ANRO Privacy Logo

AEPD Resolution: EXP202208187

Resolution Signed: 23/01/2026

AEPD Reference Number: EXP202208187

Sanction Procedure Number: CO-00128-2022 

Fine Amount: €0

Full Description

On 25th June 2022, a Spanish user (A.A.A.) filed a complaint with the Spanish Data Protection Agency (AEPD) against Vinted UAB, the Lithuanian-registered company operating the popular second-hand clothing marketplace platform. The complainant alleged that Vinted had violated three separate GDPR provisions by:

  1. Failing to properly respond to his Article 15 (access) and Article 16 (rectification) requests
  2. Linking his personal data incorrectly with another person's data, violating the data accuracy principle under Article 5.1(d) GDPR

The Background Dispute: The complainant's account had been blocked by Vinted for allegedly violating the platform's terms and conditions. On 16th May 2022, he sent an email to Vinted's Data Protection Officer (DPO) exercising his rights of access and rectification. The complainant maintained that his account had been wrongly associated with rule violations committed by other accounts operated by third parties with whom he had no connection.

Vinted's Initial Response: The following day (17th May 2022), Vinted's DPO replied, but the response appeared to confuse the complainant's request. Vinted stated that they were denying a "right of erasure" (deletion) request, explaining that because the account was blocked for terms violations, they had a legitimate interest in retaining and processing the data. The company appeared to have misunderstood the request entirely—the complainant had not asked for deletion; he had asked for access to his data and correction of inaccurate information.

The Complainant's Clarification: The user responded to Vinted, clarifying that he was not requesting deletion (Article 17 GDPR) but rather:

  • Access (Article 15): To see what data Vinted held about him
  • Rectification (Article 16): To correct data that incorrectly linked him to violations committed by others from different accounts

He specifically challenged Vinted's assertion that violations attributed to his account were actually committed by third parties using separate accounts, arguing this constituted inaccurate data processing.

Cross-Border Enforcement Mechanism: Because Vinted UAB is established in Lithuania (its main or only establishment), this became a cross-border GDPR enforcement case. Under Articles 56 and 60 GDPR, when a company's main establishment is in one EU member state but processes data affecting residents of other member states, a "one-stop-shop" mechanism applies:

  • Lead Supervisory Authority: The Lithuanian data protection authority (State Data Protection Inspectorate)
  • Concerned Authority: The Spanish AEPD (because the complainant resides in Spain and filed the complaint there)

On 4th August 2022, the AEPD provisionally archived the Spanish proceedings and transferred the case to Lithuania through the Internal Market Information System (IMI)—the EU's cross-border administrative cooperation platform. The Lithuanian authority accepted the case as lead supervisory authority.

The Lithuanian Investigation: The Lithuanian data protection authority conducted a full investigation and reached the following conclusions:

1. Articles 15 and 16 GDPR (Access and Rectification): VIOLATIONS CONFIRMED

The Lithuanian authority upheld the complaint regarding Vinted's failure to properly respond to the access and rectification requests. They found that Vinted had not adequately addressed the complainant's legitimate rights exercise.

2. Article 5.1(d) GDPR (Data Accuracy Principle): INSUFFICIENT EVIDENCE

The Lithuanian authority could not determine whether Vinted had violated the data accuracy principle. Here's why:

On 2nd July 2022—after the complaint was filed but during the investigation—Vinted deleted most of the complainant's personal data. This created an evidentiary problem: without access to the original data that allegedly incorrectly linked the complainant to third-party violations, the Lithuanian authority could not objectively verify whether the data had been inaccurate.

The Lithuanian authority explained their reasoning under domestic administrative law principles:

  • Administrative decisions must be based on objective facts, not conjecture or suspicion
  • According to Lithuanian Public Administration Law (Article 10.5), decisions must specify factual and legal basis
  • The Lithuanian Supreme Administrative Court has ruled that administrative decisions cannot be based on assumptions—they require critical and impartial evaluation of evidence
  • With the data deleted, no evidence remained to establish whether the accuracy principle had been violated

3. Article 5.2 GDPR (Accountability Principle): VIOLATION CONFIRMED

Although they couldn't prove the data accuracy violation, the Lithuanian authority found that Vinted had violated the accountability principle—the controller's obligation to demonstrate GDPR compliance. By deleting the data before the investigation concluded, Vinted made it impossible to verify their compliance with data accuracy requirements.

The Spanish AEPD's Role: Under Article 60.8 and 60.9 GDPR, when parts of a cross-border complaint are dismissed or rejected, the concerned authority (where the complaint was filed) must adopt a separate decision on those dismissed portions and notify the complainant.

The Lithuanian authority partially upheld the complaint (Articles 15, 16, and 5.2 violations) but rejected the Article 5.1(d) claim due to insufficient evidence. They communicated their draft decision to the AEPD through the IMI system, and the AEPD—as the concerned authority—accepted it without raising objections.

The AEPD's Archival Decision: Following the Article 60.9 procedure, the AEPD issued this resolution specifically addressing the rejected portion of the complaint (the data accuracy claim). They formally archived that part of the proceedings, applying the presumption of innocence principle: "An administrative infringement cannot be imputed when there is no evidence or indication from which the existence of the infringement can be derived."

What This Means:

  • The complainant's allegations about Articles 15, 16, and 5.2 GDPR were upheld by Lithuania (those proceedings resulted in separate enforcement action)
  • The Article 5.1(d) data accuracy claim was dismissed due to evidentiary destruction
  • The AEPD's archival decision closes only the rejected portion for Spanish administrative purposes
  • Vinted was notified of the decision but faces enforcement action in Lithuania for the confirmed violations

Articles Infringed

Articles Claimed (But Not Proven)Article 5.1(d) RGPD (Data Accuracy Principle): The complainant alleged that Vinted incorrectly linked his personal data with activities performed by other users from different accounts, thereby maintaining inaccurate data. However, because Vinted deleted the relevant data on 2nd July 2022 during the investigation, the Lithuanian authority could not objectively verify whether the data had been inaccurate with respect to the processing purposes. Result: Claim archived due to insufficient evidence (not a finding of compliance, but rather impossibility of verification).Note: The Lithuanian authority did find violations of Articles 15 (access), 16 (rectification), and 5.2 (accountability) GDPR in their separate decision.

Actionable Steps

Based on Resolution AT/03391/2022 - EXP202208187, businesses operating across EU borders should implement the following protocol:

1. Never Confuse Different GDPR Rights

Vinted's critical error was responding to an access/rectification request as if it were a deletion request.

Action:

  • Train DPOs and privacy teams to carefully read requests and identify which specific rights are being exercised
  • Create separate response templates for each GDPR right (access, rectification, erasure, restriction, portability, objection)
  • If uncertain about what right is being exercised, ask the data subject for clarification before responding

Each right has different legal requirements:

  • Access (Article 15): Provide data copy and specified information
  • Rectification (Article 16): Correct inaccurate data
  • Erasure (Article 17): Delete data (with specific conditions)
  • Restriction (Article 18): Limit processing
  • Portability (Article 20): Transfer data in structured format
  • Objection (Article 21): Stop certain types of processing

2. "Legitimate Interest" Does Not Override Access Rights

Vinted claimed legitimate interest in retaining blocked users' data, but this is irrelevant to access requests.

Critical Principle: Even if you have a legitimate interest (or any other lawful basis) for processing data, data subjects still retain their GDPR rights. You cannot refuse an access request simply because you're entitled to keep processing the data.

Correct Response When Account is Blocked: "We confirm your account was suspended on [date] for [reason]. Despite this suspension, we are processing your access request and will provide the requested information within 30 days. Our lawful basis for retaining your data following suspension is legitimate interest in [specify: fraud prevention, legal compliance, etc.]."

3. Preserve Evidence During Investigations

The fatal flaw: Vinted deleted data on 2nd July 2022 while the complaint (filed 25th June 2022) was under investigation.

Legal Obligation: Once you're aware that data processing is under investigation or dispute, you have an implicit obligation to preserve that data as evidence. Deleting it can:

  • Prevent authorities from verifying compliance
  • Violate the accountability principle (Article 5.2 GDPR)
  • Create adverse inferences (authorities may assume the deleted data proved the violation)

Protocol When Complaint Filed:

  1. Immediately place a legal hold on all data related to the complaint
  2. Document the data's status as of the complaint date (take screenshots, database exports, audit logs)
  3. Do NOT delete the data until:
    • The investigation concludes
    • The supervisory authority explicitly authorizes deletion
    • Legal counsel confirms preservation is no longer required
  4. If you have a legitimate reason to delete (e.g., storage limits, security risks), seek supervisory authority guidance first

4. Understand Cross-Border GDPR Enforcement

This case demonstrates the "one-stop-shop" mechanism that many businesses misunderstand.

Key Rules:

  • If your main establishment is in Lithuania, the Lithuanian authority leads investigations
  • But complaints can be filed in any EU member state where affected individuals reside
  • The lead authority coordinates with "concerned authorities" in other member states
  • Final decisions apply across the entire EU

Why This Matters:

  • A Spanish user's complaint against a Lithuanian company was investigated by Lithuania but involved Spanish participation
  • You cannot avoid enforcement by establishing in a supposedly "lenient" jurisdiction
  • All EU data protection authorities cooperate through the IMI system
  • Multiple authorities can raise objections if they disagree with the lead authority's proposed decision

Business Implication: If you operate across multiple EU countries, you're subject to coordinated pan-EU enforcement. Compliance failures in one country can trigger multi-jurisdictional investigations.

5. The Article 5.2 Accountability Principle is Enforceable

Often overlooked, Article 5.2 GDPR states: "The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (principles)."

What This Means: It's not enough to be compliant—you must be able to prove compliance.

Vinted's Accountability Violation: By deleting the data before the investigation concluded, they made it impossible to demonstrate whether they had complied with the accuracy principle. This inability to demonstrate compliance is itself a GDPR violation.

How to Demonstrate Compliance:

  • Maintain processing records (Article 30 GDPR)
  • Keep audit logs showing when data was collected, from what source, and how it's used
  • Document decision-making processes (e.g., why you linked certain accounts together)
  • Preserve evidence supporting your legal bases
  • Retain these records for the prescription period (3 years for very serious infringements in Spain)

6. Data Accuracy Requires Reasonable Verification

Although this complaint was archived, it highlights important accuracy obligations.

Article 5.1(d) GDPR requires: "Data must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay."

For Platforms Like Vinted (Multi-User Environments):

  • If you link multiple accounts or activities together, document your methodology
  • Common linking factors: IP addresses, device fingerprints, payment methods, delivery addresses, behavioral patterns
  • But linking requires reasonable accuracy—don't assume Account A and Account B are the same person without sufficient evidence
  • If a user contests your account linking, investigate and document your findings

Best Practice: When blocking an account for terms violations allegedly linked to other accounts:

  1. Document the specific evidence linking the accounts
  2. Timestamp when the link was identified
  3. Preserve this evidence in case of dispute
  4. If challenged, review the evidence objectively
  5. If the link cannot be proven on balance of probabilities, rectify the data

7. Respond to Rectification Requests Substantively

Article 16 GDPR gives data subjects the right to have inaccurate data corrected.

When a user challenges data accuracy:

  • Investigate the claim
  • Examine your evidence for the disputed data
  • If the data is accurate, explain why and provide supporting evidence
  • If the data might be inaccurate, correct it
  • If accuracy cannot be determined, consider restriction rather than maintaining potentially inaccurate data

DO NOT:

  • Dismiss rectification requests without investigation
  • Claim data is accurate without evidence
  • Conflate rectification with other rights (like erasure)

8. Special Considerations for Blocked/Suspended Accounts

When you block or suspend an account for violations, data subject rights don't disappear.

You MUST still:

  • Respond to access requests (provide data copy)
  • Consider rectification requests (correct inaccurate data)
  • Respond to other rights requests (though some may be refused on specific legal grounds)

You CAN:

  • Refuse erasure if you have compelling legitimate grounds overriding the data subject's interests (Article 17.1(f))
  • Refuse objections if you demonstrate compelling legitimate grounds (Article 21.1)

But refusal requires:

  • Specific legal justification
  • Documented balancing of interests
  • Clear communication to the data subject explaining why their request is refused

9. Presumption of Innocence in Data Protection

This case was archived applying "the presumption of innocence principle which prevents attributing an administrative infringement when no evidence or indication has been obtained from which the existence of the infringement can be derived."

What This Means:

  • Supervisory authorities cannot fine you based on allegations alone
  • They must prove violations with objective evidence
  • Insufficient evidence leads to archival, not acquittal (there's a distinction)
  • But if evidence was destroyed by your own actions, authorities may draw adverse inferences

Strategic Lesson: Evidence preservation protects both sides:

  • It allows you to prove compliance
  • It allows authorities to verify claims
  • Destroying evidence helps no one and may constitute separate violations

10. IMI System Coordination Requirements

For businesses operating in multiple EU countries:

Understand the timeline:

  • Complaint filed with concerned authority (e.g., Spain)
  • Transfer to lead authority (e.g., Lithuania) via IMI
  • Lead authority investigates and drafts decision
  • Draft shared with concerned authorities (4-week objection period)
  • If no objections, decision becomes binding on all authorities
  • Separate decisions issued where complaints are partially rejected

Your rights:

  • Receive formal notification from the lead authority
  • Make representations during investigation
  • Be informed of draft decisions
  • Challenge final decisions through administrative/judicial review

Your obligations:

  • Cooperate with the lead authority's investigation
  • Respond to information requests promptly
  • Implement any corrective measures across all EU operations (not just the lead authority's jurisdiction)

I'll create a comprehensive summary of this AEPD resolution following your established format.


AEPD Resolution: Vinted Cross-Border Data Accuracy Claim Archived

Official Resolution Date: 23/01/2026
Date Published: [Publication date from system]
AEPD Reference Number: AT/03391/2022 - EXP202208187
Sanction Procedure Number: CO-00128-2022

Fine Amount: €0 (Case archived - insufficient evidence)


Full Description

The Incident: On 25th June 2022, a Spanish user (A.A.A.) filed a complaint with the Spanish Data Protection Agency (AEPD) against Vinted UAB, the Lithuanian-registered company operating the popular second-hand clothing marketplace platform. The complainant alleged that Vinted had violated three separate GDPR provisions by:

  1. Failing to properly respond to his Article 15 (access) and Article 16 (rectification) requests
  2. Linking his personal data incorrectly with another person's data, violating the data accuracy principle under Article 5.1(d) GDPR

The Background Dispute: The complainant's account had been blocked by Vinted for allegedly violating the platform's terms and conditions. On 16th May 2022, he sent an email to Vinted's Data Protection Officer (DPO) exercising his rights of access and rectification. The complainant maintained that his account had been wrongly associated with rule violations committed by other accounts operated by third parties with whom he had no connection.

Vinted's Initial Response: The following day (17th May 2022), Vinted's DPO replied, but the response appeared to confuse the complainant's request. Vinted stated that they were denying a "right of erasure" (deletion) request, explaining that because the account was blocked for terms violations, they had a legitimate interest in retaining and processing the data. The company appeared to have misunderstood the request entirely—the complainant had not asked for deletion; he had asked for access to his data and correction of inaccurate information.

The Complainant's Clarification: The user responded to Vinted, clarifying that he was not requesting deletion (Article 17 GDPR) but rather:

  • Access (Article 15): To see what data Vinted held about him
  • Rectification (Article 16): To correct data that incorrectly linked him to violations committed by others from different accounts

He specifically challenged Vinted's assertion that violations attributed to his account were actually committed by third parties using separate accounts, arguing this constituted inaccurate data processing.

Cross-Border Enforcement Mechanism: Because Vinted UAB is established in Lithuania (its main or only establishment), this became a cross-border GDPR enforcement case. Under Articles 56 and 60 GDPR, when a company's main establishment is in one EU member state but processes data affecting residents of other member states, a "one-stop-shop" mechanism applies:

  • Lead Supervisory Authority: The Lithuanian data protection authority (State Data Protection Inspectorate)
  • Concerned Authority: The Spanish AEPD (because the complainant resides in Spain and filed the complaint there)

On 4th August 2022, the AEPD provisionally archived the Spanish proceedings and transferred the case to Lithuania through the Internal Market Information System (IMI)—the EU's cross-border administrative cooperation platform. The Lithuanian authority accepted the case as lead supervisory authority.

The Lithuanian Investigation: The Lithuanian data protection authority conducted a full investigation and reached the following conclusions:

1. Articles 15 and 16 GDPR (Access and Rectification): VIOLATIONS CONFIRMED

The Lithuanian authority upheld the complaint regarding Vinted's failure to properly respond to the access and rectification requests. They found that Vinted had not adequately addressed the complainant's legitimate rights exercise.

2. Article 5.1(d) GDPR (Data Accuracy Principle): INSUFFICIENT EVIDENCE

The Lithuanian authority could not determine whether Vinted had violated the data accuracy principle. Here's why:

On 2nd July 2022—after the complaint was filed but during the investigation—Vinted deleted most of the complainant's personal data. This created an evidentiary problem: without access to the original data that allegedly incorrectly linked the complainant to third-party violations, the Lithuanian authority could not objectively verify whether the data had been inaccurate.

The Lithuanian authority explained their reasoning under domestic administrative law principles:

  • Administrative decisions must be based on objective facts, not conjecture or suspicion
  • According to Lithuanian Public Administration Law (Article 10.5), decisions must specify factual and legal basis
  • The Lithuanian Supreme Administrative Court has ruled that administrative decisions cannot be based on assumptions—they require critical and impartial evaluation of evidence
  • With the data deleted, no evidence remained to establish whether the accuracy principle had been violated

3. Article 5.2 GDPR (Accountability Principle): VIOLATION CONFIRMED

Although they couldn't prove the data accuracy violation, the Lithuanian authority found that Vinted had violated the accountability principle—the controller's obligation to demonstrate GDPR compliance. By deleting the data before the investigation concluded, Vinted made it impossible to verify their compliance with data accuracy requirements.

The Spanish AEPD's Role: Under Article 60.8 and 60.9 GDPR, when parts of a cross-border complaint are dismissed or rejected, the concerned authority (where the complaint was filed) must adopt a separate decision on those dismissed portions and notify the complainant.

The Lithuanian authority partially upheld the complaint (Articles 15, 16, and 5.2 violations) but rejected the Article 5.1(d) claim due to insufficient evidence. They communicated their draft decision to the AEPD through the IMI system, and the AEPD—as the concerned authority—accepted it without raising objections.

The AEPD's Archival Decision: Following the Article 60.9 procedure, the AEPD issued this resolution specifically addressing the rejected portion of the complaint (the data accuracy claim). They formally archived that part of the proceedings, applying the presumption of innocence principle: "An administrative infringement cannot be imputed when there is no evidence or indication from which the existence of the infringement can be derived."

What This Means:

  • The complainant's allegations about Articles 15, 16, and 5.2 GDPR were upheld by Lithuania (those proceedings resulted in separate enforcement action)
  • The Article 5.1(d) data accuracy claim was dismissed due to evidentiary destruction
  • The AEPD's archival decision closes only the rejected portion for Spanish administrative purposes
  • Vinted was notified of the decision but faces enforcement action in Lithuania for the confirmed violations

Articles Claimed (But Not Proven)

Article 5.1(d) RGPD (Data Accuracy Principle): The complainant alleged that Vinted incorrectly linked his personal data with activities performed by other users from different accounts, thereby maintaining inaccurate data. However, because Vinted deleted the relevant data on 2nd July 2022 during the investigation, the Lithuanian authority could not objectively verify whether the data had been inaccurate with respect to the processing purposes.

Result: Claim archived due to insufficient evidence (not a finding of compliance, but rather impossibility of verification).

Note: The Lithuanian authority did find violations of Articles 15 (access), 16 (rectification), and 5.2 (accountability) GDPR in their separate decision.


Actionable Steps

Based on Resolution AT/03391/2022 - EXP202208187, businesses operating across EU borders should implement the following protocol:

1. Never Confuse Different GDPR Rights

Vinted's critical error was responding to an access/rectification request as if it were a deletion request.

Action:

  • Train DPOs and privacy teams to carefully read requests and identify which specific rights are being exercised
  • Create separate response templates for each GDPR right (access, rectification, erasure, restriction, portability, objection)
  • If uncertain about what right is being exercised, ask the data subject for clarification before responding

Each right has different legal requirements:

  • Access (Article 15): Provide data copy and specified information
  • Rectification (Article 16): Correct inaccurate data
  • Erasure (Article 17): Delete data (with specific conditions)
  • Restriction (Article 18): Limit processing
  • Portability (Article 20): Transfer data in structured format
  • Objection (Article 21): Stop certain types of processing

2. "Legitimate Interest" Does Not Override Access Rights

Vinted claimed legitimate interest in retaining blocked users' data, but this is irrelevant to access requests.

Critical Principle: Even if you have a legitimate interest (or any other lawful basis) for processing data, data subjects still retain their GDPR rights. You cannot refuse an access request simply because you're entitled to keep processing the data.

Correct Response When Account is Blocked: "We confirm your account was suspended on [date] for [reason]. Despite this suspension, we are processing your access request and will provide the requested information within 30 days. Our lawful basis for retaining your data following suspension is legitimate interest in [specify: fraud prevention, legal compliance, etc.]."

3. Preserve Evidence During Investigations

The fatal flaw: Vinted deleted data on 2nd July 2022 while the complaint (filed 25th June 2022) was under investigation.

Legal Obligation: Once you're aware that data processing is under investigation or dispute, you have an implicit obligation to preserve that data as evidence. Deleting it can:

  • Prevent authorities from verifying compliance
  • Violate the accountability principle (Article 5.2 GDPR)
  • Create adverse inferences (authorities may assume the deleted data proved the violation)

Protocol When Complaint Filed:

  1. Immediately place a legal hold on all data related to the complaint
  2. Document the data's status as of the complaint date (take screenshots, database exports, audit logs)
  3. Do NOT delete the data until:
    • The investigation concludes
    • The supervisory authority explicitly authorizes deletion
    • Legal counsel confirms preservation is no longer required
  4. If you have a legitimate reason to delete (e.g., storage limits, security risks), seek supervisory authority guidance first

4. Understand Cross-Border GDPR Enforcement

This case demonstrates the "one-stop-shop" mechanism that many businesses misunderstand.

Key Rules:

  • If your main establishment is in Lithuania, the Lithuanian authority leads investigations
  • But complaints can be filed in any EU member state where affected individuals reside
  • The lead authority coordinates with "concerned authorities" in other member states
  • Final decisions apply across the entire EU

Why This Matters:

  • A Spanish user's complaint against a Lithuanian company was investigated by Lithuania but involved Spanish participation
  • You cannot avoid enforcement by establishing in a supposedly "lenient" jurisdiction
  • All EU data protection authorities cooperate through the IMI system
  • Multiple authorities can raise objections if they disagree with the lead authority's proposed decision

Business Implication: If you operate across multiple EU countries, you're subject to coordinated pan-EU enforcement. Compliance failures in one country can trigger multi-jurisdictional investigations.

5. The Article 5.2 Accountability Principle is Enforceable

Often overlooked, Article 5.2 GDPR states: "The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (principles)."

What This Means: It's not enough to be compliant—you must be able to prove compliance.

Vinted's Accountability Violation: By deleting the data before the investigation concluded, they made it impossible to demonstrate whether they had complied with the accuracy principle. This inability to demonstrate compliance is itself a GDPR violation.

How to Demonstrate Compliance:

  • Maintain processing records (Article 30 GDPR)
  • Keep audit logs showing when data was collected, from what source, and how it's used
  • Document decision-making processes (e.g., why you linked certain accounts together)
  • Preserve evidence supporting your legal bases
  • Retain these records for the prescription period (3 years for very serious infringements in Spain)

6. Data Accuracy Requires Reasonable Verification

Although this complaint was archived, it highlights important accuracy obligations.

Article 5.1(d) GDPR requires: "Data must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay."

For Platforms Like Vinted (Multi-User Environments):

  • If you link multiple accounts or activities together, document your methodology
  • Common linking factors: IP addresses, device fingerprints, payment methods, delivery addresses, behavioral patterns
  • But linking requires reasonable accuracy—don't assume Account A and Account B are the same person without sufficient evidence
  • If a user contests your account linking, investigate and document your findings

Best Practice: When blocking an account for terms violations allegedly linked to other accounts:

  1. Document the specific evidence linking the accounts
  2. Timestamp when the link was identified
  3. Preserve this evidence in case of dispute
  4. If challenged, review the evidence objectively
  5. If the link cannot be proven on balance of probabilities, rectify the data

7. Respond to Rectification Requests Substantively

Article 16 GDPR gives data subjects the right to have inaccurate data corrected.

When a user challenges data accuracy:

  • Investigate the claim
  • Examine your evidence for the disputed data
  • If the data is accurate, explain why and provide supporting evidence
  • If the data might be inaccurate, correct it
  • If accuracy cannot be determined, consider restriction rather than maintaining potentially inaccurate data

DO NOT:

  • Dismiss rectification requests without investigation
  • Claim data is accurate without evidence
  • Conflate rectification with other rights (like erasure)

8. Special Considerations for Blocked/Suspended Accounts

When you block or suspend an account for violations, data subject rights don't disappear.

You MUST still:

  • Respond to access requests (provide data copy)
  • Consider rectification requests (correct inaccurate data)
  • Respond to other rights requests (though some may be refused on specific legal grounds)

You CAN:

  • Refuse erasure if you have compelling legitimate grounds overriding the data subject's interests (Article 17.1(f))
  • Refuse objections if you demonstrate compelling legitimate grounds (Article 21.1)

But refusal requires:

  • Specific legal justification
  • Documented balancing of interests
  • Clear communication to the data subject explaining why their request is refused

9. Presumption of Innocence in Data Protection

This case was archived applying "the presumption of innocence principle which prevents attributing an administrative infringement when no evidence or indication has been obtained from which the existence of the infringement can be derived."

What This Means:

  • Supervisory authorities cannot fine you based on allegations alone
  • They must prove violations with objective evidence
  • Insufficient evidence leads to archival, not acquittal (there's a distinction)
  • But if evidence was destroyed by your own actions, authorities may draw adverse inferences

Strategic Lesson: Evidence preservation protects both sides:

  • It allows you to prove compliance
  • It allows authorities to verify claims
  • Destroying evidence helps no one and may constitute separate violations

10. IMI System Coordination Requirements

For businesses operating in multiple EU countries:

Understand the timeline:

  • Complaint filed with concerned authority (e.g., Spain)
  • Transfer to lead authority (e.g., Lithuania) via IMI
  • Lead authority investigates and drafts decision
  • Draft shared with concerned authorities (4-week objection period)
  • If no objections, decision becomes binding on all authorities
  • Separate decisions issued where complaints are partially rejected

Your rights:

  • Receive formal notification from the lead authority
  • Make representations during investigation
  • Be informed of draft decisions
  • Challenge final decisions through administrative/judicial review

Your obligations:

  • Cooperate with the lead authority's investigation
  • Respond to information requests promptly
  • Implement any corrective measures across all EU operations (not just the lead authority's jurisdiction)

Summary of Business Risk

This resolution illustrates that partial complaint dismissal does not mean exoneration—it means insufficient evidence. Vinted avoided findings on data accuracy, but only because they deleted the evidence. They still faced enforcement for Articles 15, 16, and 5.2 violations in Lithuania.

Actual Consequences in This Case:

  • Cross-border investigation involving two supervisory authorities
  • Administrative burden of coordinated responses
  • Confirmed violations requiring corrective action in Lithuania
  • Partial archival in Spain (not a positive finding, just evidentiary insufficiency)
  • Public resolution (reputational implications)

Risks for Similar Businesses:

  • Deleting data during investigations violates accountability principle
  • Cannot refuse access requests based on legitimate interest to retain data
  • Cross-border operations face coordinated EU-wide enforcement
  • Platform account-linking decisions require documented accuracy verification
  • Blocking accounts doesn't eliminate GDPR rights

Critical Takeaway: When faced with a complaint or investigation, preserve evidence first, act second. Vinted's decision to delete data on 2nd July 2022 (one week after the complaint) prevented verification of the accuracy claim but also triggered accountability violations. Proper evidence preservation would have either proven their compliance or allowed them to identify and correct the inaccuracy, either outcome better than evidentiary destruction.

Link to Official AEPD PDF

Legal Disclaimer

Informational Purposes Only: The content provided by ANRO DIGITAL SOLUTIONS S.L.U. (including resolution summaries, infographics, and case analyses) is for educational and informational purposes only.

No Legal Advice: This information does not constitute legal advice, a formal legal opinion, or a substitute for professional legal counsel. The interpretation of data protection laws (including the GDPR, LOPDGDD, and AEPD resolutions) is subject to change and can vary based on specific facts and circumstances.

No Liability: ANRO DIGITAL SOLUTIONS S.L.U. assumes no responsibility or liability for any actions taken, or not taken, based on the information provided on this website. While we strive for accuracy, we make no guarantees regarding the completeness or timeliness of the information.

Consult a Professional: Data protection compliance is a complex legal requirement. You should not act upon this information without seeking advice from a qualified Data Protection Officer (DPO) or a specialist data protection lawyer licensed to practice in your jurisdiction.

Third-Party Links: Links to official AEPD documents are provided for convenience. We are not responsible for the content or availability of these external government portals.

Este resumen tiene carácter meramente informativo. Para más información, consulte nuestro Aviso Legal.

ANRO Privacy Logo
Providing clear, reliable information on GDPR and data privacy standards to help you navigate the digital landscape securely.
Legal
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram