Vodafone España, S.A.U.
€30,000
Insufficient technical and organisational measures to ensure information security
Decision Date
January 1, 2019
Authority
Spanish Data Protection Authority (aepd)
ES
Sector
Media, Telecoms and Broadcasting
Country
ES
Law
GDPRStatus
FINALDescription
Disclosure of customer personal data (i.a. purchase history) via an SMS to another customer. The initial fine of EUR 50.000 was reduced to EUR 30.000.
Legal Citations
Art. 5 (1)Art. 32
Issues & Violations
Insufficient technical and organisational measures to ensure information security