{"id":16563,"date":"2023-12-12T14:47:09","date_gmt":"2023-12-12T14:47:09","guid":{"rendered":"https:\/\/businessadapter.es\/endesas-sins-penalized-with-6-million\/"},"modified":"2024-12-11T10:44:38","modified_gmt":"2024-12-11T10:44:38","slug":"endesas-sins-penalized-with-6-million","status":"publish","type":"post","link":"https:\/\/businessadapter.es\/en\/endesas-sins-penalized-with-6-million\/","title":{"rendered":"Endesa&#8217;s sins penalized with $6 million"},"content":{"rendered":"\n<h1><span style=\"color: #800000;\"><strong>6 million fine for Endesa<\/strong><\/span><\/h1>\n<p>ENDESA is sanctioned by the Spanish Data Protection Agency<a href=\"https:\/\/www.aepd.es\/informes-y-resoluciones\/resoluciones\" target=\"_blank\" rel=\"noopener\">(AEPD<\/a>) with a millionaire fine of more than 6 MILLION EUROS.<\/p>\n<p style=\"text-align: justify;\">The 215-page resolution published by the AEPD bases the sanction on a <a href=\"https:\/\/businessadapter.es\/brechas-violaciones-de-seguridad\/\">violation of security<\/a> due to improper access to personal data processed by ENDESA and the integrity of such data, as certain information was modified to make fraudulent registrations.<\/p>\n<h2 style=\"text-align: left;\"><span style=\"color: #800000;\"><strong>ENDESA&#8217;s allegations<\/strong><\/span><\/h2>\n<p>We highlight ENDESA&#8217;s interpretation of the application of sanctions for violation of art. 5.1 and 32 of the <a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\" target=\"_blank\" rel=\"noopener\">GDPR <\/a>separately, since they claim that this should not be the case, since<a href=\"https:\/\/www.endesa.com\/es\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\" wp-image-13635 alignright\" src=\"https:\/\/businessadapter.es\/wp-content\/uploads\/2023\/12\/endesa-300x152.jpg\" alt=\"\" width=\"523\" height=\"265\" srcset=\"https:\/\/businessadapter.es\/wp-content\/uploads\/2023\/12\/endesa-300x152.jpg 300w, https:\/\/businessadapter.es\/wp-content\/uploads\/2023\/12\/endesa.jpg 660w\" sizes=\"(max-width: 523px) 100vw, 523px\" \/><\/a> art. 5.1 relating to confidentiality and data integrity and the security measures of art. 32 are equivalent, and that sanctioning their non-compliance separately means sanctioning the same thing twice and would be contrary to the principle of <em>non bis in idem<\/em>.<\/p>\n<p>However, for the AEPD they are two different articles and should be sanctioned separately.<\/p>\n<h2><span style=\"color: #800000;\"><strong>Details of the sanction to ENDESA<\/strong><\/span><\/h2>\n<p>We analyze below the reasons for the different penalties and the amounts imposed for each one:<\/p>\n<h4><strong>Infringement of Article 5.1.f) of the GDPR, with a fine of 2,500,000 \u20ac.<\/strong><\/h4>\n<p>Failure to implement appropriate measures to ensure the integrity and confidentiality of the personal data processed.<\/p>\n<h4><strong>Infringement of Article 32 of the GDPR with a fine of 1.500.000 \u20ac.<\/strong><\/h4>\n<p>Appropriate technical and organizational measures to ensure a level of security appropriate to the risk.<\/p>\n<h4><strong>Infringement of Article 33 of the GDPR, with a fine of 800,000 \u20ac.<\/strong><\/h4>\n<p>Failure to notify a breach of personal data security to the supervisory authority<\/p>\n<h4><strong>Infringement of Article 34 of the GDPR, with a fine of 800,000 \u20ac.<\/strong><\/h4>\n<p>Failure to communicate the personal data security breach to the affected individuals<\/p>\n<h4><strong>Infringement of Article 44 of the GDPR, with a fine of 500,000 \u20ac.<\/strong><\/h4>\n<p>Failure to comply with the obligations established in the GDPR for <a href=\"https:\/\/businessadapter.es\/en\/data-processed-by-u-s-suppliers\/\">international<\/a> data <a href=\"https:\/\/businessadapter.es\/en\/data-processed-by-u-s-suppliers\/\">transfers<\/a>.<\/p>\n<h4><strong>Total<\/strong>: \u20ac6,100,000<\/h4>\n<h2><span style=\"color: #800000;\"><strong>Business Adapter\u00ae at your service&nbsp;<\/strong><\/span><\/h2>\n<p>If you need advice to avoid penalties, contact us by email: <a href=\"mailto:info@businessadapter.es,%C2%A0\">info@businessadapter.es,&nbsp;<\/a> you can also call <a href=\"http:\/\/tel.961318804\">96 131 88 04<\/a>, or leave your message in this form:<\/p>\n<p>&nbsp;<\/p>\n<p><strong>[su_button url=&#8221;https:\/\/businessadapter.es\/contacto&#8221; target=&#8221;blank&#8221; background=&#8221;#f6f903&#8243; color=&#8221;#181818&#8243; size=&#8221;7&#8243; center=&#8221;yes&#8221; icon_color=&#8221;#000000&#8243;]Contact us, we will be pleased to help you.[\/su_button]<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>6 million fine for Endesa ENDESA is sanctioned by the Spanish Data Protection Agency(AEPD) with a millionaire fine of more [&hellip;]<\/p>\n","protected":false},"author":1373,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[75],"tags":[82,86,90,96,83],"class_list":["post-16563","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-compliance-with-lopd-and-rgpd","tag-data-protection-penalties","tag-international-data-transfer","tag-security-breach","tag-security-measures"],"_links":{"self":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16563","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/users\/1373"}],"replies":[{"embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/comments?post=16563"}],"version-history":[{"count":1,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16563\/revisions"}],"predecessor-version":[{"id":16564,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16563\/revisions\/16564"}],"wp:attachment":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/media?parent=16563"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/categories?post=16563"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/tags?post=16563"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}