Back to Feed
PolicySep 22, 2026

AEPD (Spain) - PS-00240-2025

Spain's AEPD fines Vodafone €750,000 for GDPR violations after a data breach.

Summary

Spain's Data Protection Agency (AEPD) has fined Vodafone España €750,000 for violating GDPR. The fine stems from a data breach affecting the 'Super WiFi' service, where Vodafone allowed a processor to begin operations before a valid data processing agreement was in place. The AEPD cited infringements of Articles 5(1)(f), 28, and 32 GDPR, considering previous sanctions against Vodafone as an aggravating factor.

Full text

Help AEPD (Spain) - PS-00240-2025: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 10:24, 22 September 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators315 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 10:24, 22 September 2026 AEPD - PS-00240-2025 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 5(1)(f) GDPR Article 24 GDPR Article 32 GDPR Type: Investigation Outcome: Violation Found Started: 23.11.2023 Decided: Published: Fine: 750000.0 EUR Parties: Vodafone España, S.A.U. National Case Number/Name: PS-00240-2025 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Spanish Original Source: AEPD (in ES) Initial Contributor: ricardo The DPA fined Vodafone €750,000 for infringing Articles 5(1)(f), 28 and 32 GDPR after a data breach affecting the "Super WiFi" service, finding that the controller had allowed a processor to begin operations before a data processing agreement was validly perfected. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts Vodafone, the controller, operated a service known as "Super WiFi" through a third-party processor. Following a data breach affecting the service, the DPA's investigation found that Vodafone had entered into a de facto processing relationship with this processor before the data processing conditions required by Article 28 GDPR had been formalised. The file contained two versions of a data processing agreement, neither of which was signed. The later version was dated 30 March 2023 — after processing operations had already begun. Vodafone claimed that encryption measures had been imposed on the processor. However, the only reference to this measure in the file appeared in Vodafone's initial written reply to the DPA inspector, unsupported by documentation, and appeared to rely solely on the processor's own unverified statements. The processor's system was found to lack adequate security controls. The DPA relied on two prior sanctioning decisions against Vodafone as an aggravating factor for recidivism under Article 83(2) GDPR: • PS/00538/2021, concerning disclosure of a customer's phone number to a third party and inadequate security in number-assignment procedures (Articles 5(1)(f) and 32 GDPR). • PS/00164/2022, concerning disclosure of information to a third party enabling unauthorised access to a data subject's personal data (same two articles). Vodafone had acknowledged liability in both prior proceedings. Vodafone raised several objections during the procedure. It argued: (i) the number of affected data subjects should not be held against it, since a valid contract existed with the processor; (ii) its routine use of outsourcing should not itself aggravate the negligence finding; and (iii) the two prior sanctions should not count towards a recidivism aggravator. Holding The DPA rejected Vodafone's arguments and held that: • The processing agreement with the processor was not validly perfected (i.e. signed) before processing began, so Vodafone could not rely on it to rebut the finding of an Article 28 GDPR infringement. • The negligence was aggravated not by outsourcing as such, but by Vodafone having allowed a processing relationship to proceed without first formalising the Article 28 safeguards. • The two earlier decisions (PS/00538/2021 and PS/00164/2022), both acknowledged by Vodafone, were properly considered for the recidivism aggravator under Article 83(2) GDPR. The DPA found infringements of Article 5(1)(f) GDPR (integrity and confidentiality), Article 32 GDPR (security of processing) and Article 28 GDPR (processor obligations), and imposed a fine of €750,000 to the controller Compared to its usual Article 28 case law — which typically turns on a missing or substantively deficient DPA — the AEPD here located the infringement in the timing of perfection: a signed agreement existed but post-dated the start of processing, so liability attached from the moment processing factually began. The decision also declined to treat a processor's own unverified, undocumented assertion of a security measure (encryption) as sufficient evidence of Article 32 compliance, placing the burden of independent verification on the controller. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details. Case No.: EXP202400702 DECISION ON SANCTIONING PROCEEDINGS Regarding the proceedings conducted by the Spanish Data Protection Agency and based on the following, BACKGROUND FIRST: Notification of a Personal Data Breach On November 23, 2023, this Agency was notified of a personal data breach involving VODAFONE ESPAÑA, S.A.U., Tax ID No. A80907397 (hereinafter, VODAFONE). The facts brought to the attention of this authority are as follows: On November 20, 2023, a VODAFONE supplier (***ENTERPRISE.1, hereinafter ***ENTERPRISE.1) informed that entity of a security incident that affected a file containing VODAFONE customer data. The affected customers are users of ***APP.1. According to the information provided by the supplier, the attacker (…). The affected data pertains to customers who have downloaded ***APP.1; this information contains (...). (…) SECOND: Initiation of ex officio proceedings As a result of the known facts, on December 14, 2023, the Director of the Spanish Data Protection Agency urged the Subdirectorate General of Data Inspection (SGID) to initiate the preliminary investigative proceedings referred to in Article 67 of Organic Law 3/2018, of December 5, on Data Protection and the Guarantee of Digital Rights (hereinafter, LOPDGDD). THIRD: Preliminary Investigative Procedures The Subdirectorate General for Data Inspection proceeded to conduct preliminary investigative procedures to clarify the facts in question, pursuant to the functions assigned to supervisory authorities under Article 57.1 and the powers granted in Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VIII of the LOPDGDD. On November 20, 2023, a VODAFONE supplier reported a security incident that affected a file containing VODAFONE customer data. The customers affected are (…).  Number of affected individuals according to the notification: (…)  Type of data according to the notification: (…) C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 2/49  The data controller states that the incident was communicated to those affected on December 28, 2023. 1. Analysis of the data breach. 1.1. Chronology of events. The incident originated from a cyberattack suffered by the processor, which affected the personal data of the controller’s customers. According to the controller, on 11/20/2023, its vendor ***ENTERPRISE.1, acting in the role of processor, informed it of a security incident that affected a file containing VODAFONE customer data. The data controller states: “***ENTERPRISE.1 is a VODAFONE provider of software services related to the Super Wifi 5 product, which is offered by VODAFONE Spain. To provide these services, ***ENTERPRISE.1 has developed an application through which it processes and stores data from VODAFONE users who use the application.” The affected customers (…). (…) According to the information provided, ***ENTERPRISE.1 became aware of the unauthorized access on 11/13/2023 as a result of a post on social media containing messages alluding to the incident. (…) 1.3. Impact of the breach. Possible consequences for those affected. The data controller indicates the following number of affected individuals and the type of data compromised:  Total number of affected customers: (

Entities

Vodafone (vendor)Super WiFi (product)