Vodafone España, S.A.U. – €200,000 Fine (Spain, 2024)

€200,000Agencia Española de Protección de Datos29 February 2024Spain
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Vodafone España gave a duplicate SIM card to a fraudster without checking their identity or getting permission from the real customer. This mistake allowed the fraudster to access the customer's bank account and make unauthorized transactions. The Spanish data protection authority fined Vodafone €200,000 for this failure.

What happened

Vodafone España provided a duplicate SIM card to an unauthorized third party without verifying their identity or obtaining consent.

Who was affected

The real customer whose SIM card was duplicated and whose bank account was accessed by the fraudster.

What the authority found

The Spanish data protection authority ruled that Vodafone failed to verify the identity of the third party, violating GDPR's requirement for user consent.

Why this matters

This case highlights the importance of verifying identities before sharing sensitive information. Companies should strengthen their identity verification processes to prevent unauthorized access.

GDPR Articles Cited

AI-verified

Art. 6(1) GDPR
View original scraped data
Art. 6(1) GDPR

Original data from scraper before AI verification against source document.

Source verified 10 March 2026
national law identified
Full Legal Summary
Detailed

The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM card to an unauthorized fraudulent third party without their consent. During its investigation, the DPA found that the company failed to verify the identity of the third party or obtain the data subject's consent to share their data. This allowed the fraudsters to gain access to the data subject's bank account and make unauthorized transactions.

Related Enforcement Actions (20)

Other enforcement actions involving Vodafone España, S.A.U. in ES

Current
Feb 2024

Fine

€200K

Details

Fine Date

29 February 2024

Authority

Agencia Española de Protección de Datos

Fine Amount

€200,000

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Vodafone España, S.A.U. - Spain (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: