":4,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/14330\/revisions"}],"predecessor-version":[{"id":14873,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/14330\/revisions\/14873"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/14326"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=14330"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=14330"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=14330"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}