Skip to main content

Precedent corpus / AEPD (Spain)

ENDESA ENERGIA, S.A.

AEPD (Spain) case PS-00002-2023, decided . EUR 6.1M.

ContextAppeal status not checked

We have not checked whether this decision was appealed. This is not a statement that no appeal exists.

No ConsentMark grade rests on this decision. It is published here because it is relevant enforcement, not because it bears on what a browser does before consent.

What the regulator decided

Endesa failed to implement appropriate security measures to protect customer data, allowing access credentials to its commercial platform to be offered for sale on third-party advertising channels and exposing the personal data of up to 4.8 million electricity and 1.2 million gas customers; the AEPD found composite breaches of Articles 5(1)(f), 32, 33, 34 and 44 GDPR (security, breach notification, notification to data subjects and international transfers).

Primary source

Regulator-owned URL. Quote this in legal briefs and academic citations.

https://www.aepd.es/documento/ps-00002-2023.pdf

ConsentMark interpretation

Operator-readable note on how this case shapes the ConsentMark scanner narrative. Not a legal opinion; cites the primary source.

Composite fine: EUR 2.5M (Art 5(1)(f)) + EUR 1.5M (Art 32) + EUR 800k (Art 33) + EUR 800k (Art 34) + EUR 500k (Art 44). Cite as the AEPD's flagship security-of-processing precedent - the underlying incident was credential resale, not external system compromise, so the finding turns on the absence of detection and revocation rather than the attack vector.

Verification trail

Checked against the primary source on 27th May 2026. Next review 27th November 2026.

Cite this case
BibTeX
@misc{consentmark-precedent-aepd-ps-00002-2023,
  author       = {{ConsentMark}},
  year         = {2023},
  title        = {AEPD (Spain) PS-00002-2023 - ENDESA ENERGIA, S.A.},
  howpublished = {\url{https://www.consentmark.com/precedent/aepd-ps-00002-2023}},
  note         = {ConsentMark methodology v7.8.1}
}
APA
ConsentMark. (2023, October 25). AEPD (Spain) PS-00002-2023 - ENDESA ENERGIA, S.A.. Methodology v7.8.1. https://www.consentmark.com/precedent/aepd-ps-00002-2023
Markdown
[AEPD (Spain) PS-00002-2023 - ENDESA ENERGIA, S.A. - ConsentMark](https://www.consentmark.com/precedent/aepd-ps-00002-2023)
Plain text
AEPD (Spain) PS-00002-2023 - ENDESA ENERGIA, S.A. - ConsentMark, 2023-10-25, methodology v7.8.1, https://www.consentmark.com/precedent/aepd-ps-00002-2023