VODAFONE ESPAÑA, S.A.U. – €56,000 Fine (Spain, 2023)

€56,000Agencia Española de Protección de Datos13 September 2023Spain
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Vodafone España, S.A.U. was fined €56,000 for mistakenly sharing another customer's contract with a person who requested their own contract. This breach of confidentiality shows how important it is for companies to protect personal information.

What happened

Vodafone sent a customer the contract and personal data of another individual instead of their own.

Who was affected

The affected person was a customer of Vodafone who received another person's private contract details.

What the authority found

The Spanish data protection authority found that Vodafone violated GDPR by not having proper security measures to prevent such data breaches.

Why this matters

This case serves as a warning that companies must ensure they handle personal data carefully. Businesses should strengthen their data protection practices to avoid costly mistakes.

GDPR Articles Cited

AI-verified

Art. 32(GDPR)
Art. 33(GDPR)
Art. 34(GDPR)
Art. 5(1)(f) GDPR
Art. 4(12) GDPR
Art. 83(4) GDPR
Art. 83(5) GDPR
View original scraped data
Art. 4(12) GDPR
Art. 5(1)(f) GDPR
Art. 32(GDPR)
Art. 33(GDPR)
Art. 34(GDPR)
Art. 83(4) GDPR
Art. 83(5) GDPR

Original data from scraper before AI verification against source document.

Source verified 12 March 2026
articles corrected
national law identified
Full Legal Summary
Detailed

On 21 August 2021 the data subject filed a complaint against Vodafone España, S.A.U., the controller, for violating their right of access. The data subject requested VODAFONE to provide a copy of their commercial telephone contract, since the company was, allegedly, not applying the contracted tariff. After several unsuccessful attempts to receive their contract, the controller sent an email containing contract of another customer as well as an audio recording of that customer's data. The DPA ('AEPD') highlighted the breach of confidentially and security by VODAFONE for sharing a commercial contract of another individual with the data subject, violating Article 5(1)(f) GDPR. According to the evidence presented, the data subject acquired access to name, ID number and telephone number of an unknown person without any authorization to disclose their data to third parties. The AEPD, therefore, found a violation of Article 32 GDPR for not implementing the appropriate technical and organization measures to prevent such incident. The AEPD fined VODAFONE €50,000 for violating Article 5(1)(f) GDPR and €20,000 for violating Article 32 GDPR. However, in this case, the AEPD gave two possibilities to VODAFONE to either acknowledge the liability, leading to a greater reduction in the final amount, totaling €42,000 or to pay a fine of €56,000 and renounce any form of appeal against the sanction. VODAFONE opted for a voluntary payment option, paying a fine of €56,000. This payment utilized the reduction offered in the initial agreement for early payment, indicating a renunciation of any form of administrative appeal against the sanction.

Related Enforcement Actions (8)

Other enforcement actions involving VODAFONE ESPAÑA, S.A.U. in ES

Current
Sept 2023

Fine

€56K

Details

Fine Date

13 September 2023

Authority

Agencia Española de Protección de Datos

Fine Amount

€56,000

GDPRhub ID

gdprhub-7631

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. VODAFONE ESPAÑA, S.A.U. - Spain (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: