Spain Spain

Vodafone España, S.A.U.

3,940,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2022-02-01.

Rank · Sector
#41
of 369 in Media, Telecoms and Broadcasting
Rank · Spain
#11
of 1,075
Rank · All fines
#88
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2022-02-01
Controller / Processor
Vodafone España, S.A.U.
Sector
Media, Telecoms and Broadcasting
Quoted Articles
Art. 5 (1) f) GDPR, Art. 5 (2) GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The Spanish DPA has fined Vodafone España, S.A.U. EUR 3.94 million. Nine Vodafone customers had filed complaints with the DPA. In the course of its investigation, the DPA found that fraudsters had pretended to be the data subjects when contacting Vodafone and had demanded a copy of their SIM cards. As a result, they were able to conclude contracts at the expense of the data subjects and carry out various transfers. According to the DPA, Vodafone had not properly verified the identity of the fraudsters before issuing the SIM cards and ensured that the inquirers were really the SIM card holders due to a lack of sufficient security measures.

Open original source Links to the regulator's original publication or another source.

Related fines