Vodafone Spain – €40,000 Fine (Spain, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Vodafone Spain was fined €40,000 for sending a woman invoices meant for someone else and failing to address her complaints. The Spanish DPA found that Vodafone mishandled personal data by not safeguarding it properly. This case highlights the importance of ensuring data accuracy and responding promptly to customer issues.
What happened
Vodafone Spain sent invoices to the wrong email address and failed to resolve the issue after being notified.
Who was affected
A woman who received invoices meant for another Vodafone customer.
What the authority found
The Spanish DPA ruled that Vodafone Spain unlawfully processed personal data by not securing it adequately, violating GDPR's integrity and confidentiality principles.
Why this matters
This fine emphasizes the need for companies to maintain accurate data records and respond effectively to customer complaints. It highlights the risk of penalties for negligent data handling and the importance of implementing strong data protection measures.
GDPR Articles Cited
An individual repeatedly received emails containing Vodafone invoices belonging to a third party. They tried reaching out to the company by email and telephone to resolve this issue, but were never properly helped. Thus, they filed a complaint to the Spanish DPA (AEPD), which informed Vodafone of the issue. The company assured the DPA it had both dealt with the problem and communicated the resolution to the complainant. The complainant nonetheless kept receiving invoices. The DPA communicated this to the company, which then provided evidence the complainant's email address had been deleted from its systems. It claimed the problem was caused by the customer (that the invoices were actually intended for) entering the complainant's email address instead of their own. The Spanish DPA held that Vodafone Spain unlawfully processed the complainant's personal data, as the company had no lawful basis to send them invoices belonging to one of its customers. It found this to constitute a severe and negligent violation (Article 83(2)(a) and (b) GDPR) of Articles 5(1)(f) and 32 GDPR, as the complainant's data was neither processed with integrity and confidentiality nor appropriately safeguarded. It originally imposed a fine of €30,000 for the violation of Article 5(1)(f) GDPR and €20,000 for the violation of Article 32 GDPR, but this was reduced to a total fine amounting to €40,000 because Vodafone Spain made use of a reduction procedure proposed by the DPA.
Related Enforcement Actions (2)
Other enforcement actions involving Vodafone Spain in ES
Fine
€40K
Details
Fine Date
13 October 2021
Authority
Agencia Española de Protección de Datos
Fine Amount
€40,000
GDPRhub ID
gdprhub-4254About this data
Cite as: Cookie Fines. Vodafone Spain - Spain (2021). Retrieved from cookiefines.eu
Last updated: