Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
TELEFÓNICA DE ESPAÑA SAU: Non-compliance with general data processing principles
How it connects
Related across sources
News De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming). News Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Guidance Guidelines 07/2020 on the concepts of controller and processor in the GDPR Literature GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection Guidance Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 Literature GDPR Implementation Series ∙ Spain: Preparations for a New Law on Data Protection to Implement the GDPR
Full text
The Spanish DPA has imposed a fine of EUR 1.3 million on TELEFÓNICA DE ESPAÑA SAU. The controller had reported a security incident to the DPA, stating that they had suffered a cyber attack that allowed unauthorised third parties to access personal customer data via an employee's account. During its investigation, the DPA found that the controller had failed to implement appropriate technical and organisational measures to protect personal data that could have prevented such an incident. The fine is composed as follows: EUR 500,000 for the violation of Art. 5 (1) f) GDPR and EUR 800,000 for the violation of Art. 32 GDPR.
Industry: Media, Telecoms and Broadcasting
Original document at the source www.aepd.es