Spain's data protection authority has fined a solar-panel marketer €10,000 over a 46-second sales call. The central piece of evidence in the case is the recording provided by the citizen himself, the very move the authority has been recommending since 2023. The complainant was on Spain's do-not-call registry, asked where his number had come from, and the agent replied that she worked "from a database".
The resolution splits the fine into two halves. €5,000 for calling without valid consent and another €5,000 for failing to explain where the data came from, which is mandatory whenever the data is not collected from the person directly.
The detail that matters to any SMB sits in the company's defence. It argued that the data came from external providers, under a contract guaranteeing its lawfulness, and that the calls were handled by an automated platform with no manual dialling. It made no difference. Whoever makes the call answers for it, even if the database was bought and the campaign outsourced. Delegating the execution does not delegate the responsibility.
And there is a change of scenery worth noting. Every person with a phone is now a potential case file. The question is no longer whether your campaign complies on paper, but what can be heard when someone records it. How the regulator reads a company's preparation is something we covered in €680,000 after the breach.