ORANGE ESPAGNE S.A.U. – €80,000 Fine (Spain, 2020)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Orange Espagne opened phone lines in a customer's name without their permission, which is a serious issue. This led to the customer being wrongly listed as having unpaid bills. The fine of €80,000 shows that companies must ensure they have proper consent before processing personal information.
What happened
Orange Espagne processed personal data without the customer's consent, leading to unauthorized phone lines being opened.
Who was affected
The customer whose identity was used to open the phone lines without their consent.
What the authority found
The Spanish data protection authority found that Orange Espagne failed to verify the identity of the contracting parties, violating GDPR's requirement for user consent.
Why this matters
This case highlights the importance of companies verifying identities before processing personal data. It serves as a reminder that negligence can lead to significant fines and reputational damage.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
A customer of the data controller filed a complaint with the Spanish DPA (AEPD), alleging that up to six phone lines had been opened in his name despite the data subject not having given his consent. It was a fraud by which someone pretends to be a real client of the company - after obtaining their documentation - and calls the operator to contract voice or Internet products pretending to be that real user. The situation also led to the inclusion of the customer who reported the operator in the files of ASNEF (Asociación Nacional de Establecimientos Financieros de Crédito), in whose records the customers of companies with outstanding invoices are stored. Orange replied to the AEPD that the consent had been unequivocal and did not attribute falsity to the line registrations that have met the regulatory recruitment requirements Is the processing of personal data, without the express consent of the person involved in the contract, a violation of Article 6(1)(a) GDPR? The AEPD considered that ORANGE ESPAGNE did not act with due diligence to identify the contracting parties. Therefore, it processed personal data without accrediting that it had the legal basis to do so. Furthermore, it was not aligned with the principle of proactive liability, which consists of previously determining that it met the requirements for processing the complainant's data. The fact that it was a non-intentional negligent action, that basic personal identifiers were affected and the continued nature of the infringement were considered aggravating factors, determining the amount of the fine in €80,000.
Related Enforcement Actions (2)
Other enforcement actions involving ORANGE ESPAGNE S.A.U. in ES
Fine
€80K
Details
Fine Date
11 August 2020
Authority
Agencia Española de Protección de Datos
Fine Amount
€80,000
GDPRhub ID
gdprhub-2698About this data
Cite as: Cookie Fines. ORANGE ESPAGNE S.A.U. - Spain (2020). Retrieved from cookiefines.eu
Last updated: