Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Vodafone España, S.A.U.: Non-compliance with general data processing principles
How it connects
Related across sources
News Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures News UK data protection reform: How the UK's GDPR may change Guidance Guidelines 07/2020 on the concepts of controller and processor in the GDPR Literature GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection Guidance Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 Literature GDPR Implementation Series ∙ Spain: Preparations for a New Law on Data Protection to Implement the GDPR
Full text
The Spanish DPA has fined Vodafone España, S.A.U. EUR 3.94 million. Nine Vodafone customers had filed complaints with the DPA. In the course of its investigation, the DPA found that fraudsters had pretended to be the data subjects when contacting Vodafone and had demanded a copy of their SIM cards. As a result, they were able to conclude contracts at the expense of the data subjects and carry out various transfers. According to the DPA, Vodafone had not properly verified the identity of the fraudsters before issuing the SIM cards and ensured that the inquirers were really the SIM card holders due to a lack of sufficient security measures.
Industry: Media, Telecoms and Broadcasting
Original document at the source www.aepd.es