AEPD (Spain) · 30 September 2024
Posada El Azufral
About: Data principles, Unlawful processing
Fine€1,200Violation found
- Regulator
- AEPD (Spain)
- Decided
- 30 September 2024
- Country
- Spain
- Sector
- Not given
- Regulator’s reference
- EXP202316537
- Fino case number
- 2024/ES/155
What happened
The DPA fined a hotel €1,200 for breaching Article 5(1)(c) GDPR by retaining copies of travellers' IDs. The hotel was ordered to implement appropriate technical and organisational measures, i.e. to remove the requirement to provide an ID and to delete IDs already on file.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(c)Read →
- Art. 6Lawfulness of processing6(1)(c)Read →
- Art. 58Powers58(2)(d)Read →
- Art. 83General conditions for imposing administrative fines83(5)(a)Read →
- Data principles
- Unlawful processing
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2024/ES/155.