Vodafone España, S.A.U. – €200,000 Fine (Spain, 2024)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Vodafone España, S.A.U. was fined for giving a duplicate SIM card to someone who wasn't authorized, leading to fraud. The company failed to verify the identity of the requester or get consent from the original customer. This case serves as a warning to businesses about the importance of verifying customer identities before sharing sensitive information.
What happened
Vodafone provided a duplicate SIM card to an unauthorized third party without the customer's consent.
Who was affected
A customer whose SIM card was duplicated and used by fraudsters to access their bank account.
What the authority found
The Spanish data protection authority ruled that Vodafone did not take necessary steps to confirm the identity of the third party, violating GDPR rules.
Why this matters
This case highlights the critical need for companies to implement strict identity verification processes. Businesses should ensure they have proper protocols to protect customer data from unauthorized access.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM card to an unauthorized fraudulent third party without their consent. During its investigation, the DPA found that the company failed to verify the identity of the third party or obtain the data subject's consent to share their data. This allowed the fraudsters to gain access to the data subject's bank account and make unauthorized transactions.
Related Enforcement Actions (20)
Other enforcement actions involving Vodafone España, S.A.U. in ES
Fine
€200K
Details
Fine Date
8 February 2024
Authority
Agencia Española de Protección de Datos
Fine Amount
€200,000
Enforcement Tracker ID
ETid-2263
About this data
Cite as: Cookie Fines. Vodafone España, S.A.U. - Spain (2024). Retrieved from cookiefines.eu
Last updated: