Back to Feed
GDPRSep 22, 2026

AEPD (Spain) - PS-00240-2025

Spain's AEPD fines Vodafone €750K for inadequate security and missing processor agreement in Super WiFi breach.

Summary

Spain's Data Protection Authority (AEPD) fined Vodafone España €750,000 for violations of GDPR Articles 5(1)(f), 28, and 32 following an unauthorized data access incident affecting the Super WiFi service. The DPA found that Vodafone failed to implement adequate security measures, processed data without a valid processor agreement (the agreement was only signed in September 2024, months after the November 2023 breach), and could not demonstrate proper encryption or audit controls of the third-party processor.

Full text

Help AEPD (Spain) - PS-00240-2025: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 12:53, 22 September 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators326 editsTag: Visual edit← Older edit Latest revision as of 14:14, 22 September 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators326 editsTag: Visual edit Line 92: Line 92: }}}} The DPA fined Vodafone €750,000 for infringing Articles 5(1)(f), 28 and 32 GDPR after a data breach affecting the "Super WiFi" service, finding inadequate security and that processing began without a valid processor agreement.The DPA fined Vodafone €750,000 for infringing [[Article 5 GDPR|Articles 5(1)(f)]], [[Article 28 GDPR|28]] and [[Article 32 GDPR|32 GDPR]] after a data breach affecting the "Super WiFi" service, finding inadequate security and that processing began without a valid processor agreement. == English Summary ==== English Summary == Latest revision as of 14:14, 22 September 2026 AEPD - ps-00240-2025 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 5(1)(f) GDPR Article 28 GDPR Article 32 GDPR Type: Investigation Outcome: Violation Found Started: 23.11.2023 Decided: Published: 18.09.2026 Fine: 750000.0 EUR Parties: Vodafone España, S.A.U. National Case Number/Name: ps-00240-2025 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Spanish Original Source: AEPD (in ES) Initial Contributor: ricardo The DPA fined Vodafone €750,000 for infringing Articles 5(1)(f), 28 and 32 GDPR after a data breach affecting the "Super WiFi" service, finding inadequate security and that processing began without a valid processor agreement. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts Vodafone España, S.A.U., the controller, operated a service known as "Super WiFi" through a third-party processor. Following a data breach affecting the service, the DPA's investigation found that personal data processed on behalf of the controller had been accessed without authorisation. The processor provided software services related to the Super WiFi service and processed and stored personal data of the controller's customers. The processor informed the controller of the security incident on 20 November 2023, and the controller notified the DPA of the personal data breach on 23 November 2023. The controller submitted a processing agreement which stated that it had entered into force in December 2022. However, the agreement was only formally signed in September 2024, after the data breach had occurred. The controller argued that the agreement had already been binding before its signature and that the absence of a signature did not mean that no contract existed. The controller also relied on two documents dated 22 December 2022 and 30 March 2023 to demonstrate that it had carried out audit and control activities concerning the processor. Neither document was signed and the DPA considered that they did not sufficiently demonstrate how the processor's security measures had actually been verified. The controller also claimed that encryption measures had been imposed on the processor. However, the only reference to this measure in the file appeared in the controller's initial written reply to the DPA inspector, unsupported by documentation, and the information available to the DPA indicated that the affected data were accessible in unencrypted form. The documents relied on by the controller referred to pseudonymisation but did not establish that encryption had been implemented. The controller raised several objections during the procedure. It argued in particular that a valid processing agreement already existed when the processing took place, that it had implemented adequate security and oversight measures, and that the previous sanctions should not be taken into account as an aggravating factor. Holding The DPA rejected the controller's arguments. First, regarding Article 28 GDPR, the DPA held that a processor must be bound by a written contract or other legal act from the moment it begins processing personal data on behalf of the controller. Although the agreement submitted by the controller referred to an effective date in December 2022, it was not formally signed until September 2024. The DPA considered that giving the agreement retroactive effect could not remedy the period during which processing had already taken place without a formally perfected agreement. Therefore, the controller infringed Article 28 GDPR. The DPA stressed that allowing agreements concluded after processing had begun to operate retroactively would undermine the purpose of Article 28 GDPR. The processor must be formally subject to the controller's instructions and to the safeguards required by the GDPR throughout the processing relationship, rather than having those safeguards formalised ex post. Second, the DPA found an infringement of Article 32 GDPR. It considered that the technical and organisational measures implemented in relation to the processor were insufficient. In particular, the controller had not adequately demonstrated that relevant security measures were actually implemented and had relied substantially on information supplied by the processor without sufficiently verifying its effectiveness. The audit documents submitted by the controller did not explain the methodology used or demonstrate effective verification of the measures in practice. The DPA also rejected the controller's reliance on encryption. The available documentation did not demonstrate that the affected personal data were encrypted, and documents concerning cryptography referred to pseudonymisation rather than encryption. Third, the DPA held that the insufficient security measures resulted in a loss of confidentiality of personal data and therefore also constituted an infringement of Article 5(1)(f) GDPR. The DPA also considered two previous decisions against the controller, PS/00538/2021 and PS/00164/2022, as aggravating factors under Article 83(2)(e) GDPR. Both concerned infringements of Articles 5(1)(f) and 32 GDPR, and the controller had acknowledged its responsibility in both proceedings. When determining the fines, the DPA took into account, among other factors, the nature and gravity of the infringements and the controller's degree of responsibility. It also considered the controller's habitual processing of large volumes of personal data as an aggravating factor under Article 76(2)(b) LOPDGDD. The DPA imposed three administrative fines: €500,000 for the infringement of Article 5(1)(f) GDPR, €150,000 for the infringement of Article 32 GDPR and €100,000 for the infringement of Article 28 GDPR. The total fine therefore amounted to €750,000. No additional corrective measure was imposed. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details. Case No.: EXP202400702 DECISION ON SANCTIONING PROCEEDINGS Regarding the proceedings conducted by the Spanish Data Protection Agency and based on the following, BACKGROUND FIRST: Notification of a Personal Data Breach On November 23, 2023, this Agency was notified of a personal data breach involving VODAFONE ESPAÑA, S.A.U., Tax ID No. A80907397 (hereinafter, VODAFONE). The facts brought to the attention of this authority are as follows: On November 20, 2023, a VODAFONE supplier (***ENTERPRISE.1, hereinafter ***ENTERPRISE.1) informed that entity of a security incident that affected a file containing VODAFONE customer data. The affected customers are users of ***APP.1. According to the information provided by the supplier, the attacker (…).

Entities

Vodafone (vendor)Super WiFi (product)