The Spanish authority closes a data breach case against Vodafone Spain without sanction
In a notable decision, the Spanish authority dismissed proceedings against a data controller for a data breach that occurred at its processor, considering that the latter had acted outside the clear and precise contractual instructions given to it.
Facts and context
The Spanish Data Protection Authority (AEPD) has today published a decision to dismiss the case against VODAFONE ESPAÑA, S.A.U. concerning a data breach that occurred at one of its processors.
The case originated from a data breach notification by VODAFONE ESPAÑA, S.A.U. on 9 October 2023, following a cyberattack affecting one of its distributors and leading to the publication of customer data on the deep web.
Reasons for the decision
- Obligation to formalize the relationship with the processor (Article 28 of the GDPR): The authority initially reproached VODAFONE for the absence of framework contracts with two of its distributors acting as processors. However, the company produced the contracts in question, whose signature validity (one certified by a trusted third party, the other electronic and annexed) could not be challenged by the authority. The authority therefore concluded that this breach was not established.
- Obligation to ensure data security (Article 5(1)(f) of the GDPR and Article 32 of the GDPR): The authority analyzed whether the responsibility for the breach could be attributed to VODAFONE. It found that the processing contracts contained precise instructions and security clauses, including the obligation for the processor to carry out vulnerability assessments. Relying on the European Data Protection Board guidelines 7/2020 and the Court of Justice of the European Union ruling of 5 December 2023 (case C-683/21), the authority considered that the data controller's responsibility does not extend to cases where the processor acts outside or incompatibly with the instructions received. In this case, the breach resulted from the processor's failure to comply with these instructions, thus exonerating VODAFONE from its responsibility.
Authority's decision
Consequently, the authority decided to dismiss the proceedings and did not impose any sanction against VODAFONE ESPAÑA, S.A.U.
Lessons learned
This decision recalls that:
- A data controller can be exonerated from liability for a data breach occurring at its processor, provided it demonstrates that the latter acted outside the clear and adequate contractual instructions given.
- Processing contracts must contain precise and verifiable technical and organizational security measures, such as the obligation to carry out vulnerability assessments, and not be limited to general clauses.
- In case of dispute over the existence of a processing contract, the production of a signed document, including by electronic signature, places the burden of proving its invalidity on the supervisory authority.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire