The Spanish authority fines XFERA MÓVILES €200,000 for fraudulent SIM card duplicate in violation of the GDPR
The Spanish data protection authority sanctioned a telecommunications operator for issuing a SIM card duplicate to a fraudster, considering that the failure of the point of sale agent to properly apply identity verification procedures constituted unlawful data processing due to a lack of diligence by the data controller.
Facts and context
The Spanish data protection authority (AEPD) published a sanction decision against XFERA MÓVILES, S.A.U. (including the imposition of a €200,000 fine) for breaches related to the lawfulness of processing in the context of a SIM card duplicate request.
The case originated from a complaint by a person whose SIM card was fraudulently duplicated by an unauthorized third party on July 24, 2023, at an operator distributor, after presentation of a falsified identity document.
Reasons for the decision
Obligation of lawfulness of processing (Article 6(1) of the GDPR): The authority considered that issuing a SIM card duplicate to an unauthorized third party constituted unlawful processing of personal data. Although the company invoked contract performance (Article 6(1)(b) of the GDPR) as the legal basis, the AEPD ruled that this basis could not justify handing over the card to a person whose identity had not been verified with due diligence. The company acknowledged a "one-off human error" by the point of sale agent, who did not properly compare the data on the presented identity document with those of the legitimate holder. The authority rejected the argument that this was strict liability, specifying that the sanction was based on a lack of diligence (fault), the company being responsible for ensuring that its procedures, even if formally existing, are effectively applied by its agents to prevent such unauthorized processing.
Authority's decision
Consequently, the authority imposed a €200,000 fine on XFERA MÓVILES, S.A.U.
Furthermore, the authority ordered the company to demonstrate, within six months, the adoption of corrective measures ensuring the lawfulness of data processing when issuing SIM card duplicates.
Lessons learned
This decision reminds that:
The mere existence of internal security procedures is insufficient; the data controller must ensure their effective and consistent application by its staff and distributors to guarantee the lawfulness of processing.
A "one-off human error" by an agent does not exempt the data controller from liability, as it is bound by a duty of care in supervising and controlling the application of its security policies.
Issuing a SIM card duplicate to an unauthorized third party following a failed identity verification constitutes unlawful processing under Article 6 of the GDPR, not merely a security incident.
The data controller's liability in case of fraud is not strict liability but relies on demonstrating a breach of its duty of care (fault or negligence) in implementing appropriate verification measures.
The national identification number is data whose unauthorized processing presents a high risk to rights and freedoms, constituting a severity factor that may justify a higher sanction.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire