Spanish Data Protection Authority (AEPD) · 28 November 2025
SPRINTER MEGACENTROS DEL DEPORTE, S.L.
Insufficient technical and organisational measures to ensure information security
Fine€1,560,000Fine issued
- Regulator
- Spanish Data Protection Authority (AEPD)
- Decided
- 28 November 2025
- Country
- Spain
- Sector
- Industry and Commerce
- Regulator’s reference
- Not recorded
- Fino case number
- 2025/ES/010
What happened
The DPA fined a sports retail company €2,600,000 after personal data of more than 6 million people was published in the dark web in course of a ransomware attack. The DPA found that the company lacked adequate security measures under Article 5(1)(f) GDPR.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 34Communication of a personal data breach to the data subjectRead →
- Data breach
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2025/ES/010.