AEPD (Spain) - ps-00148-2025
Spain's AEPD fines XFERA MÓVILES €200,000 for GDPR violation over SIM card issuance.
Summary
Spain's AEPD has fined telecom provider XFERA MÓVILES €200,000 for violating Article 6(1) of the GDPR. The company issued a duplicate SIM card to an unauthorized third party who presented a forged identity document, failing to adequately verify the individual's identity. The DPA ruled that the contractual relationship did not legitimize processing based on a fraudulent request.
Full text
Help AEPD (Spain) - ps-00148-2025: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 13:30, 13 August 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators254 edits Tag: Decisions [1.0] Latest revision as of 13:32, 13 August 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators254 editsTag: Visual edit (2 intermediate revisions by the same user not shown)Line 13: Line 13: |Original_Source_Name_1=AEPD|Original_Source_Name_1=AEPD |Original_Source_Link_1=https://www.aepd.es/documento/ps-00148-2025.pdf|Original_Source_Link_1=https://www.aepd.es/documento/ps-00148-2025.pdf |Original_Source_Language_1=|Original_Source_Language_1=Spanish |Original_Source_Language__Code_1=|Original_Source_Language__Code_1=ES Latest revision as of 13:32, 13 August 2026 AEPD - ps-00148-2025 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 6(1) GDPR Type: Complaint Outcome: Upheld Started: 05.09.2023 Decided: Published: 10.08.2026 Fine: 200000.0 EUR Parties: XFERA MÓVILES, S.A.U. National Case Number/Name: ps-00148-2025 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Spanish Original Source: AEPD (in ES) Initial Contributor: bms The DPA fined a telecom provider €200,000 for violating Article 6(1) GDPR after issuing a duplicate SIM card to an unauthorised third party without adequately verifying their identity. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts XFERA MÓVILES, S.A.U. (XFERA), the controller, is a telecommunications provider. The data subject was a customer of the controller and held a mobile telephone line. On 24 July 2023, an unauthorised third party requested a duplicate SIM card for the data subject's mobile line through one of the controller's distributors. The third party presented a copy of an identity document purportedly belonging to the data subject. An agent of the controller identified the third party as the account holder following an in-person visual verification of the identity document. The document was subsequently scanned and a duplicate SIM card was issued. However, a comparison between the identity document presented by the third party and the data subject's actual information showed several discrepancies. Although the identification number, name, surnames and nationality matched, other information, including the place and date of birth, address and parents' names, did not. The controller acknowledged that its agent had not verified all the information contained in the identity document and had therefore departed from the controller's internal procedure. However, it argued that this was an isolated human error, that it had appropriate procedures in place and that the processing was lawful under Article 6(1)(b) GDPR because of its contractual relationship with the data subject. Holding The DPA held that the controller violated Article 6(1) GDPR. The DPA considered that issuing a duplicate SIM card constituted processing of personal data, since both the information used to issue the card and the SIM card itself were linked to an identifiable subscriber. It held that the controller had processed the data subject's personal data without a valid legal basis because it failed to adequately verify the identity of the person requesting the duplicate SIM card. The contractual relationship with the data subject could not legitimise processing carried out on the basis of a request made by an unauthorised third party. In particular, the DPA noted that the controller had failed to carry out checks required by its own procedures. Consequently, the duplicate SIM card was issued to a third party who was neither the account holder nor demonstrated that they were authorised to act on the account holder's behalf. The DPA rejected the controller's argument that the infringement resulted exclusively from third-party fraud. It considered that the fraudulent conduct of a third party did not exempt the controller from exercising sufficient diligence to verify the identity of persons requesting the processing of personal data. The mere existence of internal procedures was insufficient if those procedures were not effectively implemented. The DPA also rejected the argument that imposing a fine would amount to strict liability. It found that the controller's liability resulted from its lack of due diligence in ensuring that the processing had a lawful basis, rather than merely from the occurrence of the fraudulent SIM swap. When determining the fine, the DPA took into account, among other factors, the nature of the infringement, the controller's negligence, the categories of personal data concerned, a previous infringement involving an unauthorised SIM duplication and the close connection between the controller's business activities and the processing of personal data. Consequently, the DPA imposed a fine of €200,000 for the violation of Article 6(1) GDPR. Pursuant to Article 58(2)(d) GDPR, it also ordered the controller, within six months from the decision becoming final and enforceable, to provide evidence that it had adopted measures to prevent similar incidents and ensure compliance with the principle of lawfulness. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the original. Please refer to the original for more details. Retrieved from "https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_ps-00148-2025&oldid=52691" Categories: AEPD (Spain)SpainArticle 6(1) GDPR2026Spanish This page was last edited on 13 August 2026, at 13:32. Content is available under Creative Commons Attribution-NonCommercial-ShareAlike unless otherwise noted. Privacy policy About GDPRhub Disclaimers