P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Spain fines Securitas Direct €100,000 for routing data rights to a premium rate 902 number

The AEPD fined Securitas Direct €100,000 because one alarm plaque told people to exercise access and objection on a chargeable 902 line. The free channels on its website did not cure it.

By Parminder Kumar Sharma · · 12 min read

Editorial illustration for the briefing: Spain fines Securitas Direct €100,000 for routing data rights to a premium rate 902 number

A fine signed in 2023, published 1,300 days later

The Spanish data protection authority, the AEPD, signed resolution PS/00426/2021 on 23 February 2023. Its own resolutions database gives the publication date as 15 September 2026. That is 1,300 days between signature and publication, on our arithmetic. The European Data Protection Board summarised the case on 22 September 2026, which is where most UK compliance teams will have met it for the first time.

The substance is small and unusually clear. Securitas Direct put a warning plaque on the outside of the homes it fits with alarms and cameras. One model of that plaque carried a premium-rate 902 number, the company's web address, and the line derecho de acceso y oposición en el tel. indicado, meaning the rights of access and objection are exercised on the number shown. The AEPD found that this breached Article 12 of the GDPR, in particular Article 12(2), fined the company €100,000, and ordered it to replace the plaques within twelve months.

What the delay does not establish is anything about the state of the case. The published file carries no printed date, records no appeal, and gives no reason for the three and a half years between signature and publication. Spanish law, Article 50 of the LOPDGDD, requires publication once the parties have been notified, and a company that tells the AEPD it intends to go to the Audiencia Nacional can have the resolution stayed. We could not verify whether that happened here, and we do not assert it.

What the AEPD actually decided, and what it refused to decide

The complaint came from FACUA, a consumer association, on 10 June 2021. It argued that the 902 number was not free and so breached Article 12(7) of the LOPDGDD, the Spanish rule that the controller's own actions in answering a rights request must be free of charge.

The AEPD rejected that argument. A 902 number carries no payment to the person called: the caller pays for use of the network, not for the content of the service. Free of charge, in Article 12(5) of the GDPR and Article 12(7) of the LOPDGDD, means no consideration flowing to the controller. On that ground the AEPD found for Securitas Direct.

The infringement it did find is narrower and harder to argue with. Article 12(2) says the controller shall facilitate the exercise of data subject rights. Read with Article 12(2) of the LOPDGDD, which says the means offered must be easily accessible, the AEPD held that all the means a controller offers must clear that bar, not merely one of them. A 902 call costs more than a call to an ordinary landline or mobile number and, per the national numbering guide, is not usually included in the flat-rate bundles most consumers buy. So the plaque named a means that was not easy to use, even though the privacy policy behind the web address on the same plaque offered a free email address and a postal address.

EDPB summary against the text of AEPD resolution PS/00426/2021

PointEDPB news item, 22 Sep 2026AEPD resolution
Ground of the fineRights must be exercisable free of chargeArticle 12(5) was respected; the breach is the duty in Article 12(2) to facilitate
Other free channelsDid not remedy the issueAgreed, because every means offered must be easily accessible
Date of final decision1 February 2023Signed 23 February 2023 per the AEPD listing; no date printed in the file
Corrective measureReplace the notices within 12 monthsSame, running from the date the resolution becomes enforceable

The decision is also explicit that a premium-rate number on a warning sign is not itself unlawful. Private security rules require a contact number on the sign so that police or a neighbour can report an alarm. What crossed the line was the legend tying two named rights, access and objection, to that number.

Four comfortable arguments that failed

Securitas Direct fought the case at every stage, and the arguments it used are the ones most organisations reach for. They are worth setting out because each of them is a label rather than a control.

Defences raised by Securitas Direct and the AEPD's answer, from PS/00426/2021

Argument advancedHow the AEPD answered
The 902 line was an extra channel, complementary to the free ones on the websiteArticle 12(2) of the LOPDGDD refers to the means in the plural, without distinction, so all of them must be easily accessible
Only one rights request in the first quarter of 2021 arrived through the 902 line, so nobody was deterredTake-up through other channels does not cure the channel named on the sign; the sign is the first layer of information people see
Private security rules oblige us to print a contact number on the plaqueAccepted, and never in issue; the breach is the sentence routing access and objection to that number
Regional consumer authorities closed identical complaints about the same numberDifferent test and different protected person: consumer law protects the customer where an alternative geographic number exists, the GDPR protects the data subject

There is one more point that a UK reader should notice. The company's own advertising used a free 900 number for sales enquiries while the rights legend pointed at a chargeable 902 number. The AEPD used that contrast as evidence of a serious lack of diligence, and was careful to say it was not enough to prove intent. Method separated from accusation: the regulator treated the sales number as evidence of what the company knew about call costs, not as proof that it set out to obstruct anyone.

How €100,000 was reached, and what was not discounted

A timeline, not to scale, of the AEPD case against Securitas Direct: the plaque with the 902 rights legend first used in 2011, the GDPR applying on 25 May 2018, the FACUA complaint on 10 June 2021, the legend dropped in September 2021, proceedings opened on 24 May 2022, a fine of 100,000 EUR proposed on 27 January 2023 and signed on 23 February 2023, publication on 15 September 2026. Bars below show the replacement deadline growing from one month to six to twelve.
Drawn from AEPD resolution PS/00426/2021, the AEPD resolutions listing and the EDPB news item of 22 September 2026.

The resolution records turnover for Securitas Direct España of €820 million in 2019. Article 83(5) sets the ceiling at the higher of €20 million or 4 per cent of total worldwide annual turnover for the preceding financial year. On the only turnover figure the decision gives, 4 per cent is €32.8 million, so the fine is about 0.3 per cent of the applicable ceiling and about 0.012 per cent of that turnover. That arithmetic is ours, and the decision does not compute a ratio or name a group turnover figure.

Aggravating factors applied in PS/00426/2021, and factors the decision records as absent

FactorWhat the decision says
Article 83(2)(a), nature, gravity and durationNational coverage, an enormous number of plaques, the first information a passer by receives, and use of the sign for more than three years after the GDPR became applicable
Article 83(2)(b), intent or negligenceSerious lack of diligence; intent expressly not established
Article 83(2)(k) with Article 76(2)(b) LOPDGDDThe company's business consists of processing personal data, so a higher standard of care applies
Mitigating factorsNone found
Reduction for voluntary payment or admissionNot recorded anywhere in the published resolution

On the reduction point, which matters to anyone modelling Spanish exposure: Article 85 of the Spanish administrative procedure law normally lets a firm cut a proposed fine by acknowledging liability or paying early. The published resolution records no such reduction, and the amount proposed on 27 January 2023 is the amount imposed. The opening decision, where those options are usually set out, is not published, so whether a reduction was offered is not stated. The reference to a voluntary payment period in the operative part is the collection window, not a discount.

The corrective order moved the other way. One month in the opening decision, six months in the proposal, twelve months in the final resolution. Securitas Direct had argued the order was impossible to comply with, since it could not enter the homes of former customers. The AEPD answered that a high cost is not impossibility, that former customers are outside the order because the company no longer processes data there, and that failure to comply with an order under Article 58(2) is a separate infringement under Article 83(6), exposed to the same ceiling.

The UK reading: the same duty, plus two new ones

Article 12(2) of the UK GDPR is word for word the EU text: the controller shall facilitate the exercise of data subject rights. Article 12(5) keeps the free of charge rule. Nothing in the Data (Use and Access) Act 2025 touched either provision.

What the UK does not have is the Spanish sentence the AEPD leaned on, Article 12(2) of the LOPDGDD, that the means must be easily accessible and that the right cannot be refused because the person chose a different means. A Spanish decision is not binding here, and the ICO reaches a similar destination by a different route: its right of access guidance says a subject access request can be made verbally or in writing, including by social media, to any part of your organisation, and does not have to go to a specific person or contact point. Organisations may invite use of a form or portal, but should make clear that it is not compulsory. On that guidance, a UK organisation that routes rights requests through one costly channel does not merely make the request expensive, it fails to recognise the requests arriving everywhere else.

Data (Use and Access) Act 2025 changes relevant to rights handling, with commencement from legislation.gov.uk

ProvisionWhat it doesIn force
Section 78Inserts Article 15(1A): the data subject is entitled only to what a reasonable and proportionate search producesRoyal Assent, 19 June 2025, treated as in force from 1 January 2024
Section 76Inserts Article 12A: one month from the relevant time, extendable by two months, with the clock stopped while identity or clarification is awaited5 February 2026, by S.I. 2026/82
Section 103Inserts section 164A of the Data Protection Act 2018: controllers must facilitate complaints, acknowledge within 30 days and respond without undue delay19 June 2026, by S.I. 2026/82

Section 164A(2) is the provision to hold next to this Spanish case. It says a controller must facilitate the making of complaints by taking steps such as providing a complaint form which can be completed electronically and by other means. The verb is the same verb as Article 12(2). Article 12(4) of the UK GDPR now also requires a controller refusing a request to tell the person they can complain to the controller under section 164A, as well as to the Commissioner.

The inference, and we label it as inference because no UK decision has tested it: a complaints route that costs money to use, or that exists only on a premium line or only inside an app, looks weak against a duty to facilitate that Parliament has just written twice. The AEPD's reasoning, that every route you publish must clear the bar and a good route elsewhere does not cure a bad route here, transfers to section 164A without much strain.

What to check this week

Take this with you

Rights and complaints channel audit

  • List every place your organisation tells the public how to exercise data rights or complain: signage, stickers on cameras, IVR menus, app screens, contracts, invoices, receipts, email footers and the privacy notice.
  • For each one, record the cost to the person of using it. Premium or non geographic numbers, per minute charges and paid postal returns all count.
  • Check the first layer specifically. The AEPD treated the plaque, not the privacy policy behind it, as the main way the controller engages the person.
  • Remove any wording that ties a named right to a single channel, such as access and objection on the number shown. Name the right and point to a free route.
  • Confirm that a request arriving anywhere, by phone, by social media, to a branch or to any employee, is recognised and logged, as the ICO guidance requires.
  • Publish a complaints route that meets section 164A: a form completable electronically and by other means, with a 30 day acknowledgement built into the workflow.
  • Update refusal letters so they mention the right to complain to the controller under section 164A as well as to the ICO.
  • Check physical estate you cannot easily reach. Old signs, stickers and plaques on sites you no longer service are the expensive part of any order to replace them.
  • Record the decision and the date. The AEPD counted the years a non compliant sign stayed in use as an aggravating factor.

The question that exposes the gap

Securitas Direct kept a plaque in use for about ten years, and dropped the rights legend from new plaques in September 2021, within three months of the complaint. The fine still landed, because the AEPD counted the plaques already on walls. An order to replace them followed, on a twelve month clock, with the company's own estimate of the cost running to a figure the published file redacts.

So the question is not whether your privacy notice offers a free channel. It is this: if someone read only the first thing your organisation shows them, the sign on the wall, the recorded menu, the line on the receipt, which route would they take to exercise a right or make a complaint, what would it cost them, and how many of those artefacts are still out there carrying wording you retired years ago?

Related: our briefing on the EDPB guidelines covering whether to fine at all, and how the DSA and the GDPR interact, adopted on 21 September 2026, one day before the EDPB published this Spanish case.

Sources

  1. PrimaryResolution PS/00426/2021 against Securitas Direct España, S.A.U., read in full for the facts, the Article 12 reasoning, the aggravating factors, the 100,000 EUR fine and the twelve month orderAgencia Española de Protección de Datosaccessed 2026-09-22
  2. PrimaryAEPD resolutions listing entry for PS-00426-2021, used for the signature date of 23 February 2023 and the publication date of 15 September 2026Agencia Española de Protección de Datosaccessed 2026-09-22
  3. PrimaryEDPB national news item of 22 September 2026 summarising the case, used for the summary wording and the stated date of final decisionEuropean Data Protection Boardaccessed 2026-09-22
  4. PrimaryEDPB plenary news of 21 September 2026 on the guidelines for deciding whether to impose a fine and the final DSA and GDPR guidelinesEuropean Data Protection Boardaccessed 2026-09-22
  5. PrimaryArticle 12 of the UK GDPR as amended, used to confirm the facilitation duty and the new references to Article 12A and section 164Alegislation.gov.ukaccessed 2026-09-22
  6. PrimaryData (Use and Access) Act 2025 section 103, inserting section 164A on complaints to controllers, with commencement on 19 June 2026legislation.gov.ukaccessed 2026-09-22
  7. PrimaryData (Use and Access) Act 2025 section 76 on time limits and Article 12A, in force 5 February 2026legislation.gov.ukaccessed 2026-09-22
  8. PrimaryData (Use and Access) Act 2025 section 78 on reasonable and proportionate searches, in force at Royal Assentlegislation.gov.ukaccessed 2026-09-22
  9. PrimaryICO guidance on recognising a subject access request, used for the rule that a request may be made by any means to any part of an organisationInformation Commissioner's Officeaccessed 2026-09-22
  10. PrimaryICO news of 23 June 2026 confirming the complaints duty in force from 19 June 2026 and the 30 day acknowledgementInformation Commissioner's Officeaccessed 2026-09-22
  11. Reported byStatement by the complainant consumer association of 16 September 2026, used only to date public reporting of the resolutionFACUAaccessed 2026-09-22

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.