Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Vodafone España, S.A.U.: Non-compliance with general data processing principles
The Spanish DPA has fined Vodafone España, S.A.U.
Full text
The Spanish DPA has fined Vodafone España, S.A.U. EUR 3.94 million. Nine Vodafone customers had filed complaints with the DPA. In the course of its investigation, the DPA found that fraudsters had pretended to be the data subjects when contacting Vodafone and had demanded a copy of their SIM cards. As a result, they were able to conclude contracts at the expense of the data subjects and carry out various transfers. According to the DPA, Vodafone had not properly verified the identity of the fraudsters before issuing the SIM cards and ensured that the inquirers were really the SIM card holders due to a lack of sufficient security measures.
Industry: Media, Telecoms and Broadcasting
How it connects
Related across sources
C-311/18 Data Protection Commissioner v Facebook Ireland and Maximillian Schrems C-311/18 (Schrems II) CJEU Jul 16, 2020 Privacy Shield Processing Agreement International Transfer
C-293/12 Digital Rights Ireland Ltd v Minister for Communications C-293/12 (Digital Rights Ireland) CJEU Apr 8, 2014 IP Address Storage Limitation Right to be Forgotten
C-362/14 Maximillian Schrems v Data Protection Commissioner C-362/14 (Schrems I) CJEU Oct 6, 2015 Privacy Shield Supervision IP Address
3 O 762/19 LG Rostock: Pre-ticked cookie consent boxes invalid under Art 6(1)(a) GDPR The German consumer organisation Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V. (vzbv, the claimant) filed a lawsuit… Sep 15, 2020 Consent Legitimate Interest Controllers
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address
C-623/17 Privacy International v Secretary of State C-623/17 (Privacy International) CJEU Oct 6, 2020 IP Address Material scope (GDPR) Legitimate Interest