Skip to content
Enforcement · AEPD (Spain) ·ps-00148-2025 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

XFERA MÓVILES, S.A.U. (XFERA), the controller, is a telecommunications provider

The data subject was a customer of the controller and held a mobile telephone line.

€200,000 Fine
Spain
Art. 6 GDPR

Holding

The DPA held that the controller violated Article 6(1) GDPR. The DPA considered that issuing a duplicate SIM card constituted processing of personal data, since both the information used to issue the card and the SIM card itself were linked to an identifiable subscriber. It held that the controller had processed the data subject's personal data without a valid legal basis because it failed to adequately verify the identity of the person requesting the duplicate SIM card. The contractual relationship with the data subject could not legitimise processing carried out on the basis of a request made by an unauthorised third party. In particular, the DPA noted that the controller had failed to carry out checks required by its own procedures. Consequently, the duplicate SIM card was issued to a third party who was neither the account holder nor demonstrated that they were authorised to act on the account holder's behalf. The DPA rejected the controller's argument that the infringement resulted exclusively from third-party fraud. It considered that the fraudulent conduct of a third party did not exempt the controller from exercising sufficient diligence to verify the identity of persons requesting the processing of personal data. The mere existence of internal procedures was insufficient if those procedures were not effectively implemented. The DPA also rejected the argument that imposing a fine would amount to strict liability. It found that the controller's liability resulted from its lack of due diligence in ensuring that the processing had a lawful basis, rather than merely from the occurrence of the fraudulent SIM swap. When determining the fine, the DPA took into account, among other factors, the nature of the infringement, the controller's negligence, the categories of personal data concerned, a previous infringement involving an unauthorised SIM duplication and the close connection between the controller's business activities and the processing of personal data. Consequently, the DPA imposed a fine of €200,000 for the violation of Article 6(1) GDPR. Pursuant to Article 58(2)(d) GDPR, it also ordered the controller, within six months from the decision becoming final and enforceable, to provide evidence that it had adopted measures to prevent similar incidents and ensure compliance with the principle of lawfulness.

From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓

Case note 6 findings

Case note by GDPRhub — an account of the decision, not the decision itself. Read the decision

Paragraphs carrying a topic or an applied provision show those connections inline
§

Facts — XFERA MÓVILES, S.A.U. (XFERA), the controller, is a telecommunications provider. The data subject was a customer of the controller and held a mobile telephone line. On 24 July 2023, an unauthorised third party requested a duplicate SIM card for the data subject's mobile line through one of the controller's distributors. The third party presented a copy of an identity document purportedly belonging to the data subject. An agent of the controller identified the third party as the account holder following an in-person visual verification of the identity document. The document was subsequently scanned and a duplicate SIM card was issued. However, a comparison between the identity document presented by the third party and the data subject's actual information showed several discrepancies. Although the identification number, name, surnames and nationality matched, other information, including the place and date of birth, address and parents' names, did not.

§

The controller acknowledged that its agent had not verified all the information contained in the identity document and had therefore departed from the controller's internal procedure. However, it argued that this was an isolated human error, that it had appropriate procedures in place and that the processing was lawful under Article 6(1)(b) GDPR because of its contractual relationship with the data subject. Holding — The DPA held that the controller violated Article 6(1) GDPR. The DPA considered that issuing a duplicate SIM card constituted processing of personal data, since both the information used to issue the card and the SIM card itself were linked to an identifiable subscriber. It held that the controller had processed the data subject's personal data without a valid legal basis because it failed to adequately verify the identity of the person requesting the duplicate SIM card. The contractual relationship with the data subject could not legitimise processing carried out on the basis of a request made by an unauthorised third party.

§

In particular, the DPA noted that the controller had failed to carry out checks required by its own procedures. Consequently, the duplicate SIM card was issued to a third party who was neither the account holder nor demonstrated that they were authorised to act on the account holder's behalf. The DPA rejected the controller's argument that the infringement resulted exclusively from third-party fraud. It considered that the fraudulent conduct of a third party did not exempt the controller from exercising sufficient diligence to verify the identity of persons requesting the processing of personal data. The mere existence of internal procedures was insufficient if those procedures were not effectively implemented. The DPA also rejected the argument that imposing a fine would amount to strict liability. It found that the controller's liability resulted from its lack of due diligence in ensuring that the processing had a lawful basis, rather than merely from the occurrence of the fraudulent SIM swap.

§

When determining the fine, the DPA took into account, among other factors, the nature of the infringement, the controller's negligence, the categories of personal data concerned, a previous infringement involving an unauthorised SIM duplication and the close connection between the controller's business activities and the processing of personal data. Consequently, the DPA imposed a fine of €200,000 for the violation of Article 6(1) GDPR. Pursuant to Article 58(2)(d) GDPR, it also ordered the controller, within six months from the decision becoming final and enforceable, to provide evidence that it had adopted measures to prevent similar incidents and ensure compliance with the principle of lawfulness. Holding — The DPA held that the controller violated Article 6(1) GDPR. The DPA considered that issuing a duplicate SIM card constituted processing of personal data, since both the information used to issue the card and the SIM card itself were linked to an identifiable subscriber.

§

It held that the controller had processed the data subject's personal data without a valid legal basis because it failed to adequately verify the identity of the person requesting the duplicate SIM card. The contractual relationship with the data subject could not legitimise processing carried out on the basis of a request made by an unauthorised third party. In particular, the DPA noted that the controller had failed to carry out checks required by its own procedures. Consequently, the duplicate SIM card was issued to a third party who was neither the account holder nor demonstrated that they were authorised to act on the account holder's behalf. The DPA rejected the controller's argument that the infringement resulted exclusively from third-party fraud. It considered that the fraudulent conduct of a third party did not exempt the controller from exercising sufficient diligence to verify the identity of persons requesting the processing of personal data.

§

The mere existence of internal procedures was insufficient if those procedures were not effectively implemented. The DPA also rejected the argument that imposing a fine would amount to strict liability. It found that the controller's liability resulted from its lack of due diligence in ensuring that the processing had a lawful basis, rather than merely from the occurrence of the fraudulent SIM swap. When determining the fine, the DPA took into account, among other factors, the nature of the infringement, the controller's negligence, the categories of personal data concerned, a previous infringement involving an unauthorised SIM duplication and the close connection between the controller's business activities and the processing of personal data. Consequently, the DPA imposed a fine of €200,000 for the violation of Article 6(1) GDPR. Pursuant to Article 58(2)(d) GDPR, it also ordered the controller, within six months from the decision becoming final and enforceable, to provide evidence that it had adopted measures to prevent similar incidents and ensure compliance with the principle of lawfulness. Comment — Share your comments here!

How it connects

6 of 6 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-654/23 Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) Het Hof van Justitie van de EU (Eerste Kamer) beantwoordt een prejudiciële vraag over de uitleg van artikel 13 van Richtlijn 2002/58/EC (ePrivacy) en de verhouding tot de GDPR,… Mar 27, 2025 Telecommunications Personal Data Marketing
C-654/23 Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) The Court of Justice of the European Union ruled on a preliminary reference from the Romanian Curtea de Apel Bucureşti in proceedings between Inteligo Media SA and the Romanian… First Chamber Nov 13, 2025 Telecommunications Personal Data Legitimate Interest
C-621/22 Koninklijke Nederlandse Lawn Tennisbond v Autoriteit Persoonsgegevens The CJEU ruled on a preliminary reference from the Amsterdam District Court in proceedings between the Koninklijke Nederlandse Lawn Tennisbond (KNLTB) and the Dutch Data… Ninth Chamber Oct 4, 2024 Personal Data Legitimate Interest IP Address
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
C-319/20 Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband eV The CJEU ruled on a preliminary reference from the German Federal Court of Justice in proceedings between Meta Platforms Ireland Limited and the Verbraucherzentrale Bundesverband… Third Chamber Apr 28, 2022 Personal Data IP Address Legitimate Interest