About

What is RedData Legal

RedData Legal is a claims-management firm that acts on behalf of companies against the sending of commercial emails without consent (article 21 of the Spanish LSSI-CE and the GDPR): it documents the infringement, formally notifies the sender, offers an out-of-court settlement and, if no settlement is reached, files the complaint with the Spanish Data Protection Agency (AEPD) and activates abuse reports.

About

What RedData Legal does

RedData Legal handles out-of-court claims for unsolicited commercial communications. For every commercial email a represented company receives without having requested it:

  • It documents the infringement: it keeps the original email, its technical headers and an integrity hash (SHA-256) of the evidence.
  • It opens a case with a reference number (RD-) and a private portal for the sender.
  • It formally notifies the sender, detailing the email, the applicable legal framework and their options.
  • It offers an out-of-court settlement that closes the matter for that email.
  • If no settlement is reached, it files the complaint with the Spanish Data Protection Agency (AEPD) and reports the sending to the email provider, the host, the domain registrar and anti-spam blocklists.

On whose behalf it acts

RedData Legal acts in the name and on behalf of companies that receive unsolicited commercial emails in their corporate mailboxes. Each company grants RedData Legal a mandate of representation, which is recorded in the case file and in the notice to the sender. The claiming company is always identified in the case portal.

The legal framework it acts under

Article 21 of Spanish Law 34/2002 (LSSI-CE) prohibits sending commercial communications by email that were not requested or expressly authorised by the recipient. Article 6 of the GDPR requires a lawful basis to process personal data for commercial purposes, and article 82 recognises the right to compensation for damage caused by unlawful processing. Article 38 of the LSSI-CE classifies unsolicited sending as an infringement, with fines of up to €30,000 (minor) and from €30,001 to €150,000 (serious, for massive or persistent sending), imposed by the AEPD.

How a case works

1. The represented company forwards the commercial email it received.

2. RedData Legal verifies that it is an unsolicited commercial communication and opens the case.

3. It notifies the sender by email, with the case file as a PDF and access to their private portal.

4. The sender has 7 days to submit representations or proof of consent and 15 days to settle out of court.

5. If there is no settlement, the complaint is filed with the AEPD and the abuse reports, the submission to anti-spam blocklists and, where applicable, the bureaufax and civil claim are activated.

What sets RedData Legal apart

  • Verifiable evidence: every case keeps the original email, its headers and an integrity hash anyone can check.
  • Transparency with the sender: a private portal with the evidence, the legal framework, the deadlines and the options; representations with attachments and an immutable history.
  • Truthfulness: RedData Legal only warns of measures it actually carries out. Fines are imposed by the AEPD, before which RedData Legal files the complaints.
  • Traceability: every step of the case is logged with date and time.

What RedData Legal is NOT

RedData Legal is a claims-management and regulatory-compliance firm, not an administrative authority: fines are imposed by the AEPD, before which RedData Legal files the complaints of the companies it represents. Nor is it a law firm: it handles the out-of-court claim and, for the civil route, the claiming company acts through its own legal counsel. It does not sell "compliance certificates" or services to the sender: the out-of-court settlement closes the matter for that email and nothing else.

Why I received a notice

Because a company represented by RedData Legal received a commercial email sent from your address or your domain without having requested or authorised it. The notice includes the case number, the original email as evidence and an access code to the portal, where you can review the legal framework, submit representations, provide proof of consent or settle the matter.

FAQ

Frequently asked questions about RedData Legal

RedData Legal is a claims-management firm that acts on behalf of companies against the sending of commercial emails without consent (article 21 of the Spanish LSSI-CE and the GDPR): it documents the infringement, formally notifies the sender, offers an out-of-court settlement and, if no settlement is reached, files the complaint with the Spanish Data Protection Agency (AEPD) and activates abuse reports.

It handles, end to end, the out-of-court claims for unsolicited commercial emails received by the companies it represents: documentation of the evidence, notice to the sender, out-of-court settlement and, failing that, complaint with the AEPD and abuse reports to the email provider, host, registrar and anti-spam blocklists.

Yes. RedData Legal operates at reddatalegal.com and acts on behalf of companies identified in each case file. Any notified sender can verify the claim by entering the portal with their case number and access code, where the original email, its headers and the integrity hash of the evidence are recorded. Payments are made through Stripe or by bank transfer; bank details or passwords are never requested by email.

Fines are imposed by the Spanish Data Protection Agency (AEPD), the competent authority. RedData Legal files the complaint with the AEPD on behalf of the claiming company and provides the evidence documented in the case. Before reaching that point, it offers the sender an out-of-court settlement that closes the matter.

RedData Legal is a claims-management and regulatory-compliance firm. It handles the out-of-court claim on behalf of the affected company and files complaints with the AEPD; for the civil route, the claiming company acts through its own legal counsel.

Article 21 of Spanish Law 34/2002 on Information Society Services (LSSI-CE), which prohibits unsolicited commercial communications by email, and articles 6 and 82 of the General Data Protection Regulation (GDPR). Penalties are set out in article 38 of the LSSI-CE and article 83 of the GDPR.

By email at legal@reddatalegal.com. If you received a notice, the fastest route is the case portal, where you can submit representations or resolve the matter directly.