The Spanish authority closes a procedure against Vodafone for fraudulent SIM card duplication

The Spanish authority closes a sanction procedure concerning fraud by SIM card swapping, considering that the GDPR does not apply when the telephone line is held by a legal entity, even if the user is a natural person victim of the fraud.

Facts and context

The Spanish data protection authority (AEPD) has today published a decision to close the procedure against VODAFONE ESPAÑA, S.A.U., initially opened for data processing without a legal basis following a SIM swapping fraud.

The case originates from a complaint by a natural person who, after noticing a banking fraud amounting to ***CANTIDAD.1, discovered that a third party had obtained without consent a duplicate SIM card of their professional line from the operator.

Reasons for the decision

  • Absence of breach of the lawfulness obligation of processing (Article 6(1) of the GDPR): The authority found that the telephone line in question was not held by the complainant but by their employer, a legal entity. Based on recital 14 of the GDPR, which explicitly excludes from its scope the processing of data relating to legal persons, the authority concluded that issuing the duplicate SIM card did not constitute processing of personal data of the complainant. Consequently, the provisions of the GDPR, including the requirement for a legal basis, did not apply to this operation.

Decision of the authority

Consequently, the authority ordered the closure of the sanction procedure against VODAFONE ESPAÑA, S.A.U.

Lessons learned

This decision reminds that:

  • The material scope of the GDPR is strictly limited to the protection of natural persons, as specified in recital 14.
  • Data relating to a legal person, including its contact details or contractual information of a business telephone line, are not considered personal data under the GDPR.
  • It is essential to distinguish the contract holder (the legal person) from the end user of the service (the natural person) to determine whether the GDPR applies to a given processing operation.
  • An operation that does not constitute a GDPR violation due to the regulation's inapplicability may nevertheless reveal a security flaw with harmful consequences for end users.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire