On 3 September 2023, a German resident (A.A.A.) received an unsolicited marketing email from Spanish travel company LOGITRAVEL promoting "AIDA cruises with flight and onboard credit from €799." The recipient had no prior relationship with the company and never signed up for their newsletter.
The Request for Information: On the same day, A.A.A. exercised their Article 15 GDPR right of access, requesting information about: (1) the origin of their data, (2) the legal basis for processing, and (3) a copy of their personal data.
The Company's Response: LOGITRAVEL replied on 11 September 2023, confirming the person had been removed from their mailing lists and that their data would be deleted "in accordance with applicable legal provisions." However, they completely ignored the Article 15 access request—providing no information about data origin, legal basis, or a copy of the data.
The Investigation: The German data protection authority (Lower Saxony) filed the complaint through the IMI system. It was transferred to Spain's AEPD because LOGITRAVEL's sole establishment is in Spain. The AEPD investigation revealed:
The Company's Defence: LOGITRAVEL admitted their staff made an error. When A.A.A. requested both unsubscription AND data access simultaneously, customer service agents incorrectly assumed that unsubscribing (which deleted the data) completed both requests. They failed to provide the access information before deletion.
The Corrective Actions: After receiving the AEPD's information request in October 2024, LOGITRAVEL:

Based on Resolution EXP202314369, here is the compliance protocol for handling access requests:
When someone exercises multiple rights simultaneously (e.g., unsubscription + access), each right requires separate fulfillment.
Protocol:
Legal Basis: Article 12.3 RGPD requires response within one month. Deletion does not excuse providing access information first.
You have 30 days to respond to access requests—no exceptions without formal extension notice.
Action:
Legal Shield: Article 12.3 RGPD. In this case, LOGITRAVEL took 13 months—a catastrophic violation.
Even for old data (like LOGITRAVEL's 2011 subscriptions), you must be able to reconstruct basic information.
Minimum Documentation:
Business Reality: If you genuinely cannot reconstruct these details after many years, document your reasonable efforts and explain the gap honestly. LOGITRAVEL provided what they could from 2011 but admitted gaps—the AEPD accepted this.
Marketing opt-outs ≠ full data deletion.
Protocol:
The AEPD explicitly noted that customer service agents misunderstood the procedure.
Action:
When LOGITRAVEL eventually responded in October 2024, they explained the gaps in their records and what they could provide.
Best Practice:
Legal Effect: This honesty helped LOGITRAVEL avoid a fine—they got a warning instead.
This case involved IMI (Internal Market Information system) because the complaint came from Germany.
Business Impact:
Good News: LOGITRAVEL escaped with a warning (€0 fine) despite a clear, serious violation because:
Bad News: The same violation by a company with prior offences or refusing to cooperate would likely result in fines up to €20 million or 4% of global turnover under Article 83.5 RGPD.
Key Takeaway: Access requests are not optional, and "we deleted your data" is never an acceptable response to "show me my data." You must provide the information BEFORE deletion.
Informational Purposes Only: The content provided by ANRO DIGITAL SOLUTIONS S.L.U. (including resolution summaries, infographics, and case analyses) is for educational and informational purposes only.
No Legal Advice: This information does not constitute legal advice, a formal legal opinion, or a substitute for professional legal counsel. The interpretation of data protection laws (including the GDPR, LOPDGDD, and AEPD resolutions) is subject to change and can vary based on specific facts and circumstances.
No Liability: ANRO DIGITAL SOLUTIONS S.L.U. assumes no responsibility or liability for any actions taken, or not taken, based on the information provided on this website. While we strive for accuracy, we make no guarantees regarding the completeness or timeliness of the information.
Consult a Professional: Data protection compliance is a complex legal requirement. You should not act upon this information without seeking advice from a qualified Data Protection Officer (DPO) or a specialist data protection lawyer licensed to practice in your jurisdiction.
Third-Party Links: Links to official AEPD documents are provided for convenience. We are not responsible for the content or availability of these external government portals.
Este resumen tiene carácter meramente informativo. Para más información, consulte nuestro Aviso Legal.