ANRO Privacy Logo

AEPD Resolution: EXP202314369

Resolution Signed: 20/01/2026

AEPD Reference Number: EXP202314369

Sanction Procedure Number: PA-00028-2025 

Fine Amount: €0

Full Description

On 3 September 2023, a German resident (A.A.A.) received an unsolicited marketing email from Spanish travel company LOGITRAVEL promoting "AIDA cruises with flight and onboard credit from €799." The recipient had no prior relationship with the company and never signed up for their newsletter.

The Request for Information: On the same day, A.A.A. exercised their Article 15 GDPR right of access, requesting information about: (1) the origin of their data, (2) the legal basis for processing, and (3) a copy of their personal data.

The Company's Response: LOGITRAVEL replied on 11 September 2023, confirming the person had been removed from their mailing lists and that their data would be deleted "in accordance with applicable legal provisions." However, they completely ignored the Article 15 access request—providing no information about data origin, legal basis, or a copy of the data.

The Investigation: The German data protection authority (Lower Saxony) filed the complaint through the IMI system. It was transferred to Spain's AEPD because LOGITRAVEL's sole establishment is in Spain. The AEPD investigation revealed:

  • A.A.A.'s data (name, email, language preference) had been in LOGITRAVEL's systems since 5 October 2011
  • Between August 2022 and September 2023, the person received 61 marketing emails (1-2 per week)
  • The company had no record of how consent was originally obtained due to the age of the registration
  • LOGITRAVEL provided historical privacy policies but could not produce the actual subscription log from 2011

The Company's Defence: LOGITRAVEL admitted their staff made an error. When A.A.A. requested both unsubscription AND data access simultaneously, customer service agents incorrectly assumed that unsubscribing (which deleted the data) completed both requests. They failed to provide the access information before deletion.

The Corrective Actions: After receiving the AEPD's information request in October 2024, LOGITRAVEL:

  • Finally sent A.A.A. the access information on 28 October 2024 (over a year late)
  • Updated internal procedures to separate unsubscription from data access requests
  • Implemented employee training on GDPR rights handling
  • Created clear protocols requiring immediate escalation of rights requests to the DPO

Articles Infringed

Article 15 GDPR (Right of Access): LOGITRAVEL violated the data subject's right to obtain confirmation of data processing and receive a copy of their personal data. The company failed to respond to the access request within the one-month deadline (or even the extended two-month period). Typification: Article 83.5(b) RGPD classifies this as a serious infringement. Under Spanish law (Article 72.1.k LOPDGDD), impediment, obstruction, or repeated non-attention to rights under Articles 15-22 RGPD is considered a very serious infraction with a three-year prescription period. Note: While the infraction was very serious, the AEPD opted for a warning instead of a fine, considering the company's eventual cooperation and remedial measures.
Data Access Request infographic

Actionable Steps

Based on Resolution EXP202314369, here is the compliance protocol for handling access requests:

1. Never Conflate Rights Requests

When someone exercises multiple rights simultaneously (e.g., unsubscription + access), each right requires separate fulfillment.

Protocol:

  • Create separate workflows for deletion and access requests
  • Even if you're deleting someone's data, you must provide access information FIRST
  • Document each right separately in your systems

Legal Basis: Article 12.3 RGPD requires response within one month. Deletion does not excuse providing access information first.

2. The One-Month Clock is Absolute

You have 30 days to respond to access requests—no exceptions without formal extension notice.

Action:

  • Set automated alerts at Day 7, Day 14, and Day 21 to monitor pending requests
  • If you need an extension (up to 60 days more), you must notify the requester within the first 30 days explaining why
  • If you notify on Day 31, the extension is legally invalid

Legal Shield: Article 12.3 RGPD. In this case, LOGITRAVEL took 13 months—a catastrophic violation.

3. Maintain Access Request Documentation

Even for old data (like LOGITRAVEL's 2011 subscriptions), you must be able to reconstruct basic information.

Minimum Documentation:

  • Date of data collection
  • Source of data (direct from user, third party, public register)
  • Legal basis for processing
  • Categories of data held
  • Any third parties who received the data

Business Reality: If you genuinely cannot reconstruct these details after many years, document your reasonable efforts and explain the gap honestly. LOGITRAVEL provided what they could from 2011 but admitted gaps—the AEPD accepted this.

4. Separate Unsubscription from Deletion

Marketing opt-outs ≠ full data deletion.

Protocol:

  • "Unsubscribe" buttons should remove someone from marketing lists
  • This does NOT automatically delete all their data if you have other lawful grounds to keep it (e.g., contracts, legal obligations)
  • When someone unsubscribes, ask: "Do you also want us to delete all your personal data?" Don't assume.

5. Train Front-Line Staff

The AEPD explicitly noted that customer service agents misunderstood the procedure.

Action:

  • GDPR rights training must be mandatory for anyone who receives customer requests
  • Create simple flowcharts: "Did customer ask for access? → Route to DPO/Compliance, NOT customer service"
  • Test understanding quarterly

6. Document Your Reasonable Efforts

When LOGITRAVEL eventually responded in October 2024, they explained the gaps in their records and what they could provide.

Best Practice:

  • If you can't provide complete information, document why
  • Show what efforts you made to reconstruct the information
  • Provide everything you do have

Legal Effect: This honesty helped LOGITRAVEL avoid a fine—they got a warning instead.

7. Cross-Border Complaints Are Serious

This case involved IMI (Internal Market Information system) because the complaint came from Germany.

Business Impact:

  • Cross-border cases take longer (authorities must coordinate)
  • But penalties can be just as severe
  • If you operate internationally, your DPO must understand IMI procedures

Summary of Business Risk

Good News: LOGITRAVEL escaped with a warning (€0 fine) despite a clear, serious violation because:

  1. They eventually cooperated fully
  2. They implemented comprehensive corrective measures
  3. The violation appeared to be procedural error, not malicious
  4. They demonstrated genuine remediation efforts

Bad News: The same violation by a company with prior offences or refusing to cooperate would likely result in fines up to €20 million or 4% of global turnover under Article 83.5 RGPD.

Key Takeaway: Access requests are not optional, and "we deleted your data" is never an acceptable response to "show me my data." You must provide the information BEFORE deletion.

Link to Official AEPD PDF

Legal Disclaimer

Informational Purposes Only: The content provided by ANRO DIGITAL SOLUTIONS S.L.U. (including resolution summaries, infographics, and case analyses) is for educational and informational purposes only.

No Legal Advice: This information does not constitute legal advice, a formal legal opinion, or a substitute for professional legal counsel. The interpretation of data protection laws (including the GDPR, LOPDGDD, and AEPD resolutions) is subject to change and can vary based on specific facts and circumstances.

No Liability: ANRO DIGITAL SOLUTIONS S.L.U. assumes no responsibility or liability for any actions taken, or not taken, based on the information provided on this website. While we strive for accuracy, we make no guarantees regarding the completeness or timeliness of the information.

Consult a Professional: Data protection compliance is a complex legal requirement. You should not act upon this information without seeking advice from a qualified Data Protection Officer (DPO) or a specialist data protection lawyer licensed to practice in your jurisdiction.

Third-Party Links: Links to official AEPD documents are provided for convenience. We are not responsible for the content or availability of these external government portals.

Este resumen tiene carácter meramente informativo. Para más información, consulte nuestro Aviso Legal.

ANRO Privacy Logo
Providing clear, reliable information on GDPR and data privacy standards to help you navigate the digital landscape securely.
Legal
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram