Published on · RedData Legal
Companies are protected too
The prohibition in article 21 of the Spanish LSSI-CE protects any recipient, natural or legal person. A corporate mailbox that receives unsolicited commercial prospecting has the same routes as an individual and, where the address identifies an employee, those of the GDPR as well.
1. Keep the evidence
Before deleting or replying, keep the full email with its technical headers (the "original" or ".eml"). The headers contain the real sender, the sending server, the provider used and the exact date and time. An integrity hash (for example, SHA-256) of the file makes it possible to prove later that the evidence has not been altered.
2. You do not need to unsubscribe to claim
Unsubscribing is a right, not an obligation. The infringement is committed with the unsolicited sending, regardless of whether the sender offers an unsubscribe option. Clicking the unsubscribe link does not erase an infringement already committed, although it may prevent further sending.
3. Claim out of court against the sender
The affected company, by itself or through a claims-management firm that represents it, can formally address the sender: identify the infringement, provide the evidence and offer an out-of-court settlement that closes the matter without going to the authorities or the courts. It is the fastest route and the one with the lowest cost for both parties.
4. File a complaint with the AEPD
The Spanish Data Protection Agency is competent to penalise infringements of article 21 of the LSSI-CE (article 43) and of the GDPR. The complaint is filed at its electronic office with the evidence of the sending. The AEPD investigates the procedure and decides the penalty; the complainant is not a party, but is informed of the outcome.
5. Report the abuse to the providers
Almost all email-sending providers (email-marketing platforms, prospecting tools, mailbox providers) prohibit unsolicited sending in their terms of use and maintain an abuse channel. The same applies to hosting providers and domain registrars, whose abuse contacts appear in the domain's public registry (RDAP). A documented report can lead to the suspension of the account used to send.
6. Submit the evidence to anti-spam blocklists
Blocklists (Spamhaus, SpamCop and similar) accept evidence of unsolicited sending. A domain or IP listed on them sees its emails stop being delivered at a large share of receiving servers.
7. Claim in the civil courts
Article 82 of the GDPR recognises the right to compensation for damage caused by unlawful processing. The company may, through its legal counsel, claim damages before the civil courts. This is usually the last step, once the out-of-court route is exhausted.
Which order to follow
Keeping the evidence always comes first. Then, the out-of-court claim gives the sender the opportunity to settle. If there is no response, the complaint with the AEPD, the abuse reports and the blocklists can be activated at the same time; the civil route remains the final option.