The Spanish authority sanctions Vodafone for sending unauthorized commercial communications via WhatsApp

The responsibility of a service provider cannot be dismissed by invoking the isolated act of a distributor, as long as the unlawful prospecting was carried out using the company's resources and in the absence of effective and demonstrable technical control mechanisms.

Facts and context

The Spanish data protection authority (AEPD) has today published a sanction decision against VODAFONE ESPAÑA, S.A.U. (including the imposition of a fine of €4,000, reduced to €3,200 after voluntary payment) for breaches related to the sending of unsolicited commercial communications.

The case originated from a complaint by a person who received, on August 11, 2025, a commercial message via instant messaging from a Vodafone point of sale, although they had not consented and were registered on the Robinson opt-out list.

Grounds for the decision

The authority found a breach of the legislation on information society services, which transposes the privacy and electronic communications directive:

  • Obligation to obtain prior consent for electronic prospecting (Article 21, paragraph 1, of Law 34/2002 on information society services and electronic commerce - LSSI): The authority found that a commercial communication had been sent to the complainant without their prior authorization and despite their registration on an opt-out list. Vodafone argued that it was a one-off unauthorized initiative by a store employee, contrary to internal instructions. The AEPD rejected this argument, considering that the communication was sent from a phone number belonging to Vodafone and within its commercial network. The authority emphasized that the existence of internal policies or contractual clauses prohibiting such practices is insufficient if the company cannot prove the implementation of effective technical and organizational mechanisms to actively prevent the sending of unauthorized communications, notably through automated prior verifications or audits. The absence of such effective controls was qualified as an organizational failure engaging the company's responsibility.

Authority's decision

Consequently, the authority imposed a fine of €4,000 on VODAFONE ESPAÑA, S.A.U., reduced to €3,200 following the company's voluntary payment, which implies acknowledgment of its responsibility.

Lessons learned

This decision reminds that:

  • The responsibility of a company is engaged for unlawful prospecting actions carried out by its employees or distribution network, even if these contravene internal instructions, as long as they are carried out using the company's means.
  • The existence of internal policies or contractual clauses is not a sufficient defense if the company cannot demonstrate the existence of effective and verifiable technical and organizational measures to prevent breaches.
  • The absence of preventive control systems, such as automatic blocking of sends to numbers registered on opt-out lists, can be qualified as an organizational failure attributable to the data controller.
  • The burden of proof of the effectiveness of compliance measures implemented lies with the entity concerned.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire