[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2lyEYEuT3l8ZbRCTWEh1uz8ffnLnqPwKI8fkIockBj4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"4f408124-9bf7-425f-96ab-68fba60b7283","vodafone-espaa-fined-750k-for-allowing-processor-to-operate-without-valid-data-processing-agreement","51d12726-2a12-4ece-bbf8-d111a1d0f336","Vodafone España Fined €750K for Allowing Processor to Operate Without Valid Data Processing Agreement","Vodafone España permitted a third-party data processor to begin handling personal data under its 'Super WiFi' service before a legally compliant Data Processing Agreement (DPA) was established, violating GDPR Articles 5(1)(f), 28, and 32. This failure represents a fundamental breakdown in vendor onboarding governance, where contractual and compliance controls were not verified before data flows commenced. The absence of a valid DPA means there were no enforceable obligations on the processor regarding data security, confidentiality, or breach notification. This case underscores that controllers remain fully accountable for processor activities, making pre-engagement due diligence a non-negotiable requirement. Repeat infringements, as seen here with prior Vodafone sanctions, attract aggravated penalties and signal systemic cultural or process failures to regulators.","**Immediate actions:**\n- Audit all active third-party processors to confirm valid, GDPR-compliant Data Processing Agreements are in place before any data sharing continues.\n- Immediately suspend data flows to any processor where a compliant DPA cannot be confirmed.\n\n**Vendor onboarding controls:**\n- Implement a mandatory 'DPA gate' in the vendor onboarding workflow that prevents data transfer initiation until legal and compliance teams sign off on a valid agreement.\n- Maintain a centralised processor register that tracks DPA status, review dates, and security assessment outcomes for every third-party data handler.\n- Conduct pre-engagement data protection impact assessments (DPIAs) for processors handling sensitive or large-scale personal data.\n\n**Long-term improvements:**\n- Establish a recurring annual review cycle for all processor agreements to ensure ongoing GDPR compliance and alignment with current processing activities.\n- Embed data protection training into procurement and commercial teams so contractual GDPR requirements are understood at the point of supplier selection.\n- Implement automated alerting in contract management systems to flag expiring or missing DPAs before they lapse.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5(1)(f) – Integrity and confidentiality principle","GDPR Article 28 – Processor obligations and Data Processing Agreements","GDPR Article 32 – Security of processing","GDPR Article 83(4) – Administrative fines for Article 28 infringements","NIST SP 800-53 SA-9 – External System Services","NIST SP 800-53 CA-3 – System Interconnections","CIS Control 15 – Service Provider Management","ISO\u002FIEC 27001:2022 Annex A 5.19 – Information security in supplier relationships","ISO\u002FIEC 27001:2022 Annex A 5.20 – Addressing information security within supplier agreements","ITIL 4 – Supplier Management Practice","published","2026-09-22T12:22:41.777482+00:00","2026-09-22T12:22:41.69+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_PS-00240-2025&diff=53139&oldid=0","aepd-spain-ps-00240-2025-534b61","AEPD (Spain) - PS-00240-2025",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]