The Spanish authority sanctions Vodafone for GDPR breaches with a total fine of 1,050,000 euros

The Spanish data protection authority (AEPD) has sanctioned Vodafone España with a fine of €1,050,000 for serious breaches of the principles of lawfulness and security, which allowed the opening of a line and the communication of an invoice to an unauthorized third party.

Facts and context

The Spanish data protection authority (AEPD) published a sanction decision against Vodafone España, S.A.U. (including the imposition of a fine of €1,050,000) for breaches related to the lawfulness of processing and the security of personal data.

The case originated from a complaint by a customer whose invoice, containing personal data, was communicated to a third party without her consent, despite a prior request to strengthen the security of her account.

Grounds for the decision

  • Obligation of lawfulness of processing (Article 6(1) of the GDPR): The authority found that a telephone line was opened in the complainant's name without a legal basis. Although Vodafone invoked a validation process by a one-time code sent to another line of the customer, the authority considered that the operator did not demonstrate that the person making the request had legitimately passed the security checks, rendering the processing unlawful.
  • Second breach of the obligation of lawfulness of processing (Article 6(1) of the GDPR): The authority also found a violation for the modification of the complainant's contact details and the communication of a duplicate of her invoice to a third party. Vodafone acknowledged that an agent of its subcontractor did not follow the security procedure. The absence of call recording prevented verification that the third party met identification requirements, thus depriving the processing of any legal basis.
  • Obligation of security of processing (Article 32 of the GDPR): The authority concluded that Vodafone's technical and organizational measures were insufficient, notably for management carried out by phone. The security policy did not prevent a third party from accessing data and performing unauthorized operations. The authority emphasized that a third party's fraud does not exempt the controller from liability if its control and verification measures are deficient, citing the Spanish Supreme Court case law (appeal 6109/2020) in support.

Authority's decision

Consequently, the authority imposed a total fine of €1,050,000 on Vodafone España, S.A.U., broken down into €150,000 for the unlawful line opening, €150,000 for the communication of the invoice, and €750,000 for the breach of the security obligation.

Furthermore, the authority ordered Vodafone to adopt, within six months, the necessary measures to bring its processing into compliance with Articles 6 and 32 of the GDPR, to prevent third parties from performing unauthorized operations.

Lessons learned

This decision reminds that:

  • The fraudulent intervention of a third party does not exempt the controller from liability if the security measures implemented are insufficient to robustly verify the identity of the requester.
  • The principle of proactive accountability (Article 5(2) of the GDPR) requires not only implementing protective measures but also being able to demonstrate their effective application, for example through the recording of critical calls.
  • Previous breaches of the same nature constitute an aggravating circumstance (Article 83(2)(e) of the GDPR) justifying a higher sanction, especially for companies whose main activity relies on large-scale processing of personal data.
  • The fault of an employee or subcontractor who does not follow an internal procedure does not mitigate the controller's responsibility but rather reveals a failure in its organizational and control measures.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire