Back to Feed
PolicySep 22, 2026

AEPD (Spain) - PS-00240-2025

Spain's AEPD fines Vodafone €750,000 for GDPR violations after a data breach.

Summary

Spain's data protection authority (AEPD) has fined Vodafone €750,000 for multiple GDPR violations following a data breach affecting its 'Super WiFi' service. The violations include inadequate security measures and allowing a processor to begin operations before a valid data processing agreement was in place. The AEPD cited previous sanctions against Vodafone as an aggravating factor.

Full text

Help AEPD (Spain) - PS-00240-2025: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 10:24, 22 September 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators322 edits Tag: Decisions [1.0] Latest revision as of 12:53, 22 September 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators322 editsTag: Visual edit (6 intermediate revisions by the same user not shown)Line 7: Line 7: |DPA_With_Country=AEPD (Spain)|DPA_With_Country=AEPD (Spain) |Case_Number_Name=PS-00240-2025|Case_Number_Name=ps-00240-2025 |ECLI=|ECLI= Line 26: Line 26: |Date_Started=23.11.2023|Date_Started=23.11.2023 |Date_Decided=|Date_Decided= |Date_Published=|Date_Published=18.09.2026 |Year=2023|Year=2023 |Fine=750000.0|Fine=750000.0 Line 36: Line 36: |GDPR_Article_2=Article 24 GDPR|GDPR_Article_2=Article 28 GDPR |GDPR_Article_Link_2=Article 24 GDPR|GDPR_Article_Link_2=Article 28 GDPR Line 92: Line 92: }}}} The DPA fined Vodafone €750,000 for infringing Articles 5(1)(f), 28 and 32 GDPR after a data breach affecting the "Super WiFi" service, finding that the controller had allowed a processor to begin operations before a data processing agreement was validly perfected.The DPA fined Vodafone €750,000 for infringing Articles 5(1)(f), 28 and 32 GDPR after a data breach affecting the "Super WiFi" service, finding inadequate security and that processing began without a valid processor agreement. == English Summary ==== English Summary == === Facts ====== Facts === Vodafone, the controller, operated a service known as "Super WiFi" through a third-party processor. Following a data breach affecting the service, the DPA's investigation found that Vodafone had entered into a de facto processing relationship with this processor before the data processing conditions required by [[Article 28 GDPR|Article 28 GDPR]] had been formalised.Vodafone España, S.A.U., the controller, operated a service known as "Super WiFi" through a third-party processor. Following a data breach affecting the service, the DPA's investigation found that personal data processed on behalf of the controller had been accessed without authorisation. The file contained two versions of a data processing agreement, neither of which was signed. The later version was dated 30 March 2023 — after processing operations had already begun.The processor provided software services related to the Super WiFi service and processed and stored personal data of the controller's customers. The processor informed the controller of the security incident on 20 November 2023, and the controller notified the DPA of the personal data breach on 23 November 2023. Vodafone claimed that encryption measures had been imposed on the processor. However, the only reference to this measure in the file appeared in Vodafone's initial written reply to the DPA inspector, unsupported by documentation, and appeared to rely solely on the processor's own unverified statements. The processor's system was found to lack adequate security controls.The controller submitted a processing agreement which stated that it had entered into force in December 2022. However, the agreement was only formally signed in September 2024, after the data breach had occurred. The controller argued that the agreement had already been binding before its signature and that the absence of a signature did not mean that no contract existed. The DPA relied on two prior sanctioning decisions against Vodafone as an aggravating factor for recidivism under [[Article 83 GDPR|Article 83(2) GDPR]]:The controller also relied on two documents dated 22 December 2022 and 30 March 2023 to demonstrate that it had carried out audit and control activities concerning the processor. Neither document was signed and the DPA considered that they did not sufficiently demonstrate how the processor's security measures had actually been verified. • PS/00538/2021, concerning disclosure of a customer's phone number to a third party and inadequate security in number-assignment procedures (Articles 5(1)(f) and 32 GDPR). • PS/00164/2022, concerning disclosure of information to a third party enabling unauthorised access to a data subject's personal data (same two articles).The controller also claimed that encryption measures had been imposed on the processor. However, the only reference to this measure in the file appeared in the controller's initial written reply to the DPA inspector, unsupported by documentation, and the information available to the DPA indicated that the affected data were accessible in unencrypted form. The documents relied on by the controller referred to pseudonymisation but did not establish that encryption had been implemented. Vodafone had acknowledged liability in both prior proceedings.The controller raised several objections during the procedure. It argued in particular that a valid processing agreement already existed when the processing took place, that it had implemented adequate security and oversight measures, and that the previous sanctions should not be taken into account as an aggravating factor. Vodafone raised several objections during the procedure. It argued: (i) the number of affected data subjects should not be held against it, since a valid contract existed with the processor; (ii) its routine use of outsourcing should not itself aggravate the negligence finding; and (iii) the two prior sanctions should not count towards a recidivism aggravator.=== Holding === The DPA rejected the controller's arguments. First, regarding [[Article 28 GDPR]], the DPA held that a processor must be bound by a written contract or other legal act from the moment it begins processing personal data on behalf of the controller. Although the agreement submitted by the controller referred to an effective date in December 2022, it was not formally signed until September 2024. The DPA considered that giving the agreement retroactive effect could not remedy the period during which processing had already taken place without a formally perfected agreement. Therefore, the controller infringed [[Article 28 GDPR]]. === Holding ===The DPA stressed that allowing agreements concluded after processing had begun to operate retroactively would undermine the purpose of [[Article 28 GDPR]]. The processor must be formally subject to the controller's instructions and to the safeguards required by the GDPR throughout the processing relationship, rather than having those safeguards formalised ex post. The DPA rejected Vodafone's arguments and held that: • The processing agreement with the processor was not validly perfected (i.e. signed) before processing began, so Vodafone could not rely on it to rebut the finding of an [[Article 28 GDPR|Article 28 GDPR]] infringement.Second, the DPA found an infringement of [[Article 32 GDPR]]. It considered that the technical and organisational measures implemented in relation to the processor were insufficient. In particular, the controller had not adequately demonstrated that relevant security measures were actually implemented and had relied substantially on information supplied by the processor without sufficiently verifying its effectiveness. The audit documents submitted by the controller did not explain the methodology used or demonstrate effective verification of the measures in practice. • The negligence was aggravated not by outsourcing as such, but by Vodafone having allowed a processing relationship to proceed without first formalising the Article 28 safeguards.The DPA also rejected the controller's reliance on encryption. The available documentation did not demonstrate that the affected personal data were encrypted, and documents concerning cryptography referred to pseudonymisation rather than encryption. • The two earlier decisions (PS/00538/2021 and PS/00164/2022), both acknowledged by Vodafone, were properly considered

Entities

Vodafone (vendor)