Vodafone Spain – €40,000 Fine (Spain, 2021)

€40,000Agencia Española de Protección de Datos13 October 2021Spain
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Vodafone Spain was fined €40,000 for sending a woman invoices meant for someone else and failing to address her complaints. The Spanish DPA found that Vodafone mishandled personal data by not safeguarding it properly. This case highlights the importance of ensuring data accuracy and responding promptly to customer issues.

What happened

Vodafone Spain sent invoices to the wrong email address and failed to resolve the issue after being notified.

Who was affected

A woman who received invoices meant for another Vodafone customer.

What the authority found

The Spanish DPA ruled that Vodafone Spain unlawfully processed personal data by not securing it adequately, violating GDPR's integrity and confidentiality principles.

Why this matters

This fine emphasizes the need for companies to maintain accurate data records and respond effectively to customer complaints. It highlights the risk of penalties for negligent data handling and the importance of implementing strong data protection measures.

GDPR Articles Cited

Art. 32 GDPR
Art. 5(1)(f) GDPR
Full Legal Summary
Detailed

An individual repeatedly received emails containing Vodafone invoices belonging to a third party. They tried reaching out to the company by email and telephone to resolve this issue, but were never properly helped. Thus, they filed a complaint to the Spanish DPA (AEPD), which informed Vodafone of the issue. The company assured the DPA it had both dealt with the problem and communicated the resolution to the complainant. The complainant nonetheless kept receiving invoices. The DPA communicated this to the company, which then provided evidence the complainant's email address had been deleted from its systems. It claimed the problem was caused by the customer (that the invoices were actually intended for) entering the complainant's email address instead of their own. The Spanish DPA held that Vodafone Spain unlawfully processed the complainant's personal data, as the company had no lawful basis to send them invoices belonging to one of its customers. It found this to constitute a severe and negligent violation (Article 83(2)(a) and (b) GDPR) of Articles 5(1)(f) and 32 GDPR, as the complainant's data was neither processed with integrity and confidentiality nor appropriately safeguarded. It originally imposed a fine of €30,000 for the violation of Article 5(1)(f) GDPR and €20,000 for the violation of Article 32 GDPR, but this was reduced to a total fine amounting to €40,000 because Vodafone Spain made use of a reduction procedure proposed by the DPA.

Details

Fine Date

13 October 2021

Authority

Agencia Española de Protección de Datos

Fine Amount

€40,000

GDPRhub ID

gdprhub-4254

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Vodafone Spain - Spain (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: