Spain fines Securitas Direct €100,000 for routing data rights to a premium rate 902 number
The AEPD fined Securitas Direct €100,000 because one alarm plaque told people to exercise access and objection on a chargeable 902 line. The free channels on its website did not cure it.
By Parminder Kumar Sharma · · 12 min read

A fine signed in 2023, published 1,300 days later
The Spanish data protection authority, the AEPD, signed resolution PS/00426/2021 on 23 February 2023. Its own resolutions database gives the publication date as 15 September 2026. That is 1,300 days between signature and publication, on our arithmetic. The European Data Protection Board summarised the case on 22 September 2026, which is where most UK compliance teams will have met it for the first time.
The substance is small and unusually clear. Securitas Direct put a warning plaque on the outside of the homes it fits with alarms and cameras. One model of that plaque carried a premium-rate 902 number, the company's web address, and the line derecho de acceso y oposición en el tel. indicado, meaning the rights of access and objection are exercised on the number shown. The AEPD found that this breached Article 12 of the GDPR, in particular Article 12(2), fined the company €100,000, and ordered it to replace the plaques within twelve months.
What the delay does not establish is anything about the state of the case. The published file carries no printed date, records no appeal, and gives no reason for the three and a half years between signature and publication. Spanish law, Article 50 of the LOPDGDD, requires publication once the parties have been notified, and a company that tells the AEPD it intends to go to the Audiencia Nacional can have the resolution stayed. We could not verify whether that happened here, and we do not assert it.
What the AEPD actually decided, and what it refused to decide
The complaint came from FACUA, a consumer association, on 10 June 2021. It argued that the 902 number was not free and so breached Article 12(7) of the LOPDGDD, the Spanish rule that the controller's own actions in answering a rights request must be free of charge.
The AEPD rejected that argument. A 902 number carries no payment to the person called: the caller pays for use of the network, not for the content of the service. Free of charge, in Article 12(5) of the GDPR and Article 12(7) of the LOPDGDD, means no consideration flowing to the controller. On that ground the AEPD found for Securitas Direct.
The infringement it did find is narrower and harder to argue with. Article 12(2) says the controller shall facilitate the exercise of data subject rights. Read with Article 12(2) of the LOPDGDD, which says the means offered must be easily accessible, the AEPD held that all the means a controller offers must clear that bar, not merely one of them. A 902 call costs more than a call to an ordinary landline or mobile number and, per the national numbering guide, is not usually included in the flat-rate bundles most consumers buy. So the plaque named a means that was not easy to use, even though the privacy policy behind the web address on the same plaque offered a free email address and a postal address.
EDPB summary against the text of AEPD resolution PS/00426/2021
| Point | EDPB news item, 22 Sep 2026 | AEPD resolution |
|---|---|---|
| Ground of the fine | Rights must be exercisable free of charge | Article 12(5) was respected; the breach is the duty in Article 12(2) to facilitate |
| Other free channels | Did not remedy the issue | Agreed, because every means offered must be easily accessible |
| Date of final decision | 1 February 2023 | Signed 23 February 2023 per the AEPD listing; no date printed in the file |
| Corrective measure | Replace the notices within 12 months | Same, running from the date the resolution becomes enforceable |
The decision is also explicit that a premium-rate number on a warning sign is not itself unlawful. Private security rules require a contact number on the sign so that police or a neighbour can report an alarm. What crossed the line was the legend tying two named rights, access and objection, to that number.
Four comfortable arguments that failed
Securitas Direct fought the case at every stage, and the arguments it used are the ones most organisations reach for. They are worth setting out because each of them is a label rather than a control.
Defences raised by Securitas Direct and the AEPD's answer, from PS/00426/2021
| Argument advanced | How the AEPD answered |
|---|---|
| The 902 line was an extra channel, complementary to the free ones on the website | Article 12(2) of the LOPDGDD refers to the means in the plural, without distinction, so all of them must be easily accessible |
| Only one rights request in the first quarter of 2021 arrived through the 902 line, so nobody was deterred | Take-up through other channels does not cure the channel named on the sign; the sign is the first layer of information people see |
| Private security rules oblige us to print a contact number on the plaque | Accepted, and never in issue; the breach is the sentence routing access and objection to that number |
| Regional consumer authorities closed identical complaints about the same number | Different test and different protected person: consumer law protects the customer where an alternative geographic number exists, the GDPR protects the data subject |
There is one more point that a UK reader should notice. The company's own advertising used a free 900 number for sales enquiries while the rights legend pointed at a chargeable 902 number. The AEPD used that contrast as evidence of a serious lack of diligence, and was careful to say it was not enough to prove intent. Method separated from accusation: the regulator treated the sales number as evidence of what the company knew about call costs, not as proof that it set out to obstruct anyone.
How €100,000 was reached, and what was not discounted
The resolution records turnover for Securitas Direct España of €820 million in 2019. Article 83(5) sets the ceiling at the higher of €20 million or 4 per cent of total worldwide annual turnover for the preceding financial year. On the only turnover figure the decision gives, 4 per cent is €32.8 million, so the fine is about 0.3 per cent of the applicable ceiling and about 0.012 per cent of that turnover. That arithmetic is ours, and the decision does not compute a ratio or name a group turnover figure.
Aggravating factors applied in PS/00426/2021, and factors the decision records as absent
| Factor | What the decision says |
|---|---|
| Article 83(2)(a), nature, gravity and duration | National coverage, an enormous number of plaques, the first information a passer by receives, and use of the sign for more than three years after the GDPR became applicable |
| Article 83(2)(b), intent or negligence | Serious lack of diligence; intent expressly not established |
| Article 83(2)(k) with Article 76(2)(b) LOPDGDD | The company's business consists of processing personal data, so a higher standard of care applies |
| Mitigating factors | None found |
| Reduction for voluntary payment or admission | Not recorded anywhere in the published resolution |
On the reduction point, which matters to anyone modelling Spanish exposure: Article 85 of the Spanish administrative procedure law normally lets a firm cut a proposed fine by acknowledging liability or paying early. The published resolution records no such reduction, and the amount proposed on 27 January 2023 is the amount imposed. The opening decision, where those options are usually set out, is not published, so whether a reduction was offered is not stated. The reference to a voluntary payment period in the operative part is the collection window, not a discount.
The corrective order moved the other way. One month in the opening decision, six months in the proposal, twelve months in the final resolution. Securitas Direct had argued the order was impossible to comply with, since it could not enter the homes of former customers. The AEPD answered that a high cost is not impossibility, that former customers are outside the order because the company no longer processes data there, and that failure to comply with an order under Article 58(2) is a separate infringement under Article 83(6), exposed to the same ceiling.
The UK reading: the same duty, plus two new ones
Article 12(2) of the UK GDPR is word for word the EU text: the controller shall facilitate the exercise of data subject rights. Article 12(5) keeps the free of charge rule. Nothing in the Data (Use and Access) Act 2025 touched either provision.
What the UK does not have is the Spanish sentence the AEPD leaned on, Article 12(2) of the LOPDGDD, that the means must be easily accessible and that the right cannot be refused because the person chose a different means. A Spanish decision is not binding here, and the ICO reaches a similar destination by a different route: its right of access guidance says a subject access request can be made verbally or in writing, including by social media, to any part of your organisation, and does not have to go to a specific person or contact point. Organisations may invite use of a form or portal, but should make clear that it is not compulsory. On that guidance, a UK organisation that routes rights requests through one costly channel does not merely make the request expensive, it fails to recognise the requests arriving everywhere else.
Data (Use and Access) Act 2025 changes relevant to rights handling, with commencement from legislation.gov.uk
| Provision | What it does | In force |
|---|---|---|
| Section 78 | Inserts Article 15(1A): the data subject is entitled only to what a reasonable and proportionate search produces | Royal Assent, 19 June 2025, treated as in force from 1 January 2024 |
| Section 76 | Inserts Article 12A: one month from the relevant time, extendable by two months, with the clock stopped while identity or clarification is awaited | 5 February 2026, by S.I. 2026/82 |
| Section 103 | Inserts section 164A of the Data Protection Act 2018: controllers must facilitate complaints, acknowledge within 30 days and respond without undue delay | 19 June 2026, by S.I. 2026/82 |
Section 164A(2) is the provision to hold next to this Spanish case. It says a controller must facilitate the making of complaints by taking steps such as providing a complaint form which can be completed electronically and by other means. The verb is the same verb as Article 12(2). Article 12(4) of the UK GDPR now also requires a controller refusing a request to tell the person they can complain to the controller under section 164A, as well as to the Commissioner.
The inference, and we label it as inference because no UK decision has tested it: a complaints route that costs money to use, or that exists only on a premium line or only inside an app, looks weak against a duty to facilitate that Parliament has just written twice. The AEPD's reasoning, that every route you publish must clear the bar and a good route elsewhere does not cure a bad route here, transfers to section 164A without much strain.
What to check this week
Take this with you
Rights and complaints channel audit
- List every place your organisation tells the public how to exercise data rights or complain: signage, stickers on cameras, IVR menus, app screens, contracts, invoices, receipts, email footers and the privacy notice.
- For each one, record the cost to the person of using it. Premium or non geographic numbers, per minute charges and paid postal returns all count.
- Check the first layer specifically. The AEPD treated the plaque, not the privacy policy behind it, as the main way the controller engages the person.
- Remove any wording that ties a named right to a single channel, such as access and objection on the number shown. Name the right and point to a free route.
- Confirm that a request arriving anywhere, by phone, by social media, to a branch or to any employee, is recognised and logged, as the ICO guidance requires.
- Publish a complaints route that meets section 164A: a form completable electronically and by other means, with a 30 day acknowledgement built into the workflow.
- Update refusal letters so they mention the right to complain to the controller under section 164A as well as to the ICO.
- Check physical estate you cannot easily reach. Old signs, stickers and plaques on sites you no longer service are the expensive part of any order to replace them.
- Record the decision and the date. The AEPD counted the years a non compliant sign stayed in use as an aggravating factor.
The question that exposes the gap
Securitas Direct kept a plaque in use for about ten years, and dropped the rights legend from new plaques in September 2021, within three months of the complaint. The fine still landed, because the AEPD counted the plaques already on walls. An order to replace them followed, on a twelve month clock, with the company's own estimate of the cost running to a figure the published file redacts.
So the question is not whether your privacy notice offers a free channel. It is this: if someone read only the first thing your organisation shows them, the sign on the wall, the recorded menu, the line on the receipt, which route would they take to exercise a right or make a complaint, what would it cost them, and how many of those artefacts are still out there carrying wording you retired years ago?
Related: our briefing on the EDPB guidelines covering whether to fine at all, and how the DSA and the GDPR interact, adopted on 21 September 2026, one day before the EDPB published this Spanish case.
Sources
- PrimaryResolution PS/00426/2021 against Securitas Direct España, S.A.U., read in full for the facts, the Article 12 reasoning, the aggravating factors, the 100,000 EUR fine and the twelve month orderAgencia Española de Protección de Datosaccessed 2026-09-22
- PrimaryAEPD resolutions listing entry for PS-00426-2021, used for the signature date of 23 February 2023 and the publication date of 15 September 2026Agencia Española de Protección de Datosaccessed 2026-09-22
- PrimaryEDPB national news item of 22 September 2026 summarising the case, used for the summary wording and the stated date of final decisionEuropean Data Protection Boardaccessed 2026-09-22
- PrimaryEDPB plenary news of 21 September 2026 on the guidelines for deciding whether to impose a fine and the final DSA and GDPR guidelinesEuropean Data Protection Boardaccessed 2026-09-22
- PrimaryArticle 12 of the UK GDPR as amended, used to confirm the facilitation duty and the new references to Article 12A and section 164Alegislation.gov.ukaccessed 2026-09-22
- PrimaryData (Use and Access) Act 2025 section 103, inserting section 164A on complaints to controllers, with commencement on 19 June 2026legislation.gov.ukaccessed 2026-09-22
- PrimaryData (Use and Access) Act 2025 section 76 on time limits and Article 12A, in force 5 February 2026legislation.gov.ukaccessed 2026-09-22
- PrimaryData (Use and Access) Act 2025 section 78 on reasonable and proportionate searches, in force at Royal Assentlegislation.gov.ukaccessed 2026-09-22
- PrimaryICO guidance on recognising a subject access request, used for the rule that a request may be made by any means to any part of an organisationInformation Commissioner's Officeaccessed 2026-09-22
- PrimaryICO news of 23 June 2026 confirming the complaints duty in force from 19 June 2026 and the 30 day acknowledgementInformation Commissioner's Officeaccessed 2026-09-22
- Reported byStatement by the complainant consumer association of 16 September 2026, used only to date public reporting of the resolutionFACUAaccessed 2026-09-22


