Compliance and data protection

Effectively Protecting Privacy by Stopping Data Violations.

RedData Legal is a claims-management firm that acts on behalf of companies against the sending of commercial emails without consent (article 21 of the Spanish LSSI-CE and the GDPR): it documents the infringement, formally notifies the sender, offers an out-of-court settlement and, if no settlement is reached, files the complaint with the Spanish Data Protection Agency (AEPD) and activates abuse reports.

LSSI-CE · Art. 21RGPD · Art. 6RGPD · Art. 82LSSI-CE · Art. 38AEPD

Who we are

A serious, traceable and lawful process.

Every claim has a reference, a verifiable timeline and a portal where the notified party can review the evidence, the legal framework and their options. No empty threats: only what the law allows and what we actually do.

What is RedData Legal

Activity

What we do.

We document the infringement

We gather the technical evidence of the unsolicited email: sender, headers, date and content, with an integrity hash.

We claim out of court

We formally notify the sender and offer an out-of-court settlement to resolve the matter before any administrative or judicial route.

What happens if ignored

If there is no settlement, every channel is prepared at once:

  • Complaint before the Spanish Data Protection Agency (fines of up to €30,000 under the LSSI-CE and higher under the GDPR).
  • Abuse report to their email provider, which may suspend or cancel the account used to send.
  • Notice to the hosting provider and the domain registrar.
  • Submission of the evidence to the main anti-spam blocklists.

If activated, the domain loses reputation and the brand may no longer be able to send email normally.

The process

How it works

The affected company forwards us the commercial email it received without requesting it. We verify that it is an unsolicited commercial communication.

We open a claim with a reference, keep the original email and its technical headers, and compute an integrity hash of the evidence.

We send the sender a formal notice detailing the infringement, the applicable legal framework and a link to their private portal, where they can review everything.

The sender can settle the matter out of court. Upon payment, the claiming company waives further action for that email and a closure document is issued.

If there is no settlement

We file the complaint before the AEPD, with exposure to penalties of up to €30,000 under the LSSI-CE and far higher under the GDPR.

We report the sending to their email provider (Mailchimp, Brevo, Instantly, Google or others), which may suspend or cancel the accounts used to send.

We notify the hosting provider and the domain registrar through their abuse contacts.

We submit the evidence to the main blocklists. A listed domain sees its emails rejected or sent to spam at a large share of destinations.

Where applicable, we send a bureaufax and assess a civil claim. Everything is documented in the claim.

Learn more

Legal framework

Legal basis

Law 34/2002 (LSSI-CE), articles 21 and 38 · Regulation (EU) 2016/679 (GDPR), articles 6, 82 and 83.