top of page

TOM’s Breach, Audit Rights & Indemnities by Spanish Data Protection Authority under GDPR

1h
5 min read

The General Data Protection Regulation (“GDPR”) is globally one of the most comprehensive and consequential data protection regimes. GDPR encapsulates one of the stringent data protection laws governing the processing and protection of personal data as formulated by the European Union (“EU”). Spain, as a member of the EU, is governed by the GDPR, that is directly applicable and binding upon all the EU Member States. Spain by way of its own legislation, Ley Orgánica 3/2018 (LOPDGDD), adapts GDPR within Spain; with Agencia Española de Protección de Datos (“AEPD”), or the Spanish Data Protection Agency acting as the national regulator/ authority ensuring GDPR implementation within Spain.


Regulatory Framework


AEPD ensures security over data breaches, by way of enforcing adherence with the provisions of GDPR. Some of the key GDPR provisions being:


  • Article 32 (Security of processing), that obligates controllers and processors to implement technical and organisational measures (“TOMs”) appropriate to the risk, taking into account the implementation costs, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for individual rights and freedoms. TOMs specifically encompass pseudonymisation, encryption, confidentiality, integrity, resilience of systems, and processes for regularly testing, assessing, and evaluating the effectiveness of security measures.


  • Article 28(1) & 28(3) (Processor Governance), that imposes a strict duty on data controllers to engage only those processors providing "sufficient guarantees" to implement appropriate TOMs. Under Article 28(3)(h), data processing agreements (“DPAs”) must expressly mandate that the processor makes available all information necessary to demonstrate compliance and allows for and contributes to audits, including inspections, conducted by the controller or an auditor mandated by the controller.


  • Article 5(2) and 24 (Principle of Accountability), which establishes that the controller remains directly responsible for, and must be able to demonstrate compliance with, all data protection principles, including active supervision of third-party processors.


  • Articles 82 & 83 (Civil Compensation vs. Administrative Sanctions), that distinguishes between civil indemnification for material or non-material damage suffered by data subjects under Article 82 and administrative fines imposed by supervisory authorities under Article 83.


  • Articles 33 & 34 (Personal Data Breach Notification), which impose time-bound notification duties once a personal data breach has occurred. Article 33 requires the controller to notify the AEPD without undue delay and, where feasible, within 72 hours of becoming aware of the breach, unless it is unlikely to result in a risk to individuals' rights and freedoms. Furthermore Article 34 requires the controller to communicate the breach to affected data subjects without undue delay where it is likely to result in a high risk to their rights and freedoms. Under Article 33(2), the processor is separately obligated to notify the controller without undue delay upon becoming aware of a breach.


Judicial Interpretation & AEPD Enforcement Doctrines:


1. TOMs Breaches and the Standard of Security (Article 32 GDPR)


TOMs are the practical safeguards adopted by the controller to protect personal data against unauthorised or unlawful processing, loss, destruction, alteration or access. The AEPD's enforcement doctrine mirrors the jurisprudence of the Court of Justice of the European Union (CJEU) in Case C-340/21 Natsionalna agentsia za prihodite, which establishes that the occurrence of a data breach does not create an irrebuttable presumption that the controller/ processor failed to implement appropriate TOMs nor does it establish that Article 32 has been violated. The adequacy of TOMs must be assessed concretely, having regard to the risks, state of the art, cost,nature / scope / context / purpose of processing, etc. In its sanctioning resolutions, the AEPD evaluates TOM adequacy on a substantive rather than formalistic basis. For instance, in AEPD Resolution EXP202209677 (HM Hospitales), the authority imposed a €200,000 fine under Article 32 GDPR in circumstances involving deficiencies in the security and maintenance of software used in the processing of special-category health data and the entity, acting as a controller, failed to conduct regular audits and vulnerability assessments on health-data software over a multi-year period. The Authority held that continuous verification and testing are mandatory statutory components of Article 32(1)(d) GDPR, particularly when processing special category data.


2. Active Duty of Supervision & Audit Rights (Article 28 GDPR)


Audit rights are the mechanism through which the controller can verify whether the processor is complying with these obligations. Article 28(3)(h) requires a processor to provide information necessary to demonstrate compliance and to allow and contribute to audits and inspections conducted by the controller or its authorised auditor. Accordingly, Audit Rights are not merely commercial protections; they form part of the controller’s ability to monitor and demonstrate compliance with the GDPR. In a landmark recent enforcement decision, AEPD had imposed two fines on Vodafone España, S.A.U amounting to €1.8 million for various GDPR violations. The telecommunications company has already paid the fines and filed two appeals with the National Court, denying direct responsibility for the incidents and claiming they were caused by third parties. In this case, AEPD had imposed two fines of €150,000 each for violating Article 6.1 of the GDPR, concerning the lawfulness of processing personal data, and an additional penalty of €750,000 for non-compliance with Article 32, regarding technical and organizational security measures.


In pursuance to the same, AEPD have articulated some of the key standards in respect to the data processor oversight and audit rights; such as the Audit rights as envisaged under Article 28(3)(h) not merely an optional contractual entitlement for the benefit of the controller; rather its operating as an administrative requirement ensuring that the controller actively verifies that processors, distributors, and sub-agents maintain effective technical and organizational safeguards. Moreover, mere inserting of standard data protection clauses into commercial agreements without demanding demonstrable evidence of compliance, conducting pre-contractual due diligence, or performing periodic verification audits constitutes a direct violation of Article 28(1) and Article 24 GDPR.


3. Contractual Indemnities


Indemnities serve a different but complementary purpose. While TOMs are primarily preventive measures; and audit rights are designed for oversight, an indemnity is a contractual mechanism for allocating the financial consequences of a breach between the parties. A DPA may, for example, require the processor to indemnify the controller for specified losses, claims, costs or liabilities arising from the processor’s breach of its GDPR obligations.


Article 82 provides the GDPR’s statutory framework for liability and compensation. A person suffering material or non-material damage due to a GDPR violation has a right to compensation, while controllers and processors may be liable depending on their respective role and responsibility in the processing. A contractual indemnity does not remove a party’s statutory responsibility to data subjects or the regulator; rather, it determines how specified financial consequences may be allocated between the contracting parties.  


Conclusion


TOMs, audit rights and indemnities constitute three interrelated aspects of contractual and regulatory protection under the GDPR. While TOMs operate as preventive safeguards against data security risks, audit rights enable the controller to actively monitor and demonstrate the processor’s compliance, and indemnities provide a mechanism for allocating the financial consequences arising from a breach. The AEPD’s enforcement approach, read with the relevant provisions of the GDPR, reinforces the principle of proactive accountability under Article 5(2) of GDPR. Moreover, compliance cannot merely be ensured by incorporating standard data protection provisions into commercial agreements; rather the Controllers are required to undertake appropriate due diligence, ensure that processors implement adequate TOMs, and carry out meaningful and periodic verification of such measures. At the same time, contractual indemnities, while providing recourse between the contracting parties, do not absolve a controller or processor of its statutory obligations or regulatory liability under the GDPR. Accordingly, effective data protection governance requires a combination of appropriate technical and organisational safeguards, active processor oversight and suitable contractual allocation of financial risks.


The authors of the article are: Ms. Tripti Vini, Senior Partner; Mr. Rahul Jain, Partner; and Ms. Bushra Alam, Associate.


Comments


SUBSCRIBE TO OUR NEWSLETTER

Get updates on the latest publications, judgements, policy updates, webinars, reports and much more.

Thank you for subscribing!

bottom of page