The Spanish authority imposes a €750,000 fine on VODAFONE ESPAÑA for data security breaches and lack of a valid data processing agreement
The Spanish data protection authority sanctioned a telecommunications operator for a data breach resulting from the absence of a valid data processing agreement and adequate security measures at its processor, emphasizing the unshakable responsibility of the controller in overseeing its processing chain.
Facts and context
The Spanish data protection authority (AEPD) today published a sanction decision against VODAFONE ESPAÑA, S.A.U. (including the imposition of a €750,000 fine) for breaches related to the absence of a data processing agreement, insufficient security measures, and a breach of data confidentiality.
The case originated from a data breach notification by VODAFONE on November 23, 2023, following a cyber incident at its processor, ***EMPRESA.1***, which led to unauthorized access to a file containing customer data.
Reasons for the decision
- Obligation to formalize the relationship with a processor (Article 28 of the GDPR): The authority found that at the time of the data breach, there was no valid data processing agreement concluded between VODAFONE, as the controller, and its processor ***EMPRESA.1***. The contract was only signed on September 4, 2024, well after the incident. The authority ruled that a contract formalized after the breach, even with a purportedly retroactive effective date, does not exempt the controller from liability, as it does not guarantee the processor's effective compliance with GDPR obligations during the uncovered period.
- Obligation to ensure the security of processing (Article 32 of the GDPR): The investigation revealed serious deficiencies in technical and organizational measures. The authority considered that a breach of this article occurs as soon as security measures are inadequate for the risk, without the need for an actual data breach to materialize. In this case, failures were identified such as the absence of encryption of data at rest (the exfiltrated data was in clear text), lack of control over the geographical origin of connections, and weaknesses in user access lifecycle management, constituting a structural vulnerability.
- Obligation to ensure the integrity and confidentiality of data (Article 5, paragraph 1, point f) of the GDPR): The loss of confidentiality of customer data (name, first name, email) is a direct consequence of the previous breaches. The authority considered that the insufficiency of security measures allowed unauthorized access and breach of the confidentiality principle. In accordance with the proactive accountability obligations of Articles 5, paragraph 2, and 24 of the GDPR, VODAFONE, as the controller, was held responsible for this breach, having failed to demonstrate that appropriate measures were implemented to protect the data.
Authority's decision
Consequently, the authority imposed a €750,000 fine on VODAFONE ESPAÑA, S.A.U. This fine is broken down into €100,000 for the breach of Article 28, €150,000 for that of Article 32, and €500,000 for the breach of Article 5, paragraph 1, point f) of the GDPR.
Lessons learned
This decision confirms / specifies / recalls that:
- A data processing agreement must be formalized and in effect *before* any data processing begins; its late signature, even with retroactive effect, does not cover the prior period and constitutes a breach in itself.
- The controller remains fully responsible for breaches occurring at its processor, especially when lack of supervision and absence of an adequate contractual framework cause the incident.
- The breach of the security obligation (Article 32) is constituted by the mere absence of appropriate technical and organizational measures, regardless of the actual materialization of a data breach.
- Control and audit activities of a processor must be effective and documented; unsigned forms without methodological description are deemed insufficient to demonstrate adequate supervision.
- Previous sanctions for similar breaches (e.g., confidentiality or security measures violations) are considered a relevant aggravating factor when determining the amount of the fine.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire