Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
TELEFÓNICA MÓVILES ESPAÑA, S.A.U.: Non-compliance with general data processing principles
The Spanish DPA has fined TELEFÓNICA MÓVILES ESPAÑA, S.A.U.
Full text
The Spanish DPA has fined TELEFÓNICA MÓVILES ESPAÑA, S.A.U. EUR 900,000. Four Telefónica customers had filed complaints with the DPA. In the course of its investigation, the DPA found that fraudsters had pretended to be the data subjects when contacting Telefónica and had demanded a copy of their SIM cards. As a result, they were able to conclude contracts at the expense of the data subjects and carry out various transfers. According to the DPA, Telefónica had not properly verified the identity of the fraudsters before issuing the SIM cards and ensured that the inquirers were really the SIM card holders.
Industry: Media, Telecoms and Broadcasting
How it connects
Related across sources
C-362/14 Schrems I Maximillian Schrems, an Austrian citizen, had been a Facebook user since 2008 Some of Mr. Schrems personal data had been transferred by Facebook Ireland to its servers belonging to Facebook Inc., located in the US. Personal data transferred by undertakings… C-362/14 - Schrems I ·CJEU Jun 10, 2015 International Transfer Personal Data Right of Access
3 O 762/19 LG Rostock: Pre-ticked cookie consent boxes invalid under Art 6(1)(a) GDPR The German consumer organisation Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V. (vzbv, the claimant) filed a lawsuit… Sep 15, 2020 Consent Legitimate Interest Controllers
C-154/21 RW v Österreichische Post AG The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article… CJEU ·First Chamber Jan 12, 2023 Right of Access Personal Data Recipient
C-40/17 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV C-40/17 (Fashion ID) CJEU Jul 29, 2019 Controllers Legitimate Interest Processors
C-293/12 Digital Rights Ireland Ltd v Minister for Communications C-293/12 (Digital Rights Ireland) CJEU Apr 8, 2014 IP Address Storage Limitation Right to be Forgotten
CJEU: Processing of beneficiary data not based on consent; individuals must be informed Purpose for processing: The legislation at issue does base the processing on consent. Rather, it provides that they are to be informed. Thus, processing is not based on their… Nov 9, 2010 Consent Personal Data Right to Restriction