Vodafone España, S.A.U. – €56,000 Fine (Spain, 2023)

€56,000Agencia Española de Protección de Datos1 August 2023Spain
reduced
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Vodafone España, S.A.U. was fined EUR 56,000 for mistakenly disclosing personal data to a fraudster who pretended to be a customer. This is important because it shows that companies need to verify identities before sharing sensitive information. Protecting customer data is crucial to maintaining trust.

What happened

Vodafone España, S.A.U. disclosed personal data after failing to verify the identity of a third party requesting a phone number change.

Who was affected

The affected person was the original customer whose data was shared without their consent.

What the authority found

The DPA ruled that Vodafone did not take adequate steps to confirm the identity of the requester, violating GDPR's requirements for data processing.

Why this matters

This ruling emphasizes the need for companies to implement strong identity verification processes. Businesses should review their procedures to prevent unauthorized data access.

GDPR Articles Cited

AI-verified

Art. 6(1) GDPR
View original scraped data
Art. 6(1) GDPR

Original data from scraper before AI verification against source document.

Source verified 12 March 2026
national law identified
Full Legal Summary
Detailed

The Spanish DPA has imposed a fine on Vodafone España, S.A.U.. Fraudulent third parties had pretended to be the data subject and asked the controller to change their phone number in order to buy a cell phone under the new phone number. The controller complied with this request and sent the new contract to the new number, which resulted in the disclosure of some of the data subject's personal data. During its investigation, the DPA found that the company had failed to verify the identity of the third party or obtain the data subject's consent to disclose their data. The original fine of EUR 70,000 was reduced to EUR 56,000 due to a voluntary payment.

Related Enforcement Actions (20)

Other enforcement actions involving Vodafone España, S.A.U. in ES

Current
Aug 2023

Fine

€56K

Details

Fine Date

1 August 2023

Authority

Agencia Española de Protección de Datos

Fine Amount

€56,000

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Vodafone España, S.A.U. - Spain (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: