Spain Spain

Xfera Moviles S.A.

60,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2019-11-19.

Rank · Sector
#155
of 369 in Media, Telecoms and Broadcasting
Rank · Spain
#176
of 1,075
Rank · All fines
#627
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2019-11-19
Controller / Processor
Xfera Moviles S.A.
Sector
Media, Telecoms and Broadcasting
Quoted Articles
Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

An individual complainant had received an SMS from Xfera Móviles which was to be addressed to a third party and which allowed him to access the account and personal data of this third party on the Xfera Móviles website via the telephone number and password received by SMS.

Open original source Links to the regulator's original publication or another source.

Related fines