[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ffpxsniiYdwhPImuFBRxBWmp6TOICARG2N59u7w8Qzuo":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"0c47f9b6-f716-41a9-9d6e-1ce842a13160","1m-gdpr-fine-for-weak-call-center-identity-verification","10c9949b-8bcd-4d18-bf44-b21198927795","€1M GDPR Fine for Weak Call Center Identity Verification","Spain's AEPD imposed a €1,000,000 fine on an energy company after finding that its call center relied solely on static, easily obtainable customer data (such as name, address, or account number) to verify caller identity — with no multi-factor authentication in place. This approach violates GDPR Article 32, which requires organisations to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Critically, the absence of audit trails meant the company could not demonstrate compliance, compounding the regulatory breach. This case highlights that identity verification over voice channels is a significant attack vector and must be treated with the same rigour as digital authentication systems.","**Immediate actions:**\n- Replace static-data-only verification with multi-factor authentication for call center identity checks (e.g., one-time passcodes sent to registered devices).\n- Implement and activate audit logging for all customer identity verification events in call center platforms.\n\n**Long-term improvements:**\n- Develop and enforce a formal Identity Verification Policy that defines minimum assurance levels aligned with GDPR Article 32 requirements.\n- Conduct regular third-party audits of call center authentication procedures to proactively identify compliance gaps.\n- Integrate knowledge-based authentication with dynamic, non-public data points or biometric voice verification where feasible.\n\n**Detection & compliance measures:**\n- Establish a continuous monitoring programme to review verification logs for anomalies such as repeated failed attempts or unusual access patterns.\n- Map all customer authentication processes to GDPR obligations and maintain documented evidence of compliance for regulatory accountability.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 32 – Security of processing","GDPR Article 5(1)(f) – Integrity and confidentiality principle","NIST SP 800-63B – Digital Identity Guidelines (Authenticator Assurance Levels)","NIST AC-17 – Remote Access","NIST IA-2 – Identification and Authentication","NIST AU-2 – Audit Events","CIS Control 6 – Access Control Management","CIS Control 8 – Audit Log Management","ISO\u002FIEC 27001:2022 – A.8.5 Secure authentication","ITIL Service Management – Information Security Management (audit and compliance)","published","2026-09-16T08:22:39.881469+00:00","2026-09-16T08:22:39.767+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_EXP202406239&diff=53070&oldid=52120","aepd-spain-exp202406239-32448c","AEPD (Spain) - EXP202406239",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":37,"name":38,"slug":39,"description":40,"color":41},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",[]]