DIGI SPAIN TELECOM, S.L. – €200,000 Fine (Spain, 2025)

€200,000Agencia Española de Protección de Datos30 May 2025Spain
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

DIGI SPAIN TELECOM, S.L. (the controller) is a telecommunications company. On 6 April 2021, a third person requested to duplicate the data subject’s SIM card at a store that sold the controller's products. The data subject lost phone service. Two hours later, the data subject obtained a new SIM card duplicate at a different store, which gave them access to the service again. According to the data subject, the controller did not take any measures to verify the identity of the person requesting the SIM card duplicate. Furthermore, the third person committed identity theft, because the data subject noticed an unauthorised bank transfer from their account (this was not addressed in the case). The data subject presented a complaint to the DPA on 12 July 2023. The DPA imposed a €200,000 fine on the controller for duplicating SIM cards for unauthorised third parties on 8 November 2024. The controller then filed an internal appeal to the DPA on 11 December 2024. The controller argued that its procedure for situations such as these that was carefully followed, and allowed it to process data lawfully in accordance to its obligations. The controller also contested the unauthorised bank transfer as a result of the SIM duplicate. In addition, it argued that it could not be held completely responsible for identifying and mitigating fraud. The controller requested a lower fine based on mitigating circumstances, stating that the DPA had set a disproportionately high fine. Among others, it argued that it had effectively solved the situation and that it did not process special categories of personal data. According to the DPA, the controller duplicated the data subject’s SIM card without a valid legal basis under Article 6(1) GDPR, despite the protocols set in place by the controller. The protocol to verify an individual’s identity was based solely on matching specific data with its database, and did not ensure that the data subject was involved or aware. The DPA stated that the

GDPR Articles Cited

AI-verified

Art. 6(1) GDPR
Art. 6(1)(a) GDPR
Art. 82(2) GDPR
View original scraped data
Art. 6(1) GDPR
Art. 6(1)(a) GDPR
Art. 6(1)(b) GDPR
Art. 82(2) GDPR

Original data from scraper before AI verification against source document.

Source verified 6 March 2026
verified correct
Full Legal Summary

DIGI SPAIN TELECOM, S.L. (the controller) is a telecommunications company. On 6 April 2021, a third person requested to duplicate the data subject’s SIM card at a store that sold the controller's products. The data subject lost phone service. Two hours later, the data subject obtained a new SIM card duplicate at a different store, which gave them access to the service again. According to the data subject, the controller did not take any measures to verify the identity of the person requesting the SIM card duplicate. Furthermore, the third person committed identity theft, because the data subject noticed an unauthorised bank transfer from their account (this was not addressed in the case). The data subject presented a complaint to the DPA on 12 July 2023. The DPA imposed a €200,000 fine on the controller for duplicating SIM cards for unauthorised third parties on 8 November 2024. The controller then filed an internal appeal to the DPA on 11 December 2024. The controller argued that its procedure for situations such as these that was carefully followed, and allowed it to process data lawfully in accordance to its obligations. The controller also contested the unauthorised bank transfer as a result of the SIM duplicate. In addition, it argued that it could not be held completely responsible for identifying and mitigating fraud. The controller requested a lower fine based on mitigating circumstances, stating that the DPA had set a disproportionately high fine. Among others, it argued that it had effectively solved the situation and that it did not process special categories of personal data. According to the DPA, the controller duplicated the data subject’s SIM card without a valid legal basis under Article 6(1) GDPR, despite the protocols set in place by the controller. The protocol to verify an individual’s identity was based solely on matching specific data with its database, and did not ensure that the data subject was involved or aware. The DPA stated that the

Details

Fine Date

30 May 2025

Authority

Agencia Española de Protección de Datos

Fine Amount

€200,000

Enforcement Tracker ID

ETid-2098

GDPRhub ID

gdprhub-9315

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. DIGI SPAIN TELECOM, S.L. - Spain (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: