Spain Spain

Xfera Moviles S.A.

60,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2019-11-19.

Rank · Sector
#152
of 366 in Media, Telecoms and Broadcasting
Rank · Spain
#172
of 1,071
Rank · All fines
#620
of 3,042

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2019-11-19
Controller / Processor
Xfera Moviles S.A.
Sector
Media, Telecoms and Broadcasting
Quoted Articles
Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

An individual complainant had received an SMS from Xfera Móviles which was to be addressed to a third party and which allowed him to access the account and personal data of this third party on the Xfera Móviles website via the telephone number and password received by SMS.

Open original source Links to the regulator's original publication or another source.

Related fines