Spain Spain

Vodafone España, S.A.U.

136,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2023-03-15.

Rank · Sector
#101
of 369 in Media, Telecoms and Broadcasting
Rank · Spain
#88
of 1,075
Rank · All fines
#420
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2023-03-15
Controller / Processor
Vodafone España, S.A.U.
Sector
Media, Telecoms and Broadcasting
Quoted Articles
Art. 6 GDPR, Art. 32 GDPR
Type of violation
Insufficient legal basis for data processing

Summary

The Spanish DPA (AEPD) has imposed a fine on Vodafone España, S.A.U. A data subject had filed a complaint against the data controller as unauthorized fraudsters managed to access their Vodafone account and make changes to their contract. During its investigation, the DPA found that Vodafone had carried out the changes without verifying the identity of the person requesting them and determining whether they were actually requested by the data subject. The original fine of EUR 170,000 was reduced to EUR 136,000 due to voluntary payment and admission of responsibility.

Open original source Links to the regulator's original publication or another source.

Related fines