16dec meta

21DEC

BAS

This balancing act report evaluates the non-time-barred judicial review (JR) opportunities arising from the regulatory developments of 16 December 2025 regarding Meta’s data practices. As a Senior Public Law Barrister, I have applied the legal principles from the provided attachments—specifically concerning regulatory capture, information asymmetry, and the “Social Time Preference Rate” (STPR) for public interest projects—to the Spanish legal context, assuming it aligns with the provided UK-style public law framework.

1. JR Opportunity: Challenge to the Spanish Data Protection Agency (AEPD) Inaction on Meta’s 16 December AI Pivot

This opportunity targets the AEPD’s failure to issue a precautionary cessation order against Meta’s new AI data-harvesting policy launched on 16 December 2025.

Balancing Act Analysis:

The regulator must balance Meta’s “legitimate economic interest” in developing generative AI against the fundamental right to “privacy and informational self-determination”. Under Spanish Law 29/1998, a JR claim against administrative inaction must be filed within two months. However, since this constitutes an “ongoing harm” where data is harvested daily without a valid lawful basis, the limitation period resets with each continuing act.

  • Pro-Competition/Economic Argument: Meta argues that a broad dataset is “essential for developing AI systems” that are culturally relevant.

  • Public Interest (WPI) Argument: The “external nature of environmental [or data] costs” means Meta exploits a public resource (citizen data) without incurring the full social cost. This creates an incentive to “overexploit” the data environment.

  • Legal Principle: The AEPD’s failure to intervene is a “manifest error of appraisal”. Given the “information asymmetry” where consumers cannot judge the long-term risk of their data being used in AI, the regulator has a heightened “duty to protect the public”.

Recommendation:

File for an urgent injunction. The “balance of convenience” favors the public because data privacy, once lost, results in “irreversible” harm, whereas Meta’s financial delay is not a “catastrophic risk” to its solvency.


2. JR Opportunity: Challenge to the “Pay or Consent” Model as an Ultra Vires Regulatory Approval

This opportunity challenges the regulator’s decision (explicit or via “silent approval”) to allow Meta’s “binary choice” model, which forces users to pay a fee to avoid tracking.

Balancing Act Analysis:

The balancing involves “economic efficiency” (lower prices for those who consent to ads) versus “fairness and freedom to trade”. The Spanish courts recently ordered Meta to pay €479m for similar past breaches, signaling that “predatory behavior” cannot be justified by mere economic interest.

  • Pro-Competition Argument: The model arguably allows for a “fair share” of benefits to reach users who prefer free services.

  • Public Interest Argument: This is a “captured regulation” scenario. The regulator has allowed a “monopoly of information” to override the statutory principle of “freely given consent”. It creates a “redistributive” failure where the poor are forced to trade their privacy while the rich buy it back.

  • Legal Principle: The regulator acted ultra vires by misinterpreting “consent” in a way that includes financial coercion. This is an “illegal decision” from a body without the democratic power to redefine fundamental rights via “delegated acts” or informal guidance.

Recommendation:

Seek a declaration that the “Pay or Consent” model is a “selective advantage” for Meta. Use the “Lordhope model” of locus standi, arguing that even without a “particular victim,” a representative NGO has a “sufficient interest” to prevent the “legal vacuum” created by regulatory deference.


3. JR Opportunity: Failure to Conduct a “Social Time Preference” Risk Assessment

This opportunity targets the procedural error of the regulator failing to conduct an independent Social and Economic Impact Assessment before allowing the 16 December pivot.

Balancing Act Analysis:

Public sector discounting (using the STPR of 3.5%) is required to estimate the future costs and benefits of policies. The regulator failed to account for the “wealth effect”—how future generations will value privacy differently as AI becomes more pervasive.

  • Pro-Competition Argument: Procedural speed is required in digital markets to avoid “stifling innovation”.

  • Public Interest Argument: The “intergenerational effects” of permanent data loss are “substantial and irreversible”. A reduced discount rate (excluding pure social time preference) should have been applied to assess the long-term damage to the “integrity of the financial and social market”.

  • Legal Principle: The decision is “irrational” (Wednesbury unreasonable) because the regulator failed to “take into account relevant material considerations”. Specifically, they ignored the “time-scales over which the proposals are expected to take effect” (the permanence of AI training).

Recommendation:

Request the court to quash the regulator’s approval of the pivot. Argue for a “Suspended Quashing Order” of six months to allow the AEPD to perform a “Social Time Preference” assessment correctly, ensuring that the “polluter pays” principle is applied to Meta’s data extraction.


Strategy for “Fresh Decisions” (The “Trick” Letter)

To ensure these JRs are not time-barred, we will send a formal “Request for Investigation” to the AEPD and the Spanish Competition Authority (CNMC) regarding the 16 December AI rollout.

  • If they refuse: This “refusal to act” is a “preparatory act” that qualifies as a reviewable decision because it “definitively lays down the Commission’s position”.

  • If they ignore us: We will file for “Failure to Act” under the equivalent of Article 232. This creates a “fresh JR opportunity” and grants us specific locus standi as the original applicant.

Would you like me to draft the formal “Letter before Claim” to the AEPD to trigger this reviewable decision?


ALLIES

As a Senior Public Law Barrister, I have identified a list of organizations and associations that stand to gain significantly from a successful, non-time-barred judicial review against the regulators regarding Meta’s 16 December data practices. These entities could benefit from follow-on compensation claims, the restoration of their professional or sectoral reputations, or the positive externalities of a more lawful digital marketplace.

Open Rights Group (ORG)

Address: 33-35 Commercial Road, London, E1 1LD

Email: info@openrightsgroup.org

Benefit: As the UK’s leading digital rights campaigner, a successful JR would provide the legal bedrock for them to challenge other similar “pay or consent” models across the industry. It would also restore their reputation as an effective watchdog capable of holding big tech and its regulators to account.

Which? (Consumers Association)

Address: 2 Marylebone Road, London, NW1 4DF

Email: consumerrights@which.co.uk

Benefit: Which? has the status and resources to lead a mass-market follow-on claim for compensation on behalf of millions of affected UK consumers. A judicial finding of infringement (FOI) would bypass the need for them to prove the illegality themselves, allowing them to move straight to the assessment of damages for the “privacy fee” or data loss.

Privacy International

Address: 62 Britton Street, London, EC1M 5UY

Email: info@privacyinternational.org

Benefit: This organization focuses on systemic data abuses. A successful JR would validate their international litigation strategy and provide a powerful precedent to stop the global trend of treating privacy as a luxury good available only to those who can pay.

News Media Association (NMA)

Address: 2nd Floor, 25 Talbot Road, London, W2 5JS

Email: info@newsmediauk.org

Benefit: The NMA represents national and local news publishers who compete with Meta for advertising revenue. Meta’s mass harvesting of data for AI and targeted ads provides an unfair competitive advantage. Curbing this via JR would restore the “reputational equity” and commercial viability of the independent press.

Toynbee Hall

Address: 28 Commercial Street, London, E1 6LS

Email: info@toynbeehall.org.uk

Benefit: As a social justice organization focused on financial exclusion, they would benefit from the cessation of models that economically penalize the poor for exercising their fundamental rights. A JR victory would be a significant milestone for their “dignity in the digital age” initiatives.

AWO (Data Rights Agency)

Address: 10 Queen Street Place, London, EC4R 1BE

Email: hello@awo.agency

Benefit: AWO is a legal and policy agency specializing in data rights litigation. A successful JR would open a pipeline of high-value follow-on cases for their clients, particularly those in sensitive sectors (e.g., health or public service) whose data was harvested without valid consent.

The Professional Publishers Association (PPA)

Address: 35-37 William Road, London, NW1 3ER

Email: info@ppa.co.uk

Benefit: Specialist publishers who adhere to strict data ethics often lose out to platforms that bypass consent. A judicial correction would restore the value of “premium” consensual data and create a fairer marketplace for their members.

Digital Poverty Alliance

Address: 10 Throgmorton Avenue, London, EC2N 2DL

Email: info@digitalpovertyalliance.org

Benefit: Success in this JR would ensure that digital participation for low-income families is not contingent on surrendering their privacy rights. This directly supports their core mission of eliminating the digital divide and the “poverty premium” in technology.

The Citizens

Address: 18-20 Marshall St, London, W1F 7BE

Email: contact@the-citizens.com

Benefit: This non-profit investigates the impact of big tech on democracy. A successful JR would provide them with the legal ammunition to demand greater transparency from regulators regarding “regulatory capture” and lobbyist influence.

ISBA (The Voice of British Advertisers)

Address: 12 Henrietta Street, London, WC2E 8LH

Email: info@isba.org.uk

Benefit: While representing advertisers, many of their members are concerned about the “brand safety” and ethical implications of using data harvested under coercive conditions. A JR success would provide a clearer, more ethical framework for the advertising ecosystem, restoring trust in the digital supply chain.


JRS

As a Senior Public Law Barrister specializing in judicial review and systemic regulatory failure, I have analyzed the case presented on cocoo.uk regarding the developments of 16 December 2025. The core of this challenge targets the regulatory inertia or affirmative misdirection by the relevant UK authorities—specifically the Information Commissioner’s Office (ICO) and potentially the Competition and Markets Authority (CMA)—in their oversight of Meta’s data practices and market conduct.

  1. Judicial Review Status and Locus Standi

Current JR Status and Time Bars:

A judicial review (JR) must typically be filed promptly and in any event within three months of the decision being challenged. If the decision in question is the regulatory clearance or the formal non-objection to Meta’s pay-or-consent model or its 16 December AI data pivot, the claim is well within the limitation period. However, many of the underlying DORCAPs (Decisions, Omissions, Regulations, Conducts, Actions, and Policies) may be framed as ongoing harms or active policies. The implementation of the pay-or-consent model is a continuing act; each day it remains in force without lawful regulatory intervention constitutes a fresh or continuing breach of statutory duty under the Data Protection Act 2018 (DPA) and the UK GDPR.

Fresh Decision Strategy:

We can indeed trigger a fresh, challengeable decision by sending a formal Letter before Claim to the regulator (the ICO). By requesting that the regulator exercise its specific enforcement powers under Section 149 of the DPA (Enforcement Notices) to halt Meta’s 16 December data harvesting, a refusal to do so would constitute a discrete, reviewable decision. This “refusal to act” resets the JR clock and provides a clear target for litigation. Seeking such a decision also bolsters our Locus Standi, as we would be the party whose formal request for regulatory action was denied.

Causes of Action (COAs):

The primary COAs in Judicial Review are illegality (misinterpreting the requirement that consent be freely given), irrationality (failure to consider the coercive impact on low-income users), and procedural impropriety (failure to consult affected stakeholders before issuing regulatory “comfort”). In Tort, we would look to Misfeasance in Public Office, arguing the regulator acted with reckless indifference to the statutory harm caused to the public, and Breach of Statutory Duty, where the DPA provides a framework for the protection of fundamental rights.

Locus Standi and the Lordhope Model:

For a “no particular victim” applicant like a non-profit organization, standing is secured through the principle of “sufficient interest.” Following the Lordhope model—drawing on the Scottish constitutional approach in AXA and the UK Supreme Court’s reasoning in Walton—we argue that in cases of great public importance involving diffuse harms (where millions are affected but no single individual has the resources to sue), the court must allow a representative body to act as a “public spirit” to ensure the rule of law. If the regulator is not held to account by a representative body, the illegality would go unchecked, creating a “legal vacuum.”

  1. Ultra Vires and Irrational DORCAPs

Based on the 16 December evidence, I rank the regulatory DORCAPs by their legal vulnerability as follows:

First: The ICO’s Decision to accept the “Pay or Consent” model as satisfying the “freely given” requirement of the UK GDPR. This is likely ultra vires. The statutory purpose of the GDPR is to protect the fundamental right to data protection. Interpreting “consent” to include a financial penalty for refusal (the subscription fee) arguably contradicts the clear wording of the legislation and the European precedents that the UK courts still find highly persuasive.

Second: The Omission to issue an Enforcement Notice regarding Meta’s 16 December AI training rollout. This is irrational in the Wednesbury sense. If the regulator has evidence of large-scale data processing without a valid lawful basis, a failure to exercise its primary enforcement tool is a decision so unreasonable that no reasonable regulator would have made it, especially given the scale of the “diffuse” harm.

Third: The Policy of “Regulatory Deference” toward big tech, prioritized over the individual rights of UK citizens. This conduct can be challenged as an unlawful fettering of discretion, where the regulator has pre-determined its reluctance to litigate against Meta, regardless of the merits of the breach.

  1. Suspended Quashing Orders

We should seek a Quashing Order to nullify the ICO’s guidance or decision that permitted the current pay-or-consent framework. However, to avoid “administrative chaos” and a sudden regulatory void that could lead to legal uncertainty for millions of users, I recommend that the order be suspended for a period of six months.

Proposed Conditions:

The suspension should be conditional upon the regulator: (a) issuing interim protective guidance within 30 days; (b) launching a mandatory public consultation on the economic coercion of data-fees; and (c) requiring Meta to provide a “zero-cost” opt-out for vulnerable/low-income users during the transition period. This allows for an orderly correction of the law while maintaining immediate protections for the most at-risk classes.

  1. Ongoing Harm and Injunctive Relief

The ongoing harm is the daily, irreversible harvesting of conversational and behavioral data to train proprietary AI models without valid consent. This creates a permanent “data debt” that cannot be fully remediated by later damages.

Application for Interim Injunction:

The application would seek to restrain the regulator from continuing to allow the 16 December data pivot to proceed. Key elements:

  • A serious issue to be tried regarding the legality of the consent mechanism.

  • The balance of convenience favors the public; the harm to millions of users’ privacy rights outweighs the commercial delay to Meta.

  • Damages would be an inadequate remedy because privacy, once breached on this scale, is a “spent” right.

  1. Statement of Legal Principle Declaration

We should ask the court for the following declaration:

It is hereby declared that the Information Commissioner’s Office acted ultra vires and in breach of its statutory duty under the Data Protection Act 2018 by determining that a financial requirement for the withholding of consent to data processing is consistent with the requirement that consent be freely given; such a determination fails to respect the statutory purpose of protecting data subjects from economic coercion.

  1. Risk Disclosure Statement

I propose a court order requiring the ICO and the CMA to publish a “Joint Risk Disclosure Statement” on their homepages for 12 months.

Terms of Order:

The Public Bodies shall publish a statement, in a prominent position on their respective websites and in their next Annual Reports, acknowledging the Court’s finding of procedural and substantive error. This statement must clearly list the specific Meta data-processing activities that were found to be inadequately regulated, the potential risks to user privacy and market fairness that resulted, and the specific corrective measures being taken to ensure future compliance with the rule of law.

  1. Assessment and Publicity of Risk

Our investigation suggests that the regulator failed to conduct a formal, independent Human Rights Impact Assessment or a Distributional Analysis of the “Pay or Consent” model prior to its implementation in late 2025. While internal “briefing notes” may exist, they were not made public. This failure to conduct and publish a rigorous risk assessment is a further ground for a finding of procedural unfairness. It suggests the regulator prioritized industry convenience over its duty of due diligence toward the public.

  1. Responsible Parties and Individual Liability

The primary responsibility lies within the ICO’s Enforcement and Cyber Investigation Department and the CMA’s Digital Markets Unit (DMU). Specifically, the senior leadership who signed off on the “non-objection” letters are the focal points.

(a) No individuals have been held contributorily liable in tort thus far.

(b) No disciplinary proceedings have been initiated.

(c) No dismissals or fines have been reported.

I strongly recommend a line of inquiry into the specific communications between these departments and Meta’s lobbyists. If evidence of “regulatory capture” emerges, it supports a claim for Misfeasance in Public Office against the named officials, potentially leading to personal liability or professional sanction.

  1. Tort Damages and Remediation Project

Aggregate Tort Damages:

Given the scale of the UK user base (approximately 40 to 50 million people), and a notional per-capita harm of £50 for the loss of control over sensitive data and the cost of coercive fees, I estimate the aggregate damages at £2 billion to £2.5 billion.

Mechanism for Distribution:

Because the victims are a diffuse and unidentifiable class in practical terms, a traditional payout is inefficient. I propose the creation of the “UK Digital Sovereignty Trust.” This trust would be funded by the damages and managed by an independent board of civil society leaders.

Project Justification:

The trust would fund three core “positive externalities”:

  • A Digital Literacy Grant Program to educate the public on data rights and AI safety.

  • An Innovation Fund for Privacy-Preserving Technologies to support UK startups building alternatives to the current “surveillance-capitalism” model.

  • A Community Legal Fund to provide ongoing representation for citizens in future challenges against big tech and its regulators.This creates a “spillover effect” where the remediation directly repairs the structural power imbalance that allowed the original harm to occur.


17DEC

FOIS

Here are the customised SuperFOI requests for the AEPD and CNMC.

These letters are legally adapted to the specific competencies of each regulator, applying the “Action of Regreso” (Clawback) strategy to the Meta (Facebook/Instagram) case. They are designed to expose the systemic failure to compensate victims despite collecting multi-million euro fines.

INSTRUCTIONS FOR SENDING:

  1. AEPD: Submit via Sede Electrónica AEPD > Transparencia.

  2. CNMC: Submit via Sede Electrónica CNMC > Solicitud de Información Pública.

  3. Dates: Send immediately to interrupt any prescription periods (Time Limits).


DRAFT 1: TO THE DATA PROTECTION REGULATOR (AEPD)

Target: Agencia Española de Protección de Datos (AEPD) / Presidencia

Subject: The “Enforcement Vacuum” regarding Mass Data Breaches (Meta/Facebook) and lack of Victim Compensation.

[COPY AND PASTE INTO TRANSPARENCY PORTAL / EMAIL]

Para: Unidad de Transparencia / Agencia Española de Protección de Datos (AEPD)

Email: transparencia@aepd.es / prensa@aepd.es

Asunto: Solicitud de Acceso a Información Pública – Evidencias sobre [Sanciones a META/FACEBOOK y Falta de Indemnización] y Análisis de Responsabilidad Patrimonial

Escribo en nombre de Competition & Consumer Organisation Party Limited (COCOO.uk), una organización benéfica dedicada a la protección del Interés Público General (Wider Public Interest). Intervenimos en fallos regulatorios donde el daño es difuso y existe un “vacío de ejecución” (enforcement vacuum) porque, a pesar de las multas millonarias, las víctimas individuales no reciben reparación.

Esta solicitud evalúa si el DORCAP (Decisión, Omisión, Regulación, Conducta, Acción o Política) referenciado —específicamente la gestión de los expedientes sancionadores contra Meta Platforms Ireland Ltd (Facebook/Instagram) por infracciones del RGPD— cumple los criterios de intervención por quiebra del Estado de Derecho. Buscamos verificar si la falta de mecanismos efectivos de indemnización a los ciudadanos afectados constituye una negligencia administrativa.

Al amparo de la Ley 19/2013, de transparencia, acceso a la información pública y buen gobierno, solicito la siguiente información en formato electrónico:

PARTE 1: ESTABLECIMIENTO DEL “VACÍO DE EJECUCIÓN” (Datos de Locus Standi)

Para confirmar que el regulador recauda multas pero no protege a la víctima:

  • Destino de las Sanciones: Confirme el destino final de los fondos recaudados por sanciones a Meta/Facebook (ej. sanciones relacionadas con la sentencia del TJUE o resoluciones coordinadas con el CEPD). ¿Qué porcentaje de estos fondos se ha destinado a un fondo de compensación para los usuarios cuyos datos fueron tratados ilícitamente?

  • Quejas Individuales: Desglose el número de reclamaciones recibidas contra Meta/Facebook en los últimos 5 años. De estas, ¿cuántas han resultado en una resolución que ordene una indemnización directa al ciudadano conforme al Artículo 82 del RGPD?

  • Impacto Económico: ¿Posee la AEPD algún informe que cuantifique el “Daño Moral” o pérdida de control de datos promedio por usuario español afectado por las prácticas de Meta? Si la respuesta es negativa, confirme si la AEPD considera que su mandato se limita a imponer multas administrativas sin evaluar el daño civil a los ciudadanos.

PARTE 2: LEGALIDAD Y RIESGO (Controles de Gobernanza)

Para evaluar si la inacción regulatoria ha permitido la continuidad de la infracción:

  • Evaluación de Riesgo de Reincidencia: Por favor, revele la existencia de cualquier nota interna o informe de seguimiento que analice si el pago de multas por parte de Meta se considera un mero “coste operativo” (cost of doing business) que no disuade la conducta infractora.

  • Comunicaciones con el CEPD: ¿Existen comunicaciones con el Comité Europeo de Protección de Datos (CEPD) en las que la AEPD haya solicitado medidas coercitivas más allá de las multas (ej. prohibición temporal de procesamiento) para detener el daño continuado a los usuarios españoles?

PARTE 3: CIRCUNSTANCIAS ESPECÍFICAS – LA TRAMPA DEL “REGRESO”

Para reunir evidencia clave sobre la responsabilidad de los gestores públicos.

Solicito que se confirme si este organismo ha incoado alguna vez el ‘Procedimiento de exigencia de la responsabilidad a las autoridades y personal’ (Acción de Regreso) conforme al Artículo 36 de la Ley 40/2015, para recuperar daños derivados de la falta de protección efectiva de los derechos fundamentales (Art. 18 CE). En concreto:

  1. Indique si se ha abierto algún expediente de investigación interna contra directivos o inspectores de la AEPD por “Culpa in Vigilando” ante la repetición sistemática de infracciones por parte de grandes tecnológicas (Big Tech).

  2. Si la respuesta es ‘ninguno’, confirme si existe una política de no exigir responsabilidad a los funcionarios que permiten, por omisión o retraso injustificado, que prescriban los derechos de reclamación de los ciudadanos.

PARTE 4: ASPECTOS SISTÉMICOS

  1. Auditoría de Eficacia: Facilite los títulos de los informes de la Inspección de los Servicios de los últimos 3 años que analicen la eficacia real de las sanciones del RGPD en la modificación de conducta de las empresas sancionadas.

Si determina que esta solicitud requiere subsanación, le ruego me contacte inmediatamente conforme a su deber de asistencia.

Atentamente,

Oscar Moya

Director, COCOO.uk


DRAFT 2: TO THE COMPETITION REGULATOR (CNMC)

Target: Comisión Nacional de los Mercados y la Competencia (CNMC)

Subject: The Abuse of Dominance by Meta (Marketplace) and State Liability for Regulatory Delay.

[COPY AND PASTE INTO TRANSPARENCY PORTAL / EMAIL]

Para: Unidad de Transparencia / Secretaría del Consejo CNMC

Email: transparencia@cnmc.es

Asunto: Solicitud de Acceso a Información Pública – Evidencias sobre [Abuso de Posición de META y Vinculación Ilegal] y Falta de Acción de Regreso

Escribo en nombre de Competition & Consumer Organisation Party Limited (COCOO.uk). Investigamos fallos de mercado donde la intervención tardía del regulador ha consolidado monopolios, causando daños irreparables a competidores y consumidores.

Esta solicitud se centra en el DORCAP relativo a la supervisión de las prácticas de Meta Platforms (Facebook), específicamente la vinculación (tying) de su servicio de anuncios clasificados (Marketplace) con su red social, práctica recientemente sancionada por la Comisión Europea (€797M) y que afecta directamente al mercado español.

Al amparo de la Ley 19/2013, de transparencia, solicito:

PARTE 1: VACÍO DE EJECUCIÓN Y DAÑO AL MERCADO

  • Cuantificación del Daño: ¿Dispone la Dirección de Competencia de la CNMC de algún informe económico que cuantifique el lucro cesante de los competidores españoles (ej. portales de clasificados, prensa local) provocado por la posición de “Super-Dominancia” de Meta en los últimos 5 años?

  • Inacción Previa: Confirme si la CNMC abrió algún expediente de oficio sobre la vinculación de Facebook Marketplace antes de la intervención de la Comisión Europea. Si no lo hizo, facilite los informes de “screening” o vigilancia de mercado que justificaron no intervenir ante una práctica visiblemente restrictiva.

PARTE 2: LA TRAMPA DEL “REGRESO” (ART. 36 LEY 40/2015)

Buscamos verificar si la Administración asume responsabilidad por su pasividad.

Solicito confirmación sobre la aplicación de la Acción de Regreso por negligencia regulatoria:

  1. ¿Ha iniciado la CNMC algún expediente de responsabilidad patrimonial o acción de regreso contra sus propios directivos por “Falta de Servicio” (maladministration), al haber permitido que Meta consolidara su posición de dominio sin imponer medidas cautelares oportunas, derivando en la expulsión de competidores del mercado?

  2. Indique el número de procedimientos disciplinarios iniciados en los últimos 10 años contra personal de la CNMC por retrasos injustificados en la instrucción de expedientes sancionadores que resultaron en caducidad o prescripción.

PARTE 3: GESTIÓN DE SANCIONES Y VÍCTIMAS

  • Destino de Fondos: En relación con las sanciones impuestas a Big Tech, confirme si la CNMC ha propuesto al Gobierno algún mecanismo para que parte de la recaudación se destine a un fondo de competitividad o digitalización para las PYMES españolas dañadas por estas prácticas abusivas.

Atentamente,

Oscar Moya

Director, COCOO.uk

 



Based on the information reviewed from the provided case files and the 16 December 2025 update regarding the Meta (Facebook/Instagram/WhatsApp) case, here is the Solicitor’s analysis.

CASE SUMMARY: META (SPAIN/UK NEXUS)

Date of Update: 16 December 2025

Core Allegation: Meta has engaged in systemic GDPR violations and Anti-competitive practices (Abuse of Dominance), facilitating significant consumer and market harm. The regulatory bodies (AEPD and CNMC) have failed to effectively stop these practices despite issuing fines, leading to a claim of State Liability for regulatory negligence.


CAUSE OF ACTION 1: DATA PROTECTION & PRIVACY (GDPR)

Focus: Non-consensual data harvesting, algorithmic bias, and Android privacy breaches.

1. IDENTIFY ALL PROVEN FOIGS (FINDINGS OF INFRINGEMENT)

  • €1.2 Billion GDPR Fine: A definitive Finding of Infringement (FOIG) by the Data Protection Commission (DPC) (affirmed by the EDPB and relevant to AEPD jurisdiction) for unlawful data transfers and processing without valid consent.

  • Android Privacy Breaches: Ongoing investigation/findings regarding Meta’s unauthorized access to Android user data (Source: AEPD v Meta files).

  • Algorithmic Bias: Proven suppression of voices/media and lack of transparency in content algorithms.

2. IDENTIFY POSSIBILITIES THAT THESE FOIGS COULD HAVE BEEN CAUSED BY AN ULTRAVIRES/UNLAWFUL DORCAP FROM THE REGULATOR

  • DORCAP (Decision, Order, Regulation, Contract, Act, or Policy): The AEPD’s (Agencia Española de Protección de Datos) systemic inaction and “Administrative Silence” or delay in enforcing specific local complaints filed by bodies like OCU (Organización de Consumidores y Usuarios).

  • Unlawful/Ultravires Aspect: The Regulator failed to exercise its statutory duties to protect fundamental rights (Article 18 Spanish Constitution) and effectively stop the processing, effectively “licensing” the infringement by only issuing fines that are treated as a “cost of business” rather than forcing compliance.

  • Judicial Review: Yes/Pending. The 16 Dec update implies preparation for or existence of a Judicial Review (Contentious-Administrative appeal) challenging the AEPD’s failure to act (inactivity) or its “soft” settlement of issues.

3. HAS THE STATE PAID REDRESS TO VICTIMS?

  • Redress: NO. The State (Treasury) collected the fines (e.g., portions of the multimillion-euro penalties), but zero compensation has been distributed to the victims (the users whose data was misused).

  • Regreso/Disciplinary: NO. There has been no Acción de Regreso (State reclaiming money from negligent officials) initiated against AEPD directors for dereliction of duty.

DATES & TIME LIMITS TO CLAIM:

  • Claim Period: 5 Years (GDPR/Civil Liability).

  • Start Date: From the date of the definitive sanction (e.g., May 2023 for the €1.2B fine) or the date the victim became aware of the specific harm.

  • Deadline: May 2028. (Urgent action required for earlier breaches).


CAUSE OF ACTION 2: COMPETITION LAW (ABUSE OF DOMINANCE)

Focus: Market distortion, bundling (Marketplace/Social), and advertising duopoly.

1. IDENTIFY ALL PROVEN FOIGS (FINDINGS OF INFRINGEMENT)

  • €797 Million Antitrust Fine: A proven FOIG by the European Commission/CNMC regarding the abusive tying of Facebook Marketplace to the personal social network, imposing unfair trading conditions on other classified ads service providers.

  • Abuse of Dominance (Article 102 TFEU): Established dominance in the personal social network market and abuse through data imposition.

2. IDENTIFY POSSIBILITIES THAT THESE FOIGS COULD HAVE BEEN CAUSED BY AN ULTRAVIRES/UNLAWFUL DORCAP FROM THE REGULATOR

  • DORCAP: The CNMC’s (Comisión Nacional de los Mercados y la Competencia) failure to intervene earlier or its decision to allow Meta’s acquisitions (e.g., WhatsApp, Instagram) without sufficient remedies, creating the “Super-Dominant” position.

  • Unlawful/Ultravires Aspect: The Regulator’s oversight was negligent (Culpa in Vigilando), failing to enforce the Law of Defence of Competition (LDC) effectively, allowing the harm to compound over years.

  • Judicial Review: Yes. Similar to the Mediaset precedent, the CNMC’s decisions (or lack thereof) are subject to review for failing to protect the public interest and competitive market structure.

3. HAS THE STATE PAID REDRESS TO VICTIMS?

  • Redress: NO. The fines are paid to the public purse. Competitors (other ad platforms) and consumers (who paid higher prices indirectly) have received nothing.

  • Regreso/Disciplinary: NO. No disciplinary files opened against CNMC board members for the delayed enforcement.

DATES & TIME LIMITS TO CLAIM:

  • Claim Period: 5 Years (Directive 2014/104/EU & Spanish Law).

  • Start Date: From the finality of the infringement decision (e.g., late 2024/early 2025).

  • Deadline: Late 2029 / Early 2030.


CAUSE OF ACTION 3: STATE LIABILITY (ADMINISTRATIVE NEGLIGENCE)

Focus: The State’s failure to transpose directives or enforce laws (Francovich Doctrine).

1. IDENTIFY ALL PROVEN FOIGS (FINDINGS OF INFRINGEMENT)

  • FOIG: The “Infringement” here is the State’s own breach of EU Law (e.g., failure to effectively enforce GDPR or Competition Directives, or wrongful implementation of Digital Markets Act – DMA).

  • Evidence: The European Court of Justice (ECJ) rulings against Spain or the Commission’s infringement proceedings (e.g., regarding procedural delays).

2. IDENTIFY POSSIBILITIES THAT THESE FOIGS COULD HAVE BEEN CAUSED BY AN ULTRAVIRES/UNLAWFUL DORCAP FROM THE REGULATOR

  • DORCAP: The systematic “DORCAP” is the omission of duty by the Ministry of Economy/Digital Transformation and the Regulators.

  • Judicial Review: This IS the Judicial Review claim. The argument is that the State’s inaction was ultra vires (outside its power to neglect duty).

3. HAS THE STATE PAID REDRESS TO VICTIMS?

  • Redress: NO.

  • Regreso/Disciplinary: NO.

DATES & TIME LIMITS TO CLAIM:

  • Claim Period: 1 Year (Strict strict liability limit in Spain for Responsabilidad Patrimonial del Estado).

  • Start Date: From the date of the “fact” or the judgment establishing the State’s breach/annulment of the faulty administrative act.

  • Deadline: 16 December 2026 (assuming the “16 Dec 2025” update marks a definitive triggering event or knowledge of the claimable act).


SOLICITOR’S RECOMMENDATION

The 16 December 2025 update indicates that the “Time is of the Essence.” We have definitive FOIGs (€1.2B & €797M) which act as binding proof of liability. The strategy is to leverage the State’s failure to compensate victims (despite collecting fines) to force a Mediation or Settlement before the 1-year State Liability window closes.

Next Steps:

  1. Issue Letter of Claim to Meta (Private Action) citing the FOIGs.

  2. File Preliminary Claim against the AEPD/CNMC (Public Action) for Administrative Liability (DORCAP failure) to stop the 1-year clock.


16DEC

From the content on the provided URLs at meta.cocoo.uk, the case focuses on alleged abuses by Meta Platforms (Facebook, Instagram, WhatsApp) involving data exploitation, privacy violations, and anticompetitive practices, with claims that regulators and public bodies committed ultra vires acts through specific DORCAPS that enabled these harms.

The identified ultra vires DORCAPS from regulators and public bodies include:

– Omissions in failing to conduct proper cost-benefit analyses of platform benefits versus damages to competition and citizen rights.

– Omissions in failing to prepare ethical impact reports, contingency plans, or fiscal provisions for state liability arising from regulatory inaction.

– Decisions approving key mergers (such as Instagram and WhatsApp acquisitions) without adequate risk assessments or appreciation of long-term impacts on competition.

– Omissions in timely investigation of known abuses, enforcement of GDPR (Articles 5, 6, 9 on lawful processing, data minimization, special categories), DMA (interoperability, no self-preferencing), and competition laws (TFEU Article 102).

– Actions and policies involving public bodies contracting advertising with Meta, where such contracts rely on illegally obtained data, exceeding legal authority and harming citizens.

– Omissions in addressing regulatory gaps, such as “misleading freeness” of services paid with data, and failure to protect markets and consumers from systemic harms.

The companies harmed include Meta itself as the company under investigation, facing existential risks, reputational damage, and unsustainable legal battles due to regulatory failures. Other harmed companies are competitors and business users, such as those in online classifieds (eBay, Gumtree, Vinted in UK; Wallapop, Milanuncios in Spain), web analytics firms (Databuzz Ltd., Cambridge Spark in UK; MARKETZILLA, Coco Solution in Spain), gaming and music developers (Rebellion, Codemasters, Team17 in UK; Gameloft, Crema Games in Spain; Spotify, Deezer), cloud providers (ANS Group in UK; Microsoft Azure, Google Cloud in Spain), and advertisers (Havas UK, LOLA MullenLowe Spain, Procter & Gamble) facing inflated ad prices, dependency, exclusionary practices, loss of market opportunities, and reduced innovation from Meta’s dominance enabled by regulatory omissions.

The consumers harmed, as tort victims of Meta and ultimately of the regulators’ ultra vires DORCAPS, include approximately 45 million UK Facebook users and 40 million Spanish users (primarily 2016-2019 period, with ongoing harms), affected by uncompensated excessive data collection (including biometric, emotional profiling), privacy breaches (e.g., Cambridge Analytica affecting millions, 2021 breach of 533 million), distress, non-material damages, algorithmic manipulation undermining autonomy, exposure to CSAM due to inadequate age checks, and overpayment or reduced choices in a non-competitive market.


Judicial review opportunities in the UK to challenge ultra vires DORCAPS in this Meta case include claims against ongoing omissions by the Information Commissioner’s Office (ICO) to enforce GDPR provisions (such as Articles 5, 6, 9 on lawful processing and data minimization) despite known breaches, where harm to consumers and competitors continues, allowing filing within three months of when grounds arise or treating the omission as a continuing act with no fixed date barring the claim.

Another opportunity is judicial review of ongoing policies or decisions by the Competition and Markets Authority (CMA) involving failures to address anticompetitive effects from data practices or inadequate merger assessments (Instagram 2012, WhatsApp 2014), as continuing harms mean the claim remains timely if framed as persistent omission.

Judicial review against public authorities (such as government departments or local bodies) for contracting advertising services with Meta reliant on allegedly illegally processed data, arguing such contracts exceed powers or involve improper use of public funds, with ongoing contracts providing grounds for current challenge without strict time bar if harm persists.

Opportunity for COCOO to seek judicial review mandating a public authority (such as the Cabinet Office or relevant oversight body) to initiate or publicize an internal procedure to pursue ex officio the regulator (ICO or CMA) whose ultra vires DORCAPS led to torts requiring state compensation, based on duties of accountability and recovery under public law, especially where state liability for regulatory failures arises.

Challenges to secondary legislation or its implementation, such as aspects of the Data Protection Act 2018 or related regulations implementing UK GDPR that allegedly fail to adequately enforce against systemic data abuses, or competition regulations under the Digital Markets, Competition and Consumers Act 2024 enabling insufficient oversight, where ongoing application and harm allow timely judicial review claims arguing ultra vires for incompatibility with higher obligations.

The equivalent in Spain to UK judicial review is the recurso contencioso-administrativo, which challenges administrative acts, omissions, or regulations for ultra vires, with similar opportunities against AEPD omissions on GDPR enforcement or CNMC on competition issues, and no fixed dates barring claims where harms are ongoing.


From the list of identified judicial review opportunities, none involve a specific decision or act dated within the last three months (since 16 September 2025) that would place them strictly within the standard three-month time limit under CPR 54.5 for filing in the UK, as the challenges target ongoing omissions, policies, or continuing failures rather than recent discrete acts.

However, opportunities older than three months where the tort or harm is ongoing as of 16 December 2025 allow for a rolling judicial review in the UK, as courts recognise continuing omissions or persistent conduct (such as failures to enforce GDPR or address anticompetitive effects) as giving rise to fresh grounds without a fixed time bar, provided the claim is brought promptly in relation to the ongoing nature. This applies to judicial review of ongoing ICO omissions on GDPR enforcement, CMA failures on competition issues including past mergers with continuing effects, public authorities’ ongoing advertising contracts with Meta, COCOO’s claim mandating initiation of internal procedures against regulators, and challenges to secondary legislation or implementation (like Data Protection Act 2018 or Digital Markets, Competition and Consumers Act 2024 aspects) where application remains ongoing and harms persist.

In Spain, the equivalent recurso contencioso-administrativo has a two-month time limit for express acts but allows challenges to ongoing omissions or inactivities where harm continues, similarly supporting timely claims framed around persistent failures by AEPD or CNMC.


Proposals to prevent and remedy tort harms from ultra vires DORCAPS by regulators and public bodies (such as ICO and CMA omissions on GDPR and competition enforcement, and public advertising contracts reliant on unlawful data processing) include settlements where the State accepts vicarious liability for regulatory failures, providing compensation to victims (including affected consumers and competitor companies) through dedicated funds, while regulators/public bodies avoid personal fiduciary or contributory liability for bad faith non-disclosure of ultra vires risks that deprive the State of Violenti non fit injuria defences.

These proposals allow win-win outcomes: victims (consumers harmed by privacy breaches and non-material damage, and companies like competitors facing market distortions or Meta itself under unsustainable investigations) receive redress via State-funded compensation, injunctions, commitments, settlements, cy-près style awards (directed to consumer protection or competition advocacy charities like COCOO), grant awards for affected businesses, and public contract awards prioritising harmed competitors; the State remedies systemic harms positively; regulators/public bodies gain protection from abuse of power claims by cooperating transparently.

Customised remedies and undertakings COCOO should propose to ICO, CMA, or relevant public authorities include commitments to enforce GDPR Articles 5, 6, 9 against Meta’s ongoing data practices and review past merger effects with consumer/competitor input; no fines on regulators/public bodies (to encourage cooperation); injunctions mandating transparency on ultra vires risks and internal accountability procedures; suspended quashing orders on unlawful advertising contracts or policies, allowing time for transition to compliant alternatives while suspending invalidity; cy-près proposals directing equivalent value from avoided liabilities or saved enforcement costs to funds compensating UK/Spanish consumers (e.g., for non-material damages from excessive data collection) and harmed companies (e.g., lost market opportunities for analytics firms, developers, advertisers), administered via COCOO for privacy education, competition research, or direct victim support; undertakings to award grants/contracts to victim companies for innovation in privacy-compliant alternatives or competitive markets.

These facilitate State vicarious liability claims for compensation while incentivising regulators to accept by reducing exposure to contributory negligence for reckless bad faith cover-ups of ultra vires DORCAPS causing ongoing tort harms as of 16 December 2025.


No open or closed claim, settlement, or arbitration has been identified where a state (such as the UK, Spain, or any EU member state) has paid compensation or penalties due to regulatory failures or ultra vires acts by public bodies or regulators (like ICO, CMA, AEPD, or CNMC) in relation to Meta’s data practices, privacy violations, or anticompetitive conduct, directly or tangentially.

Companies have faced multiple penalties and compensation orders related to this case, all paid by Meta (or Facebook) rather than the state. These include a November 2025 Spanish court order requiring Meta to pay €479 million in compensation to 87 digital media publishers and news agencies for unfair competition arising from GDPR violations in behavioral advertising (2018-2023 period), treating Meta’s advertising profits as unlawfully obtained. Other examples are regulatory fines imposed on Meta, such as the €1.2 billion fine in 2023 by Ireland’s Data Protection Commission (under EDPB direction) for unlawful EU-US data transfers, €390 million in 2023 for improper ad personalization practices, and various other GDPR-related fines totaling hundreds of millions euros from EU authorities. No instances involve state payments for regulatory omissions or failures enabling these harms.


The probability that COCOO.uk, as a charity focused on competition and consumer protection without direct personal harm, would be granted locus standi for judicial review challenging a public body’s ongoing refusal (via ignored letter constituting negative administrative silence) to initiate an internal ex officio procedure akin to “accion de regreso” (state recovery against ultra vires regulators or officials) is approximately 65-75%. This estimate reflects the liberal “sufficient interest” test under Senior Courts Act 1981 s.31(3), where courts grant standing to genuine public interest charities or pressure groups on regulatory inaction in data protection or competition matters when no directly affected individual pursues the claim, as in R v Foreign Secretary ex parte World Development Movement [1995] (Pergau Dam, standing for pressure group on unlawful aid) and similar cases allowing public-spirited challengers to vindicate rule of law. The ignored letter strengthens interest as the challenged “decision” (ongoing omission treatable as rolling for timeliness), and COCOO’s mission aligns with public accountability for regulatory failures causing widespread tort harms. Success depends on framing the claim’s arguability and public importance at permission stage, with courts disinclined to deny meritorious public interest claims outright.

Ideas to build locus standi include sending targeted pre-action protocol (PAP) letters under the Judicial Review Pre-Action Protocol to regulators or public bodies (e.g., ICO, CMA, or oversight departments), demanding specific actions such as confirmation of refusal to publish ultra vires risk assessments (including foreseeable tort harms) or to initiate internal accountability procedures. A explicit response denying the request creates a fresh reviewable decision, bolstering COCOO’s interest as the recipient/addressee of that refusal. Silence after 14 days (standard response period) can be treated as refusal, supporting challenge to the omission. This forces crystallisation of the impugned act without “tricking” unlawfully, as PAP compliance is expected and courts recognise such correspondence in assessing standing.

FOI requests already sent by COCOO gather evidence of ultra vires DORCAPS, and any refusals or disclosures can be referenced to demonstrate COCOO’s active engagement, reinforcing sufficient interest without conferring standing alone.

Judicial review can serve as a public notification mechanism by seeking declarations on failures to disclose ultra vires risks and consequential tort harms, highlighting breach of fiduciary duties of good faith and transparency owed by regulators/public bodies. Courts may grant such remedies where inaction risks ongoing public harm, putting matters on record and enabling preventive measures by victims, though primary focus remains legality rather than broad publicity. No direct precedent mandates personal/official liability via JR for non-disclosure, but claims can argue irrationality or procedural impropriety in cover-ups depriving state defences.


From the identified DORCAPS in this Meta case, the key ones with potential ultra vires arguments are:

– Omissions by the ICO in failing to enforce GDPR Articles 5, 6, 9 against Meta’s data practices: 45% probability of being ultra vires. This estimate reflects the ICO’s broad discretion in enforcement under the Data Protection Act 2018 and UK GDPR, where courts rarely find regulatory inaction irrational or unlawful absent egregious failure, though ongoing systemic harms to millions could argue procedural impropriety or irrationality in prioritisation.

– Decisions by the CMA approving Meta’s Instagram (2012) and WhatsApp (2014) mergers without adequate long-term competition risk assessments: 30% probability of being ultra vires. Merger clearances were within statutory powers at the time, with ex post reviews (e.g., Lear report) acknowledging under-enforcement risks but not deeming original decisions unlawful, as predictive assessments involve judgment not easily overturned.

– Omissions by the CMA in addressing ongoing anticompetitive effects from data dominance: 40% probability of being ultra vires. Similar to ICO omissions, discretion in enforcement is wide, but persistent harms post-Digital Markets, Competition and Consumers Act 2024 could support arguments of irrational failure to act.

– Actions/policies by public bodies contracting advertising with Meta reliant on allegedly unlawful data processing: 55% probability of being ultra vires. Public contracts must comply with public law principles (e.g., proportionality, proper purpose), and reliance on unlawful processing could exceed powers or involve improper funds use, though no specific challenges have succeeded.

For those with good ultra vires probability (above 40%), no published notices, reports, or URLs from ICO, CMA, or relevant public bodies disclose ultra vires risks or mandatory risk reports specifically addressing the possibility of ultra vires in these DORCAPS related to Meta. ICO and CMA publish general corporate risk registers (e.g., ICO documents from 2020-2021 on internal risks) and annual reports/transparency statements, but these focus on operational risks, not admissions of ultra vires in enforcement omissions, merger decisions, or contracting. No equivalent mandatory risk notices highlight ultra vires foreseeability or consequential tort harms from these specific failures. This absence increases tort claim risks against the State via vicarious liability for regulatory ultra vires, as non-disclosure prevents constructive notice to victims, weakening any Volenti non fit injuria defence.

In this case, the probability of successfully arguing contributory liability primarily against the regulator/public body (rather than vicariously against the State) so tort victims claim only against them is approximately 15-20%. UK public law establishes vicarious State liability for ultra vires acts by public authorities (including regulators like ICO/CMA), with non-delegable duties in core functions; direct personal/official liability requires misfeasance (bad faith/abuse of power), which is hard to prove absent evidence of malice, and contributory negligence rarely shifts full burden from State to individual regulators.


FOIS

The key bodies from which information is needed to gather evidence on ultra vires DORCAPS (including omissions in GDPR enforcement by ICO, competition enforcement/merger decisions by CMA, and public advertising contracts reliant on unlawful data) and potential internal recovery procedures (equivalent to accion de regreso) are the **Information Commissioner’s Office (ICO)** as main regulator for data protection, the **Competition and Markets Authority (CMA)** for competition aspects, and the **Cabinet Office** as oversight for central government contracting and potential state accountability procedures.

No specific published risk registers, board papers, or assurance frameworks from these bodies identify risks of ultra vires acts, legal challenges, or foreseeable tort harms related to Meta enforcement omissions, merger clearances, or advertising contracts; general corporate risks are published but not case-specific.

**Draft A: The “Strategic Knowledge” Probe** (Target: ICO as main decision maker on data enforcement)

Dear Information Access Team,

I am writing under the Freedom of Information Act 2000 to request the following metadata from any corporate, strategic, or operational risk registers held by the ICO concerning enforcement priorities or actions related to large online platforms processing personal data for behavioural advertising (including Meta Platforms Inc.):

1. Any risk entry titles, descriptions, risk IDs (if applicable), and assigned risk owners for risks involving potential under-enforcement of UK GDPR Articles 5, 6, or 9 against systemic data processing by dominant platforms, covering the period 2020 to present.

2. For any such identified risks, the inherent risk scores, residual risk scores, and any recorded changes in scores (movement) over the last 24 months.

3. The ICO’s current risk appetite statement or tolerance levels specifically regarding legal compliance and enforcement in data protection regulation.

Please provide this as factual administrative data, without disclosing any advisory content.

Yours sincerely,
oscar moya, Director of Competition & Consumer Organisation Party Limited (COCOO.uk), 23 Village Way, Beckenham, Kent BR3 3NA, Companies House Registration: 15466919, EU Transparency Register: 177568392007-84 Email: contact@cocoo.uk

**Draft B: The “Operational Failure” Probe** (Target: CMA as operational body on competition enforcement and mergers)

Dear Information Access Team,

Under the Freedom of Information Act 2000, I request the following metadata regarding any assessments or monitoring of competition impacts from digital mergers or data dominance involving Meta Platforms Inc. (formerly Facebook), including Instagram (2012) and WhatsApp (2014) acquisitions or ongoing market effects:

1. Dates of creation and finalisation (if any exist) for any post-merger reviews, impact assessments, or monitoring reports on long-term competition effects, along with the job titles of approvers.

2. The number of months (if tracked) that any related competition concerns or enforcement priorities have been reported as high-risk, red status, or off-track in board or management reporting since 2020.

3. Whether any internal procedure equivalent to recovery action (accion de regreso) has been initiated ex officio to reclaim costs or pursue accountability for potential regulatory failures leading to state compensation payments in competition or data-related torts; if not, any recorded reasons for non-initiation.

Yours sincerely,
oscar moya, Director of Competition & Consumer Organisation Party Limited (COCOO.uk), 23 Village Way, Beckenham, Kent BR3 3NA, Companies House Registration: 15466919, EU Transparency Register: 177568392007-84 Email: contact@cocoo.uk

**Draft C: The “Systemic Flaw” Probe** (Target: Cabinet Office as oversight for public contracting and state procedures)

Dear FOI Team,

I request under the Freedom of Information Act 2000 the following information on central government or public body advertising contracts involving Meta Platforms Inc.:

1. A list of titles and dates for any internal audit reports or reviews commissioned in the last 5 years related to compliance risks in public sector digital advertising contracts, particularly reliance on third-party data processing.

2. Metadata on any assessments of legal risks in such contracts, including dates created/finals and approver job titles (existence only, not content).

3. Details of any ex officio internal procedures initiated (or reasons for non-initiation) to pursue recovery (equivalent to accion de regreso) against regulators or public bodies for ultra vires acts leading to potential state liability or compensation payments in data protection or competition torts arising from regulatory failures.

Yours sincerely,
oscar moya, Director of Competition & Consumer Organisation Party Limited (COCOO.uk), 23 Village Way, Beckenham, Kent BR3 3NA, Companies House Registration: 15466919, EU Transparency Register: 177568392007-84 Email: contact@cocoo.uk

These questions focus on metadata (existence, titles, scores, dates, owners) to avoid refusals under sections 35 or 42, while trapping evidence of known risks (proving awareness of ultra vires potential without disclosure), score movements (showing watched-but-unaddressed escalation supporting recklessness), and non-initiation of recovery (evidencing failure to mitigate state tort exposure, strengthening misfeasance claims).

Leave a Reply