{"id":18358,"date":"2025-06-16T08:00:52","date_gmt":"2025-06-16T08:00:52","guid":{"rendered":"https:\/\/letslaw.es\/?p=18358"},"modified":"2025-06-06T12:09:49","modified_gmt":"2025-06-06T12:09:49","slug":"seat-fined-improper-cookie-management","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/seat-fined-improper-cookie-management\/","title":{"rendered":"SEAT fined for improper cookie management"},"content":{"rendered":"<p>In today\u2019s digital environment, compliance with data protection regulations has become an unavoidable requirement for any company operating through online channels. The recent case of SEAT, which was sanctioned by the Spanish Data Protection Agency (AEPD) for the improper management of cookies on its website, clearly illustrates the risks organizations face when they fail to properly implement the legal requirements in this area.<\/p>\n<p>The sanction imposed on SEAT highlights the <strong>increasing scrutiny by regulators regarding how companies obtain and manage user consent for the use of tracking technologies<\/strong>. This situation serves as a warning not only to large corporations but also to small and medium-sized enterprises that have yet to fully adapt their websites to the General Data Protection Regulation (GDPR) and the Law on Information Society Services (LSSI).<\/p>\n<h2>What did SEAT do wrong?<\/h2>\n<p>The AEPD identified several deficiencies in SEAT\u2019s cookie management system. Specifically, it was found that:<\/p>\n<ul>\n<li><strong>Non-essential cookies were being installed without the user\u2019s prior consent<\/strong>, in clear violation of Article 22.2 of the LSSI.<\/li>\n<li>The initial cookie banner did not provide clear, accessible, and <strong>balanced information regarding the purposes of data processing<\/strong>, especially concerning personalization and behavioral advertising cookies.<\/li>\n<li>There was no real and easy option to reject all cookies with the same ease as accepting them, which contravenes the principles of transparency and user freedom of choice.<\/li>\n<li>Additionally, some links to the cookie policy or configuration center were not functioning correctly, hindering the effective exercise of the user\u2019s right to manage their browsing preferences.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>These practices were deemed by the AEPD to constitute a breach of the principle of lawful processing of personal data.<\/p>\n<h2>What should be changed to comply with the regulations?<\/h2>\n<p>To correct these deficiencies and avoid further sanctions, SEAT, and any company in a similar situation, should implement a series of technical and organizational measures aligned with current regulations:<\/p>\n<ul>\n<li><strong>Explicit and prior consent<\/strong>: cookies that are not technical or strictly necessary may not be installed unless the user has provided free, informed, and specific consent.<\/li>\n<li><strong>Equal ease of acceptance and rejection<\/strong>: the cookie banner must include clearly visible buttons or links that allow users to either accept or reject all cookies simply and symmetrically.<\/li>\n<li><strong>Complete and accessible information<\/strong>: the cookie policy must detail the types of cookies used, their duration, purpose, and any third parties with access to the data.<\/li>\n<li><strong>Functional preference manager<\/strong>: a cookie settings center should be enabled, allowing users to modify or withdraw their consent at any time.<\/li>\n<li><strong>Consent records<\/strong>: it is advisable to implement mechanisms to reliably document when and how consent was granted.<\/li>\n<\/ul>\n<h2>How to avoid sanctions?<\/h2>\n<p>The best way to avoid sanctions like the one imposed on SEAT is to adopt <strong>a proactive compliance strategy<\/strong> regarding cookies and data protection. The following recommendations are suggested:<\/p>\n<ol>\n<li>Conduct regular audits of all cookies used on the website.<\/li>\n<li>Update cookie notices and policies in accordance with technological or legislative changes.<\/li>\n<li>Train the technical team on the GDPR and LSSI requirements concerning the processing of personal data via cookies.<\/li>\n<li>Use certified Consent Management Platforms (CMPs) that ensure legal compliance.<\/li>\n<li>Consult with legal <a title=\"data protection experts\" href=\"https:\/\/letslaw.es\/en\/privacy-data-protection-lawyers\/\">data protection experts<\/a>, such as LETSLAW, especially during website development or redesign processes.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>In short, the sanction imposed on SEAT demonstrates that cookie management is not a minor detail in regulatory compliance, but a fundamental part of the digital responsibility of any company that interacts with users online.<\/p>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/18358#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>The case of SEAT, sanctioned by the AEPD for incorrect management of cookies on its website, is a clear example of the risks of not adapting the law.<\/p>\n","protected":false},"author":28,"featured_media":18360,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[243],"tags":[],"class_list":["post-18358","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/18358","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=18358"}],"version-history":[{"count":3,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/18358\/revisions"}],"predecessor-version":[{"id":18359,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/18358\/revisions\/18359"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/18360"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=18358"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=18358"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=18358"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}