AEPD Proceeding EXP202213023: What Swiss Companies Can Learn from the Spanish Fine

5 min readLast updated By Philipp Staiger

Proceeding EXP202213023 of the AEPD at a glance

In proceeding EXP202213023 the AEPD (Agencia Española de Protección de Datos) examined the inadequate handling of data subject requests by a controller established in Spain. Based on the published decision text, the focus of the review lay on the practical implementation of the right to erasure under Art. 17(1) GDPR and on the duty to facilitate the exercise of data subject rights under Art. 12(2) GDPR.

The AEPD imposed on the controller both a fine under Art. 83 GDPR and a corrective order requiring the adjustment of internal processes. Both instruments are anchored in Art. 58(2) GDPR and are regularly combined in Spanish supervisory practice. For Swiss controllers and processors that process data of persons located in the European Union, the proceeding offers concrete guidance on the expectations of European supervisory authorities. Engagement with the GDPR therefore remains indispensable even for companies headquartered in Switzerland; a deeper overview is provided in our GDPR guide.

Facts and legal assessment

The investigation was triggered by a complaint from a data subject whose erasure request, according to the decision, was not processed in time and not in full. The AEPD subsequently examined not only the individual case but also the underlying processes of the controller. The decisive benchmarks were Art. 5(1)(a) GDPR (lawfulness, transparency and fairness), Art. 12(3) GDPR (one-month response deadline) and Art. 17(1) GDPR (right to erasure).

The authority found that the internal workflows provided neither a clear allocation of responsibility nor a documented escalation procedure. The AEPD assessed this as a breach of the accountability principle under Art. 5(2) GDPR in conjunction with Art. 24(1) GDPR. From the perspective of Dr. M. Hofstetter, the case shows in exemplary fashion that supervisory authorities are increasingly examining not the individual incident but the structural compliance of the controller. A comparable orientation can be observed in the practice of the FDPIC (Federal Data Protection and Information Commissioner) under the Swiss DSG (Federal Act on Data Protection / FADP).

Fine, order and decision in the GDPR context

The AEPD consistently distinguishes between three instruments in its decision practice. The fine under Art. 83 GDPR covers the imposition of an administrative fine, which for breaches of data subject rights can amount to up to EUR 20 million or 4 percent of the worldwide annual turnover of the preceding financial year. The order under Art. 58(2)(d) GDPR obliges the controller to bring processing operations into compliance with the Regulation in a specified manner and within a specified period. The decision is the binding administrative act as a whole, including its reasoning and information on legal remedies.

In the present proceeding EXP202213023, fine and order were imposed cumulatively. The corrective order required the controller to demonstrably adapt its procedure for handling erasure requests within a deadline set by the authority. Non-compliance with such an order can, pursuant to Art. 83(6) GDPR, trigger a further fine within the higher administrative fine bracket. This cumulative effect is frequently underestimated in practice.

Operational weaknesses in the data subject rights workflow

A. Brunner classifies the deficiencies criticised in the proceeding from the perspective of an ISO 27001 lead auditor. Typical operational weaknesses that lead to fines under Art. 17 GDPR concern four areas.

  • First, a defined intake channel for data subject requests, operated independently of the marketing or customer service inbox, is often missing.
  • Second, there is no documented workflow that binds the identification of the data subject, the search across all data sources and the confirmation of erasure.
  • Third, processors under Art. 28 GDPR are not systematically integrated into the erasure process, although the controller is obliged under Art. 17(2) GDPR to forward such requests.
  • Fourth, evidence of the actual erasure within the meaning of the accountability principle is missing; retention periods under commercial, tax or social-insurance law are not cleanly documented.

A consistent integration with the information security management system under ISO/IEC 27001 considerably reduces this risk; details are set out in our ISO 27001 guide.

What this means for Swiss companies

Swiss controllers are directly affected in two constellations. First, they fall under the GDPR pursuant to Art. 3(2) GDPR when they offer goods or services to persons in the Union or monitor their behaviour. In this case an EU Representative under Art. 27 GDPR must regularly be appointed. Second, the Swiss DSG (Federal Act on Data Protection / FADP) applies in parallel; it entered into force on 1 September 2023 and provides in Art. 32(2)(c) DSG for an autonomous right to destruction and rectification.

K. Aebischer underlines the operational consequence. Swiss SMEs should design their processes for handling data subject requests so that they satisfy both the GDPR one-month deadline under Art. 12(3) GDPR and the requirements of the DSG. A unified workflow definition avoids duplicate processes and reduces the risk of fines vis-à-vis European supervisory authorities. A comparative overview of the two regimes is provided in our DSG guide (German-language pillar).

Documentation and evidentiary duties

The accountability principle under Art. 5(2) GDPR and Art. 24 GDPR requires the controller to actively demonstrate conformity. Proceeding EXP202213023 shows that the AEPD consistently allocates the burden of proof to the controller. Anyone who cannot show when an erasure request was received, who handled it and when erasure was carried out in which systems bears the risk of being fined.

In practice, a three-tier evidentiary architecture has proved effective. First, a ticket system or a dedicated request register documents every incoming request with a timestamp. Second, an erasure concept records in which systems, backups and at which processors personal data are stored. Third, an execution log evidences the actual erasure or anonymisation. This architecture simultaneously satisfies the requirements of Art. 30 GDPR for Records of Processing Activities (ROPA) as well as the parallel duty under Art. 12 DSG.

Transferable lessons for DACH compliance

Four transferable lessons can be drawn from the proceeding. First, controllers should actively measure their response times rather than merely setting them on paper. Second, the contractual and procedural integration of processors under Art. 28 GDPR is a frequent weak point, which in supervisory proceedings regularly results in cumulative liability. Third, the interface between data protection and IT security must be clearly regulated; in practice, erasures often fail because of backup concepts that are not aligned with the right to erasure.

Fourth, the accountability principle calls for active monitoring. N. Köhler adds, from the editorial perspective, that internal data protection policies should be drafted concisely, formally and in an audit-ready manner. A deeper engagement with the roles is provided in our comparison DPO vs. CISO; on the question of the EU Representative see EU vs. UK Representative.

How SIDD supports you

SIDD supports Swiss controllers in implementing the requirements derivable from the AEPD proceeding. In our mandate as external DPO under GDPR Art. 37 we accompany the definition of audit-ready workflows for data subject rights and ensure the interface to the European supervisory authorities. In our mandate as Swiss data protection advisor under Art. 10 DSG we manage the parallel DSG duties.

For controllers without an establishment in the Union we additionally provide the EU Representative under Art. 27 GDPR. This function is a precondition for direct reachability vis-à-vis authorities such as the AEPD and reduces the risk of being classified as unreachable in the event of proceedings. As at the time of publication, we expect European supervisory practice to continue intensifying its structural review. Early preparation is therefore the most effective protection against fines under Art. 83 GDPR.

AEPD Proceeding EXP202213023: What Swiss Companies Can Learn from the Spanish Fine

INSIGHT

All
15 January 2026
Philipp Staiger
In proceeding EXP202213023 the AEPD (Agencia Española de Protección de Datos) sanctioned the deficient implementation of the right to erasure. The article situates the fine and transfers the lessons to GDPR and Swiss DSG compliance for Swiss controllers.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.