[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxjEzW7IYlnBu3zpEQ8OhTyhXpbdJzkFxofMumfQX1Ag":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":46},"bcbb88bd-3a02-4c92-9bc8-00244538068a","telecom-fined-200k-after-issuing-duplicate-sim-to-unauthorized-third-party","4c0ff1bc-e4c5-4618-80e2-3ac63286a4aa","Telecom Fined €200K After Issuing Duplicate SIM to Unauthorized Third Party","XFERA MÓVILES failed to adequately verify the identity of an individual requesting a duplicate SIM card, despite visible discrepancies in the identification documents provided. This failure to follow its own internal verification procedures resulted in an unauthorized third party gaining access to a customer's phone number — a classic SIM-swapping enabler. Under GDPR Article 6(1), processing personal data without a valid legal basis is a serious violation, and the company's contractual relationship with the legitimate customer could not legitimize actions taken on behalf of an impersonator. This case highlights that identity verification failures are not just operational oversights — they carry significant legal and financial consequences under EU data protection law.","**Immediate Actions:**\n- Suspend SIM swap and duplicate SIM requests pending a mandatory multi-factor identity verification review.\n- Implement mandatory escalation procedures whenever discrepancies are detected in identity documents during any customer request.\n\n**Process & Policy Improvements:**\n- Enforce strict, documented identity verification checklists for all SIM-related operations, requiring supervisor sign-off when anomalies are found.\n- Conduct regular audits of SIM swap requests to detect patterns of non-compliance with internal verification procedures.\n- Establish a clear legal basis assessment step within customer-facing workflows to ensure GDPR Article 6(1) compliance before processing any sensitive request.\n\n**Detection & Monitoring:**\n- Deploy real-time alerting for unusual SIM swap activity, flagging requests that deviate from the customer's established profile or location.\n- Log all identity verification steps with timestamps and operator IDs to create an auditable trail for regulatory review.",[12,13,14,15,16,17,18,19],"GDPR Article 6(1) — Lawfulness of Processing","GDPR Article 5(1)(f) — Integrity and Confidentiality","NIST SP 800-63-3 — Digital Identity Guidelines (Identity Proofing)","CIS Control 6 — Access Control Management","CIS Control 14 — Security Awareness and Skills Training","NIST AC-2 — Account Management","NIST IA-3 — Device Identification and Authentication","ISO\u002FIEC 27001 Annex A.9 — Access Control","published","2026-08-13T14:21:12.865026+00:00","2026-08-13T14:21:12.783+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_ps-00148-2025&diff=52688&oldid=0","aepd-spain-ps-00148-2025-a6a648","AEPD (Spain) - ps-00148-2025",[28,34,40],{"id":29,"name":30,"slug":31,"description":32,"color":33},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":41,"name":42,"slug":43,"description":44,"color":45},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]