On 25th June 2022, a Spanish user (A.A.A.) filed a complaint with the Spanish Data Protection Agency (AEPD) against Vinted UAB, the Lithuanian-registered company operating the popular second-hand clothing marketplace platform. The complainant alleged that Vinted had violated three separate GDPR provisions by:
The Background Dispute: The complainant's account had been blocked by Vinted for allegedly violating the platform's terms and conditions. On 16th May 2022, he sent an email to Vinted's Data Protection Officer (DPO) exercising his rights of access and rectification. The complainant maintained that his account had been wrongly associated with rule violations committed by other accounts operated by third parties with whom he had no connection.
Vinted's Initial Response: The following day (17th May 2022), Vinted's DPO replied, but the response appeared to confuse the complainant's request. Vinted stated that they were denying a "right of erasure" (deletion) request, explaining that because the account was blocked for terms violations, they had a legitimate interest in retaining and processing the data. The company appeared to have misunderstood the request entirely—the complainant had not asked for deletion; he had asked for access to his data and correction of inaccurate information.
The Complainant's Clarification: The user responded to Vinted, clarifying that he was not requesting deletion (Article 17 GDPR) but rather:
He specifically challenged Vinted's assertion that violations attributed to his account were actually committed by third parties using separate accounts, arguing this constituted inaccurate data processing.
Cross-Border Enforcement Mechanism: Because Vinted UAB is established in Lithuania (its main or only establishment), this became a cross-border GDPR enforcement case. Under Articles 56 and 60 GDPR, when a company's main establishment is in one EU member state but processes data affecting residents of other member states, a "one-stop-shop" mechanism applies:
On 4th August 2022, the AEPD provisionally archived the Spanish proceedings and transferred the case to Lithuania through the Internal Market Information System (IMI)—the EU's cross-border administrative cooperation platform. The Lithuanian authority accepted the case as lead supervisory authority.
The Lithuanian Investigation: The Lithuanian data protection authority conducted a full investigation and reached the following conclusions:
1. Articles 15 and 16 GDPR (Access and Rectification): VIOLATIONS CONFIRMED
The Lithuanian authority upheld the complaint regarding Vinted's failure to properly respond to the access and rectification requests. They found that Vinted had not adequately addressed the complainant's legitimate rights exercise.
2. Article 5.1(d) GDPR (Data Accuracy Principle): INSUFFICIENT EVIDENCE
The Lithuanian authority could not determine whether Vinted had violated the data accuracy principle. Here's why:
On 2nd July 2022—after the complaint was filed but during the investigation—Vinted deleted most of the complainant's personal data. This created an evidentiary problem: without access to the original data that allegedly incorrectly linked the complainant to third-party violations, the Lithuanian authority could not objectively verify whether the data had been inaccurate.
The Lithuanian authority explained their reasoning under domestic administrative law principles:
3. Article 5.2 GDPR (Accountability Principle): VIOLATION CONFIRMED
Although they couldn't prove the data accuracy violation, the Lithuanian authority found that Vinted had violated the accountability principle—the controller's obligation to demonstrate GDPR compliance. By deleting the data before the investigation concluded, Vinted made it impossible to verify their compliance with data accuracy requirements.
The Spanish AEPD's Role: Under Article 60.8 and 60.9 GDPR, when parts of a cross-border complaint are dismissed or rejected, the concerned authority (where the complaint was filed) must adopt a separate decision on those dismissed portions and notify the complainant.
The Lithuanian authority partially upheld the complaint (Articles 15, 16, and 5.2 violations) but rejected the Article 5.1(d) claim due to insufficient evidence. They communicated their draft decision to the AEPD through the IMI system, and the AEPD—as the concerned authority—accepted it without raising objections.
The AEPD's Archival Decision: Following the Article 60.9 procedure, the AEPD issued this resolution specifically addressing the rejected portion of the complaint (the data accuracy claim). They formally archived that part of the proceedings, applying the presumption of innocence principle: "An administrative infringement cannot be imputed when there is no evidence or indication from which the existence of the infringement can be derived."
What This Means:
Based on Resolution AT/03391/2022 - EXP202208187, businesses operating across EU borders should implement the following protocol:
1. Never Confuse Different GDPR Rights
Vinted's critical error was responding to an access/rectification request as if it were a deletion request.
Action:
Each right has different legal requirements:
2. "Legitimate Interest" Does Not Override Access Rights
Vinted claimed legitimate interest in retaining blocked users' data, but this is irrelevant to access requests.
Critical Principle: Even if you have a legitimate interest (or any other lawful basis) for processing data, data subjects still retain their GDPR rights. You cannot refuse an access request simply because you're entitled to keep processing the data.
Correct Response When Account is Blocked: "We confirm your account was suspended on [date] for [reason]. Despite this suspension, we are processing your access request and will provide the requested information within 30 days. Our lawful basis for retaining your data following suspension is legitimate interest in [specify: fraud prevention, legal compliance, etc.]."
3. Preserve Evidence During Investigations
The fatal flaw: Vinted deleted data on 2nd July 2022 while the complaint (filed 25th June 2022) was under investigation.
Legal Obligation: Once you're aware that data processing is under investigation or dispute, you have an implicit obligation to preserve that data as evidence. Deleting it can:
Protocol When Complaint Filed:
4. Understand Cross-Border GDPR Enforcement
This case demonstrates the "one-stop-shop" mechanism that many businesses misunderstand.
Key Rules:
Why This Matters:
Business Implication: If you operate across multiple EU countries, you're subject to coordinated pan-EU enforcement. Compliance failures in one country can trigger multi-jurisdictional investigations.
5. The Article 5.2 Accountability Principle is Enforceable
Often overlooked, Article 5.2 GDPR states: "The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (principles)."
What This Means: It's not enough to be compliant—you must be able to prove compliance.
Vinted's Accountability Violation: By deleting the data before the investigation concluded, they made it impossible to demonstrate whether they had complied with the accuracy principle. This inability to demonstrate compliance is itself a GDPR violation.
How to Demonstrate Compliance:
6. Data Accuracy Requires Reasonable Verification
Although this complaint was archived, it highlights important accuracy obligations.
Article 5.1(d) GDPR requires: "Data must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay."
For Platforms Like Vinted (Multi-User Environments):
Best Practice: When blocking an account for terms violations allegedly linked to other accounts:
7. Respond to Rectification Requests Substantively
Article 16 GDPR gives data subjects the right to have inaccurate data corrected.
When a user challenges data accuracy:
DO NOT:
8. Special Considerations for Blocked/Suspended Accounts
When you block or suspend an account for violations, data subject rights don't disappear.
You MUST still:
You CAN:
But refusal requires:
9. Presumption of Innocence in Data Protection
This case was archived applying "the presumption of innocence principle which prevents attributing an administrative infringement when no evidence or indication has been obtained from which the existence of the infringement can be derived."
What This Means:
Strategic Lesson: Evidence preservation protects both sides:
10. IMI System Coordination Requirements
For businesses operating in multiple EU countries:
Understand the timeline:
Your rights:
Your obligations:
I'll create a comprehensive summary of this AEPD resolution following your established format.
AEPD Resolution: Vinted Cross-Border Data Accuracy Claim Archived
Official Resolution Date: 23/01/2026
Date Published: [Publication date from system]
AEPD Reference Number: AT/03391/2022 - EXP202208187
Sanction Procedure Number: CO-00128-2022
Fine Amount: €0 (Case archived - insufficient evidence)
Full Description
The Incident: On 25th June 2022, a Spanish user (A.A.A.) filed a complaint with the Spanish Data Protection Agency (AEPD) against Vinted UAB, the Lithuanian-registered company operating the popular second-hand clothing marketplace platform. The complainant alleged that Vinted had violated three separate GDPR provisions by:
The Background Dispute: The complainant's account had been blocked by Vinted for allegedly violating the platform's terms and conditions. On 16th May 2022, he sent an email to Vinted's Data Protection Officer (DPO) exercising his rights of access and rectification. The complainant maintained that his account had been wrongly associated with rule violations committed by other accounts operated by third parties with whom he had no connection.
Vinted's Initial Response: The following day (17th May 2022), Vinted's DPO replied, but the response appeared to confuse the complainant's request. Vinted stated that they were denying a "right of erasure" (deletion) request, explaining that because the account was blocked for terms violations, they had a legitimate interest in retaining and processing the data. The company appeared to have misunderstood the request entirely—the complainant had not asked for deletion; he had asked for access to his data and correction of inaccurate information.
The Complainant's Clarification: The user responded to Vinted, clarifying that he was not requesting deletion (Article 17 GDPR) but rather:
He specifically challenged Vinted's assertion that violations attributed to his account were actually committed by third parties using separate accounts, arguing this constituted inaccurate data processing.
Cross-Border Enforcement Mechanism: Because Vinted UAB is established in Lithuania (its main or only establishment), this became a cross-border GDPR enforcement case. Under Articles 56 and 60 GDPR, when a company's main establishment is in one EU member state but processes data affecting residents of other member states, a "one-stop-shop" mechanism applies:
On 4th August 2022, the AEPD provisionally archived the Spanish proceedings and transferred the case to Lithuania through the Internal Market Information System (IMI)—the EU's cross-border administrative cooperation platform. The Lithuanian authority accepted the case as lead supervisory authority.
The Lithuanian Investigation: The Lithuanian data protection authority conducted a full investigation and reached the following conclusions:
1. Articles 15 and 16 GDPR (Access and Rectification): VIOLATIONS CONFIRMED
The Lithuanian authority upheld the complaint regarding Vinted's failure to properly respond to the access and rectification requests. They found that Vinted had not adequately addressed the complainant's legitimate rights exercise.
2. Article 5.1(d) GDPR (Data Accuracy Principle): INSUFFICIENT EVIDENCE
The Lithuanian authority could not determine whether Vinted had violated the data accuracy principle. Here's why:
On 2nd July 2022—after the complaint was filed but during the investigation—Vinted deleted most of the complainant's personal data. This created an evidentiary problem: without access to the original data that allegedly incorrectly linked the complainant to third-party violations, the Lithuanian authority could not objectively verify whether the data had been inaccurate.
The Lithuanian authority explained their reasoning under domestic administrative law principles:
3. Article 5.2 GDPR (Accountability Principle): VIOLATION CONFIRMED
Although they couldn't prove the data accuracy violation, the Lithuanian authority found that Vinted had violated the accountability principle—the controller's obligation to demonstrate GDPR compliance. By deleting the data before the investigation concluded, Vinted made it impossible to verify their compliance with data accuracy requirements.
The Spanish AEPD's Role: Under Article 60.8 and 60.9 GDPR, when parts of a cross-border complaint are dismissed or rejected, the concerned authority (where the complaint was filed) must adopt a separate decision on those dismissed portions and notify the complainant.
The Lithuanian authority partially upheld the complaint (Articles 15, 16, and 5.2 violations) but rejected the Article 5.1(d) claim due to insufficient evidence. They communicated their draft decision to the AEPD through the IMI system, and the AEPD—as the concerned authority—accepted it without raising objections.
The AEPD's Archival Decision: Following the Article 60.9 procedure, the AEPD issued this resolution specifically addressing the rejected portion of the complaint (the data accuracy claim). They formally archived that part of the proceedings, applying the presumption of innocence principle: "An administrative infringement cannot be imputed when there is no evidence or indication from which the existence of the infringement can be derived."
What This Means:
Articles Claimed (But Not Proven)
Article 5.1(d) RGPD (Data Accuracy Principle): The complainant alleged that Vinted incorrectly linked his personal data with activities performed by other users from different accounts, thereby maintaining inaccurate data. However, because Vinted deleted the relevant data on 2nd July 2022 during the investigation, the Lithuanian authority could not objectively verify whether the data had been inaccurate with respect to the processing purposes.
Result: Claim archived due to insufficient evidence (not a finding of compliance, but rather impossibility of verification).
Note: The Lithuanian authority did find violations of Articles 15 (access), 16 (rectification), and 5.2 (accountability) GDPR in their separate decision.
Actionable Steps
Based on Resolution AT/03391/2022 - EXP202208187, businesses operating across EU borders should implement the following protocol:
1. Never Confuse Different GDPR Rights
Vinted's critical error was responding to an access/rectification request as if it were a deletion request.
Action:
Each right has different legal requirements:
2. "Legitimate Interest" Does Not Override Access Rights
Vinted claimed legitimate interest in retaining blocked users' data, but this is irrelevant to access requests.
Critical Principle: Even if you have a legitimate interest (or any other lawful basis) for processing data, data subjects still retain their GDPR rights. You cannot refuse an access request simply because you're entitled to keep processing the data.
Correct Response When Account is Blocked: "We confirm your account was suspended on [date] for [reason]. Despite this suspension, we are processing your access request and will provide the requested information within 30 days. Our lawful basis for retaining your data following suspension is legitimate interest in [specify: fraud prevention, legal compliance, etc.]."
3. Preserve Evidence During Investigations
The fatal flaw: Vinted deleted data on 2nd July 2022 while the complaint (filed 25th June 2022) was under investigation.
Legal Obligation: Once you're aware that data processing is under investigation or dispute, you have an implicit obligation to preserve that data as evidence. Deleting it can:
Protocol When Complaint Filed:
4. Understand Cross-Border GDPR Enforcement
This case demonstrates the "one-stop-shop" mechanism that many businesses misunderstand.
Key Rules:
Why This Matters:
Business Implication: If you operate across multiple EU countries, you're subject to coordinated pan-EU enforcement. Compliance failures in one country can trigger multi-jurisdictional investigations.
5. The Article 5.2 Accountability Principle is Enforceable
Often overlooked, Article 5.2 GDPR states: "The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (principles)."
What This Means: It's not enough to be compliant—you must be able to prove compliance.
Vinted's Accountability Violation: By deleting the data before the investigation concluded, they made it impossible to demonstrate whether they had complied with the accuracy principle. This inability to demonstrate compliance is itself a GDPR violation.
How to Demonstrate Compliance:
6. Data Accuracy Requires Reasonable Verification
Although this complaint was archived, it highlights important accuracy obligations.
Article 5.1(d) GDPR requires: "Data must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay."
For Platforms Like Vinted (Multi-User Environments):
Best Practice: When blocking an account for terms violations allegedly linked to other accounts:
7. Respond to Rectification Requests Substantively
Article 16 GDPR gives data subjects the right to have inaccurate data corrected.
When a user challenges data accuracy:
DO NOT:
8. Special Considerations for Blocked/Suspended Accounts
When you block or suspend an account for violations, data subject rights don't disappear.
You MUST still:
You CAN:
But refusal requires:
9. Presumption of Innocence in Data Protection
This case was archived applying "the presumption of innocence principle which prevents attributing an administrative infringement when no evidence or indication has been obtained from which the existence of the infringement can be derived."
What This Means:
Strategic Lesson: Evidence preservation protects both sides:
10. IMI System Coordination Requirements
For businesses operating in multiple EU countries:
Understand the timeline:
Your rights:
Your obligations:
Summary of Business Risk
This resolution illustrates that partial complaint dismissal does not mean exoneration—it means insufficient evidence. Vinted avoided findings on data accuracy, but only because they deleted the evidence. They still faced enforcement for Articles 15, 16, and 5.2 violations in Lithuania.
Actual Consequences in This Case:
Risks for Similar Businesses:
Critical Takeaway: When faced with a complaint or investigation, preserve evidence first, act second. Vinted's decision to delete data on 2nd July 2022 (one week after the complaint) prevented verification of the accuracy claim but also triggered accountability violations. Proper evidence preservation would have either proven their compliance or allowed them to identify and correct the inaccuracy, either outcome better than evidentiary destruction.
Informational Purposes Only: The content provided by ANRO DIGITAL SOLUTIONS S.L.U. (including resolution summaries, infographics, and case analyses) is for educational and informational purposes only.
No Legal Advice: This information does not constitute legal advice, a formal legal opinion, or a substitute for professional legal counsel. The interpretation of data protection laws (including the GDPR, LOPDGDD, and AEPD resolutions) is subject to change and can vary based on specific facts and circumstances.
No Liability: ANRO DIGITAL SOLUTIONS S.L.U. assumes no responsibility or liability for any actions taken, or not taken, based on the information provided on this website. While we strive for accuracy, we make no guarantees regarding the completeness or timeliness of the information.
Consult a Professional: Data protection compliance is a complex legal requirement. You should not act upon this information without seeking advice from a qualified Data Protection Officer (DPO) or a specialist data protection lawyer licensed to practice in your jurisdiction.
Third-Party Links: Links to official AEPD documents are provided for convenience. We are not responsible for the content or availability of these external government portals.
Este resumen tiene carácter meramente informativo. Para más información, consulte nuestro Aviso Legal.