Spain Spain

Vodafone España, S.A.U.

30,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2019.

Rank · Sector
#244
of 366 in Media, Telecoms and Broadcasting
Rank · Spain
#293
of 1,071
Rank · All fines
#875
of 3,042

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2019
Controller / Processor
Vodafone España, S.A.U.
Sector
Media, Telecoms and Broadcasting
Quoted Articles
Art. 5 (1) f) GDPR, Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

Disclosure of customer personal data (i.a. purchase history) via an SMS to another customer. The initial fine of EUR 50.000 was reduced to EUR 30.000.

Open original source Links to the regulator's original publication or another source.

Related fines