Vodafone España, S.A.U.

€3,940,000

Non-compliance with general data processing principles

Decision Date

1 de fevereiro de 2022

Authority

Spanish Data Protection Authority (aepd)

ES

Sector

Media, Telecoms and Broadcasting

Country

ES

Law

GDPR

Status

FINAL

Description

The Spanish DPA has fined Vodafone España, S.A.U. EUR 3.94 million. Nine Vodafone customers had filed complaints with the DPA. In the course of its investigation, the DPA found that fraudsters had pretended to be the data subjects when contacting Vodafone and had demanded a copy of their SIM cards. As a result, they were able to conclude contracts at the expense of the data subjects and carry out various transfers. According to the DPA, Vodafone had not properly verified the identity of the fraudsters before issuing the SIM cards and ensured that the inquirers were really the SIM card holders due to a lack of sufficient security measures.

Legal Citations

Art. 5 (1)Art. 5 (2)

Issues & Violations

Non-compliance with general data processing principles

Stay Updated on Privacy Enforcement

We respect your privacy. One email per month, no spam, unsubscribe anytime.