{"id":7654,"date":"2025-04-08T16:58:57","date_gmt":"2025-04-08T15:58:57","guid":{"rendered":"https:\/\/lawwwing.com\/?p=7654"},"modified":"2025-04-08T17:04:26","modified_gmt":"2025-04-08T16:04:26","slug":"5000-fine-mishandling-a-data-access-request","status":"publish","type":"post","link":"https:\/\/lawwwing.com\/en\/5000-fine-mishandling-a-data-access-request\/","title":{"rendered":"You think DSAR isn\u2019t a big deal? Try a \u20ac5,000 fine"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<p><strong>Crema Games<\/strong>, the company known for developing the video game <em><strong>Temtem<\/strong><\/em>, has been fined <strong>\u20ac5,000 <\/strong>by the Spanish Data Protection Authority (AEPD)<strong>.<\/strong> Why? For mishandling a user\u2019s <strong>request to access their personal data<\/strong>.<\/p>\n\n\n\n<p>In this article, we explain \u2014 in simple terms \u2014 what happened, what mistakes the company made, and how you can avoid the same issues in your own business if you run a website or work in a digital company.<\/p>\n\n\n\n<p>You can read the full decision<a href=\"https:\/\/www.aepd.es\/documento\/ps-00169-2024.pdf\" target=\"_blank\" rel=\"noreferrer noopener\"> here<\/a>.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">How it started?: a personal data access request<\/h2>\n\n\n\n<p>It all began when a user contacted Crema Games to exercise their <strong>right of access<\/strong> (under Article 15 of the <a href=\"https:\/\/lawwwing.com\/en\/what-is-gdpr-and-how-does-it-affect-your-website\/?_gl=1*1yeivi9*_up*MQ..*_ga*MTUzNDk5NzUwNy4xNzQ0MTEzNDYz*_ga_PVQTMLESR8*MTc0NDExMzQ2My4xLjAuMTc0NDExMzQ2My4wLjAuMA..\" target=\"_blank\" rel=\"noreferrer noopener\">GDPR<\/a>). The user wanted to know if <strong>Crema Games<\/strong> was processing their <strong>personal data<\/strong> and, if so, to receive a copy of it, understand what it<strong> was being used for<\/strong>, and if it had been <strong>shared with others.<\/strong><\/p>\n\n\n\n<p>The request was made via email. The user included identifiers linked to their game account and later sent a <strong>censored version of their ID documen<\/strong>t, hiding sensitive data such as the photo and ID number.<\/p>\n\n\n\n<p>However, Crema Games replied that this <strong>form of ID was not valid <\/strong>and that they required a <strong>full copy of the user\u2019s identification document<\/strong>. This was the first red flag: the AEPD considered this demand excessive and not in line with the <strong>data minimisation principle<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" width=\"1024\" height=\"512\" src=\"https:\/\/lawwwing.com\/wp-content\/uploads\/2025\/04\/2x1_NSwitch_Temtem_image1600w-1024x512.jpg\" alt=\"\" class=\"wp-image-7659\" style=\"object-fit:cover;width:1000px;height:400px\" srcset=\"https:\/\/lawwwing.com\/wp-content\/uploads\/2025\/04\/2x1_NSwitch_Temtem_image1600w-1024x512.jpg 1024w, https:\/\/lawwwing.com\/wp-content\/uploads\/2025\/04\/2x1_NSwitch_Temtem_image1600w-300x150.jpg 300w, https:\/\/lawwwing.com\/wp-content\/uploads\/2025\/04\/2x1_NSwitch_Temtem_image1600w-768x384.jpg 768w, https:\/\/lawwwing.com\/wp-content\/uploads\/2025\/04\/2x1_NSwitch_Temtem_image1600w-1536x768.jpg 1536w, https:\/\/lawwwing.com\/wp-content\/uploads\/2025\/04\/2x1_NSwitch_Temtem_image1600w.jpg 1600w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">First mistake: asking for more data than necessary<\/h2>\n\n\n\n<p>The AEPD ruled that asking for a <strong>full copy of an ID is not necessary if there are already reasonable ways to identify the person<\/strong>. In fact, the law is clear: organisations must only request and process the <strong>minimum data needed<\/strong>; no more, no less. This is the essence of the <strong>data minimisation principle<\/strong>.<\/p>\n\n\n\n<p>The idea is simple: only collect and process <strong>data that\u2019s strictly required<\/strong> for the purpose at hand. Requesting a full ID , including information that\u2019s not <strong>needed to verify identity<\/strong>, is not a proportionate measure.<\/p>\n\n\n\n<p>In this case, the user had already provided their game identifiers and had written from an email address that could reasonably be linked to their account. Therefore, <strong>the company should have accepted that as valid identification.<\/strong><\/p>\n\n\n\n<p>This is a common mistake many businesses make: thinking that asking for more data is \u201csafer\u201d, when in fact it can be <strong>illegal<\/strong> if there\u2019s no valid justification.<\/p>\n\n\n\n<p> At <strong>Lawwwing<\/strong>, we help businesses <a href=\"https:\/\/lawwwing.com\/en\/dsar-exercise\/?_gl=1*t5lxmy*_up*MQ..*_ga*MTc3ODQ5Mjk1LjE3NDQxMTM2OTk.*_ga_PVQTMLESR8*MTc0NDExMzY5OS4xLjAuMTc0NDExMzY5OS4wLjAuMA..\" target=\"_blank\" rel=\"noreferrer noopener\">manage these kinds of user requests <\/a>securely and without asking for more data than necessary. This helps avoid costly mistakes \u2014 and fines.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Second mistake: missing deadlines<\/h2>\n\n\n\n<p><strong>Crema Games<\/strong> also failed to <strong>respond <\/strong>to the AEPD within the<strong> required deadline<\/strong> when the authority contacted them for information. If you receive an official request from the AEPD, you must respond within the legal timeframe  with no excuses.<\/p>\n\n\n\n<p>This should serve as a wake-up call for businesses: <strong>deadlines matter<\/strong>. Not replying to the AEPD on time can lead to <strong>further financial fines.<\/strong><\/p>\n\n\n\n<p> With<a href=\"https:\/\/lawwwing.com\/en\/?_gl=1%2A3q208h%2A_up%2AMQ..%2A_ga%2AMTg2NDUyNTEyMC4xNzQ0MTEzOTE1%2A_ga_PVQTMLESR8%2AMTc0NDExMzkxNS4xLjAuMTc0NDExMzkxNS4wLjAuMA..\" target=\"_blank\" rel=\"noreferrer noopener\"> <strong>Lawwwing<\/strong><\/a>, you won\u2019t miss a single deadline. Our platform notifies you and helps you stay compliant, so you can avoid sanctions.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">The AEPD\u2019s resolution and the fine<\/h2>\n\n\n\n<p>After reviewing the facts, the AEPD concluded that Crema Games had breached <strong>Article 15 of the GDPR<\/strong> by not properly granting the user\u2019s right of access. The authority also noted the <strong>excessive identity verification requirements and the failure to respond within the established timeframe.<\/strong><\/p>\n\n\n\n<p>The fine imposed on Crema Games was <strong>\u20ac5,000<\/strong>, sending a clear message: if you run a business, a website, or collect personal data, you must respect the rights of your users \u2014 and comply with the rules.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Key takeaways for tech and digital companies<\/h2>\n\n\n\n<p>This case offers <strong>three important lessons<\/strong> for any business with a website, app, or customer data:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Make it easy for users to exercise their rights.<\/strong> Verify their identity, yes \u2014 but without demanding excessive documentation.<\/li>\n\n\n\n<li><strong>Respect deadlines.<\/strong> Whether responding to users or regulators, timing is crucial.<\/li>\n\n\n\n<li><strong>Apply the data minimisation principle.<\/strong> Only ask for the data you truly need \u2014 nothing more.<\/li>\n<\/ul>\n\n\n\n<p>Failing to do any of the above can result in significant fines.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">How can you avoid this happening to you?<\/h2>\n\n\n\n<p>Here are some simple tips:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Provide a clear and easy way for<strong> <a href=\"https:\/\/lawwwing.com\/en\/dsar-exercise\/?_gl=1*1s94i5d*_up*MQ..*_ga*MTEwNzA4NDA3MC4xNzQ0MTEzOTg1*_ga_PVQTMLESR8*MTc0NDExMzk4NC4xLjAuMTc0NDExMzk4NC4wLjAuMA..\" target=\"_blank\" rel=\"noreferrer noopener\">users to submit requests to exercise their rights<\/a><\/strong>  (for example, via a simple form on your website).<\/li>\n\n\n\n<li> <strong>Use proportionate methods to verify identity<\/strong>: In many cases, an email address associated with the user account is enough.<\/li>\n\n\n\n<li> <strong>Respect deadlines<\/strong>: By law, you have <strong>one month<\/strong> to reply to these requests. And if the AEPD contacts you, specific response deadlines apply too.<\/li>\n\n\n\n<li><strong>Keep records of everything:<\/strong> This way, you can prove you acted correctly if needed.<\/li>\n<\/ul>\n\n\n\n<p>If you\u2019re unsure how to implement these practices \u2014 or if you want to handle them with confidence \u2014 <strong>Lawwwing<\/strong> makes it easy. Our platform is designed to help you stay compliant without the hassle.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p>The Crema Games fine is a reminder that <strong>data protection isn\u2019t just a legal obligation<\/strong>: it\u2019s essential to building digital trust. Complying with the GDPR doesn\u2019t have to be complicated if you understand the key principles and use tools that streamline compliance.<\/p>\n\n\n\n<p>In a digital world where personal information is increasingly valuable, being a responsible data handler is <strong>no longer optional <\/strong>, it\u2019s a competitive advantage.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-1 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-background wp-element-button\" href=\"https:\/\/app.lawwwing.com\/en\/signup\/\" style=\"background-color:#5533ff\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Get Started for free<\/strong><\/a><\/div>\n<\/div>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Crema Games, the company known for developing the video game Temtem, has been fined \u20ac5,000 by the Spanish Data Protection Authority (AEPD). Why? For mishandling a user\u2019s request to access their personal data. In this article, we explain \u2014 in simple terms \u2014 what happened, what mistakes the company made, and how you can avoid [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":7698,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"categories":[210,345,436,209,202],"tags":[360,370,425,403,382],"class_list":["post-7654","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection","category-datos-personales-en","category-fines","category-gdpr-en","category-rgpd-en","tag-2025-2","tag-aepd","tag-datos-personales","tag-fines","tag-gdpr"],"acf":[],"_links":{"self":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/7654","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/comments?post=7654"}],"version-history":[{"count":5,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/7654\/revisions"}],"predecessor-version":[{"id":7687,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/7654\/revisions\/7687"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media\/7698"}],"wp:attachment":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media?parent=7654"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/categories?post=7654"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/tags?post=7654"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}