Vodafone España, S.A.U. – €200,000 Fine (Spain, 2024)

€200,000Agencia Española de Protección de Datos8 February 2024Spain
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Vodafone España, S.A.U. was fined for giving a duplicate SIM card to someone who wasn't authorized, leading to fraud. The company failed to verify the identity of the requester or get consent from the original customer. This case serves as a warning to businesses about the importance of verifying customer identities before sharing sensitive information.

What happened

Vodafone provided a duplicate SIM card to an unauthorized third party without the customer's consent.

Who was affected

A customer whose SIM card was duplicated and used by fraudsters to access their bank account.

What the authority found

The Spanish data protection authority ruled that Vodafone did not take necessary steps to confirm the identity of the third party, violating GDPR rules.

Why this matters

This case highlights the critical need for companies to implement strict identity verification processes. Businesses should ensure they have proper protocols to protect customer data from unauthorized access.

GDPR Articles Cited

AI-verified

Art. 6(1) GDPR
View original scraped data
Art. 6(1) GDPR

Original data from scraper before AI verification against source document.

Source verified 10 March 2026
national law identified
Full Legal Summary
Detailed

The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM card to an unauthorized fraudulent third party without their consent. During its investigation, the DPA found that the company failed to verify the identity of the third party or obtain the data subject's consent to share their data. This allowed the fraudsters to gain access to the data subject's bank account and make unauthorized transactions.

Related Enforcement Actions (20)

Other enforcement actions involving Vodafone España, S.A.U. in ES

Current
Feb 2024

Fine

€200K

Details

Fine Date

8 February 2024

Authority

Agencia Española de Protección de Datos

Fine Amount

€200,000

Enforcement Tracker ID

ETid-2263

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Vodafone España, S.A.U. - Spain (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: