Skip to content
Enforcement · AEPD (Spain) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

AEPD (Spain) - ps-00148-2025

€200,000 Fine
Spain
Art. 6 GDPR

How it connects

Full text

Facts — XFERA MÓVILES, S.A.U. (XFERA), the controller, is a telecommunications provider. The data subject was a customer of the controller and held a mobile telephone line. On 24 July 2023, an unauthorised third party requested a duplicate SIM card for the data subject's mobile line through one of the controller's distributors. The third party presented a copy of an identity document purportedly belonging to the data subject. An agent of the controller identified the third party as the account holder following an in-person visual verification of the identity document. The document was subsequently scanned and a duplicate SIM card was issued. However, a comparison between the identity document presented by the third party and the data subject's actual information showed several discrepancies. Although the identification number, name, surnames and nationality matched, other information, including the place and date of birth, address and parents' names, did not. The controller acknowledged that its agent had not verified all the information contained in the identity document and had therefore departed from the controller's internal procedure. However, it argued that this was an isolated human error, that it had appropriate procedures in place and that the processing was lawful under Article 6(1)(b) GDPR because of its contractual relationship with the data subject. Holding — The DPA held that the controller violated Article 6(1) GDPR. The DPA considered that issuing a duplicate SIM card constituted processing of personal data, since both the information used to issue the card and the SIM card itself were linked to an identifiable subscriber. It held that the controller had processed the data subject's personal data without a valid legal basis because it failed to adequately verify the identity of the person requesting the duplicate SIM card. The contractual relationship with the data subject could not legitimise processing carried out on the basis of a request made by an unauthorised third party. In particular, the DPA noted that the controller had failed to carry out checks required by its own procedures. Consequently, the duplicate SIM card was issued to a third party who was neither the account holder nor demonstrated that they were authorised to act on the account holder's behalf. The DPA rejected the controller's argument that the infringement resulted exclusively from third-party fraud. It considered that the fraudulent conduct of a third party did not exempt the controller from exercising sufficient diligence to verify the identity of persons requesting the processing of personal data. The mere existence of internal procedures was insufficient if those procedures were not effectively implemented. The DPA also rejected the argument that imposing a fine would amount to strict liability. It found that the controller's liability resulted from its lack of due diligence in ensuring that the processing had a lawful basis, rather than merely from the occurrence of the fraudulent SIM swap. When determining the fine, the DPA took into account, among other factors, the nature of the infringement, the controller's negligence, the categories of personal data concerned, a previous infringement involving an unauthorised SIM duplication and the close connection between the controller's business activities and the processing of personal data. Consequently, the DPA imposed a fine of €200,000 for the violation of Article 6(1) GDPR. Pursuant to Article 58(2)(d) GDPR, it also ordered the controller, within six months from the decision becoming final and enforceable, to provide evidence that it had adopted measures to prevent similar incidents and ensure compliance with the principle of lawfulness. Holding — The DPA held that the controller violated Article 6(1) GDPR. The DPA considered that issuing a duplicate SIM card constituted processing of personal data, since both the information used to issue the card and the SIM card itself were linked to an identifiable subscriber. It held that the controller had processed the data subject's personal data without a valid legal basis because it failed to adequately verify the identity of the person requesting the duplicate SIM card. The contractual relationship with the data subject could not legitimise processing carried out on the basis of a request made by an unauthorised third party. In particular, the DPA noted that the controller had failed to carry out checks required by its own procedures. Consequently, the duplicate SIM card was issued to a third party who was neither the account holder nor demonstrated that they were authorised to act on the account holder's behalf. The DPA rejected the controller's argument that the infringement resulted exclusively from third-party fraud. It considered that the fraudulent conduct of a third party did not exempt the controller from exercising sufficient diligence to verify the identity of persons requesting the processing of personal data. The mere existence of internal procedures was insufficient if those procedures were not effectively implemented. The DPA also rejected the argument that imposing a fine would amount to strict liability. It found that the controller's liability resulted from its lack of due diligence in ensuring that the processing had a lawful basis, rather than merely from the occurrence of the fraudulent SIM swap. When determining the fine, the DPA took into account, among other factors, the nature of the infringement, the controller's negligence, the categories of personal data concerned, a previous infringement involving an unauthorised SIM duplication and the close connection between the controller's business activities and the processing of personal data. Consequently, the DPA imposed a fine of €200,000 for the violation of Article 6(1) GDPR. Pursuant to Article 58(2)(d) GDPR, it also ordered the controller, within six months from the decision becoming final and enforceable, to provide evidence that it had adopted measures to prevent similar incidents and ensure compliance with the principle of lawfulness. Comment — Share your comments here!

Similar Content