The Spanish authority sanctions Vodafone Spain for a GDPR violation related to another security breach in 2023

A decision sanctioning a controller for the absence of a subcontracting contract in force at the time of a data breach, the authority having rejected the validity of a retroactively signed agreement, as well as for security measures deemed insufficient at the subcontractor.

Facts and context

The Spanish data protection authority (AEPD) has today published a sanction decision against VODAFONE ESPAÑA, S.A.U. (including the imposition of a fine of €400,000) for failures related to the security of processing and the contractual framework of its subcontractor.

The case originates from the notification of a data breach by VODAFONE, following a ransomware cyberattack targeting one of its subcontractors responsible for call center services on November 8, 2023.

Grounds for the decision

  • Obligation to ensure the security of processing (Article 32 of the GDPR): The authority considered that VODAFONE, as the controller, had not implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk. The data breach, which affected the availability of information of 98,509 individuals, was made possible by significant security failures at its subcontractor, notably the absence of two-factor authentication on a virtual private network access and up-to-date antivirus systems. The authority concluded that the controller's gross negligence was established, the controller remaining responsible for the compliance of the processing, in accordance with Article 24 of the GDPR.
  • Obligation to frame the relationship with a subcontractor by a legally binding act (Article 28 of the GDPR): The authority found that at the time of the data breach in November 2023, no valid and effective subcontracting contract bound VODAFONE to its service provider. Although an agreement was signed in January 2024 with a retroactive effective date of April 1, 2023, the authority judged that this practice violated the principle of proactive accountability and did not meet the requirement of a written and binding legal act at the time of the facts. Referring to the European Data Protection Board's Guidelines 7/2020 on the concepts of controller and processor, the authority concluded that the absence of a formal contract at the time of the incident constituted a violation of Article 28 of the GDPR.

Authority's decision

Consequently, the authority imposed a fine of €400,000 on VODAFONE ESPAÑA, S.A.U., broken down into €300,000 for the violation of Article 32 of the GDPR and €100,000 for that of Article 28 of the GDPR.

Lessons learned

This decision reminds that:

  • Signing a subcontracting contract with a retroactive effective date does not satisfy the obligation of Article 28 of the GDPR; the legal act must be formally in force before the start of processing operations and, a fortiori, at the time of a security incident.
  • The controller remains fully responsible for the security failures of its subcontractor, especially when elementary measures such as two-factor authentication or up-to-date antivirus software are lacking.
  • Proactive accountability requires the controller to ensure not only the formal existence of a subcontracting contract but also the effective implementation of appropriate security measures by its service provider before entrusting processing to them.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire