The Spanish Data Protection Agency (AEPD) has fined Flexicar €680,000 over a 2024 breach in which data submitted by customers through the contact forms on its website was compromised. The ruling, dated July 28, breaks down three infringements: €400,000 for the lack of integrity and confidentiality of the data, €250,000 for insufficient security measures and €30,000 for deficient information about data retention.

The nuance that matters to any company: the AEPD is not sanctioning the firm for suffering the attack. It is sanctioning it because the measures in place before the attack were not proportional to the risk, and because the information given afterwards fell short. Suffering a breach is not an infringement; having failed to prepare for one is.

And there is a second lesson: when data gets stolen, containing the incident does not close it. What remains is the conversation with your customers and with the regulator, and that conversation has a price. How a real incident reads from start to finish, and what it demands of whoever reviews it, is what we covered in The Hugging Face breach.