The Spanish authority fines Vodafone Spain 500,000 euros for GDPR security failures following a ransomware attack
A ransomware attack at a subcontractor led the Spanish authority to sanction the data controller, VODAFONE, with a fine of 500,000 €, holding it responsible for structural security failures on its own infrastructure, notably the absence of multi-factor authentication on a remote access.
Facts and context
The Spanish Data Protection Authority (AEPD) today published a sanction decision against VODAFONE ESPAÑA, S.A.U. (including the imposition of a 500,000 € fine) for failures related to the security of personal data processing.
The case originated from a data breach notification by VODAFONE on November 4, 2023, following a ransomware attack suffered on November 2, 2023 by one of its subcontractors.
Reasons for the decision
- Obligation to ensure the security of processing (Article 32 of the GDPR): The authority found that the data breach, which affected the confidentiality and availability of data of 724,733 customers, resulted from inadequate security measures. Although the attack targeted a subcontractor, the investigation revealed that the root cause was a structural failure in VODAFONE's infrastructure, namely access to its virtual private network (VPN) without multi-factor authentication. The subcontractor had created a generic account with a weak password, facilitating the intrusion. The AEPD rejected VODAFONE's argument to transfer responsibility to its subcontractor, considering that the data controller must ensure an appropriate level of security on its own infrastructure, including the accesses it provides to its providers. The authority recalled, relying on the Supreme Court case law (ruling no. 188/2022), that while the obligation of Article 32 is an "obligation of means," the mere finding of measures inadequate to the risk is sufficient to characterize the failure. The subcontractor's ISO 27001 certification was not deemed sufficient to exempt VODAFONE from its own negligence. Although a breach of the confidentiality principle (Article 5, paragraph 1, point f) of the GDPR) was also found, the authority decided to qualify all the facts under the sole breach of Article 32, considering it more appropriate to sanction the lack of technical and organizational measures.
Authority's decision
Consequently, the authority imposed a fine of 500,000 € on VODAFONE ESPAÑA, S.A.U..
Lessons learned
This decision reminds that:
- The responsibility for security failures lies with the data controller when the breach, although triggered by the action of a subcontractor, finds its root cause in a vulnerability of the data controller's own infrastructure.
- The certification of a subcontractor (such as the ISO 27001 standard) is an element of assessment but does not constitute a guarantee of compliance and does not exempt the data controller from its obligation to verify the adequacy of security measures in light of the specific risks of the processing.
- The absence of fundamental security measures, such as multi-factor authentication for remote access to systems containing personal data, constitutes serious negligence and a violation of the obligation to ensure security appropriate to the risk.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire