VODAFONE ESPAÑA, S.A.U. – €56,000 Fine (Spain, 2023)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Vodafone España was fined €56,000 for mistakenly sharing another customer's contract and personal data with a person who requested their own contract. This incident highlights the importance of protecting customer information and ensuring confidentiality.
What happened
Vodafone España shared a commercial contract and personal data of another customer with a person who requested their own contract.
Who was affected
The individual who requested their contract and the other customer whose information was shared were both affected.
What the authority found
The Spanish data protection authority ruled that Vodafone violated data protection rules by failing to keep customer information confidential and secure.
Why this matters
This ruling underscores the need for companies to implement strong security measures to protect customer data. It sets a precedent for holding companies accountable for breaches of confidentiality.
GDPR Articles Cited
On 21 August 2021 the data subject filed a complaint against Vodafone España, S.A.U., the controller, for violating their right of access. The data subject requested VODAFONE to provide a copy of their commercial telephone contract, since the company was, allegedly, not applying the contracted tariff. After several unsuccessful attempts to receive their contract, the controller sent an email containing contract of another customer as well as an audio recording of that customer's data. The DPA ('AEPD') highlighted the breach of confidentially and security by VODAFONE for sharing a commercial contract of another individual with the data subject, violating Article 5(1)(f) GDPR. According to the evidence presented, the data subject acquired access to name, ID number and telephone number of an unknown person without any authorization to disclose their data to third parties. The AEPD, therefore, found a violation of Article 32 GDPR for not implementing the appropriate technical and organization measures to prevent such incident. The AEPD fined VODAFONE €50,000 for violating Article 5(1)(f) GDPR and €20,000 for violating Article 32 GDPR. However, in this case, the AEPD gave two possibilities to VODAFONE to either acknowledge the liability, leading to a greater reduction in the final amount, totaling €42,000 or to pay a fine of €56,000 and renounce any form of appeal against the sanction. VODAFONE opted for a voluntary payment option, paying a fine of €56,000. This payment utilized the reduction offered in the initial agreement for early payment, indicating a renunciation of any form of administrative appeal against the sanction.
Related Enforcement Actions (2)
Other enforcement actions involving VODAFONE ESPAÑA, S.A.U. in ES
Fine
€56K
Details
Fine Date
13 September 2023
Authority
Agencia Española de Protección de Datos
Fine Amount
€56,000
Enforcement Tracker ID
ETid-853
GDPRhub ID
gdprhub-7631About this data
Cite as: Cookie Fines. VODAFONE ESPAÑA, S.A.U. - Spain (2023). Retrieved from cookiefines.eu
Last updated: