The entry into force of Royal Decree 933/2021 has put data protection in the tourism sector in the spotlight. The obligation to collect and store a large volume of sensitive information about travelers for three years has generated concern among experts, who warn of privacy risks and possible sanctions. A disproportionate measure? The data that must be registered includes personal, financial and contractual information, such as ID card, address, bank card number and emails. This volume of information, combined with the obligation to store it for three years, increases the possibilities of leaks and misuse. Furthermore, some of this data, such as bank card information, is highly sensitive, which increases the risk of identity theft in the event of security breaches. Without robust protection guarantees, the risk of losing control over personal data is very high. This rule could also violate fundamental principles of the GDPR (General Data Protection Regulation), such as the principle of minimization, which requires limiting the collection of data to the minimum necessary to fulfill the intended purpose. Administrative burdens and legal risks for companies. Data protection is not only a concern for travelers, but also a challenge for businesses. The decree imposes a heavy administrative burden, especially on small businesses and the self-employed, who must implement technological systems to register, store and protect information properly. These investments, in addition to being costly, are complex to implement in companies with limited resources, which can lead to unintentional non-compliance and, ultimately, sanctions. The fines can be significant. Failure to comply with the GDPR due to issues such as data breaches, security failures or misuse of information can result in penalties of up to 20 million euros or 4% of the company's annual turnover, whichever is greater. In addition, the decree includes specific fines for violations related to the registration of travelers, ranging from 100 to 30.000 euros, depending on the severity. No less important is the impact on daily operations. Managing this data can slow down processes at the front desk, create conflicts with clients who refuse to provide additional information, and divert resources from other critical areas of the business. This is especially relevant in a highly competitive sector like tourism, where any delay or problem can negatively impact the customer experience and, ultimately, the establishment's reputation. The importance of ensuring the proportionality of the data The precedent of the annulment of Directive 2006/24/EC by the Court of Justice of the European Union, due to its indiscriminate nature, should serve as a warning. In the words of Ruth Benito, data protection expert at Elzaburu: “The massive storage of personal data without proportionate measures or clear justification generates risks that can be irreversible for privacy.” This scenario reinforces the need to put data protection at the center of any measure that involves the mass processing of personal information. Only a balanced approach, combining robust security guarantees with clear and proportionate justification, will ensure both public security and citizens' fundamental rights. At the same time, it is crucial to protect the competitiveness of the tourism sector, one of Spain's economic engines. Within this framework, companies must prepare to face this challenge by investing in compliance and data protection systems that not only meet regulatory requirements but also strengthen traveler confidence. Ruth Benito, Of Counsel. Privacy and Data Protection
The telecommunications sector in Spain takes an important step towards self-regulation with the implementation of the new Code of Conduct. AEPD and Autocontrol have launched a new mediation system, which came into effect on December 17, to resolve disputes regarding data protection in the sector out of court. More representation from the sector, more coverage for users. One of the main new features of the Code of Conduct is the expansion of its scope. The initial operators that formed part of the Protocol – Movistar, Orange, Vodafone and MásMóvil, among others – are now joined by Euskaltel, Virgin Telco, R and Telecable. This ensures greater representation of the sector, which directly benefits users by providing a common framework for resolving data protection-related complaints. The Code also expands the cases covered within its scope of application. This means that more types of claims can now be dealt with under this mechanism, although those seeking financial compensation are expressly excluded. This approach reinforces the Code's main objective: to facilitate a quick, free and effective solution to issues related to privacy and data protection. AUTOCONTROL: the key piece of the process to promote fast and flexible agreements. To guarantee impartiality, the Code designates the Advertising Jury of AUTOCONTROL as the supervisory body. This independent third party is responsible for managing the mediations between interested parties and participating operators. Mediation has a standard duration of 30 days, extendable up to three months if there are justified reasons. Although AUTOCONTROL's solution proposals are not binding, the agreement reached by both parties will be. In case of disagreement, the interested party may request that the complaint be elevated to the AUTOCONTROL Jury, provided that the operator agrees. A notable aspect of the Code is its commitment to the confidentiality of proceedings, a crucial requirement given that many claims may include sensitive information. However, the Jury's decisions are public, which brings transparency to the process and reinforces its credibility. 'Mediation, managed by an independent third party such as AUTOCONTROL, promotes quick and flexible agreements, although the non-binding nature of the proposed solutions may limit its effectiveness in certain cases. As is usual in any type of mediation, the solution proposals offered by the mediator – in this case the AUTOCRONTROL Mediation Unit – are not binding. Only the agreement that the parties could reach and the resolution of the AUTOCONTROL Jury would be binding, in the event that the parties voluntarily decide to submit the resolution to the Jury' Agustín Alguacil. A system of sanctions with a deterrent effect due to its transfer to the Spanish Data Protection Agency (AEPD). The Code reinforces its effectiveness through a system of sanctions for non-compliant operators. Infractions are classified as minor, serious or very serious, and can lead to anything from warnings to temporary suspension of rights within the Code or even expulsion. Although the sanctions do not include economic penalties, their deterrent effect lies in the reputational impact and in the transfer of the resolutions to the Spanish Data Protection Agency (AEPD). This mechanism complements the powers of the AEPD, ensuring that the self-regulation system is aligned with national and European regulations. Overall, the Code of Conduct is an example of how the private sector can organize effective self-regulation mechanisms, seeking a balance between sector autonomy and stakeholder rights. Agustín Alguacil, Associate, Legal Area. Business and Contracts
The European Data Protection Committee has finally ruled on the pay or OK controversy that Meta, the owner of Facebook and Instagram, introduced in Europe last year. The Committee, which responds to the English acronym EDPB, concludes that the procedure used by the technology giant to try to comply with the General Data Protection Regulation (GDPR) is not valid. First of all, it should be clear that this is not a court decision or new legislation, nor is it a binding resolution. What the EDPB has issued is an opinion in which, at the request of several European data protection authorities, it provides its interpretation regarding the fit of “pay or ok” in data protection legislation. Now, the impact can be very high, especially for large platforms that until recently allowed access to their content completely free of charge. This is because, in practice, the EDPB report establishes as a general rule that the payment of an amount (whether a one-time payment or through a subscription) cannot be offered as the only alternative to cookies. In this way, those platforms that maintain the pure “pay or ok” model, without additional options, will be obliged to be able to demonstrate that the system adopted does not force its users to accept cookies, but rather that they consent to them completely freely and this , with the presumptions that the EDPB opinion actually contains, is extremely complicated, if not impossible. It is not new legislation but the opinion must be taken into consideration. It is important to note that the EDPB is not ruling on Meta in a specific and individualized way, although that is the case that underlies the cause of its opinion, but this must be taken into consideration not only by Meta, but by all major web platforms. Legislation on cookies requires that those that are not strictly necessary for the functioning of the website must be expressly consented by users in order to be activated. Among these cookies are those for behavioral advertising, with which users are profiled and then impact them with advertising. And the consent that users give must be given completely freely. A large part of the business of large platforms is based on selling brands the possibility of impacting with their advertising those users who, due to their profile, will be more inclined to purchase their products or services. But profiling as invasive as that carried out by many platforms, whether through cookies or any other system, requires the consent of users, and the EDPB understands, in essence, that if the only alternative to such consent is to pay a sum of money, it must be presumed that the consent is not freely given, especially if the amount to be paid is disproportionate and if for a long time before the platform offered its content or services for free. Furthermore, it should be noted that the "pay or ok" also violates one of the conditions for valid consent, which is that it must be specific to the particular data processing that takes place. If user consent is required to track and profile them and also to subsequently target them with advertising, both consents should be requested separately and not globally, as happens with the "pay or ok" system of Meta and others. The Committee suggests using “random” advertising as one of the possible solutions. If Meta wants to comply with the EDPB's interpretation, it seems clear that it should avoid offering only paid advertising as an alternative to profiling and behavioral advertising. The EDPB itself provides as a solution, in addition to setting non-abusive amounts for the payment method, also offering the alternative of “random” or less invasive advertising for the privacy of users. For example, letting the user themselves mark, from a closed list of options, what their interests are or the subjects on which they would like to be shown promotions and advertising. A possible solution would be that users could choose between several options, for example: a) payment modality without advertising, b) free modality with advertising according to the preferences they set c) free modality with “random” advertising without any type of profiling , and d) free modality with behavioral advertising cookies. Each of these options could entail some difference in terms of the provision of the service or the use of the platform, but in essence they should be equivalent so that the user does not feel compelled to choose just one of them because otherwise they will be causes unjustified or disproportionate harm. Furthermore, for the rest of possible cookies that also require user consent, this should be obtained separately. However, the platforms, aware of their business and their users, will surely find other solutions or different models that are in line with the opinion of the EDPB. Perhaps in some cases it is enough to lower the price to pay and in others to adopt alternatives accompanied by some type of compensation or additional consideration for the user. Although the latter must be assessed very carefully taking into account that the EDPB also indicates that personal data cannot be used as currency. The Committee provides elements to evaluate the criteria for informed, specific and unambiguous consent that large online platforms must take into account when applying "consent or payment" models. In addition to this opinion, the EDPB also announces that it will develop guidelines on "consent" models. or remuneration” with a broader scope and will collaborate with interested parties on these upcoming guidelines. Ruth Benito, Of Counsel Data Protection and Privacy of ELZABURU For more information: Javier Herreros jherreros@goodwill.es Tel. : 626 20 73 22
Electronic Arts (EA) patents a revolutionary technology that will allow it to offer customized games and advertising: The system makes video games generate new content based on the user's playing style - time spent in combat, frequency with which they choose easy challenges or complex, etc. - to offer you an experience that best suits your preferences. In turn, games can advertise DLC or micropayments more tailored to their playing style. Furthermore, according to the patent, the content and scenarios displayed in EA video games evolve as players modify their gaming habits. It is called “Human-Guided Dynamic Content Framework,” and it is registered with the WIPO World Intellectual Property Organization – WIPO and the US Patent and Trademark Office. Is this progress or will there be problems with the handling of user data? Legal advice in this sense is essential to guarantee good use of technological advances and continue generating innovation and wealth. ELZABURU is a firm specialized in industrial and intellectual property, whose mission is to protect, defend and enhance the innovation and creations of its clients. It has a team of 150 professionals made up of lawyers and technical experts from various areas (engineers, chemists, biologists, biotechnologists, physicists, etc.), who advise, manage and control the legal defense and protection of rights at all stages. of intangible assets. The firm was the first Spanish firm to obtain community customs protection. It manages more than 34.000 trademarks of Spanish companies outside our borders with more than 1.500 disputes processed or ongoing. If you have any related questions, do not hesitate to contact us: Margarita García Díaz-Varela MGD@elzaburu.es Tel.: 673 13 01 04 Javier Herreros jherreros@goodwill.es Tel.: 626 20 73 22
On December 6, the new Law on the Protection of Personal Data and Guarantee of Digital Rights (LOPDPGDD) was published in the BOE. Spanish version: https://www.elzaburu.com/blog/2018/12/nueva-lopd-parte-2.html English version: Nine basic issues concerning the new Data Protection Act (II) https://www.elzaburu .com/blog/2018/12/new-dpa-part-2.html Chinese version: https://www.elzaburu.com/ blog/2018/12/new-dpa-part-2-zh.html Source: Elzaburu Blog Author(s): Fernando Díaz Martínez, Ruth Benito Martín